Imagen de portada del espectáculo Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Podcast de Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

inglés

Tecnología y ciencia

Disfruta 30 días gratis

4,99 € / mes después de la prueba.Cancela cuando quieras.

  • 20 horas de audiolibros / mes
  • Podcasts solo en Podimo
  • Podcast gratuitos
Prueba gratis

Acerca de Critical Thinking - Bug Bounty Podcast

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Todos los episodios

152 episodios
episode Episode 152: GeminiJack and Agentic Security with Sasi Levi artwork

Episode 152: GeminiJack and Agentic Security with Sasi Levi

Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln. Follow us on twitter at: https://x.com/ctbbpodcast [https://x.com/ctbbpodcast] Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io [info@criticalthinkingpodcast.io] Shoutout to YTCracker [https://twitter.com/realytcracker] for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater [https://x.com/Rhynorater] https://x.com/rez0__ [https://x.com/rez0__] https://x.com/gr3pme [https://x.com/gr3pme] ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord [https://ctbb.show/discord]! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. CHeck out our New Christmas Swag at https://ctbb.show/merch [https://ctbb.show/merch]! Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control https://ctbb.show/tl-ec [https://ctbb.show/tl-ec] And Noma Security! https://noma.security/ [https://noma.security/] Today’s Guest: https://x.com/sasi2103 [https://x.com/sasi2103] ====== This Week in Bug Bounty ====== Vercel Platform Protection [https://hackerone.com/vercel_platform_protection?type=team] Dedicated HackerOne program for Vercel WAF [https://x.com/cramforce/status/1998072892391592195?s=20] YesWeHack Open Source Programs [https://yeswehack.com/programs?scopeType%5B%5D=open-source&page=1] Android recon for Bug Bounty hunters [https://www.yeswehack.com/learn-bug-bounty/android-recon-bug-bounty-guide] ====== Resources ====== Sasi's Tweet from 2015 [https://x.com/sasi2103/status/608349038778437632] ForcedLeak: AI Agent risks exposed in Salesforce AgentForce [https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/] Is Prompt Injection a Vulnerability? [https://danielmiessler.com/blog/is-prompt-injection-a-vulnerability] ====== Timestamps ====== (00:00:00) Introduction (00:09:16) Google Vertex AI Bug (00:29:28) Sasi's Background and Bug Bounty Journey (00:38:55) Resources for AI and Agentic Security Methodology (00:50:34) ForcedLeak (01:02:06) Is Prompt Injection a Vuln?

11 dic 2025 - 1 h 21 min
episode Episode 151: Client-side Advanced Topics artwork

Episode 151: Client-side Advanced Topics

Episode 151: In this episode of Critical Thinking - Bug Bounty Podcast we’re covering Client-side advanced topics. Justin talks Joseph (and us) through Third-Party Cookie Nuances, Iframe Tricks, URL Parsing, and more. Follow us on twitter at: https://x.com/ctbbpodcast [https://x.com/ctbbpodcast] Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io [info@criticalthinkingpodcast.io] Shoutout to YTCracker [https://twitter.com/realytcracker] for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater [https://x.com/Rhynorater] https://x.com/rez0__ [https://x.com/rez0__] https://x.com/gr3pme [https://x.com/gr3pme] ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord [https://ctbb.show/discord]! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch [https://ctbb.show/merch]! Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control https://ctbb.show/tl-ec [https://ctbb.show/tl-ec] ====== Resources ====== Nowasky's Tweet #1 https://x.com/nowaskyjr/status/1993421017381744974 [https://x.com/nowaskyjr/status/1993421017381744974] Nowasky's Tweet #2 https://x.com/nowaskyjr/status/1992717862398800081 [https://x.com/nowaskyjr/status/1992717862398800081] rep+ in Chrome DevTools https://x.com/BourAbdelhadi/status/1992622964077179229 [https://x.com/BourAbdelhadi/status/1992622964077179229] Terjanq Post from 2021 https://x.com/terjanq/status/1421093136022048775 [https://x.com/terjanq/status/1421093136022048775] ====== Timestamps ====== (00:00:00) Introduction (00:02:58) Client-side news & AI Updates (00:12:02) Third-Party Cookie Nuances & PostMessages (00:30:09) Iframe Tricks (00:47:43) URL Parsing, CSPTS, and Client-side Routes

04 dic 2025 - 1 h 7 min
episode Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration artwork

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration

Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all! Follow us on twitter at: https://x.com/ctbbpodcast [https://x.com/ctbbpodcast] Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io [info@criticalthinkingpodcast.io] Shoutout to YTCracker [https://twitter.com/realytcracker] for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater [https://x.com/Rhynorater] https://x.com/rez0__ [https://x.com/rez0__] https://x.com/gr3pme [https://x.com/gr3pme] ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord [https://ctbb.show/discord]! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch [https://ctbb.show/merch]! Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control https://ctbb.show/tl-ec [https://ctbb.show/tl-ec] ====== This Week in Bug Bounty ====== Cache Overflow on Cloudflare [https://hackerone.com/reports/3027461] ====== Resources ====== Breaking Oracle’s Identity Manager [https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/] Who Needs a Blind XSS? [https://hx01.me/hailcsv.htm] ASP.NET MVC View Engine Search Patterns [https://lab.ctbb.show/research/asp-net-mvc-view-engine-search-patterns] Heretic [https://github.com/p-e-w/heretic] Lesser known techniques for large-scale subdomain enum [https://docs.google.com/presentation/d/1UOcryh9c7zJ0UnnLwqRLFIyfU5LxSRRRt10c17dV8tI/edit?slide=id.g2d6dd8819b6_0_20#slide=id.g2d6dd8819b6_0_20] Antigravity – Known Issues [https://bughunters.google.com/learn/invalid-reports/google-products/4655949258227712/antigravity-known-issues#known-issues] Bug Bounty Daily [https://bugbountydaily.com/] Caido version of AssetNote Surf [https://github.com/caido-community/surf] ====== Timestamps ====== (00:00:00) Introduction (00:09:47) Breaking Oracle’s Identity Manager & Who Needs a Blind XSS? (00:20:37) ASP.NET [http://ASP.NET] MVC View Engine Search Patterns & Heretic (00:29:04) Lesser known techniques for large-scale subdomain enum (00:35:29) Gemini 3 & Antigravity. (00:45:57) Bug Bounty Daily (00:52:42) Surf for Caido

