How to Differentiate Yourself as a Bug Bounty Hunter - Mathias Karlsson @avlidienbrunn

Поділитися
Вставка
  • Опубліковано 5 лют 2025
  • There are a lot of illusions and misconceptions around the bug bounty industry. Is it too late to join? Are all the vulnerabilities already found? Is everything automated nowadays so there's no way to be late to the party?
    Frans and Mathias have been in the mythical world of bounties for a few years and will share their thoughts and ideas on how to actually approach it technically, methodologically and mentally. And also, how to use bug bounties for your own advantage, to improve your career and to increase your pentesting and vulnerability hunting skills.
    OWASP Stockholm:
    www.owasp.org/...
    Mathias Karlsson:
    / avlidienbrunn
  • Наука та технологія

КОМЕНТАРІ •

  • @Gray3ther
    @Gray3ther 9 місяців тому +1

    Was that Gollum in his incognito voice near the end of the Q&A? Good to hear he's out of his cave! 😂 Great talk. Awesome guy!

  • @andreslauga
    @andreslauga 3 роки тому +1

    Great! This helped me a lot! Thanks Mathias :)

  • @yodapaw9750
    @yodapaw9750 5 років тому +26

    it should be " Bugs found / ( risk of duplicate * time taken) = BBE" @2:44

    • @h4kster182
      @h4kster182 5 років тому +7

      What about : ( bugs found * probability of not duplicate ) / time taken 🤷🏽‍♂️

  • @jxkz7
    @jxkz7 9 місяців тому

    Great videos

  • @k0ns0l
    @k0ns0l 4 місяці тому

    Awesome :D

  • @DavidPerez-dt9nb
    @DavidPerez-dt9nb 4 роки тому +4

    But somehow experience should be considered against time taken, since time taken by someone like me who is a total noob cant be compared to the time taken for more experienced bounty hunters

  • @leisureclub_
    @leisureclub_ 6 років тому +4

    Assetnote has been removed from the official source.. Is there anyone who have link ?
    Thanks..

    • @benjaminmcewan6753
      @benjaminmcewan6753 5 років тому

      Www.github.com/benmcewan1 but couldn't get it working since the dependencies based ON flask updated. If you get it working let me know

    • @benjaminmcewan6753
      @benjaminmcewan6753 5 років тому

      There's other tools I've yet to look at eg sublert I think is one. Let me know how you get on

  • @Mark_1991_1
    @Mark_1991_1 5 років тому +13

    1.25 speed it's ok

    • @ramdomdeepseafish
      @ramdomdeepseafish 9 місяців тому

      1.5 is also good

    • @Mark_1991_1
      @Mark_1991_1 9 місяців тому

      @@ramdomdeepseafish Holy, 4 years has passed

    • @peasantlettuce8278
      @peasantlettuce8278 9 місяців тому

      @@Mark_1991_1 Thank you sir. It's okay to necrorevive sometimes :3

  • @ronnyj4179
    @ronnyj4179 4 роки тому +1

    0 days? lol thats not "oh". it's zero days.

    • @abdurrafeh6000
      @abdurrafeh6000 3 роки тому +3

      It’s pronounced both ways. I’ve heard Jason Haddix pronounce it like him.