Episodes

  • Episode 91: Zero to LHE in 9 Months (feat gr3pme)
    Oct 3 2024

    Episode 91: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gardner sits down with Critical Thinking’s own HackerNotes writer Brandyn Murtagh (gr3pme) to talk about his journey with Bug Bounty. We cover mentorship, networking and LHEs, ecosystem hacking, emotional regulation, and the need for self-care. Then we wrap up with some fun bugs.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Shop our new swag store at ctbb.show/swag

    Today’s Sponsor: Project Discovery - tldfinder: https://www.criticalthinkingpodcast.io/tldfinder

    Today’s guest: https://x.com/gr3pme

    Resources:

    Lessons Learned for LHEs

    https://x.com/Rhynorater/status/1579499221954473984

    Timestamps:

    (00:00:00) Introduction

    (00:07:02) Mentorship in Bug Bounty

    (00:16:30) LHE lessons, takeaways, and the benefit of feedback and networking

    (00:41:28) Choosing Targets

    (00:49:03) Vuln Classes

    (00:58:54) Bug Reports

    Show more Show less
    1 hr and 23 mins
  • Episode 90: 5k Clickjacking, Encryption Oracles, and Cursor for PoCs
    Sep 26 2024

    Episode 90: In this episode of Critical Thinking - Bug Bounty Podcast Joel and Justin recap some of their recent hacking ups and downs and have a lively chat about Cursor. Then they cover some some research about SQL Injections, Clickjacking in Google Docs, and how to steal your Telegram account in 10 seconds.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Shop our new swag store at ctbb.show/swag

    Today’s Sponsor: Project Discovery - tldfinder: https://www.criticalthinkingpodcast.io/tldfinder

    Resources:

    Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold

    Content-Type that can be used for XSS

    Clickjacking Bug in Google Docs

    Justin's Gadget Link

    https://www.youtube.com/signin?next=https%3A%2F%2Faccounts.youtube.com%2Faccounts%2FSetSID%3Fcontinue%3Dhttps%3A%2F%2Fwww.google.com%252Famp%252fpoc.rhynorater.com

    Stealing your Telegram account in 10 seconds flat

    Timestamps

    (00:00:00) Introduction

    (00:08:28) Recent Hacks and Dupes

    (00:14:00) Cursor

    (00:25:02) Exploiting Pre-Auth SQL Injection in WhatsUp Gold

    (00:34:17) Content-Type that can be used for XSS

    (00:40:25) Caido updates

    (00:43:14) Clickjacking in Google Docs, and Stealing Telegram account

    Show more Show less
    52 mins
  • Episode 89: The Untapped Bug Bounty Landscape of IoT w/ Matt Brown
    Sep 19 2024

    Episode 89: In this episode of Critical Thinking - Bug Bounty Podcast We’re joined live by Matt Brown to talk about his journey with hacking in the IoT. We cover the specializations and challenges in hardware hacking, and Matt’s personal Methodology. Then we switch over to touch on BGA Reballing, Certificate Pinning and Validation, and some of his own bug stories.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Sponsor: Project Discovery - tldfinder: https://www.criticalthinkingpodcast.io/tldfinder

    Today’s Guess Matt Brown: https://x.com/nmatt0

    Resources:

    Decrypting SSL to Chinese Cloud Servers

    https://www.youtube.com/watch?v=3qSxxNvuEtg

    mitmrouter

    https://github.com/nmatt0/mitmrouter

    certmitm Automatic Exploitation of TLS Certificate Validation Vulns

    https://www.youtube.com/watch?v=w_l2q_Gyqfo

    and

    https://media.defcon.org/DEF%20CON%2031/DEF%20CON%2031%20presentations/Aapo%20Oksman%20-%20certmitm%20automatic%20exploitation%20of%20TLS%20certificate%20validation%20vulnerabilities.pdf

    https://github.com/aapooksman/certmitm

    HackerOne Detailed Platform Standards

    https://docs.hackerone.com/en/articles/8369826-detailed-platform-standards

    Timestamps:

    (00:00:00) Introduction

    (00:13:33) Specialization and Challenges of IOT Hacking

    (00:33:03) Decrypting SSL to Chinese Cloud Servers

    (00:47:00) General IoT Hacking Methodology

    (01:26:00) Certificate Pinning and Certificate Validation

    (01:34:35) BGA Reballing

    (01:43:26) Bug Stories

    Show more Show less
    1 hr and 58 mins
  • Episode 88: News, Tools, and Writeups
    Sep 12 2024

    Episode 88: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel tackle a whole slate of new research including a new cheat sheet for URL validation bypass from Portswigger, the introduction of Sanic DNS as a high-speed DNS resolver, xsstools, and the Dockerization of Orange Confusion Attacks.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Shop our new swag store at ctbb.show/swag

    Resources

    URL Validation Bypass cheat sheet

    SanicDNS

    Orange Confusion Attacks

    WordPress GiveWP POP to RCE

    Xsstools

    Bypassing browser tracking protection

    Advanced iframe Magic

    DOM Clobbering

    https://www.ruhrsec.de/downloads/slides/Everything-You-Wanted-to-Know-About-DOM-Clobbering-But-Were-Afraid-to-Ask-Soheil-Khodayari-RuhrSec.pdf

    And

    https://domclob.xyz/domc_payload_generator/

    Timestamps:

    (00:00:00) Introduction

    (00:02:00) URL validation bypass

    (00:07:41) SanicDNS and Orange confusion attacks

    (00:20:06) WordPress GiveWP POP to RCE

    (00:31:29) Xsstools

    (00:43:56) Bypassing browser tracking protection

    (00:52:06) DOM Clobbering and mixing up your approach

    Show more Show less
    1 hr and 6 mins
  • Episode 87: 'Hacker Wife' Mariah Gardner on Bug Bounty mentality and relationships
    Sep 5 2024

    Episode 87: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with none other than his wife Mariah to talk about Bug Bounty from the perspective of a Significant Other. They share how they’ve traversed travel and Live Hacking Events, household chores, hobbies, goals, rewards, as well as how best to encourage and support the hacker/non-hacker in your life.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Shop our new swag store at ctbb.show/swag

    Today’s Guest: https://x.com/MariahG017

    Resources:

    Ruby Nealon's song

    https://x.com/_ruby/status/835306502546149376

    Don't Force Yourself to Become a Bug Bounty Hunter

    https://samcurry.net/dont-force-yourself-to-become-a-bug-bounty-hunter

    Timestamps

    (00:00:00) Introduction

    (00:03:12) Technical Questions for a Bug Bounty Wife

    (00:16:11) Mariah's First LHE experience

    (00:31:12) LHEs as a Couple

    (00:41:57) Encouragement and Risk

    (00:55:55) Hacker Family Dynamics, goals, and keeping promises

    (01:17:35) How to care for your Hacker/Hacker Wife

    Show more Show less
    1 hr and 27 mins
  • Episode 86: The X-Correlation between Frans & RCE - Research Drop
    Aug 29 2024

    Episode 86: In this episode of Critical Thinking - Bug Bounty Podcast Frans blows Justin’s mind with a sneak peak of his new presentation. Note: This is a little different from our normal episode, and video is recommended. So head over to ctbb.show/yt if you feel like you’re missing something.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Shop our new swag store at ctbb.show/swag

    Watch this Episode on Youtube - ctbb.show/yt

    Today’s Guest: Frans Rosen - https://x.com/fransrosen

    View the slides of this presentation at https://speakerdeck.com/fransrosen/x-correlation-injections-or-how-to-break-server-side-contexts

    Timestamps

    (00:00:00) Introduction

    (00:04:09) x-correlation injection

    (00:21:10) Server-side JSON-Injection

    (00:32:10) Fuzz Blindly and Optimizing Blind RCE

    Show more Show less
    42 mins
  • Episode 85: Practical Applications of DEFCON 32 Web Research
    Aug 22 2024

    Episode 85: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel talk through some of the research coming out of DEFCON, mainly from the PortSwigger team. Web timing attacks, cache exploitation, and exploits related to email protocols are all featured. Plus we also talk some fun Apache hacks from Orange Tsai

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    Check out our new SWAG store at https://ctbb.show/swag!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Sponsor - ThreatLocker

    Resources

    Listen to the whispers

    https://portswigger.net/research/listen-to-the-whispers-web-timing-attacks-that-actually-work

    Splitting the email atom

    https://portswigger.net/research/splitting-the-email-atom

    Gotta cache 'em all

    https://portswigger.net/research/gotta-cache-em-all

    HTTP Garden

    https://github.com/narfindustries/http-garden

    Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!

    https://blog.orange.tw/2024/08/confusion-attacks-en.html#%E2%9C%94%EF%B8%8F-2-2-2-Local-Gadget-to-XSS

    Trusted API Types

    https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Types_API

    Untrusted Types

    https://github.com/filedescriptor/untrusted-types

    Timestamps:

    (00:00:00) Introduction

    (00:09:45) 'Listen to the whispers'

    (00:30:03) 'Splitting the email atom'

    (00:58:42) 'Gotta cache 'em all'

    (01:21:03) 'Confusion Attacks'

    Show more Show less
    1 hr and 31 mins
  • Episode 84: 0xLupin & Takeaways from Google's Las Vegas BugSwat
    Aug 15 2024

    Episode 84: In this episode of Critical Thinking - Bug Bounty Podcast, Justin is joined by Roni Carta (@0xLupin) to discuss their MVH win at the recent Google LHE, and share some technical observations they had with the target and the event.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Find the Hackernotes: https://blog.criticalthinkingpodcast.io/

    Follow your hosts Rhynorater & Teknogeek on twitter:

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Guest: https://x.com/0xLupin

    Today’s Sponsor - ThreatLocker

    Timestamps:

    (00:00:00) Introduction

    (00:02:12) MHV Debrief

    (00:09:05) Sandboxes and Comfort Zones

    (00:13:24) SDKs and Legal Compliance

    (00:19:29) Age of Target and Platform-Exclusive Hunters

    Show more Show less
    27 mins