The Bug Hunter's Methodology - Application Analysis | Jason Haddix

Поділитися
Вставка
  • Опубліковано 1 лют 2025

КОМЕНТАРІ • 58

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 10 місяців тому +51

    Unlike most top researchers out there who do nothing but flex their bounties and give cryptic generic advise or how they got those bugs to me those people add nothing to the community. But people like Haddix who doesnt show off how much he has made or flex his bounties actually explains in detail what he does. He also updates his style and methodology and its not for everyone but he does give detail to how he finds bugs and does his recon unlike most out there and i respect that.
    Researchers who flex their bounties offer nothing to the community
    Researchers like Haddix offer a lot to the community.

    • @auwalsalisu7889
      @auwalsalisu7889 10 місяців тому +2

      you said nothing but pure 100% truth, you literally spoke my mind

    • @AnthonyMcqueen1987
      @AnthonyMcqueen1987 10 місяців тому

      @auwalsalisu7889 I am just sick of researchers out there who do nothing and show off their bounties. These people make the profession worse IMO and add nothing.
      Haddix on the other hand I respect.

    • @shiiswii4136
      @shiiswii4136 10 місяців тому

      ​@@AnthonyMcqueen1987look up Ryan John and ippsec, these guys are pure fundamentals and no nonsense in the videos

    • @Denis-xl8jx
      @Denis-xl8jx Місяць тому

      Necro thread but what else do you guys watch? I've been putting off watching these talks because 95% of them are literally just people saying nothing whilst flexing bounties, like "we did some recon, found a subdomain, found XSS, escaped some defenses, and boom 10k bounty", 15 mins video. No techniques, payloads, nothing

    • @cracc_baby
      @cracc_baby 10 днів тому

      mans is a living legend

  • @TheZenOfWeb3
    @TheZenOfWeb3 23 дні тому +3

    I'll focus on Jason Haddix's teaching and repeat them all over till I find my first bounty and I'll update here. 🤞

    • @cracc_baby
      @cracc_baby 10 днів тому

      it is an iterative process xD

  • @skysunset877
    @skysunset877 Рік тому +10

    I'm deeply grateful that you explained this specific procedure for bugbounty. As a beginner, it helped me a lot with my studies.

    • @goohaver
      @goohaver 10 місяців тому

      same here. good luck homie

  • @madcane13
    @madcane13 2 роки тому +43

    json headache... utterly... no words can explain how brilliant he is... you rock

    • @rynomas4948
      @rynomas4948 2 роки тому +8

      He is haddix bro, not headache. 😆

    • @viralledshow7079
      @viralledshow7079 2 роки тому +2

      @@rynomas4948might be auto correct error brother....!😂

    • @wk8173
      @wk8173 Рік тому

      @@rynomas4948 grateful he didn't go for json headless💀

    • @SankizTime
      @SankizTime Рік тому +1

      Lmao😂

  • @MdMilonHossainNil
    @MdMilonHossainNil 2 роки тому +3

    ❤❤Oh my God, this is what I've been waiting for!! It looks beautiful!!❤❤

  • @iqyou-gw4kd
    @iqyou-gw4kd 2 роки тому +4

    Thank you everyone for helping the community evolve

  • @eyephpmyadmin6988
    @eyephpmyadmin6988 Рік тому +1

    Took notes on everything, every tool, all the methodology

  • @popo_hack
    @popo_hack Рік тому +3

    Thank you Jason for this amazing presentation, it was very fruitful with alot of knowledge. I think it's very important to know where to start testing and what are the tools that can help you doing that😀

  • @AlecMaly
    @AlecMaly 2 роки тому +5

    Great presentation! Thank you for sharing your expertise!

  • @nathanbolen7624
    @nathanbolen7624 3 місяці тому

    i love these talks, still relevant today

  • @Suckit-b6k
    @Suckit-b6k 3 місяці тому +2

    8:30 is an incredible moment

  • @emanuelepicariello
    @emanuelepicariello Рік тому +1

    Great video thanks, it’s time to build a proper methodology now 🕵🏽‍♂️

  • @AmineAb
    @AmineAb 2 роки тому +5

    Really informative talk, but at the end he wasn’t using Notion for the note-taking part as stated, it was Obsidian.

  • @fp1036
    @fp1036 9 місяців тому

    Thank you for your passionate sharing Sir!

  • @william_ade
    @william_ade 2 роки тому +3

    This is brilliant !

  • @sapienshack1711
    @sapienshack1711 Рік тому +1

    Jason Haddix you are awesome

  • @Khal_Rheg0
    @Khal_Rheg0 10 місяців тому

    Thank you!

  • @0xfsec
    @0xfsec 2 роки тому +7

    Can I get the slide presentation?

    • @godzab
      @godzab 2 роки тому +3

      I second this!

  • @william_ade
    @william_ade 2 роки тому +5

    how can we get the slides ??

  • @4liraah
    @4liraah Рік тому

    Thanks for the talk! Any chance we can get a link to the slides?

  • @aalekhmotani3877
    @aalekhmotani3877 5 місяців тому

    Thanks a lot for all this

  • @wise.wanderer.00
    @wise.wanderer.00 2 роки тому +1

    Very informative talk

  • @actuallyclover
    @actuallyclover 10 місяців тому

    I went to college with Corben! Super smart guy

  • @bugs-lk3jf
    @bugs-lk3jf Рік тому

    Great Content , like a Boss

  • @samgold9151
    @samgold9151 2 роки тому

    Thank you

  • @hamidrahamaabakar7995
    @hamidrahamaabakar7995 Рік тому +1

    Good morning I'm very appreciate you

  • @anasshaikh5778
    @anasshaikh5778 2 роки тому +1

    Rustscan might not be helpful Since most of the programs have speed limitations like 10 req/s etc..

  • @esamlasheen453
    @esamlasheen453 Рік тому

    45:36
    Jason It's obsidian not notion!

  • @reactivicky
    @reactivicky Рік тому

    Nice tips.

  • @سامرسعيد-ي1ب
    @سامرسعيد-ي1ب 4 місяці тому

    “There are bugs in every single aplication”

  • @bountyproofs
    @bountyproofs 9 місяців тому +8

    if you don't CREATE your own METHODOLOGY this is worth NOTHING for YOU

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy 2 роки тому

    Legend :)

  • @thehackr.
    @thehackr. 2 роки тому +2

    nyc one

  • @ExploitDeveloper
    @ExploitDeveloper Рік тому

    thats good

  • @mariarahelvarnhagen2729
    @mariarahelvarnhagen2729 Рік тому

    The Financial Instruments Game

  • @shantanusharma5624
    @shantanusharma5624 Рік тому

    Woah!! I'm the 1Kth liker of this video

  • @DrakuzDark
    @DrakuzDark Рік тому +1

    I'll give you a dollar if you learn to pronounce "obligatory" properly 😂

  • @CaseyStrouse
    @CaseyStrouse Рік тому

    jsnice is the best tool I've found for making sense of obfuscated js. Definitely check it out.

  • @abd9273ndhHN
    @abd9273ndhHN Рік тому

    where to find the slides file ?

  • @awanakb4867
    @awanakb4867 2 роки тому

    how can i find these word lists

    • @AmineAb
      @AmineAb 2 роки тому +2

      Everthing is on the talk.. if you can’t find those wordlists, I don’t know how you will find bugs

    • @awanakb4867
      @awanakb4867 Рік тому

      @@AmineAb i found them already. it just needed some attention.