Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
undefined
6 snips
Aug 1, 2024 • 37min

Episode 82: Part-Time Bug Bounty

Joel Margolis, a savvy part-time bug bounty hunter, shares invaluable strategies for balancing this side hustle with other commitments. He delves into how to select impactful programs, streamline bug hunting processes, and optimize productivity. Joel emphasizes the importance of accountability, effective time management, and precise note-taking, highlighting tools like Notion. He also provides insights into notable security flaws found in Evernote and ServiceNow, showcasing the skills needed to thrive in this competitive field.
undefined
21 snips
Jul 25, 2024 • 2h 5min

Episode 81: Crushing Client-Side on Any Scope with MatanBer

Join MatanBer, a seasoned expert in client-side hacking and DevTools, as he shares invaluable insights on navigating web vulnerabilities. He discusses advanced techniques for exploiting client-side issues like XSS and HTML injection, while offering practical DevTools tips that enhance debugging efficiency. The conversation delves into the appeal of chaining attacks and overcoming Web Application Firewalls, alongside personal anecdotes that illuminate the challenges of real-world cybersecurity. It's a treasure trove of knowledge for aspiring hackers!
undefined
Jul 18, 2024 • 2h 49min

Episode 80: Pwn2Own VS H1 Live Hacking Event (feat SinSinology)

Experienced hacker SinSinology discusses differences between Pwn2Own and HackerOne events. Topics include hacking methodology, debuggers in IoT devices, Pwn2Own challenges, and bug reports. Exploring contrasts between live hacking events, navigation of hacking competitions, and steps for Pwn2Own. Gratitude expressed for bug bounty community.
undefined
Jul 11, 2024 • 1h 10min

Episode 79: The State of CSS Injection - Leaking Text Nodes & HTML Attributes

YTCracker, an artist acclaimed for his contributions to music in tech and gaming, joins the conversation on CSS injection techniques. They dissect the art of sequential import chaining and delve into font ligatures that can leak information. The discussion reveals sophisticated strategies for exploiting CSS vulnerabilities, highlighting methods for extracting HTML attributes. Tune in for insights on effective content security measures and the evolving landscape of web technologies, sprinkled with YTCracker's creative flair!
undefined
Jul 4, 2024 • 1h 6min

Episode 78: Less Writing, More Hacking - Reporting Efficiency Techniques

This podcast discusses efficient bug bounty reporting techniques, including XSS WAF bypasses, cache poisoning, and AI tools for reporting. They explore the benefits of using tools like Fabric, Loom, and ShareX, and share insights on enhancing productivity in hacking and bug bounty reporting.
undefined
Jun 27, 2024 • 1h 50min

Episode 77: Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated

Explore MongoDB NoSQL injection challenges and practical bug hunting tips. Uncover security vulnerabilities in Kakao Chat app and iOS authentication processes. Learn about time-based token risks and hacking car diagnostic ports. Discover the impact of gluten on focus and energy levels. Get insights on meal preparation, managing caloric intake, and optimizing well-being for bug hunters. Understand the importance of setting realistic goals and navigating job changes.
undefined
Jun 20, 2024 • 1h 35min

Episode 76: Match & Replace - HTTP Proxies' Most Underrated Feature

In this podcast, they discuss match and replace techniques for bug bounties, the HackerOne Ambassador World Cup, Zoom ATO bug, SharePoint XXE, and the importance of understanding browser security vulnerabilities. They explore leveraging match and replace rules in bug bounty testing, enhancing Burp Suite functionality, and updating plugin formats for improved workflow.
undefined
Jun 13, 2024 • 2h 45min

Episode 75: *Rerun* of The OG Bug Bounty King - Frans Rosen

Frans Rosen, The OG Bug Bounty King, discusses S3 subdomain takeovers, attacking modern web technologies, account hijacking using Dirty Dancing in OAuth flows, and bug bounty methodologies. Topics include bug hunting strategies, automation, entrepreneurship, and managing growth in the cybersecurity field.
undefined
5 snips
Jun 6, 2024 • 1h 38min

Episode 74: Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin)

Expert 0xLupin discusses supply chain attacks, ethical considerations for maintainers, and new tool Depi. Topics include types of attacks, vulnerabilities in CI builds, challenges in managing software dependencies, detecting supply chain attacks, domain squatting, securing bug bounty programs, significance of lock files, bug hunting emotions, analyzing attack scenarios, and risks of NPM and Yarn supply chain attacks.
undefined
May 30, 2024 • 31min

Episode 73: Sandboxed IFrames and WAF Bypasses

Discussion on WAF bypass tools, sandboxed iframes, programs redacting bug reports, optional chaining operator in JS, Chrome cache exploit, hacker team shoutout, and innovative iframe hijacking techniques.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app