DEF CON 33 - Regex For Hackers - Adam 'BuildHackSecure' Langley, Ben 'nahamsec' Sadeghipour

DEF CON 33 - Regex For Hackers - Adam 'BuildHackSecure' Langley, Ben 'nahamsec' Sadeghipour

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 50:10

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The workshop teaches regex fundamentals for security testing and bug bounty hunting 0:00-0:49, 2:39-3:25. Ben and Adam introduce themselves as experienced bug bounty hunters who co-founded HackingHub to train the next generation of hackers 1:16-2:36.

Key Takeaways:
• Regex is a search pattern language that helps find, match, and extract specific parts of text from strings, functioning like a state machine 5:38-6:11
• Common regex vulnerabilities in security implementations include missing anchors, unescaped periods, and overly permissive character sets 22:36-23:38, 24:00-25:15
• Regex can be used for reconnaissance on GitHub to discover subdomains, APIs, and leaked source code that traditional tools might miss 34:13-36:23
• Practical applications include finding SSRF vulnerabilities, open redirects, and CORS misconfigurations through regex pattern analysis 19:57-20:26, 27:36-32:05

The speakers demonstrate how regex vulnerabilities can lead to significant security issues like account takeovers, with examples earning bounties up to $14,000 27:23-27:36.

Sources:

  • 0:00-0:49 Introduction to the regex workshop at Defcon
  • 1:16-2:36 Presenters' backgrounds in bug bounty hunting and founding HackingHub
  • 5:38-6:11 Explanation of what regex is and how it functions
  • 22:36-23:38 Post message vulnerability example with regex issues
  • 34:13-36:23 Using regex for GitHub reconnaissance to find subdomains and APIs

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, good morning. >> Morning. >> See, uh, everyone showed up bright and early know it's uh, it's a little early for a conference, but thank you guys for coming this early and joining us. Uh, my name is Ben Sigapur and I have Adam here. Uh, we every year come to uh, Defcon and we try to do a workshop that's different and we'll talk about the workshop today, but this is I think a fundamentally interesting and useful skill uh, that we want you to take away. There is a lot of slides to go through today. So, we're going to go through them as fast as we can. I think he has 190 slides or something like that. >> 198 >> 198 slides. >> Takes about 18 seconds per slide. >> Yeah. So, it's uh it's going to be very fast. It's going to be a lot of reax stuff and then we're going to apply it to bug…