DEF CON 33 - Referral Beware, Your Rewards Are Mine  - Whit @un1tycyb3r Taylor

DEF CON 33 - Referral Beware, Your Rewards Are Mine - Whit @un1tycyb3r Taylor

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:33

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Whit Taylor presents research on vulnerabilities in referral reward programs, demonstrating how these common features can lead to significant security issues including financial exploits. 0:00

Key Takeaways:
• Referral programs are widely implemented by companies but often overlooked from a security perspective, with common implementations including URL-to-cookie, client-side requests, promo codes, and mobile app integrations. 1:51-4:12
• Vulnerabilities include client-side gadgets (cookie injection, patch reversals), business logic errors (infinite credit flaw, order cancellation bypass), race conditions, and referral hijacking techniques. 6:00-14:26
• The research uncovered serious financial impacts including an "infinite money flaw" that allowed generating thousands of dollars in credit, demonstrating the real-world significance of these vulnerabilities. 8:28-9:52
• Bug bounty programs often undervalued these findings, with the researcher making less than $1,000 despite over 25 submissions, highlighting challenges in security research compensation. 17:09-17:52

Taylor's work reveals that referral reward programs represent an under-researched attack surface with serious security implications that companies should address as part of their security programs.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Thank you all for coming to my talk. I was wasn't really sure what to expect, but um this is referable where your rewards are mine. Exploring insecurity and incentive rewards program. This was a project that I did for a research project I did for my work that I found a lot of interest in and I hope you guys find a lot of interest in it too. Um so just a little bit about who I am because unless you're one of these people in the front row, you have no clue who I am. Um my name is Whit Taylor. Uh if you see me online, I go by Unity Cyber on all platforms. Um, I am an application pentester at Rhino Security Labs. And outside of that, I do a whole lot of bug bounty hunting, uh, security research on open source projects, things like that. Proud father and husband, um, to a beautiful wife and a v…