Critical Thinking - Bug Bounty Podcast
Critical Thinking - Bug Bounty Podcast
  • Видео 156
  • Просмотров 275 720
The State of CSS Injection - Leaking Text Nodes & HTML Attributes (Ep. 79)
Episode 79: In this episode of Critical Thinking - Bug Bounty Podcast we deepdive CSS injection, and explore topics like sequential import chaining, font ligatures, and attribute exfiltration.
Follow us on twitter at: ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater & Teknogeek on twitter:
0xteknogeek
rhynorater
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to...
Просмотров: 596

Видео

Less Writing, More Hacking - Reporting Efficiency Techniques (Ep.78)
Просмотров 1,2 тыс.19 часов назад
Episode 78: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about writing reports. We share some tips that we’ve learned, and discuss ways that AI can (and can’t) help with that process. We also talk about the benefit of incorporating tools like Fabric, Loom, and ShareX. Follow us on twitter at: ctbbpodcast We're new to this podcasting thing, so feel free to ...
Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated (Ep.77)
Просмотров 2,4 тыс.14 дней назад
Episode 77: In this episode of Critical Thinking - Bug Bounty Podcast Joel and Justin discuss some fresh writeups including some MongoDB injections, ORMs, and exploits in Kakao and iOS before pivoting into a conversation about staying motivated and avoiding burnout while hunting. Follow us on twitter at: ctbbpodcast We're new to this podcasting thing, so feel free to send us any fee...
Match & Replace - HTTP Proxies' Most Underrated Feature (Ep. 76)
Просмотров 1,9 тыс.21 день назад
Episode 76: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about Match and Replace and the often overlooked use cases for it, like bypassing paywalls, modifying host headers, and storing payloads. We also talk about the HackerOne Ambassador World Cup and the issues with dupe submissions, and go through some write-ups. Follow us on twitter at: ctbbpodcast We'...
*Rerun* of The OG Bug Bounty King - Frans Rosen (Ep. 75)
Просмотров 1,8 тыс.28 дней назад
*Rerun* of The OG Bug Bounty King - Frans Rosen (Ep. 75)
Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin) (Ep. 74)
Просмотров 2,1 тыс.Месяц назад
Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin) (Ep. 74)
Sandboxed IFrames and WAF Bypasses (Ep. 73)
Просмотров 1,3 тыс.Месяц назад
Sandboxed IFrames and WAF Bypasses (Ep. 73)
Research TLDRs & Smuggling Payloads in Well Known Data Types (Ep. 72)
Просмотров 1,3 тыс.Месяц назад
Research TLDRs & Smuggling Payloads in Well Known Data Types (Ep. 72)
More VDP Chats & AI Bias Bounty Strats with Keith Hoodlet (Ep. 71)
Просмотров 1,3 тыс.Месяц назад
More VDP Chats & AI Bias Bounty Strats with Keith Hoodlet (Ep. 71)
NahamCon and CSP Bypasses Everywhere (Ep. 70)
Просмотров 2,5 тыс.2 месяца назад
NahamCon and CSP Bypasses Everywhere (Ep. 70)
Johan Carlsson - 3 Month Check-in on Full-time Bug Bounty. (Ep. 69)
Просмотров 2,5 тыс.2 месяца назад
Johan Carlsson - 3 Month Check-in on Full-time Bug Bounty. (Ep. 69)
0-days & HTMX-SS with Mathias (Ep. 68)
Просмотров 2 тыс.2 месяца назад
0-days & HTMX-SS with Mathias (Ep. 68)
VDPs & Accidental Program VS Hacker Debate Part 2 (Ep. 67)
Просмотров 1,7 тыс.2 месяца назад
VDPs & Accidental Program VS Hacker Debate Part 2 (Ep. 67)
CDN-CGI Research, Intent To Ship, and Louis Vuitton (Ep. 66)
Просмотров 2,1 тыс.3 месяца назад
CDN-CGI Research, Intent To Ship, and Louis Vuitton (Ep. 66)
Motivation and Methodology with Sam Curry (Zlz) (Ep. 65)
Просмотров 5 тыс.3 месяца назад
Motivation and Methodology with Sam Curry (Zlz) (Ep. 65)
.NET Remoting, CDN Attack Surface, and Recon vs Main App (Ep. 64)
Просмотров 1,9 тыс.3 месяца назад
.NET Remoting, CDN Attack Surface, and Recon vs Main App (Ep. 64)
JHaddix Returns (Ep. 63)
Просмотров 3,8 тыс.3 месяца назад
JHaddix Returns (Ep. 63)
Frontend Language Oddities (Ep. 62)
Просмотров 1,4 тыс.3 месяца назад
Frontend Language Oddities (Ep. 62)
A Hacker on Wall Street - JR0ch17 (Ep. 61)
Просмотров 1,9 тыс.4 месяца назад
A Hacker on Wall Street - JR0ch17 (Ep. 61)
Our Take on PortSwigger's Top 10 Web Hacking Techniques of 2023 (Ep. 60)
Просмотров 2,3 тыс.4 месяца назад
Our Take on PortSwigger's Top 10 Web Hacking Techniques of 2023 (Ep. 60)
Bug Bounty Gadget Hunting & Hacker's Intuition (Ep. 59)
Просмотров 3,1 тыс.4 месяца назад
Bug Bounty Gadget Hunting & Hacker's Intuition (Ep. 59)
Youssef Sammouda - Client-Side & ATO War Stories (Ep. 58)
Просмотров 5 тыс.4 месяца назад
Youssef Sammouda - Client-Side & ATO War Stories (Ep. 58)
Episode 57: Live Hacking Event Inside Scoop - H1-305
Просмотров 1,6 тыс.5 месяцев назад
Episode 57: Live Hacking Event Inside Scoop - H1-305
Using Data Science to win Bug Bounty - Mayonaise (aka Jon Colston) (Ep. 56)
Просмотров 3 тыс.5 месяцев назад
Using Data Science to win Bug Bounty - Mayonaise (aka Jon Colston) (Ep. 56)
Popping WordPress Plugins - Methodology Brain dump (Ep. 55)
Просмотров 2,2 тыс.5 месяцев назад
Popping WordPress Plugins - Methodology Brain dump (Ep. 55)
White Box Formulas - Vulnerable Coding Patterns (Ep. 54)
Просмотров 1,6 тыс.5 месяцев назад
White Box Formulas - Vulnerable Coding Patterns (Ep. 54)
500k/yr as Full-Time Bug Hunter & Content Creator - Nahamsec (Ep. 53)
Просмотров 11 тыс.6 месяцев назад
500k/yr as Full-Time Bug Hunter & Content Creator - Nahamsec (Ep. 53)
Best Technical Content from 2023 (Ep. 52)
Просмотров 2,6 тыс.6 месяцев назад
Best Technical Content from 2023 (Ep. 52)
Hacker Stats 2023 & 2024 Goals (Ep. 51)
Просмотров 1,9 тыс.6 месяцев назад
Hacker Stats 2023 & 2024 Goals (Ep. 51)
Mathias "Fall in a well" Karlsson - Bug Bounty Prophet (Ep. 50)
Просмотров 2,7 тыс.6 месяцев назад
Mathias "Fall in a well" Karlsson - Bug Bounty Prophet (Ep. 50)

