Critical Thinking - Bug Bounty Podcast cover image

Critical Thinking - Bug Bounty Podcast

Episode 75: *Rerun* of The OG Bug Bounty King - Frans Rosen

Jun 13, 2024
Frans Rosen, The OG Bug Bounty King, discusses S3 subdomain takeovers, attacking modern web technologies, account hijacking using Dirty Dancing in OAuth flows, and bug bounty methodologies. Topics include bug hunting strategies, automation, entrepreneurship, and managing growth in the cybersecurity field.
02:44:52

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Balancing time investment with program validation is crucial for efficient bug finding.
  • Analyzing error messages can reveal unique insights for targeted bug hunting approaches.

Deep dives

Investing Time for Deep Bug Hunting

Investing in deep bug hunting involves dedicating around three days to an average target to understand its complexities. Spending one and a half weeks on a program often leads to finding valuable bugs that may vary in severity but are rewarding. It's crucial to balance time investment with program validation and threat model alignment, ensuring efficient bug finding.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner