I know who your users are - abusing user enumeration for OSINT and Bug Bounty

No ratings

Presented at SEC-T 2025 by

If you’re used to seeing user enumeration marked as informational or excluded from bug bounty program scopes, you’re not alone. User enumeration is one of those findings that’s hard to prove as impactful, but also hard to get rid of. This talk will dive into user enumeration and demonstrate its real impact, something that might make clients reconsider the severity of this finding.