

Critical Thinking - Bug Bounty Podcast
Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Episodes
Mentioned books

Jan 4, 2024 • 3h
Episode 52: Best Technical Content from Year 1 of CTBB Podcast
The podcast highlights the best technical moments from the past year, including topics such as exploiting meta tags and base tags in HTML, client-side path traversal and cookie jar overflow, cross environment authentication bugs, the open-faced iframe sandwich, JS hoisting, Sean Yeoh on subdomains vs IP in recon, reversing enterprise software, building out a recon flow, hacking IIS servers, automating code review with JS Weasel and AI, post message vulnerabilities and listener tracking, hiding content from scrapers and XSLT transforms, exploring the Perforce version control system and testing methodologies, Python, reverse engineering, and bug bounties.

Dec 28, 2023 • 1h 22min
Episode 51: Hacker Stats 2023 & 2024 Goals
In this podcast episode, the hosts discuss noteworthy news items such as a Hacker One Crit and Blind CSS. They also recap their personal bug bounty stats for 2023 and share their goals for 2024. Topics include keyboard shortcut utility systems, CTF challenges, blind CSS exfiltration, and the importance of research and exploration in the hacking community.

Dec 21, 2023 • 2h 25min
Episode 50: Mathias "Fall in a well" Karlsson - Bug Bounty Prophet
Hacking master Mathias Karlsson discusses burnout, collaboration, and specialization in bug bounty. They dive into technical details of MXSS and XSLT, character encoding, and predict the future of bug bounty. They also talk about the importance of finding insecure defaults, the beauty of simple code, and the benefits of sharing research. The evolution of bug bounty programs and the rise of bug bounty budgets are explored. Techniques for bypassing Web Application Firewalls and the importance of persistence in bug bounty programs are discussed.

Dec 14, 2023 • 52min
Episode 49: Getting Live Hacking Event Invites & Bug Bounty Collab with Nagli
Nagli, cybersecurity expert and bug bounty hunter, joins Justin Gardner to discuss recent hacking discoveries. They explore finding and exploiting a backup file, vulnerabilities through Swagger files, and debate an 'undisclosed' domain. They reflect on the Live Hacking Event circuit in 2023 and preview what's to come in 2024. They also share strategies for getting invited to live hacking events and discuss their experience at previous events.

Dec 7, 2023 • 1h 37min
Episode 48: MVH, DEFCON Black Badge, Googler - Sam Erb
Sam Erb, Google Security Engineer and DEFCON Black Badge winner, discusses the importance of understanding how systems work to find vulnerabilities, his engineering background influencing his hunting style and methodologies, his career development and work with Google, recent Google Vulnerability Programs, centralized management and control of API endpoints, exploring majors and career paths in security engineering and computer science, accessing open data and hosting, experience at Google and involvement in bug bounty program, hacking on Google and manipulating protobufs, discussion on Brand Indicators for Message Identification (BIMI) and abuse-related methodologies, and bug reports and prioritizing fixes.

4 snips
Nov 30, 2023 • 1h 32min
Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans
The podcast discusses the struggles of bug bounty hunting, including feeling disconnected after live hacking events and the frustration of not finding bugs. They highlight the significance of perseverance and getting into a flow state. They explore topics such as client-side paths, manipulating webpack map files, and exploiting XSS vulnerabilities in iframed domains. They also discuss the benefits of Google's extension for hacking and techniques for bypassing Content Security Policy.

Nov 23, 2023 • 44min
Episode 46: The SAML Ramble
This podcast delves into the world of SAML and its vulnerabilities, providing insights on bug hunting methodology, the SAML authentication flow, exploiting transformations, and various types of SAML bugs and vulnerabilities.

4 snips
Nov 16, 2023 • 2h 37min
Episode 45: The OG Bug Bounty King - Frans Rosen
Frans Rosén, an OG bug bounty hunter and co-founder of Detectify, joins the podcast to discuss bug exploitation, developer terminology, collaboration challenges, and balancing hacking with parenting. They cover topics such as discovering s3 subdomain takeovers, attacking modern web technologies, and account hijacking using Dirty Dancing in sign-in OAuth flows.

Nov 9, 2023 • 1h 11min
Episode 44: URL Parsing & Auth Bypass Magic
The podcast delves into URL parsing and authentication bypass techniques, highlighting common tips and tricks for bypassing restrictions. It covers topics such as OAuth vulnerabilities, controversy surrounding vulnerability reports, Facebook login ATO, and the risks of centralization. The hosts also discuss the importance of understanding URL components, potential issues with OAuth flows in Android apps, and the vulnerabilities of URL parsing in bug bounty programs.

Nov 2, 2023 • 1h 1min
Episode 43: Caido - The Up-And-Coming HTTP Proxy
In this episode, they discuss the challenges of building an HTTP proxy tool, the importance of user feedback in shaping its development, and the balance between basic and nice-to-have features. They also explore the usefulness of collections in organizing HTTP requests, customization options for workflows, upcoming features in the Kaido tool, collaboration in bug bounty reporting, and the introduction of Kaido as an enterprise vulnerability management platform.