
DEF CON 33 - Referral Beware, Your Rewards Are Mine - Whit @un1tycyb3r Taylor
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:33
Whit Taylor presents research on vulnerabilities in referral reward programs, demonstrating how these common features can lead to significant security issues including financial exploits. 0:00
Key Takeaways:
• Referral programs are widely implemented by companies but often overlooked from a security perspective, with common implementations including URL-to-cookie, client-side requests, promo codes, and mobile app integrations. 1:51-4:12
• Vulnerabilities include client-side gadgets (cookie injection, patch reversals), business logic errors (infinite credit flaw, order cancellation bypass), race conditions, and referral hijacking techniques. 6:00-14:26
• The research uncovered serious financial impacts including an "infinite money flaw" that allowed generating thousands of dollars in credit, demonstrating the real-world significance of these vulnerabilities. 8:28-9:52
• Bug bounty programs often undervalued these findings, with the researcher making less than $1,000 despite over 25 submissions, highlighting challenges in security research compensation. 17:09-17:52
Taylor's work reveals that referral reward programs represent an under-researched attack surface with serious security implications that companies should address as part of their security programs.
Sources:
- 0:00 Introduction of the researcher and topic
- 1:51-4:12 Overview of referral program implementations
- 6:00-14:26 Details of vulnerabilities discovered
- 8:28-9:52 Infinite credit flaw explanation
- 17:09-17:52(https:/
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Thank you all for coming to my talk. I was wasn't really sure what to expect, but um this is referable where your rewards are mine. Exploring insecurity and incentive rewards program. This was a project that I did for a research project I did for my work that I found a lot of interest in and I hope you guys find a lot of interest in it too. Um so just a little bit about who I am because unless you're one of these people in the front row, you have no clue who I am. Um my name is Whit Taylor. Uh if you see me online, I go by Unity Cyber on all platforms. Um, I am an application pentester at Rhino Security Labs. And outside of that, I do a whole lot of bug bounty hunting, uh, security research on open source projects, things like that. Proud father and husband, um, to a beautiful wife and a v…