How I found the $1,500 SSRF in Stripe bug bounty program

  Рет қаралды 11,185

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

Пікірлер: 30
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Welcome to the comment section, I hope you enjoyed the video. Go here if you want to join BBRE Premium before the price goes up: bbre.dev/premium
@francisdonald4298
@francisdonald4298 2 жыл бұрын
Hey bro can learning webdevelopment assist with bugbounty???? Answer please
@sauer.voussoir
@sauer.voussoir Жыл бұрын
I disabled my adblock to support your channel, it really helps me a lot to get started on this bug bounty. Your videos are very informative.
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
Thank you!
@bertrandfossung1216
@bertrandfossung1216 2 жыл бұрын
Thanks for sharing this bro. I learnt a lot
@jpierce2l33t
@jpierce2l33t 2 жыл бұрын
Nice dude! I gotta learn Go sometime, some of its syntax is confusing because I've never studied it. A lot of it is similar to C-type languages, but a lot of it isn't 🤣
@shaarawyshaarawy8628
@shaarawyshaarawy8628 2 жыл бұрын
Good job bro ❤️❤️🙏
@aneeltripathy7420
@aneeltripathy7420 2 жыл бұрын
how can I open a web applications files in vsc ??
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
You need to have the source code
@DavenSec
@DavenSec 2 жыл бұрын
Wow that was a so nice idea to use the dns dot, congratulations man !
@j4ck_d4niels
@j4ck_d4niels 2 жыл бұрын
Thnx for sharing awesome content
@0xgodson119
@0xgodson119 2 жыл бұрын
presentation link? 8:50
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Good point, the presentation is not yet available on KZbin, I'll link it as soon as it's published.
@0xgodson119
@0xgodson119 2 жыл бұрын
@@BugBountyReportsExplained ya, that's why I asked to make sure thats not public
@chaitubhojane6137
@chaitubhojane6137 2 жыл бұрын
@@BugBountyReportsExplained I learn from u. Great lessons. You are like my ta's in uni.
@0xgodson119
@0xgodson119 2 жыл бұрын
Super Cool!
@raff000
@raff000 2 жыл бұрын
Great video but I didn't understand how would you be able to extract any information from this. If you point your webhook request to the internal network how can you get any information to be redirected to you?
@marvelmaniac_
@marvelmaniac_ 2 жыл бұрын
Its basically a blind ssrf in that case where you are able to scan internal ports and ips . (Low impact bug)
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Stripe gives you webhook logs and you can see http responses there
@raff000
@raff000 2 жыл бұрын
@@BugBountyReportsExplained ah ok that makes sense. Thanks
@kamilonurozkaleli
@kamilonurozkaleli 2 жыл бұрын
is there any other BB reports using this method or did you just invent it? Congarts btw really smart one!
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
I learnt this from another report a long time ago
@Lainad27
@Lainad27 2 жыл бұрын
why the reupload?
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
It's not a reupload. If you are signed up to my newsletter, you get access to these videos before the release on KZbin
@monKeman495
@monKeman495 2 жыл бұрын
big brain time: trailing dot in dns
@crusader_
@crusader_ 2 жыл бұрын
Loved it
@saiya-jin
@saiya-jin 2 жыл бұрын
If I subscribe now with the monthly subscription and stay subscribed with recurring payments, would it stay on the old price? Or does the old price offer only work for annual subscription?
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Yes, with the monthly subscription you also stay at the current price forever.
@saiya-jin
@saiya-jin 2 жыл бұрын
@@BugBountyReportsExplained that's great! Thanks
@sim4n6
@sim4n6 2 жыл бұрын
Sweet
How to get greater bounties for MEDIUM and LOW risk reports? Account takeover - Stripe
12:55
SSRF EXPLOITATION: FILE DISCLOSURE | 2023 | BUG BOUNTY
9:41
BePractical
Рет қаралды 8 М.
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Chain Game Strong ⛓️
00:21
Anwar Jibawi
Рет қаралды 41 МЛН
Bug Bounty | $2000 for SSRF bypass using DNS rebinding
12:47
Leet Cipher
Рет қаралды 39 М.
An overlooked parameter leads to a critical SSRF in Dropbox bug bounty program
7:36
Bug Bounty Reports Explained
Рет қаралды 8 М.
Find and Exploit Server-Side Request Forgery (SSRF)
8:56
The Cyber Mentor
Рет қаралды 46 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 86 М.
Cross Site Request Forgery vs Server Side Request Forgery Explained
12:23
Server-Side Request Forgery (SSRF) Explained
15:58
NahamSec
Рет қаралды 32 М.
This is my coolest bug bounty report (SSRF ➡ Phishing)
10:05
Bug Bounty Reports Explained
Рет қаралды 9 М.
SSRF & Network Enumeration
6:25
Ryan John
Рет қаралды 4,3 М.
GitLab’s First Critical SSRF since 2020
17:20
Bug Bounty Reports Explained
Рет қаралды 3,7 М.