Комментарии

  • @4v4
    @4v4 День назад

    Lol, "isreali"

  • @Morteums
    @Morteums 4 дня назад

    Best advice!

  • @NotSushiant
    @NotSushiant 5 дней назад

    Could you please not interrupt the guest every 0.5 second?

  • @jub0bs
    @jub0bs 6 дней назад

    Great episode, as always. 🙇 This chaining of a semi-open redirect with an open redirect as part of Kakao's bug (explained by Joel at around 22:00) reminded me of one of the first (if only modest) bounties I ever got; for more details, see report 1032610 on h1.

  • @trustedsecurity6039
    @trustedsecurity6039 7 дней назад

    I dont see any postmessage through this extension at all and i check it on all my pentest engagement since 2 years 😅

  • @01_astronaut30
    @01_astronaut30 7 дней назад

    Amazing dude ❤😂🎉😢😮😅😊

  • @MFoster392
    @MFoster392 7 дней назад

    When you listen to the top hackers most of them are 100% proud nerds, too cool :)

  • @user-mo8uj9vq5u
    @user-mo8uj9vq5u 8 дней назад

    good stuff guys love the content as always as the humor is always great

  • @01_astronaut30
    @01_astronaut30 8 дней назад

    Nice research...

  • @musawerkhan9817
    @musawerkhan9817 10 дней назад

    Vote for James Kettle Episode

  • @prakhar0x01
    @prakhar0x01 12 дней назад

    Literally feel relatable at 50:12 😅😂

  • @key2007prchoi
    @key2007prchoi 12 дней назад

    맨날쓰던 어플에 이런 취약점이 있었다니..

  • @notTh3Mag1c1an
    @notTh3Mag1c1an 13 дней назад

    I imagine all those cache poisoning bugs will be bypassed by this or not ?

  • @shpockboss3834
    @shpockboss3834 14 дней назад

    You guys should also do live recon.

  • @rodnet2703
    @rodnet2703 14 дней назад

    I agree about the dupe thing. I spent days working on an RCE and finally got it. But it ended up being a dupe. But in the time I spent looking for the information to exploit the RCE I found other bugs that got accepted. So it wasn’t a total loss

  • @papafhill9126
    @papafhill9126 15 дней назад

    I love you guys' podcast. This is so incredibly valuable. Thank you.

