『Critical Thinking - Bug Bounty Podcast』のカバーアート

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

著者: Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
無料で聴く

このコンテンツについて

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
エピソード
  • Episode 125: How to Win Live Hacking Events
    2025/06/05

    Episode 125: In this episode of Critical Thinking - Bug Bounty Podcast Justin shares insights on how to succeed at live hacking events. We cover pre-event preparations, challenges of collaboration, on-site strategies, and the importance of maintaining a healthy mindset throughout the entire process.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== This Week in Bug Bounty ======

    Decathlon Public Bug Bounty Program on YesWeHack

    ====== Resources ======

    The Ultimate Double-Clickjacking PoC

    Grafana Full read SSRF and Account Takeover: CVE-2025-4123

    Grafana CVE-2025-4123 Exploit

    What I learned from my first 100 HackerOne Reports

    Root for your friends

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:30) The Ultimate Double-Clickjacking PoC, Grafana CVE, & Evan Connelly's first 100 bugs

    (00:10:23) How to win at Live Hacking Events

    (00:11:53) Pre-event

    (00:11:45) Scope Call

    (00:33:11) Dupe window Ends

    (00:36:00) Onsite & and Day of Event

    (00:42:46) Don't define your identity on the outcome

    続きを読む 一部表示
    47 分
  • Episode 124: Bug Bounty Lifestyle = Less Hacking Time?
    2025/05/29

    Episode 124: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph cover some news from around the community, hitting on Joseph’s Anthropic safety testing, Justin’s guest appearance on For Crying Out Cloud, and several fascinating tweets. Then they have a quick Full-time Bug Bounty check-in.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor - ThreatLocker Web Control

    https://www.criticalthinkingpodcast.io/tl-webcontrol

    ====== This Week in Bug Bounty ======

    Louis Vuitton Public Bug Bounty Program

    CVE-2025-47934 was discovered on one of our Bug Bounty program : OpenPGP.js

    Stored XSS in File Upload Leads to Privilege Escalation and Full Workspace Takeover

    ====== Resources ======

    Jorian tweet

    Clipjacking: Hacked by copying text - Clickjacking but better

    Crying out Cloud Appearance

    Wiz Research takes 1st place in Pwn2Own AI category

    New XSS vector with image tag

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:10:50) Supabase

    (00:13:47) Tweet-research from Jorian and Wyatt Walls.

    (00:20:24) Anthropic safety testing challenge & Wiz Podcast guest appearance

    (00:27:44) New XSS vector, Google i/o, and coding agents

    (00:35:48) Full Time Bug Bounty

    続きを読む 一部表示
    45 分
  • Episode 123: Hacking AI Series: Vulnus ex Machina - Part 2
    2025/05/22

    Episode 123: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with part 2 of Rez0’s miniseries. Today we talk about mastering Prompt Injection, taxonomy of impact, and both triggering traditional Vulns and exploiting AI-specific features.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor - ThreatLocker User Store

    https://www.criticalthinkingpodcast.io

    /tl-userstore

    ====== This Week in Bug Bounty ======

    Earning a HackerOne 2025 Live Hacking Invite

    https://www.hackerone.com/blog/earning-hackerone-2025-live-hacking-invite

    HTTP header hacks: basic and advanced exploit techniques explored

    https://www.yeswehack.com/learn-bug-bounty/http-header-exploitation

    ====== Resources ======

    Grep.app

    https://vercel.com/blog/migrating-grep-from-create-react-app-to-next-js

    Gemini 2.5 Pro prompt leak

    https://x.com/elder_plinius/status/1913734789544214841

    Pliny's CL4R1T4S

    https://github.com/elder-plinius/CL4R1T4S

    O3

    https://x.com/pdstat/status/1913701997141803329

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:25) Grep.app, O3, and Gemini 2.5 Pro prompt leak

    (00:11:09) Delivery and impactful action

    (00:20:44) Mastering Prompt Injection

    (00:30:36) Traditional vulns in Tool Calls, and AI Apps

    (00:37:32) Exploiting AI specific features

    続きを読む 一部表示
    44 分

Critical Thinking - Bug Bounty Podcastに寄せられたリスナーの声

カスタマーレビュー:以下のタブを選択することで、他のサイトのレビューをご覧になれます。