The Bug Hunter's Methodology - Application Analysis | Jason Haddix

  Рет қаралды 93,399

HackerOne

HackerOne

Күн бұрын

Jason is the Head of Security for a leading videogame company. Previously he was VP of Trust and Security at Bugcrowd and currently holds the 29th all-time ranked researcher position. Before that, Jason had a distinguished 10-year career as a penetration tester and was Director of Penetration Testing for HP. He is a hacker and bug hunter through and through and currently specializes in recon and web application analysis. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason lives in Colorado with his wife and three children. Jason has presented all over the world teaching ethical hacking, including speaking and keynotes at conferences such as DEFCON, BlackHat, RSA, Rootcon, NullCon, B-sides, and SANS.
This H@cktivitycon talk was given at the H1-702 Live Hacking Event in Las Vegas!
Follow Jason: / jhaddix
▼ Keep up with us ▼
◇ Twitter → / hacker0x01​
◇ Twitch → / hackeronetv
◇ Instagram → www.instagram....

Пікірлер: 53
@AnthonyMcqueen1987
@AnthonyMcqueen1987 6 ай бұрын
Unlike most top researchers out there who do nothing but flex their bounties and give cryptic generic advise or how they got those bugs to me those people add nothing to the community. But people like Haddix who doesnt show off how much he has made or flex his bounties actually explains in detail what he does. He also updates his style and methodology and its not for everyone but he does give detail to how he finds bugs and does his recon unlike most out there and i respect that. Researchers who flex their bounties offer nothing to the community Researchers like Haddix offer a lot to the community.
@auwalsalisu7889
@auwalsalisu7889 6 ай бұрын
you said nothing but pure 100% truth, you literally spoke my mind
@AnthonyMcqueen1987
@AnthonyMcqueen1987 6 ай бұрын
@auwalsalisu7889 I am just sick of researchers out there who do nothing and show off their bounties. These people make the profession worse IMO and add nothing. Haddix on the other hand I respect.
@shiiswii4136
@shiiswii4136 6 ай бұрын
​@@AnthonyMcqueen1987look up Ryan John and ippsec, these guys are pure fundamentals and no nonsense in the videos
@madcane13
@madcane13 2 жыл бұрын
json headache... utterly... no words can explain how brilliant he is... you rock
@rynomas4948
@rynomas4948 Жыл бұрын
He is haddix bro, not headache. 😆
@viralledshow7079
@viralledshow7079 Жыл бұрын
@@rynomas4948might be auto correct error brother....!😂
@wk8173
@wk8173 Жыл бұрын
@@rynomas4948 grateful he didn't go for json headless💀
@SankizTime
@SankizTime Жыл бұрын
Lmao😂
@skysunset877
@skysunset877 8 ай бұрын
I'm deeply grateful that you explained this specific procedure for bugbounty. As a beginner, it helped me a lot with my studies.
@goohaver
@goohaver 6 ай бұрын
same here. good luck homie
@iqyou-gw4kd
@iqyou-gw4kd 2 жыл бұрын
Thank you everyone for helping the community evolve
@eyephpmyadmin6988
@eyephpmyadmin6988 Жыл бұрын
Took notes on everything, every tool, all the methodology
@MdMilonHossainNil
@MdMilonHossainNil Жыл бұрын
❤❤Oh my God, this is what I've been waiting for!! It looks beautiful!!❤❤
@AmineAb
@AmineAb Жыл бұрын
Really informative talk, but at the end he wasn’t using Notion for the note-taking part as stated, it was Obsidian.
@esamlasheen453
@esamlasheen453 Жыл бұрын
hhh i see it too
@popo_hack
@popo_hack Жыл бұрын
Thank you Jason for this amazing presentation, it was very fruitful with alot of knowledge. I think it's very important to know where to start testing and what are the tools that can help you doing that😀
@AlecMaly
@AlecMaly Жыл бұрын
Great presentation! Thank you for sharing your expertise!
@rlfps
@rlfps Ай бұрын
