DEF CON 32 - Top War Stories from a TryHard Bug Bounty Hunter -Justin Rhynorater Gardner

DEF CON 32 - Top War Stories from a TryHard Bug Bounty Hunter -Justin Rhynorater Gardner

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 50:39

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The video details 11 critical vulnerabilities discovered during live bug bounty hunting, highlighting the importance of deep research, threat modeling, and creative thinking in identifying complex exploits.

Key Takeaways:
• Engine X 403 bypass leading to 4.5M PII leaks via path traversal 1:50
• Arbitrary account takeover via exposed API with hardcoded credentials 6:02
• Blind XSS via SMS leading to session token theft and mass account hijacking 10:41
• Snoop on meetings by exploiting a missing audio signal in the join flow 15:51
• Perforce server-to-client RCE via malicious file upload and path traversal 22:39
• Router shell via configuration file injection in DNS mask with tftp server exploitation 31:04

Successful bug hunting requires persistence, curiosity, and deep due diligence—especially in unfamiliar domains like IoT or desktop apps.

Sources:

  • 1:50 Engine X 403 bypass with path traversal and PII leak
  • 6:02 Arbitrary account takeover via exposed API and hardcoded credentials
  • 10:41 Blind XSS via SMS leading to session theft and mass account hijacking
  • 15:51 Meeting snooping via missing audio signal in join flow
  • 22:39 Perforce RCE via malicious file upload and path traversal
  • 31:04 Router shell via DNS mask configuration injection and tftp exploitation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

all righty y'all I think we're going to go ahead and get started a little bit early uh sorry for any of the people that are coming in at the last minute but we'll go ahead and uh get rolling also I realized that I got super lucky because uh this is the last slot of the day so uh we can go a little bit long which is exciting you guys can hear me all right on this one too right I kind of like to walk around a little bit okay so I need to point it right at it okay so uh for any of you the guys that don't know me I'm Justin Gardner AKA Rhino Raider I'm a professional live hacking event participant AKA full time bug Bounty AKA no job and uh I hack web applications mostly and iot devices uh occasionally and sometimes mobile devices when Joel is here to help me out um I'm the host of the critical…