THREAT CON 2022- XSS Curioxssity by Ahmad Ashraff

THREAT CON 2022- XSS Curioxssity by Ahmad Ashraff

THREAT CON

1 год назад

408 Просмотров

Today, all bugbounty hunters have a methodology for hunting bugs. Some focus on an intensive recon approach to identify their 'golden pots'. Some spend time analysing the source codes before the hunt and others rely exclusively on automation tools.
Whatever approach you choose, there will be a result. In this presentation, the speaker will share his experience with bugbounty by focusing on only one type of vulnerability, Cross-site Scripting (XSS).
While most of the web applications tested are generally vulnerable to this vulnerability, there are times when they are not thoroughly tested due to the annoying filters or WAF enabled on them. Does that mean they are bulletproof?
In this presentation, the presenter will share tips and tricks that he used during this situation to get a decent amount of side income.

Slides: https://2022.threatcon.io/media/BountyTrack/XSS%20Curioxssity.pdf
Ссылки и html тэги не поддерживаются


Комментарии: