Тёмный

Bug bounty: year 2 - 0days, a $20k bounty and… laziness - bounty vlog #5 

Bug Bounty Reports Explained
Подписаться 56 тыс.
Просмотров 26 тыс.
50% 1

📧 Subscribe to BBRE Premium: bbre.dev/premium
✉️ Sign up for the mailing list: bbre.dev/nl
📣 Follow me on Twitter: bbre.dev/tw
2 years ago I quit my 9-5 job for bug bounty and create content. In the bounty vlog series I transparently tell you about my journey, with exact details about the number of reports and earnings. In this video, I'm talking about my 2nd year of bug bounty which was full of highs like a $20k bounty or scalable 0days but also lows that made me question my decision.
🖥 Get $100 in credits for Digital Ocean: bbre.dev/do

Опубликовано:

 

29 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 77   
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Thank you for watching the video! If you are interested in learning bug bounty with me, check out BBRE Premium: bbre.dev/premium This Black Friday you can join us there using a once-a-year deal. When you do, you will enjoy lifelong savings because your price will be immune to next year's and future price rises!
@climbingislife
@climbingislife 10 месяцев назад
aaaaah should have read this message as I just subbed 🤕 I'll see if I can save the code for next year or something
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
@@climbingislife You didn't lose out if you wanted to sub now because the code is not active yet ;)
@specl_ed1tz
@specl_ed1tz 10 месяцев назад
I can't afford it because what you're course fee is. My full month grocery budget is that. But in future may be some day i could buy...
@cwinhall
@cwinhall 10 месяцев назад
Never change Greg! The honesty is what separates you from the crowd and I absolutely commend you for it. Most other influencers want to sell a fake lifestyle of easy reports and huge rewards. The reality is different for the vast majority and it's refreshing to see someone talking about that. 👍👍👍
@Zizo8182
@Zizo8182 10 месяцев назад
+1
@SavageMasaki
@SavageMasaki 10 месяцев назад
+2
@LiveOverflow
@LiveOverflow 10 месяцев назад
amazing video as always!
@marijasilentj969
@marijasilentj969 10 месяцев назад
Thank you so much for this video! I was kinda giving up thinking I was alone fighting procrastination and having a hard time sticking around...this was just the kind of motivation that I needed. Thanks a lot xx
@waterlord6969
@waterlord6969 10 месяцев назад
Thank you for sharing your experience! I really appreciate you showing, even for a good bb tester, your struggles. ❤❤
@amoh96
@amoh96 10 месяцев назад
im beginner bug hunter i spend 9 month hunting and study bug bounty i only hunt for vdp i found 8 bugs ( 6 rxss & 2 blind xss ) any advice for me
@tushardaga-f7q
@tushardaga-f7q 10 месяцев назад
What a Video Man, Couldn't get more realistic advice than this, Thankyou for making content for us like this...
@francoramirezcastillo8075
@francoramirezcastillo8075 10 месяцев назад
Obviously with university studies related to computer science/programming, it will be a little easier to find bugs, but someone who studied nursing or a doctor or a lawyer or without university studies, will get to that, it would be more interesting
@tomsawyer6247
@tomsawyer6247 10 месяцев назад
bug bounty hunters are free workforce, for which company can decide pay or not pay
@diymaster101
@diymaster101 4 дня назад
Bro do you have best course or tutorial for beginners im very new to this please write back to me brother ❤ 🤝
@BugBountyReportsExplained
@BugBountyReportsExplained День назад
To be fair, while I try to explain things clearly for everyone, my content aims for intermediate and advanced audience
@opchannel8141
@opchannel8141 10 месяцев назад
8:33 LMAFO I would love to see message like this from triager 🤣🤣🤣
@WebWonders1
@WebWonders1 10 месяцев назад
Always love your content the way you remain transparent 💓 to us. Thanks for sharing 🙏.
@WebWonders1
@WebWonders1 10 месяцев назад
Thanks @@ptrcan4302 it means a lot to me🥰🤩
@cyberx14
@cyberx14 10 месяцев назад
Brother iam doing BB too will share my story too but you are love ❤ keep teaching dude
@diymaster101
@diymaster101 4 дня назад
Thanks bro ❤
@radhesearch
@radhesearch 3 месяца назад
sir can you do live bug hunting
@anounTT
@anounTT 10 месяцев назад
Shoutout to the BJJ training. What color / stripe belt are you now?
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
I'm a proud stripeless white belt haha. I've only been training for about 5 months now.
@specl_ed1tz
@specl_ed1tz 10 месяцев назад
I am from India in remote area from dumka (beside Kolkata). Your are honest to your work and inspiration for us . please reply 😊
@EzProgrammingPro
@EzProgrammingPro 3 месяца назад
Finally, someone who's honest and humble, I reached out to you on twitter when I got my first bug and even though it wasn't a high payout I was still happy to even get one and give me more motivation.
@noy5626
@noy5626 10 месяцев назад
I can’t stop getting duplicates and Not Applicable
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Then you probably need a bit more education on what's an acceptable bug or not.
@philippedelteil2489
@philippedelteil2489 10 месяцев назад
Great video. We all struggle in different ways, but most of the content in RU-vid or Twitter is only success, money and fame
@crusader_
@crusader_ 10 месяцев назад
Do you still do the 100 hours challenge personally
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
No, but I probably should
@RajaKumar-no6su
@RajaKumar-no6su 4 месяца назад
Your Biggest fan from India 🇮🇳
@ricarprieto
@ricarprieto 8 месяцев назад
Thanks bro, is really really useful for us! Keep you on track, is not easy but,you and pretty much everybody, can do it with consistency and discipline!
@cymzfr
@cymzfr 10 месяцев назад
My friend, can you refund the monthly subscription because I want to subscribe , the problem is I can't pay 100$ ): this is so many for us in Iraq
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Hi, sorry but I don't have a plan to rollback monthly subscription option.
@philippedelteil2489
@philippedelteil2489 10 месяцев назад
The f u part was really funny. 🎉🎉🎉🎉
@Mohsinkhan-bh7py
@Mohsinkhan-bh7py 10 месяцев назад
Excellent 💯💯
@thewholeworldblurred
@thewholeworldblurred 9 месяцев назад
Good luck going on a live hacking event greg!
@huncking
@huncking 10 месяцев назад
Is that $10 per month subscription going to be available on black Friday?
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Hi, sorry but I don't have a plan to rollback monthly subscription option.
@servantofgod3058
@servantofgod3058 10 месяцев назад
Amazing video as always ! I've been doing bug bounty for well over two years during high school. I neglected my education and was doing bug bounty 24/7 without getting paid a single buck. One day I decided to change my methodology and stumbled upon a bug , which later rewarded me with $7,500 !! I felt greatly motivated because it only took me less than 3 hours , I stopped doing bug bounty for a year or two and came back again cuz I needed more money, despite putting in a lot of effort, I was only getting dupes and informative bugs, but I keep going nevertheless cuz I know I'm not wasting my time, I'm developing my methodology and gaining more knowledge. And that's why a lot of newbies quit bug bounty hunting, it requires DEDICATION and immense effort.
@MiroPeev
@MiroPeev 7 месяцев назад
Awesome video, thank you 👍
@sveneFX
@sveneFX 9 месяцев назад
Thank you for the valuable insight!
@pro_lover719
@pro_lover719 6 месяцев назад
Pure honesty❤ you’ve earned me as a subscriber
@Hariom_Singh22
@Hariom_Singh22 10 месяцев назад
Sir, your videos always give something new to learn ❤
@CBOPA
@CBOPA 10 месяцев назад
BRO 10:21 SOUND I ALMOST GOT A FUCKING HEART ATTACK. I'm in Ukraine and I thought a fucking rocket is closing on my house...
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
not a weapon expert here but I'd say it's closer to a sword
@CBOPA
@CBOPA 10 месяцев назад
​@@BugBountyReportsExplained I had a pretty high volume, beginning of sound was fairly similar to a certain moment when shit's heading straight towards you,
@mohamedriyaz29
@mohamedriyaz29 10 месяцев назад
It was great watching this and was inspiring and motivating me to do bug hunting !!
@ahmetsaric5364
@ahmetsaric5364 7 месяцев назад
Thank you
@mnageh-bo1mm
@mnageh-bo1mm 10 месяцев назад
also where do find the people to automate stuff 😭😭 dude u could live as a king with these payouts in a 3rd country why don't just move.
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Well, throughout a big part of the year I live in developed yet cheap Poland and then I do digital nomading in also countries like Spain and right now I am planning the trip to Thailand for a few months. Living like this was actually a big factor for my decision to quit because I knew that I can earn in dollars and spend in much weaker currencies.
@mnageh-bo1mm
@mnageh-bo1mm 10 месяцев назад
​@@BugBountyReportsExplained well played king 🔥
@climbingislife
@climbingislife 10 месяцев назад
Thanks so much for sharing man, it's such an inspiration.
@mohammadrezaabbasi4841
@mohammadrezaabbasi4841 10 месяцев назад
Thanks a lot, You're awesome man.
@nobody-ho4yp
@nobody-ho4yp 10 месяцев назад
you got a good barber bro
@internet-eye
@internet-eye 9 месяцев назад
your honesty!! 🫶🏻
@workwork-oz4sc
@workwork-oz4sc 10 месяцев назад
Awsome
@R4xcy
@R4xcy 10 месяцев назад
Thanks! Great video
@suvanedits
@suvanedits 10 месяцев назад
awesome
@tharunbaalaji8306
@tharunbaalaji8306 10 месяцев назад
Thankx
@Proxyone444
@Proxyone444 10 месяцев назад
❤❤
@miteshvalvi1170
@miteshvalvi1170 10 месяцев назад
how many points are needed for a private program
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
I think after a single report you are getting some
@miteshvalvi1170
@miteshvalvi1170 10 месяцев назад
Thank you so munch sir@@BugBountyReportsExplained
@mariosst3880
@mariosst3880 10 месяцев назад
This is great to watch and get updated. However I think sometimes big bounties can cause a "false" idea of how likely is for someone to earn enough of BB. Since it all depends on how good some programs rewards for each severity. As you said 1 good reward made a huge difference on the comparison between 2 years.
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
Well, looking at other people only sharing their big bounties was my motivation to create this series
@Phuongang-ti6ch
@Phuongang-ti6ch 4 месяца назад
What can i find in BBRE premium?
@BugBountyReportsExplained
@BugBountyReportsExplained 4 месяца назад
go to bbre.dev/premium and find out ;)
@mnageh-bo1mm
@mnageh-bo1mm 10 месяцев назад
how were you able to find these vulnerable websites that did actually have a bug bounty program also do you report the zero day instantly or wait to find vulnerable instances first in case if it has auto update or something ?
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
I used either shodan or just looked at the "These companies use our software" sections on the official websites.
@mnageh-bo1mm
@mnageh-bo1mm 10 месяцев назад
​@@BugBountyReportsExplainednice, what about the second question?
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
@@mnageh-bo1mm I report it to the vendor first and then instantly I go find vulnerable instances before there's even a fix for the 0day. This also allows me to give company more value because I can give them a temporary mitigation or a monkey patch.
@mnageh-bo1mm
@mnageh-bo1mm 10 месяцев назад
@@BugBountyReportsExplained i see but doesn't that violate the Disclosure policy?
@BugBountyReportsExplained
@BugBountyReportsExplained 10 месяцев назад
@@mnageh-bo1mm The vendor usually doesn't offer reasonable bounties anyway so I'm willing to risk not receiving it at all.
@Andrei-ds8qv
@Andrei-ds8qv 10 месяцев назад
Man this video is awesome! Tha authenticity makes it so so good 🥲 thank you a lot!!!
Далее
Live Bug Bounty Hunting  🐛💵
18:06
Просмотров 41 тыс.
Bug Bounty с нуля за 30 минут
38:43
Просмотров 11 тыс.
Se las dejo ahí.
00:10
Просмотров 2,8 млн
Катаю тележки  🛒
08:48
Просмотров 534 тыс.
"Когти льва" Анатолий МАЛЕЦ
53:01
Bug Hunting is easy if you KNOW this
8:23
Просмотров 26 тыс.
The Truth About Bug Bounties
14:12
Просмотров 118 тыс.
$0 👉🏼 $1,000/Month With Bug Bounties
11:30
Просмотров 64 тыс.
Bug Bounty Changed My Life!
11:53
Просмотров 25 тыс.
When you Accidentally Compromise every CPU on Earth
15:59
Se las dejo ahí.
00:10
Просмотров 2,8 млн