Web App Bug Bounty Maps for VR

Matty K.
Cyberpower Telenoia
2 min readNov 15, 2022
The fine grain details of the code of sand on a shoreline. [ NFT available — as entrance token ]

Only 50 NFTs of the above header image are available for the gated entry at my Spatial.io space “Ethical Hacking Lab” through which it is possible to portal into the “Web App Vulnerabilities” area.

This is now live and available on [ OpenSea ]. Only 5 tickets are on sale in the first batch for 0.005 ETH ($5)! The link to Spatial is included in the special unlockable property of the NFT, visible on the order page.

Pay in ETH, CUBE, SAND, MANA and support the creation of this InfoSec VR mapping space.

A spacecapture of the notes in Gravity Sketch, november 2022.

I use the Meta (Oculus) Quest 2 VR goggles to create a 3D notes of the general foundations of ethical Web App hacking and all about the surrounding human aspects and technologies.

Gravity Sketch is used to create the maps in 3D.

Spatial is used as the social space to place the exported 3D maps.

Immersed is used to work on research into vulnerability scanning and exploitation. This is an incredible platform for working in these three dimensions of virtual space:

  • AR — augumented reality which is extending the virtual to enhance the physical. In this case my keyboard is tracked, has a “keys layout” and my hands are also visible through the goggles on top of the keyboard.
  • MR — mixed reality in which I can also see “passthrough” into the physical space I am in while wearing the goggles and interacting with virtual objects.
  • VR — all the virtual aspects of the work.
A spacecapture of the 3D notes placed into the NFT-gated “Ethical Hacking Lab” on Spatial, november 2022.

This article will continue to be updated. Previously I have written about about my interests in Web3 DeFi InfoSec at a higher level.

Bitcoin Security Maps podcast video episode of this article.

As of the above podcast episode update one year later, I have yet to connect with people who see the significance and potential of collaborating on secure Web App Bug Bounty Hunting through VR. Hopefully it’s not because of the sock puppet moustache.

--

--

Matty K.
Cyberpower Telenoia

Niche InfoSec Consultant - Stealth Recon for Red Teams