The mindset for finding highs and crits in bug bounty with JR0ch17

📣 Follow JR0ch17 on Twitter: https://x.com/jr0ch17 ✉️ Sign up for the mailing list: https://bbre.dev/nl 📣 Follow me on Twitter: https://bbre.dev/tw Interview with Jasmin “JR0ch17” Landry, a former triager and security manager, now a full-time bug bounty hunter. We discuss bug bounty strategy, mindset, and finding high and critical vulnerabilities. BBRD podcast is also available on most popular podcast platforms: https://open.spotify.com/show/6tLoJ5f...    • Bug Bounty Reports Discussed   https://podcasts.apple.com/us/podcast... Links mentioned in the video: The web application hacker's handbook: https://amzn.to/3GS4t68 Xlif: https://docs.oracle.com/en/cloud/saas... DTD finder: https://github.com/GoSecure/dtd-finder Secondary path traversal blogpost: https://samcurry.net/hacking-starbucks OAuth dirty dancing: https://labs.detectify.com/writeups/a... Cognito doc-driver misconfiguration: https://docs.aws.amazon.com/elasticlo... Timestamps: 00:00 Intro 00:37 The road to becoming the full-time bug bounty hunter 20:06 The change in the mindset that lands a lot of highs and crits recently 23:02 SSRFs 24:33 How to test for SSTI? 28:54 Does SQLi still exist in 2025? 35:09 Where to test for XXEs? 41:33 Secondary path traversals 47:40 GraphQL bugs 51:04 The Chromium bug that still allows to control the referrer policy despite using DOM Purify 53:58 OAuth testing 1:03:41 Automation for a manual hacker

Bug bounty tools that actually land bugs with Arthur Aires
▶︎

Bug bounty tools that actually land bugs with Arthur Aires

Bug Bounty Q&A with Jhaddix & Blaklis
▶︎

Bug Bounty Q&A with Jhaddix & Blaklis

From Two Weeks to Three Days: The KEV Deadline Debate
▶︎

From Two Weeks to Three Days: The KEV Deadline Debate

Finding criticals in mobile apps - Joel Margolis (0xteknogeek) from @Critical Thinking - Bug Bounty Podcast
▶︎

Finding criticals in mobile apps - Joel Margolis (0xteknogeek) from @Critical Thinking - Bug Bounty Podcast

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab
▶︎

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab

IDOR Infinite Money Glitch? | Bug Bounty Hacktivity Explained
▶︎

IDOR Infinite Money Glitch? | Bug Bounty Hacktivity Explained

From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3
▶︎

From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3

Going full-time bug bounty, privilege escalation bugs and more with Douglas Day
▶︎

Going full-time bug bounty, privilege escalation bugs and more with Douglas Day

Top-Tier Bug Bounty Hunter Mindset - Yassine Aboukir KEYNOTE at BSides Ahmedabad 2022
▶︎

Top-Tier Bug Bounty Hunter Mindset - Yassine Aboukir KEYNOTE at BSides Ahmedabad 2022

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)
▶︎

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)

From 0 to a top bug bounty hunter - Johan Carlsson's journey to GitLab TOP1 on Hackerone
▶︎

From 0 to a top bug bounty hunter - Johan Carlsson's journey to GitLab TOP1 on Hackerone

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret
▶︎

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret

The key to succeed in bug bounty - @NahamSec
▶︎

The key to succeed in bug bounty - @NahamSec

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @Critical Thinking - Bug Bounty Podcast
▶︎

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @Critical Thinking - Bug Bounty Podcast

NahamSec Teaches Me Bug Bounty Basics
▶︎

NahamSec Teaches Me Bug Bounty Basics

How to become an XSS expert with renniepak
▶︎

How to become an XSS expert with renniepak

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

Darknet Bible: The Ultimate OpSec Guide
▶︎

Darknet Bible: The Ultimate OpSec Guide

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
▶︎

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

Inside the Mind of the TOP1 Facebook Bug Bounty Hunter - Youssef Sammouda - BBRD podcast #5
▶︎

Inside the Mind of the TOP1 Facebook Bug Bounty Hunter - Youssef Sammouda - BBRD podcast #5