PodcastsTechnologyCritical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Critical Thinking - Bug Bounty Podcast
Latest episode

173 episodes

  • Critical Thinking - Bug Bounty Podcast

    Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS

    2026-04-23 | 22 mins.
    Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out ThreatLocker Ringfencing
    https://www.criticalthinkingpodcast.io/tl-rf

    ====== Resources ======

    The ultimate Bug Bounty guide to OS command injection vulnerabilities
    www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection

    Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation
    https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin

    Aituglo featured on YWH
    https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story

    Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st
    https://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/

    ====== Resources ======

    SVG clickjacking
    https://lyra.horse/blog/2025/12/svg-clickjacking/

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:06:35) Protobuff XSS
    (00:12:51) Leaking Age & CSPTs
    (00:15:59) Capital Letters and Clickjacking
  • Critical Thinking - Bug Bounty Podcast

    Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways

    2026-04-16 | 32 mins.
    Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:01:41) Google LHE Debrief
    (00:09:27) Old AI Exfils & AI report writing
    (00:18:14) Human Tokens
    (00:26:13) Protoscope & Caido Websocket Repeater
  • Critical Thinking - Bug Bounty Podcast

    Episode 169: Attacking OAuth 2.1

    2026-04-09 | 30 mins.
    Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out ThreatLocker Ringfencing
    https://www.criticalthinkingpodcast.io/tl-rf

    ====== This Week in Bug Bounty ======

    Intigriti is providing free Burp Pro for Hackers!
    https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence

    ====== Resources ======
    Django-allauth Account Takeover (ZeroPath Audit)
    https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities

    CVE-2025-4144: Cloudflare Workers PKCE Bypass
    https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9

    CVE-2025-54576: OAuth2-Proxy Auth Bypass
    https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:02:16) OAuth 2.0 Standards
    (00:12:08) Agent to Agent Communication
    (00:17:19) CVE Case studies
  • Critical Thinking - Bug Bounty Podcast

    Episode 168: XSSDoctor - Client-side Path Traversal Research

    2026-04-02 | 1h 35 mins.
    Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Guest: https://x.com/xssdoctor

    ====== Resources ======

    The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework
    https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you

    URL validation bypass cheat sheet
    https://portswigger.net/web-security/ssrf/url-validation-bypass-cheat-sheet

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:01:37) Home Automation AI Hack & E-signature bug stories
    (00:12:15) E-signature bug
    (00:17:01) XSS DR Intro and Bug Bounty Journey
    (00:31:51) CSPT Workflows
    (01:07:57) Wildcard Path Parameters
    (01:30:34) Custom Sinks
  • Critical Thinking - Bug Bounty Podcast

    Episode 167: Stealing Bugs with Valeriy Shevchenko

    2026-03-26 | 51 mins.
    Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out ThreatLocker Ringfencing
    https://www.criticalthinkingpodcast.io/tl-rf

    Today’s Guest: https://x.com/Krevetk0Valeriy

    ====== This Week in Bug Bounty ======

    HackerOne’s Bug Bounty Maturity Framework:
    https://www.hackerone.com/blog/program-maturity-framework-bug-bounty-operations

    Intigriti is hiring a Product Security Analyst
    https://jobs.criticalthinkingpodcast.io/jobs/product-security-analyst-25ef4706

    ====== Resources ======

    Valeriy’s Blog
    https://krevetk0.medium.com/

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:03:15) Valeriy's Bug story
    (00:19:48) Anchor Programs and Bug Hunting Motivation
    (00:29:50) Stealing Bugs

More Technology podcasts

About Critical Thinking - Bug Bounty Podcast

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Podcast website

Listen to Critical Thinking - Bug Bounty Podcast, Lex Fridman Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features