Bug Bounty Reports Discussed cover image

From 0 to a top bug bounty hunter - Johan Carlsson's journey to GitLab TOP1 on Hackerone

Bug Bounty Reports Discussed

00:00

Exploring Client-Side Vulnerabilities

This chapter examines the complexities of client-side security vulnerabilities, focusing on post-message bugs and prototype pollution. The speakers share personal experiences in bug hunting, discussing exploit techniques like CSRF and client-side path traversals on platforms like GitLab. They highlight unique vulnerabilities such as cross-window forgery, illustrating the risks and mitigation strategies through practical examples and proof of concept demonstrations.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app