Video summary
ازاي Mo Salah خد 10,000$ من Atlassian؟ 😲 | أسرار البج باونتي مع 0x_MoSalah
Main summary
Key takeaways
Summary
This podcast interview follows bug bounty hunter Mohamed Salah (0x_MoSalah) as he discusses learning web security, hunting for vulnerabilities, and earning a $10,000 Atlassian bounty.
Learning and Practice
Salah began studying web fundamentals such as HTML, JavaScript, and PHP in 2023, then moved on to web security and bug bounty platforms.
His learning approach was to study each vulnerability through multiple instructors and courses, then reinforce it with hands-on labs. Resources he mentioned include PortSwigger labs and courses by Rana Khalil, Ibrahim Hegazy, and others.
He recommends using public write-ups and videos to see how vulnerabilities appear in real applications. Labs are useful, but they can make the target or vulnerability more obvious than it would be in a real-world setting. He also emphasizes taking notes on lab scenarios: without notes, it can be difficult to recall and apply a technique later, even if you have solved it before.
Vulnerability Examples
-
Password-reset account takeover: A reset flow included an email parameter and a token. The application validated the token but used the supplied email to determine which account to change. By changing the email to a victim’s address in the right reset flow, Salah could reset the victim’s password. He says he spent time understanding the precise conditions under which the issue worked.
-
CSRF involving a request-method change: A site’s normal POST request was affected by browser cookie restrictions. Salah found that sending the relevant action as a GET request worked instead, creating a CSRF scenario.
-
Trial or user-limit bypass: A service limited the number of users who could be invited after a trial. Reusing a remove-and-reinvite function with a different email allowed him to add users beyond the intended limit. He notes that whether such business-logic issues qualify for a bounty depends on the program’s policy and its assessment of impact.
The $10,000 Atlassian Report
The high-value finding was another password-reset issue. The flow contained a token and an email parameter, but the application did not correctly bind the account being changed to the reset authorization. Changing the email parameter could therefore redirect the reset to another account.
Salah first reported the issue through a third-party service’s program, then realized the affected portal was associated with Atlassian and submitted it to Atlassian as well. The report encountered confusion over scope and triage, but was eventually accepted and rewarded with $10,000.
His experience highlights the importance of checking program scope carefully, documenting impact clearly, and following up professionally when a report appears to have been misunderstood.
Hunting Approach and Advice
Salah recommends exploring an application and understanding its features, workflows, and requests before targeting specific bugs. He encourages testing a broad range of ideas—including logic flaws and broken access control—rather than learning one vulnerability type and expecting to find only that.
After manual testing, he sometimes searches public code repositories for exposed secrets using the target’s domain and relevant terms. He also checks whether a repository plausibly belongs to the target and whether its contents are recent.
He reviews software versions and relevant CVEs after examining an application, especially for newly disclosed issues, but says he does not hunt CVEs exclusively. He also advises reading each program’s policy, since some exclude categories such as certain information disclosures or limit-related issues.
Persistence, AI, and Burnout
Salah’s main advice is consistency. Long gaps can lead beginners to forget what they studied, while continuing to work on a program helps them recognize its features and requests over time. He also cautions against comparing oneself with hunters who post successes without seeing the months of work behind them.
He uses AI tools selectively—for example, to clarify uncertain information or help create a small script to extract endpoints from JavaScript. However, he warns that AI can exaggerate the severity of findings, so reports should be independently verified rather than submitted automatically.
For burnout, he recommends taking a genuine break when needed, then returning gradually through reading, videos, and eventually hands-on work. He also describes learning alongside peers as a source of motivation and shared technical ideas.
Main Speakers and Sources
- Ahmed Badry — podcast host and interviewer
- Mohamed Salah (0x_MoSalah) — guest bug bounty hunter
- Learning resources discussed include PortSwigger labs, courses by Rana Khalil and Ibrahim Hegazy, and other online courses and public vulnerability write-ups.
Rate this summary
Your feedback will help improve summaries.
Improve this summary
Reprocess with a stronger model when the summary feels incomplete or inaccurate.
Translate summary in another language
Ask questions to this video
Chat for follow-up questions, clarifications, and source-backed answers.