
DEF CON 32 - Top War Stories from a TryHard Bug Bounty Hunter -Justin Rhynorater Gardner
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 50:39
BLUF: The video details 11 critical vulnerabilities discovered during live bug bounty hunting, highlighting the importance of deep research, threat modeling, and creative thinking in identifying complex exploits.
Key Takeaways:
• Engine X 403 bypass leading to 4.5M PII leaks via path traversal 1:50
• Arbitrary account takeover via exposed API with hardcoded credentials 6:02
• Blind XSS via SMS leading to session token theft and mass account hijacking 10:41
• Snoop on meetings by exploiting a missing audio signal in the join flow 15:51
• Perforce server-to-client RCE via malicious file upload and path traversal 22:39
• Router shell via configuration file injection in DNS mask with tftp server exploitation 31:04
Successful bug hunting requires persistence, curiosity, and deep due diligence—especially in unfamiliar domains like IoT or desktop apps.
Sources:
- 1:50 Engine X 403 bypass with path traversal and PII leak
- 6:02 Arbitrary account takeover via exposed API and hardcoded credentials
- 10:41 Blind XSS via SMS leading to session theft and mass account hijacking
- 15:51 Meeting snooping via missing audio signal in join flow
- 22:39 Perforce RCE via malicious file upload and path traversal
- 31:04 Router shell via DNS mask configuration injection and tftp exploitation
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all righty y'all I think we're going to go ahead and get started a little bit early uh sorry for any of the people that are coming in at the last minute but we'll go ahead and uh get rolling also I realized that I got super lucky because uh this is the last slot of the day so uh we can go a little bit long which is exciting you guys can hear me all right on this one too right I kind of like to walk around a little bit okay so I need to point it right at it okay so uh for any of you the guys that don't know me I'm Justin Gardner AKA Rhino Raider I'm a professional live hacking event participant AKA full time bug Bounty AKA no job and uh I hack web applications mostly and iot devices uh occasionally and sometimes mobile devices when Joel is here to help me out um I'm the host of the critical…