Critical Thinking - Bug Bounty Podcast cover image

Critical Thinking - Bug Bounty Podcast

Episode 114: Single Page Application Hacking Playbook

Mar 13, 2025
Dive into the world of hacking Single Page Applications (SPAs) as the hosts unravel techniques and tools like Shadow Repeater. Explore security vulnerabilities, including cross-site scripting and JWT exploitation, while uncovering the importance of understanding API endpoints. Discover how the integration of AI can enhance testing processes and learn about recent cybersecurity news, such as the launch of Hackadvisor, a platform for bug bounty ratings. Tune in for insights that merge fitness with cybersecurity in a unique twist!
01:22:25

Podcast summary created with Snipd AI

Quick takeaways

  • Single-page applications (SPAs) can be vulnerable to exploitation through improperly secured feature flags allowing unauthorized access to backend functionalities.
  • The podcast discusses the utility of Common Crawl in identifying exposed sensitive data like API keys, using automated tools for efficient scans.

Deep dives

ThreatLocker Cloud Control: A Solution to Session Hijacking

ThreatLocker introduces Cloud Control to counter session hijacking tactics employed by attackers through phishing. Using tools like Evil Engine X, attackers can capture session tokens, bypassing security measures like two-factor authentication. Cloud Control works by allowing only approved IP addresses to connect and interact with Microsoft 365. If an attacker tries to use a stolen session token from an unapproved IP, access is denied, effectively protecting sensitive data.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner