
Critical Thinking - Bug Bounty Podcast Episode 45: The OG Bug Bounty King - Frans Rosen
4 snips
Nov 16, 2023 Frans Rosén, an OG bug bounty hunter and co-founder of Detectify, joins the podcast to discuss bug exploitation, developer terminology, collaboration challenges, and balancing hacking with parenting. They cover topics such as discovering s3 subdomain takeovers, attacking modern web technologies, and account hijacking using Dirty Dancing in sign-in OAuth flows.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
Introduction
00:00 • 2min
Introducing the Bug Bounty OG
02:03 • 16min
Uploading File Issues and Proxy Mistake
18:18 • 2min
Hacking Methodologies and Bug Hunting Approach
19:49 • 23min
Bug Hunting Strategies
43:07 • 7min
Validating Program and Threat Model in Bug Bounty Hunting
50:33 • 8min
Exploring Declocking and Exploiting Trailing Dots
58:52 • 4min
Bug Fixes and Automation Failures
01:02:30 • 14min
The Challenges and Rewards of Delegating
01:16:17 • 22min
Service Workers and Exploitation Scenarios
01:37:49 • 8min
Web Security Vulnerabilities and Bug Bounty Hunting
01:45:37 • 12min
Challenges with Serialization Frameworks and Strategies for Live Hacking Events
01:57:54 • 2min
Bug Duping and the Power of Bash Scripting
01:59:44 • 2min
The Power of Collaboration in Bug Bounty Hunting
02:01:31 • 12min
Hacking Memories and Account Hijacking
02:13:24 • 15min
Finding Bugs and Bug Bounty Hunting
02:28:27 • 8min
