

Episode 52: Best Technical Content from Year 1 of CTBB Podcast
Jan 4, 2024
The podcast highlights the best technical moments from the past year, including topics such as exploiting meta tags and base tags in HTML, client-side path traversal and cookie jar overflow, cross environment authentication bugs, the open-faced iframe sandwich, JS hoisting, Sean Yeoh on subdomains vs IP in recon, reversing enterprise software, building out a recon flow, hacking IIS servers, automating code review with JS Weasel and AI, post message vulnerabilities and listener tracking, hiding content from scrapers and XSLT transforms, exploring the Perforce version control system and testing methodologies, Python, reverse engineering, and bug bounties.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Introduction
00:00 • 4min
Exploiting Meta Tags for Manipulation and Security
04:16 • 17min
Client Side Patch of Result Bug and Cookie Jar Overflow
20:55 • 15min
Cross Environment Authentication and Shared Secrets
35:49 • 14min
JS Hoisting and Exploiting Undefined Errors
50:09 • 11min
Asset Identification Challenges in Cloud-Native Apps
01:00:56 • 2min
The Trade-offs of Over-engineering in Bug Bounty Hunting
01:02:35 • 23min
Choosing a Programming Language, Data Sources, and Code Iteration
01:25:28 • 5min
Hacking IIS Servers: File and Folder Name Guessing, Shell Access, and XXE Payloads
01:30:07 • 9min
Automating Code Review with JS Weasel and AI
01:38:38 • 25min
Post Message Vulnerabilities and Listener Tracking
02:03:21 • 16min
Building and Open-Sourcing a Parsing Function with Docker
02:19:26 • 2min
Hiding Content from Scrapers and XSLT Transforms
02:21:46 • 28min
Exploring the Perforce Version Control System and Testing Methodologies
02:49:44 • 1min
Python, Reverse Engineering, and Bug Bounties
02:51:05 • 9min