Critical Thinking - Bug Bounty Podcast

Episode 11: CV$$, Web Cache Deception, and SSTI

Mar 16, 2023
Ask episode
Chapters
Transcript
Episode notes
1
Introduction
00:00 • 2min
2
How to Find a Cool Bug on Outlook
02:27 • 2min
3
Snapchat's Bug Bounty
04:29 • 2min
4
Snapchat's Security Team Is Strong
06:38 • 4min
5
Snapchat's Bug Bounty
10:39 • 2min
6
The Importance of User Enumeration in Bug Bounties
12:16 • 2min
7
How to Chain Bugs Together
14:11 • 3min
8
CVSS and the Bug Bounty Reporting Process
17:23 • 2min
9
How to Increase Availability as a Full-Time Hacker
19:34 • 2min
10
How to Score a Vulnerability With CVS
21:24 • 2min
11
CVSS and the OWASP Rating System
23:25 • 2min
12
The Impact of Attack Complexity on Vulnerability Scores
25:00 • 3min
13
The Role of EUU IDs in Bug-Biting
28:20 • 2min
14
The Threat Model Isn't Built Around Projecting IDs
30:19 • 2min
15
CBSS: The Highs and the Lows
32:21 • 3min
16
CV SS 3.1: Extended Fields
35:49 • 2min
17
How to Use Attack Complexity to Your Advantage
37:20 • 2min
18
How Fisher and I Intercepted a Payment on the Local Network
39:27 • 3min
19
How to Hack on a Product That You Use
42:17 • 2min
20
Why LFI's Should Be High?
44:18 • 2min
21
The Importance of Webcast Deception
46:32 • 2min
22
WebCached Deception: A Live Hacking Event
48:50 • 4min
23
How to Cache a Page in an Application
52:40 • 3min
24
How to Avoid Web Caching Deception
55:18 • 2min
25
How to Test Responsibly on Prod
57:45 • 2min
26
Joel and I Are Excited to Be in LA for the World Cup
59:37 • 4min