The OG Bug Bounty King - Frans Rosen (Ep. 45)

  Рет қаралды 6,574

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Күн бұрын

In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome Frans Rosén, an OG bug bounty hunter and co-founder of Detectify. We kick off with Frans sharing his journey bug bounty and security startups, before diving headfirst into a host of his blog posts. We also cover the value of pseudo-code for bug exploitation, understanding developer terminology, the challenges of collaboration and delegating tasks, and balancing hacking with parenting. If you're interested in bug bounty or entrepreneurship, you won't want to miss it!
Follow us on twitter at: / ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Ways to Support CTBB Podcast ======
Follow us on twitter: / ctbbpodcast
Follow your hosts Rhynorater & Teknogeek on twitter:
- / rhynorater
- / 0xteknogeek
Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.
Join our Discord! ctbb.show/discord
====== Links ======
Today's Guest: / fransrosen
Detectify: labs.detectify.com/
Discovering s3 subdomain takeovers: labs.detectify.com/writeups/h...
Bucket Disclose: gist.github.com/fransr/a155e5...
A deep dive into AWS S3 access controls: labs.detectify.com/writeups/a...
Attacking Modern Web Technologies: www.slideshare.net/OWASP_Pola...
Live Hacking like a MVH: speakerdeck.com/fransrosen/li...
Account hijacking using Dirty Dancing in sign-in OAuth flows: labs.detectify.com/2022/07/06...
====== Timestamps ======
(00:00:00) Introduction
(00:04:50) Franz Rosen's Bug Bounty Journey and the creation of Detectify
(00:13:30) Benefits of pseudo-code, typing, and thinking like a developer
(00:20:20) Hunter Methodologies
(00:35:40) Time on targets, Iteration vs. Ideation, and tips for standing out
(00:51:10) S3 subdomain takeovers
(01:05:02) Blog posting and hosting motivations
(01:13:30) Detectify and entrepreneurial endeavors
(01:29:50) Attacking Modern Web Technologies
(01:46:00) postMessage and MessagePort
(01:58:09) Live Hacking and Collaboration
(02:13:50) Account Hijacking and OAuth Flows
(02:28:48) Hacking/Parenting

Пікірлер: 15
@ioanthomas7258
@ioanthomas7258 7 ай бұрын
I haven't listened to this yet, but I already know it's going to be a good episode
@abdulmoizsiddiqui6865
@abdulmoizsiddiqui6865 7 ай бұрын
most awaited podcast! thanks guys, learned alot :)
@hanzgumapac8815
@hanzgumapac8815 7 ай бұрын
Can you invite santiago lopez next. where is he now?
@MFoster392
@MFoster392 7 ай бұрын
Just a noob so a lot of your info is over my head but it's more to look up and learn so thank you fellas, you're all legends in my opinion :-)
@user-lk6rk8hb3d
@user-lk6rk8hb3d 7 ай бұрын
Super interesting and valuable. Thank you guys
@mohammadrezaabbasi4841
@mohammadrezaabbasi4841 6 ай бұрын
Pure Gold, Thanks for such awesome tips, WOW
@souraldandothi5681
@souraldandothi5681 4 ай бұрын
1:46:00 Bro pulling a big brain move!! Legend!!
@TheLakeJake3
@TheLakeJake3 7 ай бұрын
Joel give us a rig rundown of your guitar setup!
@Free.Education786
@Free.Education786 5 ай бұрын
Please, if possible, cover these advanced topics like How to bypass Drupal CMS or other secured CMS? How to bypass HARD WAF protection that stops HTML, SQL, and XSS injection payloads? Payload single-double-triple encoding using Cyber-Chef? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc.,? How to bypass Hard WAF using SQLMAP or Burpsuite? How to find hidden vulnerable parameters and endpoints inside the .js and .jason files? How to find hidden admin pages, cPanel pages, and WHM pages ? Please cover these important topics. Thanks
@suvanedits
@suvanedits 7 ай бұрын
great
@HackersRising
@HackersRising 7 ай бұрын
Seems I'm first
@crusader_
@crusader_ 7 ай бұрын
Get ngalongc
Frans Rosén - Go hack yourself…or someone else will
45:58
Alex Chapman: How to Be a High-Impact Hacker (Ep. 31)
1:24:42
Critical Thinking - Bug Bounty Podcast
Рет қаралды 4,5 М.
OMG😳 #tiktok #shorts #potapova_blog
00:58
Potapova_blog
Рет қаралды 3,9 МЛН
She ruined my dominos! 😭 Cool train tool helps me #gadget
00:40
Go Gizmo!
Рет қаралды 61 МЛН
DejaVue #E013 - The Road to Nuxt 4 (with Daniel Roe)
1:18:25
Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated (Ep.77)
1:50:20
Critical Thinking - Bug Bounty Podcast
Рет қаралды 1,5 М.
Hacking on Bug Bounties for a Living
12:59
codingo
Рет қаралды 18 М.
Gal Nagli: The Israeli Million-Dollar Hacker (Ep. 15)
1:08:26
Critical Thinking - Bug Bounty Podcast
Рет қаралды 6 М.
Youssef Sammouda - Client-Side & ATO War Stories (Ep. 58)
1:54:52
Critical Thinking - Bug Bounty Podcast
Рет қаралды 5 М.
From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3
1:08:37
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 2,4 МЛН
Simple maintenance. #leddisplay #ledscreen #ledwall #ledmodule #ledinstallation
0:19
LED Screen Factory-EagerLED
Рет қаралды 6 МЛН
Best mobile of all time💥🗿 [Troll Face]
0:24
Special SHNTY 2.0
Рет қаралды 1 МЛН
Cadiz smart lock official account unlocks the aesthetics of returning home
0:30
Will the battery emit smoke if it rotates rapidly?
0:11
Meaningful Cartoons 183
Рет қаралды 35 МЛН
Урна с айфонами!
0:30
По ту сторону Гугла
Рет қаралды 7 МЛН