DEF CON 32 - Practical Exploitation of DoS in Bug Bounty - Roni Lupin Carta

DEF CON 32 - Practical Exploitation of DoS in Bug Bounty - Roni Lupin Carta

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 30:36

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video presents practical exploitation techniques for denial of service (DoS) vulnerabilities in bug bounty programs, demonstrating how these often overlooked issues can yield substantial bounties - the presenter earned nearly $150,000 over eight months of focused research 29:07.

Key Takeaways:
• DoS vulnerabilities focus on impacting service availability and can have significant business impact, but are typically out of scope in bug bounty programs due to their potential to completely disrupt services 1:00
• Always get permission from bug bounty programs before testing DoS vulnerabilities to ensure they're aware of your testing activities 3:23
• Client-side DoS can be achieved with malformed HTML/JSON that crashes the frontend - one example earned $350 by making the sanitize HTML library crash the entire front end 8:54
• N+1 query problems can be exploited to create significant backend delays and potentially crash systems - this technique alone earned the team $46,000 12:01
• GraphQL endpoints are particularly vulnerable to DoS attacks through circular definitions, batching, aliases, and directive overloading, with the presenter earning $7,000 from GraphQL-related DoS vulnerabilities 21:27

The presenter emphasizes that while DoS vulnerabilities are often overlooked, they can be a valuable "side Golden Goose" for bug hunters when other vulnerability types are scarce 29:20.

Sources:

  • 1:00 Explanation of DoS impact and business significance
  • 3:23 Guidance on responsible disclos

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

uh so I'm happy to introduce uh Ronnie cararta uh and talking about practical exploitation in uh denial of service in bug bounties right thanks hi everyone I'm really happy to be there uh today this is the first ever uh bti Village and it's a true honor to do the first talk ever well we some technical difficulties of not having an HDMI cable but no worries we are there now um so the talk is about practical exploitation of the service in bti program so first of all my name is Ronnie I go by the nickname Lupin I'm the co-founder of lupan homes we are a security research and development company uh and I'm coming from the best city in the world uh grobble it's in the French apps lot of skiing beautiful place um I love uh denial of service I love denial of service because you can actually try t…