$3,133.70 XSS in golang's net/html library - My first Google bug bounty

  Рет қаралды 10,282

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

📧 Subscribe to BBRE Premium: bbre.dev/premium
✉️ Sign up for the mailing list: bbre.dev/nl
📣 Follow me on twitter: bbre.dev/tw
This video is a writeup of a vulnerability I found in Google's golang/net/html library that could lead to an XSS. It was my first submission to Google and I got a bounty of $3,133.70 for it.
Link to the exploit and hypothetical vulnerable app: gist.github.co...
Commit with the fix: github.com/gol...
🖥 Get $100 in credits for Digital Ocean: bbre.dev/do
Timestamps:
00:00 Intro
00:28 Preparations before reviewing the code
00:57 Where do I start security code review?
02:00 The bug - XSS in golang net/html library due to invalid parsing of the comments

Пікірлер: 26
Hacking into Google's Network for $133,337
31:32
LiveOverflow
Рет қаралды 1 МЛН
진짜✅ 아님 가짜❌???
0:21
승비니 Seungbini
Рет қаралды 10 МЛН
Vampire SUCKS Human Energy 🧛🏻‍♂️🪫 (ft. @StevenHe )
0:34
Alan Chikin Chow
Рет қаралды 138 МЛН
Their Boat Engine Fell Off
0:13
Newsflare
Рет қаралды 15 МЛН
How to turn a write-based path traversal into a critical? - Bug bounty case study
16:31
Bug Bounty Reports Explained
Рет қаралды 6 М.
CRLF + XSS + cache poisoning = Access to Github private pages for $35k bounty
11:22
Bug Bounty Reports Explained
Рет қаралды 12 М.
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 58 М.
What functionalities are vulnerable to SSRFs? Case study of 124 bug bounty reports
19:58
Bug Bounty Reports Explained
Рет қаралды 17 М.
EP004: Bug Hunters | HACKING GOOGLE
15:07
Google Malaysia
Рет қаралды 1,8 М.
Creating a YouTube TV that could steal your private videos - $6,000 CSRF
9:06
Bug Bounty Reports Explained
Рет қаралды 4,5 М.
XSS on Google Search - Sanitizing HTML in The Client?
12:58
LiveOverflow
Рет қаралды 694 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 909 М.
Bug Bounty: Content Discovery on Large Scope Like a Pro! | 2024
13:53