Couverture de Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

De : Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Écouter gratuitement

À propos de cette écoute

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Les membres Amazon Prime bénéficient automatiquement de 2 livres audio offerts chez Audible.

Vous êtes membre Amazon Prime ?

Bénéficiez automatiquement de 2 livres audio offerts.
Bonne écoute !
    Épisodes
    • Episode 127: Drama, PDF as JS Chaos, Bounty Profile Apps, And More
      Jun 19 2025
      Episode 127: In this episode of Critical Thinking - Bug Bounty Podcast we address some recent bug bounty controversy before jumping into a slew of news itemsFollow us on XShoutout to YTCracker for the awesome intro music!Today's Sponsor: Adobe====== This Week In Bug Bounty ======Hackers Guide to Google dorkingYesWeCaidoNew Dojo ChallengeSmart Contract BB tipsRed Team AAS====== Resources ======DisclosedPDF csp bypassBypassing File Upload Restrictions To Exploit Client-Side Path TraversalOBS WebSocket to RCETime in a bottle (or knapsack)How to Differentiate Yourself as a Bug Bounty HunterDisclosed. Onlinehacked-in‘EchoLeak’Piloting Edge CopilotNewtownerTips for agent promptingFirefox XSS vectorsTweet from Masato KinugawaChrome debug() function
      Afficher plus Afficher moins
      1 h et 7 min
    • Episode 126: Hacking AI Series: Vulnus ex Machina - Part 3
      Jun 12 2025

      Episode 126: In this episode of Critical Thinking - Bug Bounty Podcast we wrap up Rez0’s AI miniseries ‘Vulnus Ex Machina’. Part 3 includes a showcase of AI Vulns that Rez0 himself has found, and how much they paid out.

      Follow us on twitter at: https://x.com/ctbbpodcast

      Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

      Shoutout to YTCracker for the awesome intro music!

      ====== Links ======

      Follow your hosts Rhynorater and Rez0 on Twitter:

      https://x.com/Rhynorater

      https://x.com/rez0__

      ====== Ways to Support CTBBPodcast ======

      Hop on the CTBB Discord at https://ctbb.show/discord!

      We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

      You can also find some hacker swag at https://ctbb.show/merch!

      Today’s Sponsor - ThreatLocker Web Control

      https://www.criticalthinkingpodcast.io/tl-webcontrol

      ====== Resources ======

      Claude Code System Prompt

      Attacking AI Agents

      Probability of Hacks

      New Gemini for Workspace Vulnerability Enabling Phishing & Content Manipulation

      How to Hack AI Agents and Applications

      ====== Timestamps ======

      (00:00:00) Introduction

      (00:02:53) NahamCon Recap, Claude news, and wunderwuzzi writeups

      (00:08:57) Probability of Hacks

      (00:11:27) First AI Vulnerabilities

      (00:18:57) AI Vulns on Google

      (00:25:11) Invisible prompt Injection

      Afficher plus Afficher moins
      39 min
    • Episode 125: How to Win Live Hacking Events
      Jun 5 2025

      Episode 125: In this episode of Critical Thinking - Bug Bounty Podcast Justin shares insights on how to succeed at live hacking events. We cover pre-event preparations, challenges of collaboration, on-site strategies, and the importance of maintaining a healthy mindset throughout the entire process.

      Follow us on twitter at: https://x.com/ctbbpodcast

      Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

      Shoutout to YTCracker for the awesome intro music!

      ====== Links ======

      Follow your hosts Rhynorater and Rez0 on Twitter:

      https://x.com/Rhynorater

      https://x.com/rez0__

      ====== Ways to Support CTBBPodcast ======

      Hop on the CTBB Discord at https://ctbb.show/discord!

      We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

      You can also find some hacker swag at https://ctbb.show/merch!

      ====== This Week in Bug Bounty ======

      Decathlon Public Bug Bounty Program on YesWeHack

      ====== Resources ======

      The Ultimate Double-Clickjacking PoC

      Grafana Full read SSRF and Account Takeover: CVE-2025-4123

      Grafana CVE-2025-4123 Exploit

      What I learned from my first 100 HackerOne Reports

      Root for your friends

      ====== Timestamps ======

      (00:00:00) Introduction

      (00:02:30) The Ultimate Double-Clickjacking PoC, Grafana CVE, & Evan Connelly's first 100 bugs

      (00:10:23) How to win at Live Hacking Events

      (00:11:53) Pre-event

      (00:11:45) Scope Call

      (00:33:11) Dupe window Ends

      (00:36:00) Onsite & and Day of Event

      (00:42:46) Don't define your identity on the outcome

      Afficher plus Afficher moins
      47 min

    Ce que les auditeurs disent de Critical Thinking - Bug Bounty Podcast

    Moyenne des évaluations utilisateurs. Seuls les utilisateurs ayant écouté le titre peuvent laisser une évaluation.

    Commentaires - Veuillez sélectionner les onglets ci-dessous pour changer la provenance des commentaires.

    Il n'y a pas encore de critique disponible pour ce titre.