

Critical Thinking - Bug Bounty Podcast
Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Episodes
Mentioned books

May 23, 2024 • 53min
Episode 72: Research TLDRs & Smuggling Payloads in Well Known Data Types
Discussing PDF.JS XSS and NextJS SSRF, improving bug bounty statistics, concealing data in IPv6 addresses, navigating RFC compliance, business logic vulnerabilities, bug hunting strategies, JavaScript in software development, and transitioning to a new tool efficiently.

May 16, 2024 • 1h 45min
Episode 71: More VDP Chats & AI Bias Bounty Strats with Keith Hoodlet
Cybersecurity expert Keith Hoodlet discusses VDPs and AI bias bounties, highlighting challenges in securing large organizations and the importance of understanding human biases when hacking AI. They also touch on bug bounty programs, government grants for VDPs, and testing scenarios with chatbots.

May 9, 2024 • 43min
Episode 70: NahamCon and CSP Bypasses Everywhere
Cybersecurity researcher Ben Sadeghipour discusses NahamCon news, LHEs, CI/CD, and drops cool CSP Bypasses. Topics include WordPress hacking, bug bounty rewards, sponsorships, maximizing bonuses, anticipation for NahamCon, Deppie tool, CSP bypass techniques, and bypassing Google CSP.

May 2, 2024 • 1h 49min
Episode 69: Johan Carlsson - 3 Month Check-in on Full-time Bug Bounty.
Johan Carlsson, a dedicated bug bounty hunter, shares his journey transitioning to full-time bug hunting. He discusses the thrill of discovering vulnerabilities like a CSP bypass in GitHub and a critical flaw in GitLab. Johan highlights his focus on complex bug types like ReDoS and OAuth, emphasizing the unpredictability that accompanies bug hunting. He also offers insights into balancing personal life with his bug bounty career, navigating financial challenges, and the importance of community support in this unique profession.

Apr 25, 2024 • 1h 4min
Episode 68: 0-days & HTMX-SS with Mathias
Security researcher Mathias discusses HTMX vulnerabilities and bug bounty challenges like CSP bypass, XSS conversions, and HTMX disable bypasses. They also explore CDN-CGI functionality, CTF Challenge results, and the use of HTMX in larger applications with performance trade-offs.

Apr 18, 2024 • 1h 20min
Episode 67: VDPs & Accidental Program VS Hacker Debate Part 2
Exploring the benefits of Vulnerability Disclosure Programs (VDPs) and the ongoing Program VS Hacker debate. Touching on leaderboard accuracy and financial support for talented individuals. Delving into bug bounty hunting challenges and governance of bug fixes and hacker compensation. Valuing research in bug bounty programs and the importance of immediate response in securing systems.

15 snips
Apr 11, 2024 • 58min
Episode 66: CDN-CGI Research, Intent To Ship, and Louis Vuitton
In this podcast, they discuss YesWeHack Louis Vuitton LHE, importance of failure in bug bounty, CDN CGI research, benefits of cold showers, Louis Vuitton live hacking event, bug bounty dominance, browser market share insights, OAuth flow vulnerabilities, Kaido workflows, Blink's features, DOM secrets, data attributes in frameworks.

14 snips
Apr 4, 2024 • 2h 29min
Episode 65: Motivation and Methodology with Sam Curry (Zlz)
Sam Curry, an ethical hacker, discusses pushing boundaries in bug bounty hunting, hacking Tesla, casinos, Starbucks, and getting detained at the airport. Topics include hacking ethics, bug bounty efficacy, collaboration, and secondary context bugs.

8 snips
Mar 28, 2024 • 1h 8min
Episode 64: .NET Remoting, CDN Attack Surface, and Recon vs Main App
.NET Remoting exploitation, Dom Purify bypass, Cloudflare CDN-CGI endpoint, JavaScript deobfuscation, bug bounty collaboration, impactful POCs, hiding XSS payloads with URL updates

14 snips
Mar 21, 2024 • 1h 22min
Episode 63: JHaddix Returns
JHaddix, bug bounty hunting expert, discusses updates to The Bug Hunter's Methodology, threat intelligence, buying credentials from the dark web, new recon techniques, and integrating AI into workflows. The podcast touches on red teaming, FIS hunting, and personal hacking journey insights.