Critical Thinking - Bug Bounty Podcast cover image

Critical Thinking - Bug Bounty Podcast

Latest episodes

undefined
Oct 17, 2024 • 1h 41min

Episode 93: A Chat with Dr. Bouman - Life as a Hacker and a Doctor

Dr. Jonathan Bouman, a unique blend of medical doctor and hacker, shares his fascinating journey of balancing healthcare and bug bounty hunting. He discusses the ethical responsibilities that tie both fields together and reflects on the challenges faced when protecting sensitive healthcare data. The conversation highlights experiences with Amazon's bug bounty program and explores the importance of collaboration in the hacking community. Additionally, Dr. Bouman emphasizes maintaining well-being for tech professionals amid the pressures of dual careers.
undefined
Oct 10, 2024 • 48min

Episode 92 - SAML XPath Confusion, Chinese DNS Poisoning, and AI Powered 403 Bypasser

A deep dive into cybersecurity reveals startling insights about vulnerabilities like SAML exploitation and DNS poisoning linked to China's Great Firewall. Discover a groundbreaking 0-click exploit within MediaTek chipsets that could endanger Android and IoT devices. The conversation highlights innovative AI-enhanced tools for web fuzzing and discusses community efforts to navigate CSP bypass techniques. Plus, tips for budding researchers on overcoming common challenges in vulnerability assessments add an inspiring touch!
undefined
Oct 3, 2024 • 1h 23min

Episode 91: Zero to LHE in 9 Months (feat gr3pme)

Brandyn Murtagh, known as gr3pme, is a HackerNotes writer with a decade of cybersecurity experience. He shares his unique journey into bug bounty hunting, discussing the power of mentorship and the importance of emotional regulation. The conversation delves into strategies for selecting targets and the benefits of networking in the hacking community. Murtagh also highlights insights on ecosystem hacking and vulnerability discovery, particularly in fintech, making the complex world of bug hunting both approachable and engaging for listeners.
undefined
11 snips
Sep 26, 2024 • 52min

Episode 90: 5k Clickjacking, Encryption Oracles, and Cursor for PoCs

Tune in for some hilarious tales from the coding world, including food expense reports linked to an app development tool. Discover the intricacies of exploiting a major clickjacking vulnerability in Google Docs. They also dive deep into the alarming ease of hijacking Telegram accounts in seconds. Alongside debates on AI coding tools and SQL injections, the podcast highlights the gaming spirit in ethical hacking and introduces a new merch store for fans. It's a blend of tech insights and lighthearted banter that you won't want to miss!
undefined
Sep 19, 2024 • 1h 58min

Episode 89: The Untapped Bug Bounty Landscape of IoT w/ Matt Brown

Matt Brown, an expert in IoT hacking and hardware methodologies, shares his thrilling journey through the world of cybersecurity. He dives into the complexities of hardware hacking, including BGA reballing and vulnerabilities in SSL connections. The conversation unveils techniques for exploiting IoT devices and emphasizes the importance of hands-on experience. Brown also dissects the pitfalls of certificate validation, recounting his own bug stories to illustrate real-world challenges in IoT security. Prepare to be fascinated by the dynamic realm of ethical hacking!
undefined
Sep 12, 2024 • 1h 6min

Episode 88: News, Tools, and Writeups

Dive into the world of web security as the hosts explore a new cheat sheet for URL validation bypass. Learn about the innovative Sanic DNS for high-speed lookups and Dockerization strategies for Orange Confusion Attacks. Discover insights on PHP object injection exploits affecting WordPress and discuss the impact of browser tracking protections. With a blend of nostalgia and creativity, the conversation highlights the evolving landscape of cybersecurity and the importance of collaboration in tackling vulnerabilities.
undefined
Sep 5, 2024 • 1h 27min

Episode 87: 'Hacker Wife' Mariah Gardner on Bug Bounty mentality and relationships

Mariah Garder, an insightful voice in the Bug Bounty community, shares her experiences navigating relationships within this unique field. She discusses the emotional rollercoaster of live hacking events and the importance of mutual support between hackers and their partners. Mariah emphasizes balancing personal ambitions with family life, addressing the complexities of work-life dynamics. Listeners will enjoy her tips on maintaining communication and nurturing relationships while pursuing a rewarding but demanding passion.
undefined
Aug 29, 2024 • 42min

Episode 86: The X-Correlation between Frans & RCE - Research Drop

Frans Rosen, a cybersecurity expert, shares groundbreaking insights from his latest presentation. He discusses X-correlation injections and their effects on server-side vulnerabilities, emphasizing the role of request IDs. Frans delves into fuzz testing techniques, revealing how to uncover hidden software weaknesses, and highlights the complexities of managing cross-origin APIs. Additionally, he explores security challenges related to JSON Web Tokens and logging pipelines, providing practical solutions for developers and security professionals.
undefined
Aug 22, 2024 • 1h 31min

Episode 85: Practical Applications of DEFCON 32 Web Research

In this discussion, security researcher Orange Tsai dives into web application vulnerabilities uncovered at DEFCON 32. He shares insights on innovative timing attacks and cache exploitation techniques. The conversation shifts to the practicalities of parsing email addresses, highlighting SMTP injection risks. Tsai also addresses the relevance of legacy protocols and their modern exploits. Lively anecdotes about DEFCON and unique collectibles add a light-hearted touch, making complex topics more engaging.
undefined
Aug 15, 2024 • 27min

Episode 84: 0xLupin & Takeaways from Google's Las Vegas BugSwat

Roni Carta, known as 0xLupin and celebrated for their MVH win at Google LHE, joins the discussion to share insights from a recent collaborative hacking experience. They emphasize the importance of understanding business contexts when identifying vulnerabilities. Legal considerations in bug bounty hunting are also highlighted, showcasing the need for close collaboration between security and legal teams. Roni shares amusing anecdotes from the Google event, illustrating community bonds and the fascinating world of bug bounty hunting.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode