『Critical Thinking - Bug Bounty Podcast』のカバーアート

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

著者: Justin Gardner (Rhynorater) Joseph Thacker (Rez0) & Brandyn Murtagh (gr3pme)
無料で聴く

今ならプレミアムプランが3カ月 月額99円

2026年5月12日まで。4か月目以降は月額1,500円で自動更新します。

概要

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
エピソード
  • Episode 169: Attacking OAuth 2.1
    2026/04/09

    Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    ====== This Week in Bug Bounty ======


    Intigriti is providing free Burp Pro for Hackers!

    https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence


    ====== Resources ======

    Django-allauth Account Takeover (ZeroPath Audit)

    https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities


    CVE-2025-4144: Cloudflare Workers PKCE Bypass

    https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9


    CVE-2025-54576: OAuth2-Proxy Auth Bypass

    https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:16) OAuth 2.0 Standards

    (00:12:08) Agent to Agent Communication

    (00:17:19) CVE Case studies



    続きを読む 一部表示
    30 分
  • Episode 168: The Doctor is in (devtools)
    2026/04/02

    Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!


    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Guest: https://x.com/xssdoctor


    ====== Resources ======


    Lab.ctbb.show


    URL validation bypass cheat sheet

    https://portswigger.net/web-security/ssrf/url-validation-bypass-cheat-sheet


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:01:37) Home Automation AI Hack & E-signature bug stories

    (00:12:15) E-signature bug

    (00:17:01) XSS DR Intro and Bug Bounty Journey

    (00:31:51) CSPT Workflows

    (01:07:57) Wildcard Path Parameters

    (01:30:34) Custom Sinks

    続きを読む 一部表示
    1 時間 36 分
  • Episode 167: Stealing Bugs with Valeriy Shevchenko
    2026/03/26

    Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!


    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today's Sponsor: Check out ThreatLocker Ringfencing

    https://www.criticalthinkingpodcast.io/tl-rf


    Today’s Guest: https://x.com/Krevetk0Valeriy


    ====== This Week in Bug Bounty ======


    HackerOne’s Bug Bounty Maturity Framework:

    https://www.hackerone.com/blog/program-maturity-framework-bug-bounty-operations


    Intigriti is hiring a Product Security Analyst

    https://jobs.criticalthinkingpodcast.io/jobs/product-security-analyst-25ef4706


    ====== Resources ======


    Valeriy’s Blog

    https://krevetk0.medium.com/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:15) Valeriy's Bug story

    (00:19:48) Anchor Programs and Bug Hunting Motivation

    (00:29:50) Stealing Bugs

    続きを読む 一部表示
    52 分
まだレビューはありません