April 24, 2023, 2:40 p.m. | Bug Bounty Reports Explained

Bug Bounty Reports Explained www.youtube.com

📧 Subscribe to BBRE Premium: https://bbre.dev/premium
📰 Article about writing this query and more practical tips: https://members.bugbountyexplained.com/how-to-write-a-new-codeql-query-and-maximise-payout-rce-via-zipslip-query/
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on twitter: https://bbre.dev/tw

This video is an explanation of a CodeQL query to detect RCE via ZipSlip for which GitHub Security Lab rewarded me $5,500.

Pull request with a change: http://github.com/github/codeql/pull/12208
Hackerone report: http://hackerone.com/reports/1914118

🖥 Get $100 in credits for Digital Ocean: https://bbre.dev/do


Timestamps:
00:00 Intro
00:42 Finding the bug
03:57 The …

bounty bug codeql detect flow github github security lab lab query rce sanitizer security video

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC