Upgrade to PRO for Only $50/Year—Limited-Time Offer! 🔥
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Free Bugs Campaign
Search
8ayac
March 11, 2019
Technology
0
960
Free Bugs Campaign
Burp Suite Japan LT Carnivalの登壇資料
8ayac
March 11, 2019
Tweet
Share
More Decks by 8ayac
See All by 8ayac
MBSD Cybersecurity Challenges 2018 最終審査会 発表スライド
8ayac
0
1.8k
MBSD Cybersecurity Challenges 2017 最終審査会 発表スライド
8ayac
0
610
Other Decks in Technology
See All in Technology
Modern Data Stack大好きマンが語るSnowflakeの魅力
sagara
0
280
AI時代の開発フローとともに気を付けたいこと
kkamegawa
0
390
Introduction to Bill One Development Engineer
sansan33
PRO
0
330
Contract One Engineering Unit 紹介資料
sansan33
PRO
0
9.9k
pmconf2025 - 他社事例を"自社仕様化"する技術_iRAFT法
daichi_yamashita
0
540
useEffectってなんで非推奨みたいなこと言われてるの?
maguroalternative
9
6.2k
生成AI・AIエージェント時代、データサイエンティストは何をする人なのか?そして、今学生であるあなたは何を学ぶべきか?
kuri8ive
2
1.9k
Design System Documentation Tooling 2025
takanorip
1
930
プラットフォームエンジニアリングとは何であり、なぜプラットフォームエンジニアリングなのか
doublemarket
1
550
Claude Code はじめてガイド -1時間で学べるAI駆動開発の基本と実践-
oikon48
43
26k
AI 時代のデータ戦略
na0
8
3.3k
プロダクトマネージャーが押さえておくべき、ソフトウェア資産とAIエージェント投資効果 / pmconf2025
i35_267
2
360
Featured
See All Featured
Typedesign – Prime Four
hannesfritz
42
2.9k
Why You Should Never Use an ORM
jnunemaker
PRO
60
9.6k
Designing Experiences People Love
moore
142
24k
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
1.8k
Building Adaptive Systems
keathley
44
2.9k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
285
14k
Navigating Team Friction
lara
191
16k
The Hidden Cost of Media on the Web [PixelPalooza 2025]
tammyeverts
1
80
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
46
7.8k
Building Applications with DynamoDB
mza
96
6.8k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
231
22k
Transcript
None
: -> @8ayac (Twitter/HackerOne/Flickr) 2 PSIRT (’18/04~) MBSD Cybersecurity Challenges
(’17/’18) GitLab Bug Bounty Program - Hall of Fame 7 (2018) 45 BugHunt / (←New!) CWE CWE-79 / CWE-400 Follow @8ayac 1
Follow @8ayac 2
Free Bugs Campaign Follow @8ayac 3
Free Hugs Campaign ※ Follow @8ayac 4
None
None
Burp Pro Cy-PSIRT HackerOne Follow @8ayac 7
CVE-XXXX-XXXX … ( Burp Pro ) Follow @8ayac 8
None
Follow @8ayac 10
Follow @8ayac 11
None
None
Follow @8ayac 14
Follow @8ayac 15
+ DEMO + α Stored XSS(1) - $0 - $0
Stored XSS(2) - $0 Free Bugs Campaign Follow @8ayac 16
None
OSS GitLab Issue Tracker / ✨ Follow @8ayac 18
None
Title: Issue Stored XSS Issue Type: XSS(CWE-79) Severity: High(7~8.9) Affected
Versions: 11.3.x < 11.3.1 11.2.x < 11.2.4 11.1.x < 11.1.7 Report: https://hackerone.com/reports/384255 Follow @8ayac 20
None
https://github.com/gitlabhq/gitlabhq/commit/6d360c210d3d822fc266eecc04753481ae4bda70#diff-ebb2ac556337fa87bae1c9e999fca8cfR2 Follow @8ayac 22
None
Follow @8ayac 24
Follow @8ayac 25
Follow @8ayac 26
Follow @8ayac 27
GitLab Public Program 10 Follow @8ayac 28
Title: Issue Type: Information Exposure Through Browser Caching(CWE-525) Severity: Medium
Affected Versions: 11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/407763 Follow @8ayac 29
None
https://github.com/gitlabhq/gitlabhq/commit/782badd0a2cd00d2a9cbe591e78b30aca32e252b#diff-55c5b7aecfb519d0e4880eaf2788eb6e Follow @8ayac 31
None
Follow @8ayac 33
Follow @8ayac 34
Follow @8ayac 35
Follow @8ayac 36
Follow @8ayac 37
Follow @8ayac 38
Follow @8ayac 39
Follow @8ayac 40
Follow @8ayac 41
Follow @8ayac 42
Public Program Private Follow @8ayac 43
Title: Stored XSS Issue Type: XSS(CWE-79) Severity: High Affected Versions:
11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/409380 Follow @8ayac 44
None
Follow @8ayac 46
None
None
GitLab Public Program ! !(Low $1000) : https://hackerone.com/gitlab/policy_versions?change=3597572# Follow @8ayac
49
Follow @8ayac 50
Follow @8ayac 51
Follow @8ayac 52
Follow @8ayac 53
Follow @8ayac 54
Follow @8ayac 55
Follow @8ayac 56
None
None
@zseano : Are you submitting bugs for free when others
are being paid?... Follow @8ayac 59
Follow @8ayac 60
Private Private Researcher Follow @8ayac 61
Private Private Researcher Follow @8ayac 62
Free Bugs Campaign : Public Private Follow @8ayac 63
Follow @8ayac 64
Follow @8ayac 65
None
$500 ( ) “Private Program” GitLab ( HackEDU) 100 Burp
( ) Follow @8ayac 67
☺