100 hours of reviewing the source code - Bounty vlog #3 - Elastic

  Рет қаралды 9,769

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

📋 Check out my notes from Elastic: bbre.dev/elastic
📧 Subscribe to BBRE Premium: bbre.dev/premium
✉️ Sign up for the mailing list: bbre.dev/nl
📣 Follow me on twitter: bbre.dev/tw
This video is about my bug bounty journey. This time, I challenged myself to spent 100 hours on a Hackerone's public bug bounty program: Elasticsearch.
🖥 Get $100 in credits for Digital Ocean: bbre.dev/do
Timestamps:
00:00 Intro
00:27 How much time did I spent on setup?
01:24 Path traversal in Datafeeds
04:33 Potential SSRF in package file proxying
05:26 Enterprise search and JRuby
07:25 Badly written regexes in JavaScript
08:48 Funtionality DoS
10:41 Finding a duplicate
11:15 Reversing patches and writing plugins
13:12 Finally, finding a valid bug
14:39 Lessons learned

Пікірлер: 25
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Welcome to the comment section. I hope you enjoyed the video! If you want to check out my notes, go to bbre.dev/elastic
@_CryptoCat
@_CryptoCat 2 жыл бұрын
another great video and props for sharing the notes! if somebody reviews them and finds a bug you missed, it would be really cool to see 🙂
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
I'd hate it and love it at the same time 😂
@ssfdf7751
@ssfdf7751 2 жыл бұрын
Like before watching the video !
@GaurangTandon
@GaurangTandon Жыл бұрын
Thanks for making this honest and comprehensive description of what a bounty hunting journey looks like. Please do make more of these. Even the descriptions of failed bounty attempts are very interesting and teach a lot to a beginner like me.
@crusader_
@crusader_ 2 жыл бұрын
Thanks so much. Loved it
@Mohsinkhan-bh7py
@Mohsinkhan-bh7py 2 жыл бұрын
Learned a lot, today brother :)
@0xsudip892
@0xsudip892 2 жыл бұрын
Thank you sir. Keep it up :)
@ahmadshami5847
@ahmadshami5847 2 жыл бұрын
pretty cool video 👌👌 showing the struggles and the pain involved in such work really sheds the light on the problems that actually discourage a lot of people. I personally am expecting to struggle a lot but that video actually motivates me more to start, no pain no gain. thanks for being honest about your experience and showing everyone the hard truth of the industry, and as always great job man 👌👌
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Thanks for appreciating that!
@farcryman1
@farcryman1 2 жыл бұрын
Great video 👍
@OthmanAlikhan
@OthmanAlikhan Жыл бұрын
Thanks for the video =)
@fallenangel5265
@fallenangel5265 2 жыл бұрын
please do again the challenge of 100 hours
@Dodo-rb4zf
@Dodo-rb4zf 2 жыл бұрын
bug bounty: working for a month, getting paid for a week, no recognition, NDA trap
@sebastianchmielewski6281
@sebastianchmielewski6281 2 жыл бұрын
no risk, no fun
@ZarakKhanNiazi
@ZarakKhanNiazi 2 жыл бұрын
i love it How you Say " Enjoy " I wanna make a one hour auto repeat video of you saying Enjoy haha.. i dont know i enjoy it too much
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Haha, what can I say - enjoy my enjoy
@ZarakKhanNiazi
@ZarakKhanNiazi 2 жыл бұрын
@@BugBountyReportsExplained yeah :)
@medhasni6432
@medhasni6432 Жыл бұрын
hey sir, smart contract testing or web apps testing? like where would the bugs and the rewards exist more?
@cheesaskris6161
@cheesaskris6161 2 жыл бұрын
Does it work on linux?
@utensilapparatus8692
@utensilapparatus8692 2 жыл бұрын
I would'nt recommend wormhole or pip/npm installer (package.json [dependecies]) 🎃
@jpierce2l33t
@jpierce2l33t 2 жыл бұрын
Wow no wonder it's a struggle getting into bug bounty, when you've got dudes like that out here just casually banging out decompilers for obscure languages just to audit the source 🤦‍♂️🤣
@exoooooooo
@exoooooooo 2 жыл бұрын
Not every hunting process like that, this dude just want to look cool by reviewing a code and expect huge bounty from a low severity bug
@dennismunyaka6537
@dennismunyaka6537 2 жыл бұрын
4 months at 584 just isnt worth the effort.bounties is a love hate relationship
@muhammaddaniyal8637
@muhammaddaniyal8637 2 жыл бұрын
Hi can you please made video on ethical hacking career roadmap or also mention some free resources
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 141 М.
What functionalities are vulnerable to SSRFs? Case study of 124 bug bounty reports
19:58
Bug Bounty Reports Explained
Рет қаралды 14 М.
THE POLICE TAKES ME! feat @PANDAGIRLOFFICIAL #shorts
00:31
PANDA BOI
Рет қаралды 25 МЛН
路飞被小孩吓到了#海贼王#路飞
00:41
路飞与唐舞桐
Рет қаралды 70 МЛН
Этот Пёс Кое-Что Наделал 😳
00:31
Глеб Рандалайнен
Рет қаралды 2,9 МЛН
Security source code review expert - Shubham Shah
55:16
Bug Bounty Reports Explained
Рет қаралды 10 М.
This is my coolest bug bounty report (SSRF ➡ Phishing)
10:05
Bug Bounty Reports Explained
Рет қаралды 8 М.
How to do Code Review - The Offensive Security Way
58:58
OWASP DevSlop
Рет қаралды 31 М.
eBPF: Unlocking the Kernel [OFFICIAL DOCUMENTARY]
30:00
Speakeasy Productions
Рет қаралды 89 М.
From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3
1:08:37
Stable Diffusion in Code (AI Image Generation) - Computerphile
16:56
Computerphile
Рет қаралды 287 М.
$XX,000 Airbnb impossible XSS with 4 bypasses
9:15
Bug Bounty Reports Explained
Рет қаралды 27 М.
Hacker101 - JavaScript for Hackers (Created by @STOKfredrik)
24:17
Why didn't the Angular team just use RxJS instead of Signals?
8:15
Joshua Morony
Рет қаралды 89 М.
iPhone socket cleaning #Fixit
0:30
Tamar DB (mt)
Рет қаралды 11 МЛН
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 3,1 МЛН
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 2,2 МЛН