Главная
Study mode:
on
1
Intro
2
About Me
3
Why this topic
4
Tips and Tricks
5
Private vs Ongoing
6
Private Bounty Email
7
Why you need to be fast
8
Issues in the first program
9
Difference between private and ongoing program
10
My approach
11
High potential of duplication
12
Main section
13
Understanding the background
14
Multiple tests
15
Duplicates
16
Business
17
Business Examples
18
Duplicate Submission
19
Duplicate Accepted
20
User Agents Chain
21
Mobile Site
22
I will dip em
Description:
Discover effective strategies for uncovering valuable vulnerabilities in established bug bounty programs through this insightful conference talk from Bugcrowd's LevelUp 2017. Learn how to approach recently joined programs that have been active for months, gaining valuable insights from the presenter's personal experiences and methodologies. Explore the differences between private and ongoing programs, understand the importance of swift action, and delve into techniques for navigating potential duplication issues. Gain a deeper understanding of program backgrounds, multiple testing approaches, and business considerations that can lead to successful bug submissions. Examine real-world examples and learn how to leverage user agent chains and mobile site testing to maximize your chances of finding hidden gems in older bug bounty programs.

Finding Hidden Gems in Old Bug Bounty Programs - Yappare, Bugcrowd's LevelUp 2017

Bugcrowd
Add to list
0:00 / 0:00