Logo

    Bug Bounty Reports Discussed

    From Bug Bounty Reports Discussed podcast you can learn from the best bug bounty hunters in the world. I ask them about their methodologies, tools they use, the advice they give to beginners and many more... Subscribe to never miss an episode!
    en13 Episodes

    People also ask

    What is the main theme of the podcast?
    Who are some of the popular guests the podcast?
    Were there any controversial topics discussed in the podcast?
    Were any current trending topics addressed in the podcast?
    What popular books were mentioned in the podcast?

    Episodes (13)

    AI and hacking - opportunities and threats - Joseph “rez0” Thacker

    AI and hacking - opportunities and threats - Joseph “rez0” Thacker
    📧 Subscribe to BBRE Premium: https://bbre.dev/premium
    📖 Check out AppSecEngineer, the sponsor of today's video: https://www.appsecengineer.com
    📣 Follow GUEST on Twitter: https://twitter.com/@rez0
    ✉️ Sign up for the mailing list: https://bbre.dev/nl
    📣 Follow me on Twitter: https://bbre.dev/tw
    In this interview we are discussing with rez0 a range of topics around AI - the new vulnerability opportunities it created, how can I help us in hacking and if it will replace us in the future.
    Resources and people mentioned in the podcast:
    https://olickel.com/everything-i-know-about-prompting-llms
    https://www.anthropic.com/index/prompting-long-context
    https://simonwillison.net
    https://llm-attacks.org/zou2023universal.pdf
    http://llm-attacks.org
    BBRD podcast is also available on most popular podcast platforms:
    https://open.spotify.com/show/6tLoJ5foOoZPPELwrHPBO4
    https://podcasts.google.com/feed/aHR0cHM6Ly93d3cuc3ByZWFrZXIuY29tL3Nob3cvNTA3Mzc4MS9lcGlzb2Rlcy9mZWVk
    https://podcasts.apple.com/us/podcast/bug-bounty-reports-discussed/id1583400215?uo=4

    Timestamps:
    00:00 Intro
    00:32 Check out AppSecEngineer, the sponsor of this podcast
    01:36 rez0's regular bug bounty hacking style
    22:39 AI and hacking

    The key to succeed in bug bounty - NahamSec

    The key to succeed in bug bounty - NahamSec
    In this episode with @NahamSec we are talking about bug bounty. Ben has a unique insight into mistakes beginners make since he's the biggest content creator in the bug bounty space and gets asked a lot of questions. We are talking about his methodology, the role of recon and much more.

    Security source code review expert - Shubham Shah

    Security source code review expert - Shubham Shah
    In this podcast episode, I interview Shubham Shah - one of my biggest authorities in bug bounty space and expert in source code review who regularly finds 0days.

    📧 Subscribe to BBRE Premium: https://bbre.dev/premium
    ✉️ Sign up for the mailing list: https://bbre.dev/nl
    📣Follow me on Twitter: https://bbre.dev/tw
    📣 Follow Shubs on Twitter: http://twitter.com/infosec_au/


    Timestamps:
    00:00 Intro
    00:18 Shubs' background
    13:04 Choosing good targets for finding 0days
    20:41 How to audit the source code?
    33:34 Who should consider a career as a full-time bug bounty hunter?
    38:04 Sharing knowledge and disclosing 0days
    45:54 What skills does Shubs pay attention to when recruiting security researchers?
    48:48 AI in security research

    Bug bounty automation and scaling 0days - Michael Ness

    Bug bounty automation and scaling 0days - Michael Ness
    In this podcast, I interview Michael Ness about bug bounty automation and scaling 0 days to get multiple payouts for a single bug. We also talk about how to make the automation better and about some tips to upcoming bug hunters.

    📧 Subscribe to BBRE Premium: https://bbre.dev/premium
    ✉️ Sign up for the mailing list: https://bbre.dev/nl
    📣Follow me on Twitter: https://bbre.dev/tw
    📣 Follow Michael on Twitter: https://twitter.com/mikey96_bh
    Check out Overcast Security: https://search.overcast-security.app

    From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson

    From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson
    📧 Subscribe to BBRE Premium: https://bbre.dev/premium
    ✉️ Sign up for the mailing list: https://bbre.dev/nl
    📣 Follow me on Twitter: https://bbre.dev/tw
    📣 Follow Johan on Twitter: https://twitter.com/joaxcar
    In this podcast I interview one of bug bounty hunters who started very recently but already is having a lot of success - Johan Carlsson. We talk about his hacking methodology, his journey with GitLab and his tips for bug bounty hunters.

    🖥 Get $100 in credits for Digital Ocean: https://bbre.dev/do

    Accidentally finding a $50,000 vulnerability - Augusto Zanellato - Bug Bounty Reports Discussed #2

    Accidentally finding a $50,000 vulnerability - Augusto Zanellato - Bug Bounty Reports Discussed #2
    ✉️ Sign up for the newsletter: https://mailing.bugbountyexplained.com/

    This podcast is an interview with Augusto Zanellato, the hacker who submitted report with a GitHub rest API token leaked which had access to Shopify's Github account. It was reported on Hackerone to Shopify and Augusto got $50,000 for it. The best thing is that he didn't even look for a security issue.

    Link to the report explained: https://youtu.be/TOgIgD0KUVs
    The report on Hackerone: https://hackerone.com/reports/1087489
    Subscribe to Bug Bounty Reports Explained on YouTube: https://www.youtube.com/c/BugBountyReportsExplained/

    Augusto's media:
    https://twitter.com/auguzanellato
    https://hackerone.com/augustozanellato?type=user
    https://github.com/augustozanellato

    Finding bugs in Google VRP without recon - David Schütz - BBRD #01

    Finding bugs in Google VRP without recon - David Schütz - BBRD #01
    The video with David's bug: https://youtu.be/miQvovD3c04
    Original writeup: https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/

    ✉️ Sign up for the newsletter to receive the best hacking info right to your inbox: https://mailing.bugbountyexplained.com/

    In this episode I interview David Schütz, the 19-years old Google VRP hacker who constantly finds bugs in functionalities we use often like private videos on YouTube. We talk about his career, learning process, methodology, tooling and many more aspects that might help beginner bug bounty hunters.
    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io