27 nov 2025 - 57 min
episode Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains artwork

Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains

Episode 149: In this episode of Critical Thinking - Bug Bounty Podcast The DEFCON videos are up, and Justin and Joseph talk through some of their favorites. Follow us on X [https://x.com/ctbbpodcast] Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io [info@criticalthinkingpodcast.io] Shoutout to YTCracker [https://twitter.com/realytcracker] for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater [https://x.com/Rhynorater], rez0 [https://x.com/rez0__] and gr3pme [https://x.com/gr3pme] on X: ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord! [https://ctbb.show/discord] We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch [https://ctbb.show/merch]! ====== Resources ====== Unicode surrogates conversion [https://lab.ctbb.show/research/unicode-surrogates-to-replacement-characters] Prompt. Scan. Exploit [https://www.youtube.com/watch?v=y_aQQmDMaY4] Breaking into thousands of cloud based VPNs with 1 bug [https://www.youtube.com/watch?v=RNXCnJvE1Zg&list=PL6rDwEAPMIRSsWupDGpV4bMf7CiLTF0wk] Examining Access Control Vulnerabilities in GraphQL [https://www.youtube.com/watch?v=mPo-an8BUXc] Smart Bus Smart Hacking [https://www.youtube.com/watch?v=AOp0QtUORBc&list=PL6rDwEAPMIRSsWupDGpV4bMf7CiLTF0wk&index=6] Passkeys Pwned [https://www.youtube.com/watch?v=LCGm5-ZjKK0] Bypassing Intent Destination Checks [https://www.youtube.com/watch?v=kSJBEZkJ4vM&list=PL6rDwEAPMIRSsWupDGpV4bMf7CiLTF0wk&index=3] Gemini Agents in Google Calendar [https://www.youtube.com/watch?v=CUxbDRR0A8I] Exploitation of DOM Clobbering Vuln at Scale [https://www.youtube.com/watch?v=JL2PT1Dac3g] TheHulk [https://github.com/jackfromeast/TheHulk] Smart Devices, Dumb Resets [https://www.youtube.com/watch?v=rLnlLLKISyY&list=PL6rDwEAPMIRSsWupDGpV4bMf7CiLTF0wk&index=4] Mac PRT Cookie Theft [https://www.youtube.com/watch?v=T13YfM8z0lE&list=PL6rDwEAPMIRSsWupDGpV4bMf7CiLTF0wk&index=7] ====== Timestamps ====== (00:00:00) Introduction (00:10:10) Prompt. Scan. Exploit (00:23:52) Breaking into thousands of cloud based VPNs with 1 bug (00:33:25) Access Control Vulns in GraphQL, Smart Bus Hacking, & Passkeys Pwned (00:44:10) Bypassing Intent Destination Checks & Invoking Gemini Agents (00:57:08) DOM Clobbering, Mac PRT Cookie Theft, & Smart Devices, Dumb Resets

20 nov 2025 - 1 h 2 min
episode Episode 148: MCP Hacking Guide artwork

Episode 148: MCP Hacking Guide

Episode 148: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us a crash course on Model Context Protocol. Follow us on twitter at: https://x.com/ctbbpodcast [https://x.com/ctbbpodcast] Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io [info@criticalthinkingpodcast.io] Shoutout to YTCracker [https://twitter.com/realytcracker] for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater [https://x.com/Rhynorater] https://x.com/rez0__ [https://x.com/rez0__] https://x.com/gr3pme [https://x.com/gr3pme] ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord [https://ctbb.show/discord]! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch [https://ctbb.show/merch]! ====== Timestamps ====== (00:00:00) Introduction (00:02:51) MCP Architecture & Authentication (00:13:08) Roots, Sampling, & Elicitation (00:19:15) Tools and Resources

13 nov 2025 - 32 min
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
MI TOC es feliz, que maravilla. Ordenador, limpio, sugerencias de categorías nuevas a explorar!!!
Me suscribi con los 14 días de prueba para escuchar el Podcast de Misterios Cotidianos, pero al final me quedo mas tiempo porque hacia tiempo que no me reía tanto. Tiene Podcast muy buenos y la aplicación funciona bien.
App ligera, eficiente, encuentras rápido tus podcast favoritos. Diseño sencillo y bonito. me gustó.
contenidos frescos e inteligentes
La App va francamente bien y el precio me parece muy justo para pagar a gente que nos da horas y horas de contenido. Espero poder seguir usándola asiduamente.

Elige tu suscripción

Premium

20 horas de audiolibros

  • Podcasts solo en Podimo

  • Podcast gratuitos

  • Cancela cuando quieras

Disfruta 30 días gratis
Después 4,99 € / month

Prueba gratis

Premium Plus

100 horas de audiolibros

  • Podcasts solo en Podimo

  • Podcast gratuitos

  • Cancela cuando quieras

Disfruta 30 días gratis
Después 9,99 € / month

Prueba gratis

Sólo en Podimo

Audiolibros populares

Prueba gratis

Disfruta 30 días gratis. 4,99 € / mes después de la prueba. Cancela cuando quieras.