Bug Bounty Reports Discussed cover image

From reporting self-XSSes to improving browser security mechanisms - Michał Bentkowski

Bug Bounty Reports Discussed

CHAPTER

Transitioning from Simple Bugs to Complex Bugs

The speaker discusses their journey in finding non-exploitable bugs to bugs that were rewarded, and how their work as a pentester helped them understand attack scenarios and the exploitability of bugs. They share experiences with SQL injection vulnerabilities, the importance of considering severity ratings in context, preparing for arguments when reporting vulnerabilities, and the significance of attack preconditions and threat models. They also talk about the difference between reporting vulnerabilities in bug bounty and pen testing, the challenges of communicating multiple bugs in reports, and the importance of providing detailed information and proof of concepts in bug reports.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner