
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
How to Bypass GitHub's a Lot Flow
This is an example of C surf that does not use get or post. This is a C surf done with a head request, which was really interesting to me. It actually in this case, it was triggering the same thing as a post request would do. The OAuth bypass landed him a pretty sick, I think there was a 25 K bounty, right? 25 K.
Transcript
Play full episode