The mindset for finding highs and crits in bug bounty with JR0ch17

📣 Follow JR0ch17 on Twitter: https://x.com/jr0ch17 ✉️ Sign up for the mailing list: https://bbre.dev/nl 📣 Follow me on Twitter: https://bbre.dev/tw Interview with Jasmin “JR0ch17” Landry, a former triager and security manager, now a full-time bug bounty hunter. We discuss bug bounty strategy, mindset, and finding high and critical vulnerabilities. BBRD podcast is also available on most popular podcast platforms: https://open.spotify.com/show/6tLoJ5f...    • Bug Bounty Reports Discussed   https://podcasts.apple.com/us/podcast... Links mentioned in the video: The web application hacker's handbook: https://amzn.to/3GS4t68 Xlif: https://docs.oracle.com/en/cloud/saas... DTD finder: https://github.com/GoSecure/dtd-finder Secondary path traversal blogpost: https://samcurry.net/hacking-starbucks OAuth dirty dancing: https://labs.detectify.com/writeups/a... Cognito doc-driver misconfiguration: https://docs.aws.amazon.com/elasticlo... Timestamps: 00:00 Intro 00:37 The road to becoming the full-time bug bounty hunter 20:06 The change in the mindset that lands a lot of highs and crits recently 23:02 SSRFs 24:33 How to test for SSTI? 28:54 Does SQLi still exist in 2025? 35:09 Where to test for XXEs? 41:33 Secondary path traversals 47:40 GraphQL bugs 51:04 The Chromium bug that still allows to control the referrer policy despite using DOM Purify 53:58 OAuth testing 1:03:41 Automation for a manual hacker

Bug bounty tools that actually land bugs with Arthur Aires
▶︎

Bug bounty tools that actually land bugs with Arthur Aires

Top War Stories from a Try Hard Bug Bounty Hunter, Rhynorater | Bug Bounty Village, DEF CON 32
▶︎

Top War Stories from a Try Hard Bug Bounty Hunter, Rhynorater | Bug Bounty Village, DEF CON 32

Your Privacy Settings Are Lying to You (CISO Alex Shulman-Peleg Explains)
▶︎

Your Privacy Settings Are Lying to You (CISO Alex Shulman-Peleg Explains)

Modern Recon for Red Teams and Pentesters | Jason Haddix
▶︎

Modern Recon for Red Teams and Pentesters | Jason Haddix

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret
▶︎

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab
▶︎

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab

Bug Bounty Q&A with Jhaddix & Blaklis
▶︎

Bug Bounty Q&A with Jhaddix & Blaklis

How to become an XSS expert with renniepak
▶︎

How to become an XSS expert with renniepak

XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)
▶︎

XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @Critical Thinking - Bug Bounty Podcast
▶︎

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @Critical Thinking - Bug Bounty Podcast

Finding criticals in mobile apps - Joel Margolis (0xteknogeek) from @Critical Thinking - Bug Bounty Podcast
▶︎

Finding criticals in mobile apps - Joel Margolis (0xteknogeek) from @Critical Thinking - Bug Bounty Podcast

My Full Bug Bounty Recon Methodology Using My Bug Bounty Hunting Framework | Beta Launch @ DEFCON 33
▶︎

My Full Bug Bounty Recon Methodology Using My Bug Bounty Hunting Framework | Beta Launch @ DEFCON 33

Red Team Home Lab - Initial Access Demo
▶︎

Red Team Home Lab - Initial Access Demo

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

DEF CON 32 - Top War Stories from a TryHard Bug Bounty Hunter -Justin Rhynorater Gardner
▶︎

DEF CON 32 - Top War Stories from a TryHard Bug Bounty Hunter -Justin Rhynorater Gardner

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
▶︎

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)
▶︎

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)

Art of VirusTotal Hacking
▶︎

Art of VirusTotal Hacking

How to Crush Bug Bounties in the first 12 Months
▶︎

How to Crush Bug Bounties in the first 12 Months

From Bug Bounty Hunter to over $100M+ Exit | Anand Prakash | Be Fearless Podcast EP 3
▶︎

From Bug Bounty Hunter to over $100M+ Exit | Anand Prakash | Be Fearless Podcast EP 3

Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
▶︎

Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)

From prison, to $5M in bug bounty, to head of AppSec: The story of hacker dawgyg
▶︎

From prison, to $5M in bug bounty, to head of AppSec: The story of hacker dawgyg

Inside an Ethical Hacker’s Mind: Godfather Orwa on #cybersecurity & #bugbounty Secrets | Episode 3
▶︎

Inside an Ethical Hacker’s Mind: Godfather Orwa on #cybersecurity & #bugbounty Secrets | Episode 3

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations
▶︎

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations