Couverture de Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

De : Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Écouter gratuitement

À propos de ce contenu audio

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Les membres Amazon Prime bénéficient automatiquement de 2 livres audio offerts chez Audible.

Vous êtes membre Amazon Prime ?

Bénéficiez automatiquement de 2 livres audio offerts.
Bonne écoute !
    Épisodes
    • Episode 145: Gr3pme's Secret: Bug Bounty Note Taking Methodology
      Oct 23 2025

      Episode 145: In this episode of Critical Thinking - Bug Bounty Podcast Brandyn lets us in on some of his notetaking tips, including his Templates, Threat Modeling, and ways he uses notes to help with collaboration.

      Follow us on twitter at: https://x.com/ctbbpodcast

      Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

      Shoutout to YTCracker for the awesome intro music!

      ====== Links ======

      Follow your hosts Rhynorater, Rez0, & gr3pme on Twitter:

      https://x.com/Rhynorater

      https://x.com/rez0__

      https://x.com/gr3pme

      ====== Ways to Support CTBBPodcast ======

      Hop on the CTBB Discord at https://ctbb.show/discord!

      We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

      You can also find some hacker swag at https://ctbb.show/merch!

      Today's Sponsor: ThreatLocker. Check out ThreatLocker Network Control

      https://www.criticalthinkingpodcast.io/tl-nc

      ====== This Week in Bug Bounty ======

      The minefield between syntaxes

      https://www.yeswehack.com/learn-bug-bounty/syntax-confusion-ambiguous-parsing-exploits

      ====== Resources ======

      Brandyn's Notion Template

      https://terrific-dart-70e.notion.site/Example-Target-CTBB-294f4ca0f42481cca0b0ca6ac0a7c81d

      ====== Timestamps ======

      (00:00:00) Introduction

      (00:07:25) Templates, Target, and Tech Stack

      (00:13:33) Threat Modeling and Attack Vectors

      Afficher plus Afficher moins
      28 min
    • Episode 144: Google’s Top AI Hackers: Busfactor and Monke
      Oct 16 2025

      Episode 144: In this episode of Critical Thinking - Bug Bounty Podcast Joseph is joined by Vitor Falcão and Ciarán Cotter to discuss their success at the recent Mexico LHE, as well as their journey and routines in fulltime hacking.

      Follow us on twitter at: https://x.com/ctbbpodcast

      Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

      Shoutout to YTCracker for the awesome intro music!

      ====== Links ======

      Follow your hosts Rhynorater and Rez0 on Twitter:

      https://x.com/Rhynorater

      https://x.com/rez0__

      ====== Ways to Support CTBBPodcast ======

      Hop on the CTBB Discord at https://ctbb.show/discord!

      We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

      You can also find some hacker swag at https://ctbb.show/merch!

      Today's Sponsor: ThreatLocker. Check out ThreatLocker DAC

      https://www.criticalthinkingpodcast.io/tl-dac

      Today’s Guests:

      Vitor Falcão

      https://x.com/busf4ctor

      Ciarán Cotter

      https://x.com/monkehack

      ====== This Week in Bug Bounty======

      Securing the Age of AI Autonomy: Priorities for 2026

      https://www.hackerone.com/events/bionic-hacking

      ====== Resources ======

      AI Vulnerability Reward Program Rules

      https://bughunters.google.com/about/rules/google-friends/5222232590712832/ai-vulnerability-reward-program-rules

      My First 3 Months as a Full-Time Bug Bounty Hunter

      https://vitorfalcao.com/posts/3-months-as-a-full-time-bug-bounty-hunter/

      ====== Timestamps ======

      (00:00:00) Introduction

      (00:02:32) Client side Bug Story & Vitor's BB journey

      (00:13:59) Google LHE Mexico takeaways

      (00:26:55) Full-time hunting reflections

      (00:33:39) Hacking routines

      (00:42:56) Hacking AI

      Afficher plus Afficher moins
      53 min
    • Episode 143: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!
      Oct 9 2025

      Episode 143: In this episode of Critical Thinking - Bug Bounty Podcast Justin brings Brandyn back to announce him as our newest co-host. We chat about recent LHE experiences, and then break down some news.

      Follow us on twitter at: https://x.com/ctbbpodcast

      Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

      Shoutout to YTCracker for the awesome intro music!

      ====== Links ======

      Follow your hosts Rhynorater and Rez0 on Twitter:

      https://x.com/Rhynorater

      https://x.com/rez0__

      ====== Ways to Support CTBBPodcast ======

      Hop on the CTBB Discord at https://ctbb.show/discord!

      We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

      You can also find some hacker swag at https://ctbb.show/merch!

      ====== This Week in Bug Bounty ======

      YesWeHack won the European commission: https://www.yeswehack.com/news/european-commission-tender-won-yeswehack

      YesWeHack now have authorised cve numbering authority: https://www.yeswehack.com/news/yeswehack-authorised-cve-numbering-authority

      A wide range of highly used open source bug bounty program such as Log4J, Systemd, GNOME and a lot more:

      https://event.yeswehack.com/events/open-the-code-source-the-bounty

      ====== Resources ======

      Attributes reference inside HTML

      Explaining XSS without parentheses and semi-colons

      Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame

      One Token to rule them all

      flareprox

      Caido 101: How to master it

      ====== Timestamps ======

      (00:00:00) Introduction

      (00:03:16) LHE approaches and accomplishments

      (00:30:54) Attributes reference inside HTML & Explaining XSS without parentheses and semi-colons

      (00:44:33) One Token to rule them all

      (00:57:13) Flareprox & Caido 101

      Afficher plus Afficher moins
      1 h et 4 min
    Aucun commentaire pour le moment