My Favorite Bug Bounty Findings In 2025

My Favorite Bug Bounty Findings In 2025

Source: YouTube · NahamSec · published Dec 30, 2025 · 18:25

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The speaker introduces the Hamicon CTF, explaining that its custom "mission" challenges are directly inspired by real-world vulnerabilities they have discovered and reported through bug bounty programs 0:00-0:28.

Key Takeaways:
• Hamicon places a strong emphasis on its annual Capture The Flag (CTF) competition 0:00-0:07.
• Each year, the CTF features a custom "mission" built around a fake web app loaded with vulnerabilities 0:09-0:18.
• These mission challenges are directly inspired by actual vulnerabilities the speaker has found and reported on various bug bounty platforms 0:19-0:28.
• The speaker intends to walk through some of the challenges without fully solving them to avoid spoiling the event for active participants 0:29-0:33.

This video serves as a high-level walkthrough of the CTF's design, bridging the gap between practical bug bounty hunting and educational security challenges.

Sources:

  • 0:00-0:07 Introduction to Hamicon and its CTF tradition
  • 0:09-0:18 Explanation of the fake web app "missions"
  • 0:19-0:28 Using real bug bounty reports as challenge inspiration
  • 0:29-0:33 Intent to partially walkthrough without spoiling the CTF

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I just got done hosting the Hamicon and if you've ever attended any of the conferences in the past few years, you know how much pride we take in our CTF and this year's was no different. Every year we have a tradition of creating what we call a mission for our CTF and the mission is typically a fake vulnerability or a fake web app with a bunch of vulnerabilities within it and when we want to create these missions, we kind of go through my vulnerabilities I have found and reported to different bug bounty platforms and we kind of use them as inspiration to create these different challenges and this year's was no different and I kind of want to walk you through some of them. I don't want to solve the entire thing because I know people are still going through that mission and we didn't get a l…