
Critical Thinking - Bug Bounty Podcast
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Latest episodes

Sep 19, 2024 • 1h 58min
Episode 89: The Untapped Bug Bounty Landscape of IoT w/ Matt Brown
Matt Brown, an expert in IoT hacking and hardware methodologies, shares his thrilling journey through the world of cybersecurity. He dives into the complexities of hardware hacking, including BGA reballing and vulnerabilities in SSL connections. The conversation unveils techniques for exploiting IoT devices and emphasizes the importance of hands-on experience. Brown also dissects the pitfalls of certificate validation, recounting his own bug stories to illustrate real-world challenges in IoT security. Prepare to be fascinated by the dynamic realm of ethical hacking!

Sep 12, 2024 • 1h 6min
Episode 88: News, Tools, and Writeups
Dive into the world of web security as the hosts explore a new cheat sheet for URL validation bypass. Learn about the innovative Sanic DNS for high-speed lookups and Dockerization strategies for Orange Confusion Attacks. Discover insights on PHP object injection exploits affecting WordPress and discuss the impact of browser tracking protections. With a blend of nostalgia and creativity, the conversation highlights the evolving landscape of cybersecurity and the importance of collaboration in tackling vulnerabilities.

Sep 5, 2024 • 1h 27min
Episode 87: 'Hacker Wife' Mariah Gardner on Bug Bounty mentality and relationships
Mariah Garder, an insightful voice in the Bug Bounty community, shares her experiences navigating relationships within this unique field. She discusses the emotional rollercoaster of live hacking events and the importance of mutual support between hackers and their partners. Mariah emphasizes balancing personal ambitions with family life, addressing the complexities of work-life dynamics. Listeners will enjoy her tips on maintaining communication and nurturing relationships while pursuing a rewarding but demanding passion.

Aug 29, 2024 • 42min
Episode 86: The X-Correlation between Frans & RCE - Research Drop
Frans Rosen, a cybersecurity expert, shares groundbreaking insights from his latest presentation. He discusses X-correlation injections and their effects on server-side vulnerabilities, emphasizing the role of request IDs. Frans delves into fuzz testing techniques, revealing how to uncover hidden software weaknesses, and highlights the complexities of managing cross-origin APIs. Additionally, he explores security challenges related to JSON Web Tokens and logging pipelines, providing practical solutions for developers and security professionals.

Aug 22, 2024 • 1h 31min
Episode 85: Practical Applications of DEFCON 32 Web Research
In this discussion, security researcher Orange Tsai dives into web application vulnerabilities uncovered at DEFCON 32. He shares insights on innovative timing attacks and cache exploitation techniques. The conversation shifts to the practicalities of parsing email addresses, highlighting SMTP injection risks. Tsai also addresses the relevance of legacy protocols and their modern exploits. Lively anecdotes about DEFCON and unique collectibles add a light-hearted touch, making complex topics more engaging.

Aug 15, 2024 • 27min
Episode 84: 0xLupin & Takeaways from Google's Las Vegas BugSwat
Roni Carta, known as 0xLupin and celebrated for their MVH win at Google LHE, joins the discussion to share insights from a recent collaborative hacking experience. They emphasize the importance of understanding business contexts when identifying vulnerabilities. Legal considerations in bug bounty hunting are also highlighted, showcasing the need for close collaboration between security and legal teams. Roni shares amusing anecdotes from the Google event, illustrating community bonds and the fascinating world of bug bounty hunting.

Aug 8, 2024 • 55min
Episode 83: Brainstorming Proxy Plugins
Dive into a lively brainstorming session filled with innovative ideas for plugins and improvements! The hosts discuss a 403 bypassing workflow, text expander features, and the exciting integration of AI in software. Explore the clever use of HTML entities for web security and the potential of tools like Espanso for efficiency. They also tackle the complexities of API testing, emphasizing the need for better functionalities in security tools. Get ready for a mix of humor and tech insights in this engaging conversation!

5 snips
Aug 1, 2024 • 37min
Episode 82: Part-Time Bug Bounty
Joel Margolis, a savvy part-time bug bounty hunter, shares invaluable strategies for balancing this side hustle with other commitments. He delves into how to select impactful programs, streamline bug hunting processes, and optimize productivity. Joel emphasizes the importance of accountability, effective time management, and precise note-taking, highlighting tools like Notion. He also provides insights into notable security flaws found in Evernote and ServiceNow, showcasing the skills needed to thrive in this competitive field.

21 snips
Jul 25, 2024 • 2h 5min
Episode 81: Crushing Client-Side on Any Scope with MatanBer
Join MatanBer, a seasoned expert in client-side hacking and DevTools, as he shares invaluable insights on navigating web vulnerabilities. He discusses advanced techniques for exploiting client-side issues like XSS and HTML injection, while offering practical DevTools tips that enhance debugging efficiency. The conversation delves into the appeal of chaining attacks and overcoming Web Application Firewalls, alongside personal anecdotes that illuminate the challenges of real-world cybersecurity. It's a treasure trove of knowledge for aspiring hackers!

Jul 18, 2024 • 2h 49min
Episode 80: Pwn2Own VS H1 Live Hacking Event (feat SinSinology)
Experienced hacker SinSinology discusses differences between Pwn2Own and HackerOne events. Topics include hacking methodology, debuggers in IoT devices, Pwn2Own challenges, and bug reports. Exploring contrasts between live hacking events, navigation of hacking competitions, and steps for Pwn2Own. Gratitude expressed for bug bounty community.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.