DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

  Рет қаралды 51,746

DEFCONConference

DEFCONConference

Күн бұрын

Пікірлер: 122
@bgorortayber
@bgorortayber 2 ай бұрын
Some things that happened to me while doing Bug Bounty: 1. Downgrading the score of a vulnerability that was previously reported twice and rated as "Medium". 2. Reporting to a open source project, they see the bug, they remove all the files from their Github, bumped up the version, then, told me that I've found the vulnerability in an older version. 3. The program imported all the existing bugs into the platform, afterwards, marked them as duplicate once they got reported. And the list goes on, the lesson is simple, never hack for free. All the best for you and your family, Jason.
@official.sirhaxalot
@official.sirhaxalot 2 ай бұрын
I got repeatedly fisted doing bb. Wrote a blog about it if you're interested?
@incognitoworth1205
@incognitoworth1205 2 ай бұрын
This is f*cking true
@trevermcbride4041
@trevermcbride4041 2 ай бұрын
I reported a vulnerability once that was currently working on the platform that allowed you to bypass mfa, and was told its a duplicate vulnerability from a internal bulletin a year before I submitted it to them.
@bgorortayber
@bgorortayber 2 ай бұрын
@@trevermcbride4041 Name and shame!
@Studio23Media
@Studio23Media 2 ай бұрын
@@trevermcbride4041 YIKES!! That's embarrassing for them to admit. 😂
@asurhacks
@asurhacks 2 ай бұрын
This kinda guy is worshipped by everyone in their respective field. Someone who speaks up against the odd. Mad respect to boss haddix the legend.
@effsixteenblock50
@effsixteenblock50 2 ай бұрын
Mad respect to Haddix for this truth telling. No doubt he's been conflicted about this stuff for a long time and is finally in a position where he feels like he can talk about it. Something else that needs to be addressed is that when researchers are continuously facing these BS practices, many of them might just opt to sell their P-1 / 0 days to a buyer that pays way more and with much less friction than the programs.
@huzaifamuhammad8044
@huzaifamuhammad8044 2 ай бұрын
I'm afraid some might even turn into the other side (black hat)
@handle_your_set
@handle_your_set 2 ай бұрын
@@huzaifamuhammad8044 IMO, that would be the appropriate response to corporate consolidation and research theft.
@youreabigguy
@youreabigguy 2 ай бұрын
​​@@huzaifamuhammad8044 This happens frequently, I know this for a fact
@detecht
@detecht 2 ай бұрын
Seeing you speak on this, makes the rest of us feel like we can too. Thank you for having the courage to say what we've all been thinking. We love you, jHaddix ❤
@manufaleschini
@manufaleschini 2 ай бұрын
I love this talk and have the highest respekt of Jason. He is one of the most brilliant minds in the Bug Bounty scene and such a wonderful human being. He doesn't have to fight for this community, he does it at will. I admire your support for the "nonames" and new hunters in the field. May god bless you and your wife. 🙏🏻
@WarmEmpanada
@WarmEmpanada 2 ай бұрын
Wishing the best for you and your family Jason ❤
@TimHerbert509
@TimHerbert509 Ай бұрын
Thanks for helping us up and comers! Prayers for your family.
@elite_fitness
@elite_fitness 20 күн бұрын
Jhaddix you the man. You took big risks doing this but you did what is right and we appreciate you.
@brunoeligiopavesi6987
@brunoeligiopavesi6987 2 ай бұрын
As usual Jason's talks are always very interesting.
@youreabigguy
@youreabigguy 2 ай бұрын
It should be well known by now, never to short, be stingy with, get over on or underestimate your hackers... When very talented researchers get screwed over they begin to thinking and being a legitimate researcher isn't worth it, and go from reporting bugs to selling exploits on the black market.
@theodorekorehonen
@theodorekorehonen Ай бұрын
If the suits that run these ticketing systems think the people that generate the revenue used to pay their salaries should simp for them and on top of that, be thankful for the privilege to work for them, I think marketplaces for bugs on the non clearnet might just grow in popularity. Greedy people seem to manage to ruin everything
@devz9530
@devz9530 Ай бұрын
yes I think this will be the next step for the bug bounty scene and corporates will be forced to react, either by bidding on the exploits themselves on the black market, or creating a better marketplace solution that favors us hackers
@zerocewl
@zerocewl 2 ай бұрын
Awesome talk by jason haddix thanks, And Prayers to your family jason 🙏
@matt5721
@matt5721 2 ай бұрын
Wow that's nuts about the traffic being monitored for the top 250. It would be petty cash to them AND create competition by paying those 250, but they discourage them instead.
