The Road to Riches: From Binary Researcher to Bounty Hunter


When it comes to Bug Bounty, most people will think that it may still be a white hat hacker hacking a website and get a huge bounty.
However, in recent years, venders have invested more resources in the Bounty Program of Binary type or mobile devices, and the bounty amount is much higher than web hacking.

This talk will share my experience as a “Reverse Engineer” participating in various Bounty Programs in recent years and some tips for reporting bugs.
I will also discuss how it’s different from the website-type Bounty Program, and mention some little-known secrets and misconceptions about the Bounty Program.


Lays

Lays

Shih-Fong Peng, aka Lays, is Co-Founder and research team leader of TrapaSecurity, currently focusing on reverse engineering and vulnerability research.
He is a member of HITCON and 217 CTF team which achieved second place at DEF CON CTF 25 and 27.
He is also one of the 2019, 2020 MSRC Most Valuable Security Researcher and has reported vulnerabilities to Microsoft, Google, Samsung, Trend Micro, NETGEAR, WD, Synology, etc.

Blog: https://blog.l4ys.tw
Twitter: @_L4ys