
DEF CON 33 - Regex For Hackers - Adam 'BuildHackSecure' Langley, Ben 'nahamsec' Sadeghipour
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 50:10
The workshop teaches regex fundamentals for security testing and bug bounty hunting 0:00-0:49, 2:39-3:25. Ben and Adam introduce themselves as experienced bug bounty hunters who co-founded HackingHub to train the next generation of hackers 1:16-2:36.
Key Takeaways:
• Regex is a search pattern language that helps find, match, and extract specific parts of text from strings, functioning like a state machine 5:38-6:11
• Common regex vulnerabilities in security implementations include missing anchors, unescaped periods, and overly permissive character sets 22:36-23:38, 24:00-25:15
• Regex can be used for reconnaissance on GitHub to discover subdomains, APIs, and leaked source code that traditional tools might miss 34:13-36:23
• Practical applications include finding SSRF vulnerabilities, open redirects, and CORS misconfigurations through regex pattern analysis 19:57-20:26, 27:36-32:05
The speakers demonstrate how regex vulnerabilities can lead to significant security issues like account takeovers, with examples earning bounties up to $14,000 27:23-27:36.
Sources:
- 0:00-0:49 Introduction to the regex workshop at Defcon
- 1:16-2:36 Presenters' backgrounds in bug bounty hunting and founding HackingHub
- 5:38-6:11 Explanation of what regex is and how it functions
- 22:36-23:38 Post message vulnerability example with regex issues
- 34:13-36:23 Using regex for GitHub reconnaissance to find subdomains and APIs
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, good morning. >> Morning. >> See, uh, everyone showed up bright and early know it's uh, it's a little early for a conference, but thank you guys for coming this early and joining us. Uh, my name is Ben Sigapur and I have Adam here. Uh, we every year come to uh, Defcon and we try to do a workshop that's different and we'll talk about the workshop today, but this is I think a fundamentally interesting and useful skill uh, that we want you to take away. There is a lot of slides to go through today. So, we're going to go through them as fast as we can. I think he has 190 slides or something like that. >> 198 >> 198 slides. >> Takes about 18 seconds per slide. >> Yeah. So, it's uh it's going to be very fast. It's going to be a lot of reax stuff and then we're going to apply it to bug…