
Critical Thinking - Bug Bounty Podcast Episode 44: URL Parsing & Auth Bypass Magic
Nov 9, 2023
The podcast delves into URL parsing and authentication bypass techniques, highlighting common tips and tricks for bypassing restrictions. It covers topics such as OAuth vulnerabilities, controversy surrounding vulnerability reports, Facebook login ATO, and the risks of centralization. The hosts also discuss the importance of understanding URL components, potential issues with OAuth flows in Android apps, and the vulnerabilities of URL parsing in bug bounty programs.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8
Introduction
00:00 • 2min
Technical Issue with Stuck Desk and Recalibration
02:30 • 2min
Chrome extension for revealing hidden elements
04:05 • 18min
Facebook Login Vulnerability
22:16 • 10min
A Story About the Creator of 'Glob' and Tricky Linux Files
32:26 • 2min
Understanding URL Components
34:28 • 20min
OAuth Flows and URL Parsing in Android Apps
54:43 • 7min
URL parsing, authentication bypass, and the risks of centralization
01:01:24 • 10min