@AlexbongoKurban
@AlexbongoKurban 2 ай бұрын
Why do you think in the programs they request or require you to put a custom header with your username of the bug bounty program?
@matt5721
@matt5721 2 ай бұрын
@@AlexbongoKurban so you just commented without watching? They're stealing from the top 250
@sithrebel1548
@sithrebel1548 Ай бұрын
​@@matt5721 cry harder
@XtremuZ
@XtremuZ 22 күн бұрын
@@sithrebel1548 whenever some of them become rogue, let's see who cries harder
@Thiccolo
@Thiccolo 2 ай бұрын
This needs to be put out there even more
@almc8445
@almc8445 2 ай бұрын
Almost all of the issues here seem like they come from the same reason we have unions for regular employees… Hackers union anyone?
@TESTA-CC
@TESTA-CC Ай бұрын
We Have a Hackers Union....it's called Code!
@almc8445
@almc8445 Ай бұрын
@ Code doesn’t stop a race to the bottom for wages. That’s exactly my point…
@PixelPulse_Playbook
@PixelPulse_Playbook 2 ай бұрын
Some hackers create informative content, and that's a good thing. However, I believe that sometimes you need to stand up for your community. It's great content, and I respect you, bro.
@tobias8933
@tobias8933 Ай бұрын
Thanks for speaking up! I've discovered a high severity vulnerability in a well-known social media platform a couple months ago. The triaging process was an absolutely ridiculous shit show. It took 6 months, included two interventions from the platform's support team and right before the payout, they decreased the severity rating reducing the payout by 90%. 0/5 Never again.
@theodorekorehonen
@theodorekorehonen Ай бұрын
I'm assuming there's some forced arbitration thing so they can tell you to GFY whenever they pull their scam?
@evilcorp3037
@evilcorp3037 2 ай бұрын
Wow, really eye opening! Thank you very much
@shmo9943
@shmo9943 Ай бұрын
Pissing off hackers is a very bold move
@official.sirhaxalot
@official.sirhaxalot 2 ай бұрын
Putting personal shit to one side to work is the epitome of a professional. Excellent talk. I hope your wife recovers.
@2rx_bni
@2rx_bni 2 ай бұрын
No it's deranged they should have given him an out. Don't do this. It's unhinged.
@galloe
@galloe 2 ай бұрын
​@@2rx_bniYeah, fuck that. A talk over my wife, there's no way in hell I'd ever do that.
@trustedsecurity6039
@trustedsecurity6039 2 ай бұрын
​@@2rx_bni totally!!! The worst is his "my kids are watching my others kids" WTF!!! Kids must be sas for their mom and this guy isnt even there for them... Bad Parents really!!!
@emarbeats6896
@emarbeats6896 2 ай бұрын
​@@trustedsecurity6039seems like hes working pretty hard to provide for his family.
@johnandmegh
@johnandmegh Ай бұрын
Setting aside whatever their family dynamics might be, which might make it totally ok in his particular case…the caveat given at the beginning tacitly encourages the behavior of “I’d rather push myself past the normal point and do a worse job, than take time away for me and my family”, which I believe is negative for most people.
@jhaddixP
@jhaddixP 2 ай бұрын
@michaelr.3799
@michaelr.3799 2 ай бұрын
Thank you for doing this, wishing your wife a speedy recovery.
@mohamedmater1230
@mohamedmater1230 2 ай бұрын
wishing your wife a speedy recovery Thanks JHaddix
@comosaycomosah
@comosaycomosah 2 ай бұрын
very hard to navigate appreciate you advocating for the little guy always
@tallst1
@tallst1 2 ай бұрын
Glorified ticketing system
@EarthWalkerOne
@EarthWalkerOne 2 ай бұрын
Bug Bounty is the same as the BetterBusinessBurreau. Started by bad businesses to limit the number of lawsuits they receive...
@alextravine9422
@alextravine9422 2 ай бұрын
It would appear to me that the bug bounty program is corrupted and should not be something to participate in.
@EarthWalkerOne
@EarthWalkerOne 2 ай бұрын
Seems like all that really needs to happen is companies and especially Platforms being taught a lesson. Bounty platforms should also be anonymous, there should be no room for celebrity/favoritism or targeted monitoring. If we're in this to make things more secure and get paid, then bug bounty programs and platforms should really try to incentivize white hat behavior. If I'm not going to get paid either way, the world will become more secure by forcing companies to listen and practice security if their vulns given away in alternative markets. If they're going to make getting compensated fairly difficult, you can just name your price elsewhere...
