Critical Thinking - Bug Bounty Podcast cover image

Episode 28: Surfin' with CSRFs

Critical Thinking - Bug Bounty Podcast

00:00

How to Bypass GitHub's a Lot Flow

This is an example of C surf that does not use get or post. This is a C surf done with a head request, which was really interesting to me. It actually in this case, it was triggering the same thing as a post request would do. The OAuth bypass landed him a pretty sick, I think there was a 25 K bounty, right? 25 K.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app