Главная
Study mode:
on
1
Intro
2
history && topics
3
light reading
4
Sublist3r
5
Sub Scraping (bespoke)
6
Sub Bruting
7
Acquisitions
8
Port Scanning
9
Visual Identification
10
Platform identification and CVE searching
11
Content Discovery/ Directory Bruting
12
Parameter Bruting?
13
XSS (not a lot)
14
Blind XSS
15
XSSHunter
16
XSS Polyglot #4
17
Jackmasa's
18
SSTI
19
SSRF (GET examples)
20
SSRF Resources
21
Code Injection.CMD
22
Backslash Powered Scanner
23
Subdomain takeover!
24
Robbing Misconfigured Sh** (AWS)
Description:
Dive into advanced bug bounty hunting and web hacking techniques in this comprehensive conference talk from Bugcrowd's LevelUp 2017. Explore a wide range of topics, including subdomain enumeration with Sublist3r, port scanning, visual identification, platform identification, CVE searching, content discovery, and directory bruting. Learn about various attack vectors such as XSS (Cross-Site Scripting), including blind XSS and XSS polyglots, SSTI (Server-Side Template Injection), SSRF (Server-Side Request Forgery), and code injection. Discover tools like XSSHunter and Backslash Powered Scanner, and gain insights into subdomain takeovers and AWS misconfigurations. Enhance your bug hunting skills with this in-depth methodology presented by Jason Haddix, covering everything from initial reconnaissance to advanced exploitation techniques.

Bug Bounty Hunting Methodology - Jason Haddix from Bugcrowd's LevelUp

Bugcrowd
Add to list
0:00 / 0:00