
Episode 62: Frontend Language Oddities
Critical Thinking - Bug Bounty Podcast
00:00
Yelp Cookie Bridge Bug Exploitation and Cookie Bombing
The chapter explores a bug in Yelp's cookie bridge leading to unauthorized account access across domains. It details a security researcher's exploitation using cookie bombing to manipulate cookies and gain control over user accounts. The episode also mentions a tool called Wakare for decompiling JavaScript code and the significance of monitoring code evolution in repositories like chat GPT source watch.
Transcript
Play full episode