AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
Nagli emphasizes the importance of automation in his bug hunting process, spending most of his time coding and refining his scripts. He mentions the challenges of maintaining and fixing the codes, as well as dealing with large domain lists when hacking. Nagli also highlights the value of collaboration, sharing insights and findings with other hackers in order to improve and find better bugs.
Nagli discusses his experiences with traveling to live hacking events and the challenges of managing time on flights. He explains that he spends time working on his laptop, usually watching Netflix or researching topics related to hacking. While he is focused on his business and product development, Nagli still participates in bug bounties and attends live hacking events.
Nagli shares his approach to managing his finances, remaining conservative with his investments and using his earnings to cover travel expenses and daily costs. He mentions his interest in purchasing assets like real estate or luxury items in the future. Nagli also expresses his excitement about integrating AI into his product, particularly for features such as auto-triage and analyzing JavaScript files.
During a live hacking event, the podcast guest, Nagli, discovered a web cache deception vulnerability in Chat GPT. By injecting a test.css file into different endpoints, Nagli was able to confirm that the cache server was responding with a hit. This allowed unauthorized users to access sensitive data, including JSON Web Tokens (JWTs). Nagli promptly reported the vulnerability and received a quick response from the program manager. Although the bug did not result in a financial reward, it gained significant exposure on Twitter, showcasing the value of finding bugs in AI systems.
At a live hacking event, Nagli and a team discovered an SSRF vulnerability in a small web app. Through the Burp Suite active scan feature, Nagli found that injecting payload at the end of specific URLs led to a successful SSRF attack. The team noticed that this injection technique provided access to a bearer token leak, potentially allowing unauthorized access with super admin privileges. The bug showcased the importance of investigating callback requests thoroughly and leveraging collaboration to identify unique vulnerabilities that may not be immediately apparent.
Episode 15: In this episode of Critical Thinking - Bug Bounty Podcast we talk with the latest Million-Dollar bug bounty hunter: @naglinagli . He talks about his climb from $1,000 in bounties to $1,000,000, recon tips and tricks, and some bug reports that made the news and landed him the "Best Bug" award at a H1 Live Hacking event.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
Follow Nagli and his new startup Shockwave:
https://twitter.com/naglinagli
https://twitter.com/shockwave_sec
HackMD Collaborative Notes:
Ian Carroll's Airline Miles Website:
Nagli's Tweet in ChatGPT Web Cache Deception:
https://twitter.com/naglinagli/status/1639343866313601024
Timestamps:
(00:00:00) Intro
(00:04:40) Nagli’s Climb
(00:05:40) What kind of vulns do you look for?
(00:09:25) Working with other hackers
(00:10:20) Bug Bounty Hunter’s Guild
(00:12:35) Shockwave product
(00:14:12) Outsourcing tool development
(00:18:46) What got you started?
(00:21:13) Manual hacking vs recon suite + LHE focus
(00:25:00) How do you take notes
(00:29:42) Biggest things that you’ve learned over the past 2 years
(00:31:29) How do you ingest new techniques?
(00:31:50) Collaboration
(00:37:20) Justin Ranting about “Trained Eyes”
(00:40:18) Time spent coding vs hacking
(00:45:28) Travel and spending habits
(00:54:16) Grep is Nagli’s database
(00:56:20) Nagli’s ChatGPT Web Cache Deception
(00:58:44) What does your alerting look like?
(01:01:50) Nagli’s “Most Critical” SSRF
(01:04:30) Burp Active Scan
Listen to all your favourite podcasts with AI-powered features
Listen to the best highlights from the podcasts you love and dive into the full episode
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
Listen to all your favourite podcasts with AI-powered features
Listen to the best highlights from the podcasts you love and dive into the full episode