Obtenez 3 mois à 0,99 $/mois

OFFRE D'UNE DURÉE LIMITÉE
Page de couverture de Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Auteur(s): Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Écouter gratuitement

À propos de cet audio

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Épisodes
  • Episode 152: GeminiJack and Agentic Security with Sasi Levi
    Dec 11 2025

    Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    CHeck out our New Christmas Swag at https://ctbb.show/merch!

    Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

    https://ctbb.show/tl-ec

    And Noma Security! https://noma.security/

    Today’s Guest: https://x.com/sasi2103

    ====== This Week in Bug Bounty ======

    Vercel Platform Protection

    Dedicated HackerOne program for Vercel WAF

    YesWeHack Open Source Programs

    Android recon for Bug Bounty hunters

    ====== Resources ======

    Sasi's Tweet from 2015

    ForcedLeak: AI Agent risks exposed in Salesforce AgentForce

    Is Prompt Injection a Vulnerability?

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:09:16) Google Vertex AI Bug

    (00:29:28) Sasi's Background and Bug Bounty Journey

    (00:38:55) Resources for AI and Agentic Security Methodology

    (00:50:34) ForcedLeak

    (01:02:06) Is Prompt Injection a Vuln?

    Voir plus Voir moins
    1 h et 22 min
  • Episode 151: Client-side Advanced Topics
    Dec 4 2025

    Episode 151: In this episode of Critical Thinking - Bug Bounty Podcast we’re covering Client-side advanced topics. Justin talks Joseph (and us) through Third-Party Cookie Nuances, Iframe Tricks, URL Parsing, and more.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

    https://ctbb.show/tl-ec

    ====== Resources ======

    Nowasky's Tweet #1

    https://x.com/nowaskyjr/status/1993421017381744974

    Nowasky's Tweet #2

    https://x.com/nowaskyjr/status/1992717862398800081

    rep+ in Chrome DevTools

    https://x.com/BourAbdelhadi/status/1992622964077179229

    Terjanq Post from 2021

    https://x.com/terjanq/status/1421093136022048775

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:58) Client-side news & AI Updates

    (00:12:02) Third-Party Cookie Nuances & PostMessages

    (00:30:09) Iframe Tricks

    (00:47:43) URL Parsing, CSPTS, and Client-side Routes

    Voir plus Voir moins
    1 h et 7 min
  • Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration
    Nov 27 2025

    Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

    https://ctbb.show/tl-ec

    ====== This Week in Bug Bounty ======

    Cache Overflow on Cloudflare

    ====== Resources ======

    Breaking Oracle’s Identity Manager

    Who Needs a Blind XSS?

    ASP.NET MVC View Engine Search Patterns

    Heretic

    Lesser known techniques for large-scale subdomain enum

    Antigravity – Known Issues

    Bug Bounty Daily

    Caido version of AssetNote Surf

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:09:47) Breaking Oracle’s Identity Manager & Who Needs a Blind XSS?

    (00:20:37) ASP.NET MVC View Engine Search Patterns & Heretic

    (00:29:04) Lesser known techniques for large-scale subdomain enum

    (00:35:29) Gemini 3 & Antigravity.

    (00:45:57) Bug Bounty Daily

    (00:52:42) Surf for Caido

    Voir plus Voir moins
    57 min
Pas encore de commentaire