  • @user-mk3zz8zn9b
    @user-mk3zz8zn9b 15 дней назад

    This is news to me, hearing english (justin talking about calories and diets) from these guys, never knew they could speak

  • @ninjafit-
    @ninjafit- 15 дней назад

    My bug bounty dads 🥰😂

  • @lacouille5943
    @lacouille5943 15 дней назад

    Hey guys! Thanks for always delivering everyweek! It's been part of my weekly routine for months and have already watched all of the episodes. Keep grinding, we all appreciate you!

  • @crusader_
    @crusader_ 15 дней назад

    First

  • @01_astronaut30
    @01_astronaut30 17 дней назад

  • @Morteums
    @Morteums 19 дней назад

    Thanks

  • @KiDR_IANI
    @KiDR_IANI 20 дней назад

    💜💜💚

  • @Morteums
    @Morteums 20 дней назад

    Cookie Bugs - Smuggling & Injection from Ankur Sundara, is that the paper you referenced ?

    • @Rhyn0r4t3r
      @Rhyn0r4t3r 17 дней назад

      Yep, that's the one.

  • @JeffSherlock
    @JeffSherlock 23 дня назад

    Tired of the "OG" crap.

    • @ezpzb
      @ezpzb 23 дня назад

      get over it jeff

  • @KiDR_IANI
    @KiDR_IANI 25 дней назад

    ❤❤❤❤

  • @makedredd299
    @makedredd299 25 дней назад

    2:13:22 🦐 🥪 * Gliding in on a shrimp sandwich 🇸🇪 = * Getting everything served on a silver platter. * Getting success without effort. * Getting a free ride.

  • @xscitobor1233
    @xscitobor1233 29 дней назад

    Can you add a link to the episode so we don't have to go searching guys?

  • @MarkFoudy
    @MarkFoudy 29 дней назад

    Dude, I am sick too!

  • @bughunter9766
    @bughunter9766 29 дней назад

    The legend ❤

  • @mr.researcher1525
    @mr.researcher1525 29 дней назад

    host just destroyed my 10mintues 🤬

    • @odenko7680
      @odenko7680 29 дней назад

      No, I find it very helpful and motivation to me

  • @RezaSahaf
    @RezaSahaf 29 дней назад

    Thank you so much for commitment and keeping it up ❤

  • @sudoer92
    @sudoer92 29 дней назад

    i just stopped what i was doing when i saw "Frans Rosen"🙂

  • @jren2956
    @jren2956 Месяц назад

    🔥

  • @user-mk3zz8zn9b
    @user-mk3zz8zn9b Месяц назад

    Okay, so who was explaining both of them were just chatting, 🤧 , guys you were supposed to explain, all of the pipelining and ci cd stuff, how are we supposed to know... you cant just assume that. 😵

    • @Mary-le5db
      @Mary-le5db 10 дней назад

      no wonder I didn't understand half of it.

  • @01_astronaut30
    @01_astronaut30 Месяц назад

    Amazing🎉😊

  • @someone0x
    @someone0x Месяц назад

    Great Info Thanks So Much For the Episode.

  • @aatankbadboy3941
    @aatankbadboy3941 Месяц назад

    Bro Can you explain a little bit more

  • @0xdead4f
    @0xdead4f Месяц назад

    Am i the only one that does not understand a thing about what they said ?

    • @fnulnu5645
      @fnulnu5645 Месяц назад

      All I heard was cache... or cash... I hope it was cash

    • @sebastianm8028
      @sebastianm8028 Месяц назад

      Me when they go deep on s and client side path traversal lol. Since I'm a dev this one was fine for me

  • @crusader_
    @crusader_ Месяц назад

    Bruh the fact that shubs said it's a "known technique" but none of us knew that, makes me wonder how many more of such techniques he has up his sleeves

  • @MarkFoudy
    @MarkFoudy Месяц назад

    Always excellent podcast! Thanks guys!

  • @KarahannAe
    @KarahannAe Месяц назад

    28:45 i feel like programs would argue that this isnt actually bug and group admin should be careful not to invite malicious people.

  • @Jonas-zp1ep
    @Jonas-zp1ep Месяц назад

    Are you reporting the found issues to the library owners?

  • @mwnasmgrr8004
    @mwnasmgrr8004 Месяц назад

    Can you guys interview the bugbountyhq mark Litchfield...

  • @Blu3ther
    @Blu3ther Месяц назад

    Perfect timing on the WAF tutorial. It follows up & meshes well with Shubs WAF tips from NahanCon2024. ❤ you guys...thanx for sharing!! 💪

  • @MFoster392
    @MFoster392 Месяц назад

    Great pod per usual :)

  • @who8mypnuts
    @who8mypnuts Месяц назад

    Where is your Caido plugin version of nowafpls? Or should I be searching for nowafplz? :P

  • @theskelet4r
    @theskelet4r Месяц назад

    I Love Thursdays! Thank you for another awesome episode

  • @crusader_
    @crusader_ Месяц назад

    Shout out to riddle