How to Differentiate Yourself as a Bug Bounty Hunter - Mathias Karlsson @avlidienbrunn

แชร์
ฝัง
  • เผยแพร่เมื่อ 8 ต.ค. 2018
  • There are a lot of illusions and misconceptions around the bug bounty industry. Is it too late to join? Are all the vulnerabilities already found? Is everything automated nowadays so there's no way to be late to the party?
    Frans and Mathias have been in the mythical world of bounties for a few years and will share their thoughts and ideas on how to actually approach it technically, methodologically and mentally. And also, how to use bug bounties for your own advantage, to improve your career and to increase your pentesting and vulnerability hunting skills.
    OWASP Stockholm:
    www.owasp.org/index.php/Stock...
    Mathias Karlsson:
    / avlidienbrunn
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 17

  • @Gray3ther
    @Gray3ther หลายเดือนก่อน

    Was that Gollum in his incognito voice near the end of the Q&A? Good to hear he's out of his cave! 😂 Great talk. Awesome guy!

  • @andreslauga
    @andreslauga 3 ปีที่แล้ว +1

    Great! This helped me a lot! Thanks Mathias :)

  • @BLKSD
    @BLKSD หลายเดือนก่อน

    Great videos

  • @yodapaw9750
    @yodapaw9750 5 ปีที่แล้ว +24

    it should be " Bugs found / ( risk of duplicate * time taken) = BBE" @2:44

    • @h4kster182
      @h4kster182 5 ปีที่แล้ว +7

      What about : ( bugs found * probability of not duplicate ) / time taken 🤷🏽‍♂️

  • @leisureclub_
    @leisureclub_ 5 ปีที่แล้ว +4

    Assetnote has been removed from the official source.. Is there anyone who have link ?
    Thanks..

    • @benjaminmcewan6753
      @benjaminmcewan6753 5 ปีที่แล้ว

      Www.github.com/benmcewan1 but couldn't get it working since the dependencies based ON flask updated. If you get it working let me know

    • @benjaminmcewan6753
      @benjaminmcewan6753 5 ปีที่แล้ว

      There's other tools I've yet to look at eg sublert I think is one. Let me know how you get on

  • @DavidPerez-dt9nb
    @DavidPerez-dt9nb 4 ปีที่แล้ว +3

    But somehow experience should be considered against time taken, since time taken by someone like me who is a total noob cant be compared to the time taken for more experienced bounty hunters

  • @anivibe7322
    @anivibe7322 4 ปีที่แล้ว +13

    1.25 speed it's ok

    • @ramdomdeepseafish
      @ramdomdeepseafish หลายเดือนก่อน

      1.5 is also good

    • @anivibe7322
      @anivibe7322 หลายเดือนก่อน

      @@ramdomdeepseafish Holy, 4 years has passed

    • @peasantlettuce8278
      @peasantlettuce8278 หลายเดือนก่อน

      @@anivibe7322 Thank you sir. It's okay to necrorevive sometimes :3

  • @ronnyj4179
    @ronnyj4179 4 ปีที่แล้ว +1

    0 days? lol thats not "oh". it's zero days.

    • @abdurrafeh6000
      @abdurrafeh6000 2 ปีที่แล้ว +4

      It’s pronounced both ways. I’ve heard Jason Haddix pronounce it like him.

    • @lmfao69420
      @lmfao69420 7 หลายเดือนก่อน

      If you're reading out a number (such as a phone number or zip code), it's common to read out the "0" as an oh.
      So I don't think it seems too weird to pronounce zero day as "oh" day.