
Episode 18: Audit Code, Earn Bounties
Critical Thinking - Bug Bounty Podcast
00:00
How to Integrate Sources and Sinks Into a Report
A report that popped up in a live hacking event three years ago. It was while we were fuzzing the API calls or playing around with the API calls and those errors would return a string that contained the company's name but also contained like the microservice they were talking about. We reported it directly to the company as like now your production source code is kind of out there flopping around. And then we didn't even get to talk about like okay sources and sinks and like you know going through the application and and stuff like that.
Transcript
Play full episode