@SimonCas
@SimonCas Ай бұрын
They want to play a game, we like playing games 😊
@robertbruce7686
@robertbruce7686 Ай бұрын
Another excellent talk!!
@trailer-g1118
@trailer-g1118 Ай бұрын
I have learnt something but also discouraged, whether to start bug bounty or something else........please advice..
@ak1t4hax0r8
@ak1t4hax0r8 2 ай бұрын
Amazing talk! thanks for sharing Jason!
@joygatewood8028
@joygatewood8028 20 күн бұрын
Question - at 4:03 Jason mentions that AI is being used to train on attack traffic and to build services out of it. Is it possible that AI is being used to become bounty hunters themselves?
@danishbhat1536
@danishbhat1536 2 ай бұрын
A wise man says wise things
@elite_fitness
@elite_fitness Ай бұрын
3 times bugcrowd has said that my report was a dupe and a year later the vuln is still there. I also think a triager took my vulns and brushed me off
@grakka72
@grakka72 Ай бұрын
Welcome to the WESTERN WORLD of capatilisme. You deserve more credit for your work.
@jmz8086
@jmz8086 2 ай бұрын
amazing presentation. thank you!
@archkittens
@archkittens Ай бұрын
How can the contract bind you re: the submission if you received no money(consideration) for the submission? It is not illegal to sell unregulated information, and it’s definitely not illegal to share unregulated information for free, the platforms and ultimately the customers are buying your right to do those things, and if they choose not to buy it your rights should be unchanged.
@TripleA679
@TripleA679 2 ай бұрын
This is why some would rather sell their discoveries on the dark web.
@TomPotato-f7v
@TomPotato-f7v Ай бұрын
I'd drop everything to be at my wife's side, instead of worrying about using mild swear words at a talk that certainly won't change the world. but that's just me. all the best to you and yours, mr haddix
@elite_fitness
@elite_fitness 20 күн бұрын
I smell a little animosity, perhaps Jason was at the conference, hours from home and she had to go get stitches.. Hes not a Dr . Have you been doing this dirty crap or something?
@0xbeven462
@0xbeven462 2 ай бұрын
🎉 great talk , though it maybe underrvalued your illustrated valuable insights into shady platforms and shit loads that occur to bug hunters, misrepresentation etc, nice talk
@mohamednasseribrahem
@mohamednasseribrahem 2 ай бұрын
I am starting hunting nowadays but I am a little afraid of this question Will bug hunt decline or end with the rise of the AI?
@TheStarcalibur
@TheStarcalibur Ай бұрын
They most probalbly think "thats their passion. They do it anyway, why should we pay for this?!" That is on so many sides just wrong and abusive. But i think its also a hint about who these people are. And think about if the hacking comunity should not branch out and make their own Bug bounty site. They have all the expertise. Dear .... If you read this idea and start doing it. Reach out to me and take me on board for sparking that process :) In a few years i will do it, bringing the right people together :)
@24bkdoor
@24bkdoor Ай бұрын
There are also organizations that wait for you to publicly disclose vulnerabilities and intentionally ignore your reports so you do so, platforms that suggest bugs are not shared with customers but are. The struggle they are face with are the legal implications of not protecting their systems. Lately the pros of ethical reporting are outweighed by the cons. I hope your talk inspires change.
@shadowunifer
@shadowunifer Ай бұрын
This is why I’m extremely paranoid about how I submit bugs and tend to sell them instead. My time and skills are valuable.
@cosmin91ro
@cosmin91ro 2 ай бұрын
you have my respects man, but I was expecting mentioning about wanna be hackers that throws shitty reports and spams both platform triagers and programs' security teams, hoping to full them to get a 100$ bounty
@pcguy619
@pcguy619 Ай бұрын
For real… or CVEs rated at high 9s that claim “code execution is possible” but are at most only memory corruption. POC or GTFO!
@nullvoid3545
@nullvoid3545 2 ай бұрын
Why not make A but bounty "union" that instead acts as an intermediary between hunters and the platforms taking the contracts for bug bounties. If the platforms wont take your bugs because you didn't sign A contract, then you now have A barrier for negotiating. The bugs can be sent to either regulators(Does threatening to report A crime count as extortion?) or the company themselves with the advantage that A group representative has A larger megaphone to(responsibly) disclose publicly that this company would not pay you under this more equitable arrangement. Best I got. But I think it's A better plan than hoping they simply choose to be less exploitative.(On the internet?)
