

Critical Thinking - Bug Bounty Podcast
Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Episodes
Mentioned books

6 snips
Aug 1, 2024 • 37min
Episode 82: Part-Time Bug Bounty
Joel Margolis, a savvy part-time bug bounty hunter, shares invaluable strategies for balancing this side hustle with other commitments. He delves into how to select impactful programs, streamline bug hunting processes, and optimize productivity. Joel emphasizes the importance of accountability, effective time management, and precise note-taking, highlighting tools like Notion. He also provides insights into notable security flaws found in Evernote and ServiceNow, showcasing the skills needed to thrive in this competitive field.

21 snips
Jul 25, 2024 • 2h 5min
Episode 81: Crushing Client-Side on Any Scope with MatanBer
Join MatanBer, a seasoned expert in client-side hacking and DevTools, as he shares invaluable insights on navigating web vulnerabilities. He discusses advanced techniques for exploiting client-side issues like XSS and HTML injection, while offering practical DevTools tips that enhance debugging efficiency. The conversation delves into the appeal of chaining attacks and overcoming Web Application Firewalls, alongside personal anecdotes that illuminate the challenges of real-world cybersecurity. It's a treasure trove of knowledge for aspiring hackers!

Jul 18, 2024 • 2h 49min
Episode 80: Pwn2Own VS H1 Live Hacking Event (feat SinSinology)
Experienced hacker SinSinology discusses differences between Pwn2Own and HackerOne events. Topics include hacking methodology, debuggers in IoT devices, Pwn2Own challenges, and bug reports. Exploring contrasts between live hacking events, navigation of hacking competitions, and steps for Pwn2Own. Gratitude expressed for bug bounty community.

Jul 11, 2024 • 1h 10min
Episode 79: The State of CSS Injection - Leaking Text Nodes & HTML Attributes
YTCracker, an artist acclaimed for his contributions to music in tech and gaming, joins the conversation on CSS injection techniques. They dissect the art of sequential import chaining and delve into font ligatures that can leak information. The discussion reveals sophisticated strategies for exploiting CSS vulnerabilities, highlighting methods for extracting HTML attributes. Tune in for insights on effective content security measures and the evolving landscape of web technologies, sprinkled with YTCracker's creative flair!

Jul 4, 2024 • 1h 6min
Episode 78: Less Writing, More Hacking - Reporting Efficiency Techniques
This podcast discusses efficient bug bounty reporting techniques, including XSS WAF bypasses, cache poisoning, and AI tools for reporting. They explore the benefits of using tools like Fabric, Loom, and ShareX, and share insights on enhancing productivity in hacking and bug bounty reporting.

Jun 27, 2024 • 1h 50min
Episode 77: Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated
Explore MongoDB NoSQL injection challenges and practical bug hunting tips. Uncover security vulnerabilities in Kakao Chat app and iOS authentication processes. Learn about time-based token risks and hacking car diagnostic ports. Discover the impact of gluten on focus and energy levels. Get insights on meal preparation, managing caloric intake, and optimizing well-being for bug hunters. Understand the importance of setting realistic goals and navigating job changes.

Jun 20, 2024 • 1h 35min
Episode 76: Match & Replace - HTTP Proxies' Most Underrated Feature
In this podcast, they discuss match and replace techniques for bug bounties, the HackerOne Ambassador World Cup, Zoom ATO bug, SharePoint XXE, and the importance of understanding browser security vulnerabilities. They explore leveraging match and replace rules in bug bounty testing, enhancing Burp Suite functionality, and updating plugin formats for improved workflow.

Jun 13, 2024 • 2h 45min
Episode 75: *Rerun* of The OG Bug Bounty King - Frans Rosen
Frans Rosen, The OG Bug Bounty King, discusses S3 subdomain takeovers, attacking modern web technologies, account hijacking using Dirty Dancing in OAuth flows, and bug bounty methodologies. Topics include bug hunting strategies, automation, entrepreneurship, and managing growth in the cybersecurity field.

5 snips
Jun 6, 2024 • 1h 38min
Episode 74: Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin)
Expert 0xLupin discusses supply chain attacks, ethical considerations for maintainers, and new tool Depi. Topics include types of attacks, vulnerabilities in CI builds, challenges in managing software dependencies, detecting supply chain attacks, domain squatting, securing bug bounty programs, significance of lock files, bug hunting emotions, analyzing attack scenarios, and risks of NPM and Yarn supply chain attacks.

May 30, 2024 • 31min
Episode 73: Sandboxed IFrames and WAF Bypasses
Discussion on WAF bypass tools, sandboxed iframes, programs redacting bug reports, optional chaining operator in JS, Chrome cache exploit, hacker team shoutout, and innovative iframe hijacking techniques.