
Overview

Udemy Special: Ends May 28!
Learn Data Science. Courses starting at $12.99.
Get Deal
Explore the world of offensive security and ethical hacking in this 42-minute conference talk by Ben Sadeghipour (NahamSec) recorded at YOW! Australia 2024. Discover how AI can enhance bug bounty hunting through real-world examples of critical vulnerabilities in modern web applications. Learn about asset discovery techniques, including a fascinating case study of hacking NASA, and understand common vulnerabilities like insecure direct object references, unauthenticated API access that leaks user PII, IIS short name enumeration, and zip slip attacks. The presentation includes a practical demonstration and concludes with valuable insights for aspiring ethical hackers. Perfect for cybersecurity enthusiasts, this talk showcases how ethical hackers have earned significant bounties ($1M since 2022) and how AI tools can streamline the vulnerability discovery process.
Syllabus
00:00 Intro
02:07 What's a bug bounty?
03:11 $1M since 2022
04:06 Easier with AI
06:21 Applied AI for bug bounties
08:16 Asset discovery
09:55 Hacking NASA
16:33 Insecure direct object reference
18:59 Unauthenticated access to the API leaks user PIl
23:11 IIS short name enumeration
31:53 Zip slip
37:20 Demo
39:20 Final thoughts
41:35 Outro
Taught by
GOTO Conferences