@mattf.2142
@mattf.2142 25 күн бұрын
This is the reason I didn't pursue these platforms. I literally signed up, and found an XSS attack on a site. It took me like 10 minutes. And I couldn't believe it. But when I submitted the report, they said it was already found. It probably was, as it was so easy. But why wasn't it fixed? And there's no proof. Fook that.
@AlexFlores-o5b
@AlexFlores-o5b 2 ай бұрын
Where can I sign up? Can’t be worst than AT&T
@sysadmin1350
@sysadmin1350 Ай бұрын
Great talk
@dosesandmimoses
@dosesandmimoses 2 ай бұрын
I brought this topic up to Dr. Hinton respectfully..
@monh964
@monh964 2 ай бұрын
This is sad, i thnk the black market is better
@regular3dguy830
@regular3dguy830 2 ай бұрын
Great talk!
@itsmemyme
@itsmemyme 2 ай бұрын
lets implment some decentralized id or attachment which can trace out for found instances and properly pay for percentage to hunter
@zak6820
@zak6820 2 ай бұрын
wow respect to jasson haddix
@JoeRogansForehead
@JoeRogansForehead Ай бұрын
I thought bug crowd was when more than 4 gay people formed a line?
@mwebsec
@mwebsec 25 күн бұрын
🔥🔥🔥
@slussssy01
@slussssy01 2 ай бұрын
Love you haddix
@biz1M
@biz1M Ай бұрын
Have seen BC employees stealing research (0day) then claiming the bounty on other targets leveraging the same tech stack. Repulsive behavior and blacklisted. Also seen employed hackers within firms share a 0day within the firm with strict instructions do duh, DO NOT LEAK to then be abused/leaked by said "future" employee who even went as far as asking on twitter for some bypasses for this very specific vector. BB is a scam.
@eyezikandexploits
@eyezikandexploits 2 ай бұрын
This is kinda messed up
@bughunter9766
@bughunter9766 Ай бұрын
3rd party shit happened to me,, with full access to cloud read and write,, with all the employees data.
@eshayz
@eshayz 2 ай бұрын
Hackers being replaced by AI before GTA 6
@dosesandmimoses
@dosesandmimoses 2 ай бұрын
Also- the court systems - online.
@Zarnubius
@Zarnubius 24 күн бұрын
he should have named it "how to hack the hacking community"
@LewisCowles
@LewisCowles 2 ай бұрын
Very interesting, and definitely food for thought. Doesn't sound very realistic though. "Shitty customers" feels like "anyone who doesn't do what I'd advise".
@theodorekorehonen
@theodorekorehonen Ай бұрын
Do you work for one of these companies? Your comment really has this "I'm a middle manager whose only task is to throw a wrench in the works and feel self important" energy. Or perhaps you're just someone whose personally trends towards the bootlicking side?
@myfaveyoutube
@myfaveyoutube Ай бұрын
my dude
@jnyc
@jnyc Ай бұрын
STOP HELPING THEM!! LET THEM EAT THE BUGS!
@AndreeaCe
@AndreeaCe Ай бұрын
(Better now?) American Magnet ;))
@ruckica
@ruckica 19 күн бұрын
youre not getting any cash thats for one
@usamaarshad1766
@usamaarshad1766 2 ай бұрын
Rep++
@netbin
@netbin 2 ай бұрын
/notes
@mrluke8264
@mrluke8264 21 күн бұрын
Microsoft the biggest ip thief
@k0ns0l
@k0ns0l 2 ай бұрын
YOLO :p
@0x5001
@0x5001 Ай бұрын
bug bounty is scam :)
@cyb0rgh4kr
@cyb0rgh4kr 2 ай бұрын
Freakin Jason HaddiX! best wishes to your FAM bro @jasonhaddix
@safisec
@safisec 2 ай бұрын
Thanks @jhaddixP 100% Truth.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Bug Bounty Q&A with Jhaddix & Blaklis
54:45
Bug Bounty Reports Explained
Рет қаралды 8 М.
Hackers Who Get Paid to Hack Companies | Short Documentary
15:39
a fan told me i couldn't find her book
9:10
RAINBOLT
Рет қаралды 1,2 МЛН
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН