Critical Thinking - Bug Bounty Podcast

Episode 15: The Israeli Million-Dollar Hacker


Listen Later

Episode 15: In this episode of Critical Thinking - Bug Bounty Podcast we talk with the latest Million-Dollar bug bounty hunter: @naglinagli . He talks about his climb from $1,000 in bounties to $1,000,000, recon tips and tricks, and some bug reports that made the news and landed him the "Best Bug" award at a H1 Live Hacking event.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

Follow Nagli and his new startup Shockwave:

https://twitter.com/naglinagli

https://twitter.com/shockwave_sec

HackMD Collaborative Notes:

https://hackmd.io/

Ian Carroll's Airline Miles Website:

https://seats.aero

Nagli's Tweet in ChatGPT Web Cache Deception:

https://twitter.com/naglinagli/status/1639343866313601024

Timestamps:

(00:00:00) Intro

(00:04:40) Nagli’s Climb

(00:05:40) What kind of vulns do you look for?

(00:09:25) Working with other hackers

(00:10:20) Bug Bounty Hunter’s Guild

(00:12:35) Shockwave product

(00:14:12) Outsourcing tool development

(00:18:46) What got you started?

(00:21:13) Manual hacking vs recon suite + LHE focus

(00:25:00) How do you take notes

(00:29:42) Biggest things that you’ve learned over the past 2 years

(00:31:29) How do you ingest new techniques?

(00:31:50) Collaboration

(00:37:20) Justin Ranting about “Trained Eyes”

(00:40:18) Time spent coding vs hacking

(00:45:28) Travel and spending habits

(00:54:16) Grep is Nagli’s database

(00:56:20) Nagli’s ChatGPT Web Cache Deception

(00:58:44) What does your alerting look like?

(01:01:50) Nagli’s “Most Critical” SSRF

(01:04:30) Burp Active Scan

...more
View all episodesView all episodes
Download on the App Store

Critical Thinking - Bug Bounty PodcastBy Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

  • 5
  • 5
  • 5
  • 5
  • 5

5

53 ratings


More shows like Critical Thinking - Bug Bounty Podcast

View all
Radiolab by WNYC Studios

Radiolab

44,050 Listeners

StarTalk Radio by Neil deGrasse Tyson

StarTalk Radio

14,356 Listeners

Hacked by Hacked

Hacked

190 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,005 Listeners

The Vergecast by The Verge

The Vergecast

3,718 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,032 Listeners

Click Here by Recorded Future News

Click Here

423 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,092 Listeners

The Indicator from Planet Money by NPR

The Indicator from Planet Money

9,578 Listeners

The Jordan Harbinger Show by Jordan Harbinger

The Jordan Harbinger Show

12,017 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

My First Million by Hubspot Media

My First Million

2,660 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

16,261 Listeners