1 of 30

Finding P1s at will

Satyam Gothi

2 of 30

whoami

  • Full Time Bug Bounty Hunter
  • Synack Red Team Member
  • Content Creator - @RogueSMG
  • Null Ahmedabad Volunteer

3 of 30

Bounty pls

Processing the Info

Thinking “inside” the Box

THE LAZY APPROACH

01

02

03

4 of 30

Free Food!

01

5 of 30

6 of 30

7 of 30

8 of 30

9 of 30

THAT SWEET REPLY

10 of 30

11 of 30

12 of 30

13 of 30

FEW DAYS LATER…

14 of 30

Remote Code Execution

02

15 of 30

16 of 30

17 of 30

18 of 30

19 of 30

SQL Injection

03

20 of 30

21 of 30

22 of 30

23 of 30

Improper Access Control / Information Disclosures

04

24 of 30

25 of 30

26 of 30

27 of 30

28 of 30

BONUS

29 of 30

#BUGBOUNTYTIPS #BoomP1in5mins

  • Stop assuming the “Obvious”
  • Tools are just Supplements
  • Don’t Overcomplicate stuff
  • Ask Stupid Questions
  • Don’t collaborate, make Friends
  • Compete less, enjoy more :)

30 of 30

THANK YOU

Please keep this slide for attribution

CREDITS: This presentation template was created by Slidesgo, including icons by Flaticon, and infographics & images by Freepik