I'll be watching this video a few times. Awesome, awesome!
@emanuelepicariello
@emanuelepicariello Жыл бұрын
Great video thanks, it’s time to build a proper methodology now 🕵🏽‍♂️
@fp1036
@fp1036 5 ай бұрын
Thank you for your passionate sharing Sir!
@sapienshack1711
@sapienshack1711 7 ай бұрын
Jason Haddix you are awesome
@aalekhmotani3877
@aalekhmotani3877 Ай бұрын
Thanks a lot for all this
@actuallyclover
@actuallyclover 6 ай бұрын
I went to college with Corben! Super smart guy
@0xfsec
@0xfsec 2 жыл бұрын
Can I get the slide presentation?
@godzab
@godzab 2 жыл бұрын
I second this!
@william_ade
@william_ade 2 жыл бұрын
This is brilliant !
@سامرسعيد-ي1ب
@سامرسعيد-ي1ب 18 күн бұрын
“There are bugs in every single aplication”
@william_ade
@william_ade Жыл бұрын
how can we get the slides ??
@Khal_Rheg0
@Khal_Rheg0 6 ай бұрын
Thank you!
@wise.wanderer.00
@wise.wanderer.00 2 жыл бұрын
Very informative talk
@hamidrahamaabakar7995
@hamidrahamaabakar7995 9 ай бұрын
Good morning I'm very appreciate you
@samgold9151
@samgold9151 Жыл бұрын
Thank you
@4liraah
@4liraah 8 ай бұрын
Thanks for the talk! Any chance we can get a link to the slides?
@Booom1444-_-
@Booom1444-_- 7 ай бұрын
Slides?
@bugs-lk3jf
@bugs-lk3jf Жыл бұрын
Great Content , like a Boss
@anasshaikh5778
@anasshaikh5778 Жыл бұрын
Rustscan might not be helpful Since most of the programs have speed limitations like 10 req/s etc..
@reactivicky
@reactivicky Жыл бұрын
Nice tips.
@Ln0rag
@Ln0rag Жыл бұрын
where to find the slides file ?
@thehackr.
@thehackr. 2 жыл бұрын
nyc one
@esamlasheen453
@esamlasheen453 Жыл бұрын
45:36 Jason It's obsidian not notion!
@TheCyberWarriorGuy
@TheCyberWarriorGuy Жыл бұрын
Legend :)
@ExploitDeveloper
@ExploitDeveloper Жыл бұрын
thats good
@mariarahelvarnhagen2729
@mariarahelvarnhagen2729 Жыл бұрын
The Financial Instruments Game
@shantanusharma5624
@shantanusharma5624 Жыл бұрын
Woah!! I'm the 1Kth liker of this video
@bountyproofs
@bountyproofs 5 ай бұрын
if you don't CREATE your own METHODOLOGY this is worth NOTHING for YOU
@garywilburn7384
@garywilburn7384 Жыл бұрын
I'll give you a dollar if you learn to pronounce "obligatory" properly 😂
@ll-ruby..gloom-ll
@ll-ruby..gloom-ll 9 ай бұрын
he did
@CaseyStrouse
@CaseyStrouse Жыл бұрын
jsnice is the best tool I've found for making sense of obfuscated js. Definitely check it out.
@awanakb4867
@awanakb4867 Жыл бұрын
how can i find these word lists
@AmineAb
@AmineAb Жыл бұрын
Everthing is on the talk.. if you can’t find those wordlists, I don’t know how you will find bugs
@awanakb4867
@awanakb4867 Жыл бұрын
@@AmineAb i found them already. it just needed some attention.
Updated Beginners Guide to API Bug Bounty
30:05
InsiderPhD
Рет қаралды 14 М.
Which One Is The Best - From Small To Giant #katebrush #shorts
00:17
Angry Sigma Dog 🤣🤣 Aayush #momson #memes #funny #comedy
00:16
ASquare Crew
Рет қаралды 51 МЛН
отомстил?
00:56
История одного вокалиста
Рет қаралды 7 МЛН
Pendulum series #16 - hosted by Dr Serena Wadhwa
31:51
Promila Kumar
Рет қаралды 3
Modern Adversarial Reconnaissance - Long Live the External
40:43
SANS Offensive Operations
Рет қаралды 5 М.
“Recon Like an Adversary” by Jason Haddix at IWCON2023
1:01:13
Infosec Studio by IW
Рет қаралды 15 М.
Web Application Penetration Testing - A Practical Methodology
1:16:34
#NahamCon2024: .js Files Are Your Friends | @zseano
24:04
NahamSec
Рет қаралды 9 М.
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 154 М.
Attacking organizations with big scopes: from zero to hero
50:50
Positive Events Eng
Рет қаралды 14 М.
The Bug Hunter's Methodology Full 2-hour Training by Jason Haddix
1:53:53
Red Team Village
Рет қаралды 165 М.
Which One Is The Best - From Small To Giant #katebrush #shorts
00:17