Ask a hacker: A conversation with ahacker1
Blog post from GitLab
GitLab hosted an AMA session with bug bounty hunter Alexander Siyou Tan, known as ahacker1, who specializes in hacking complex SaaS applications with a focus on authorization-based vulnerabilities, SAML, and SSO. During the AMA, Alexander shared insights into his research process, which includes using RubyMine for code analysis and sometimes consulting AI tools like ChatGPT for understanding new features. He discussed the complexity and potential in hacking SAML applications, which he likened to a SaaS application within a SaaS application, and mentioned his plans to address vulnerabilities in SAML libraries. Additionally, Alexander provided tips for participants in GitLab's Bug Bounty Program, such as leveraging open-source code analysis and studying patch releases for reverse-engineering. Outside of hacking, Alexander enjoys gaming and outdoor activities, and humorously admitted he wouldn't last long in a zombie apocalypse due to his reliance on the internet. The session is available on YouTube for those interested in the full details, and more information about the GitLab Bug Bounty Program is accessible, highlighting its achievements since launching in 2018, including resolving 1,684 reports and awarding over $4.7 million in bounties.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.