
Episode 19: Audit Code, Earn Bounties (Part 2) + Zip-Snip, Sitecore, and more!
Critical Thinking - Bug Bounty Podcast
00:00
How to Use GitHub to Download Source code.zip
There's actually a space after the, like, the one URL and then followed by, like, he owns source code.zip,. And so you would expect that this would download source code.Zip, but when you don't realize there's a space and it's actually two different URLs...you're pwned. So sneaky man, sneaky. I wouldn't go so far as to block the whole TLD because technical people making mistakes is the big risk here. It's not a lot of times that non-technical people are running W get and stuff like that.
Play episode from 07:02
Transcript


