DEF CON 33 - Sometimes you find bugs, sometimes bugs find you - Jasmin Landry JR0ch17

DEF CON 33 - Sometimes you find bugs, sometimes bugs find you - Jasmin Landry JR0ch17

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Bug bounty hunters often find vulnerabilities through luck, especially in unexpected or chaotic bugs that lead to humorous or unintended outcomes 0:19-0:25. The speaker shares four key bugs discovered during hunting, highlighting how blind testing and curiosity can yield surprising results.

Key Takeaways:
• A cloud compliance app revealed a blind XSS that exposed customer data via a deprecated QuickLook CSV plugin, leading to a P1 reward and bonus for accessing sensitive information 3:01-5:58.
• A Rails application had a blind XSS payload that triggered an internal email complaint, resulting in a four-digit bounty and a funny follow-up from the victim who claimed the researcher ruined his day 8:04-9:46.
• In a live hacking event, the researcher was added to an internal distribution list via a malformed email, gaining access to PII data for nearly a month before the bug was fixed 11:40-13:17.
• A WordPress deployment tool had a server-side template injection that exploited Ansible’s built-in lookup plugin, allowing extraction of environment variables and root-level access, with the vulnerability initially rated P2 but later recognized as severe 16:50-21:59.
• A fantasy sports app stripped passwords of certain characters, turning "I love dogs" into "I" and causing thousands of leagues to have no passwords, allowing the researcher to join them and win prize money 23:04-25:05.

These bugs showcase how seemingly minor flaws—often found through luck or poor input validation—can lead to significant data exposure, user confusion, or even unexpected rewards.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So, um, sometimes bug hunters, we find bugs, like we work really hard to find bugs, but sometimes we're lucky and bugs find us. So, my talk is about luck in a way. Um, so let's start. Um, I have to admit I grew up using PowerPoint. So, I'm still using PowerPoint for my slides. I'm not using uh Google Slides or any modern application. Um and I'm the kind of guy where black on white is like perfect, but I know it's not always visually appealing. So in PowerPoint, there's a feature called I think design suggestions where it's like AI based feature and it suggests like based on your contents a slide template for you uh where it's suggest like a couple of of designs. So, I picked one. This morning I noticed that Microsoft thinks that Canada we live in igloos. So, it shows my name based out of M…