123┌▄──────────────────────────────────────────────────────────────────────▄┐4├■▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄■[ YESWEHACK PROPHILE ON EBODA ]■▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄■┤5├■──────────────────────────────────────────────────────────────────────■┤6├■▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀■┤7└▀──────────────────────────────────────────────────────────────────────▀┘8Wed, 11 Dec 2019 12:04:26 +0100 (CET)9╔══════════════════════════════════ WHOIS ═══════════════════════════════╗10║ Handle: eboda ║11║ Handle origin: first name + last name (i'm very creative :>) ║12║ or maybe: 'adobe'[::-1], who knows... ║13║ Age of your body: 29 ║14║ Produced in: Germany ║15║ Urlz: https://bugscale.ch / @eboda_ ║16║ Computers: Just got the new Thinkpad X1 extreme ║17║ (I am part of the cult worshipping ║18║ the Thinkpad nipple) ║19║ Superpowers: I can fly ║20║ Life in a sentence: Eat Sleep Pwn Repeat (höhö) ║21╚════════════════════════════════════════════════════════════════════════╝2223QUOTES24╔════════════════════════════════════════════════════════════════════════╗25║ Any man who must say "I am king" is no true king at all ║26╚════════════════════════════════════════════════════════════════════════╝2728ARMORY29╔════════════════════════════════════════════════════════════════════════╗30║ Mostly just Burp ║31║ I do not do any automated testing or crazy recon, so I don't use many ║32║ other specific tools. ║33╚════════════════════════════════════════════════════════════════════════╝3435▀▄█▓▒░ Hello, what's your background?:36│ ───────────────────────────────────────────────────────────────────37└─ Hi! Professionally I was working as a pentester in Switzerland38 before starting to do bug hunting and research full-time.39 Less professionally, I used to play a lot of CTFs with my team Eat40 Sleep Pwn Repeat.414243▀▄█▓▒░ How did you come to Bug Bounty ?44│ ───────────────────────────────────────────────────────────────────45└─ I did a bit of bug bounty hunting on and off a few years back.46 This year I quit my pentesting job and decided to pursue bug hunting47 as a full-time career. Now that it's up to me to choose targets to48 work on, I can spend all my time doing cool research on targets49 I personally am interested in or that use some cool tech :)505152▀▄█▓▒░ You have practiced others BB platforms, what are the Pro & Cons,53│ with your experience on those platforms? / What are your54│ expectations?55│ ───────────────────────────────────────────────────────────────────56└─ I am active on multiple platforms because it allows me to reach57 more targets. When it comes to choosing a program to work on I am58 quite nit-picky, so the more choice the better!5960 Some things I'm looking for in a program:61 - Great payout (obviously, who are we kidding...)62 - Well defined scope. I don't like recon at all, so I prefer63 to be given a small list of applications to pwn64 - Does it have source code available? HUGE plus65 - Responsive and fair team. Can't really know that before your66 first reports6768 My expectations to programs are pretty straight-forward. I took the69 time and effort to test your application and (hopefully) report a70 bug, in return I expect fair treatment according to the rules you71 have published :)7273 Fool me once shame on you, fool me twice shame on me. If you try74 to pull some tricks I will just move on to another target.7576 As to BB platforms themselves, it is very important for me that the77 communication is efficient. It's just so much more pleasant to report78 bugs when you have professional triagers who understand what you79 are talking about and can intervene if you face problems with80 programs.818283▀▄█▓▒░ Appart from Bug Bounty you seem to collaborate on a lot of hacker84| events, what is your feeling on how the community is evolving?85│ ───────────────────────────────────────────────────────────────────86└─ Recently, together with some friends we have created a company87 called Bugscale to participate in bug bounties and do security88 research in general. It allows us to collaborate on our work89 efficiently, since we all chill in the same office.9091 In Switzerland the BB community is still in its infancy, as there is92 not many BB programs and you can probably count the hunters living93 from it on one hand. As far as we know, we are the first company94 in Switzerland to actually make a living off of Bug Bounties.9596 This year has seen enormous change for us though. Not only did97 YesWeHack create a subsidiary in Switzerland, but additionally BB98 programs are becoming more mainstream with conferences dedicating99 their theme to BB (see Swiss Cyber Storm for example)100 and Swiss companies actively trying to launch their BB programs.101102 The future is definitely bright for us and especially in Switzerland103 the community will evolve immensely in the upcoming years!104105106▀▄█▓▒░ What was your first computer?107│ ───────────────────────────────────────────────────────────────────108└─ My first computer was mostly used to play CS1.6 and Warcraft 3 :D109 Didn't do much hacking back then...110111112▀▄█▓▒░ Do you remember your first successful exploitation?113│ ───────────────────────────────────────────────────────────────────114└─ Not really to be honest... I guess it wasn't worth remembering :D115 When I was younger I was very much into something I would describe116 SQL injection "competitions". Basically, someone would post a117 website with a SQLi vuln and a WAF and the challenge was to dump118 all table names with a single query for example. You would end up119 with these huge SQL queries that bypass the WAF, concat results120 into variables and then dump those. It was kind of the thing that121 got me interested in security in the first place (that and CTFs).122123124▀▄█▓▒░ What keeps you going / What turns you down?125│ ───────────────────────────────────────────────────────────────────126└─ The thrill of finding a cool vuln and writing an exploit for it.127128 Doing things I don't enjoy turns me down (who would have thought :D).129 In the BB context this might include things like recon or writing130 reports :>>131132133▀▄█▓▒░ Is there a life AFK?134│ ───────────────────────────────────────────────────────────────────135└─ No of course not! jk... I have relocated to beautiful Switzerland136 some time ago, so there is no shortage of AFK life outside in137 the mountains.138 Depending on the season, I like to hike, ski or fly with my139 paraglider :)140 Also I'm into CS:GO, but that's technically not AFK I guess :D141142143▀▄█▓▒░ What is the future?144│ ───────────────────────────────────────────────────────────────────145└─ In Europe and Switzerland specifically I think we will see a sharp146 increase in companies adopting bug bounty programs. With YesWeHack147 being in Switzerland itself now, it will make it easier for148 companies to overcome initial hesitation or uncertainty regarding149 bug bounties.150151 In any case, there will always be bugs, so in one way or another152 we will be able to keep busy ;)153154155--------[ EOF156157

YESWEHACK PROPHILE ON EBODA
December 11, 2019


