
Critical Thinking - Bug Bounty Podcast Episode 69: Johan Carlsson - 3 Month Check-in on Full-time Bug Bounty.
12 snips
May 2, 2024 Johan Carlsson, a dedicated bug bounty hunter, shares his journey transitioning to full-time bug hunting. He discusses the thrill of discovering vulnerabilities like a CSP bypass in GitHub and a critical flaw in GitLab. Johan highlights his focus on complex bug types like ReDoS and OAuth, emphasizing the unpredictability that accompanies bug hunting. He also offers insights into balancing personal life with his bug bounty career, navigating financial challenges, and the importance of community support in this unique profession.
AI Snips
Chapters
Transcript
Episode notes
Johan's Career Path
- Johan Carlsson's career path took a turn from art to computer science after an 8-year break.
- His thesis project on GitLab introduced him to bug bounty hunting.
First Bug Bounty Experience
- Johan learned about bug bounties through an ethical hacking course where finding bugs earned extra credit.
- He found his first bug by accident, a simple XSS, after a code change on GitLab.
Form-Action CSP Directive
- The
form-actionCSP directive is crucial for controlling form submissions, but often missed. - It's not covered by
default-srcand doesn't affect fetch-based requests.

