logo
episode-header-image
Sep 2023
1h 25m

Episode 35: King of Collaboration: Dougl...

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
About this episode

Episode 35: In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome Douglas Day, a bug bounty hunter known for his unique methodologies and collaborative spirit. We talk about his approach to finding new endpoints in applications, his ingenious technique of exploiting Intercom widgets, and collaboration preferences and tips at LHEs. We also touch on the struggle of justifying hobbies that don't generate income and the importance of finding enjoyment in the process.We hope you enjoy this episode as much as we did!

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

Today’s Guest:

https://twitter.com/ArchAngelDDay

https://hackerone.com/the_arch_angel

https://bugcrowd.com/arch_angel

100 Short Bug Bounty Rules

https://twitter.com/ArchAngelDDay/status/1661924038875435008

Blog about Intercom

https://dday.us/2021/11/03/h1vendorATO.html

Blog about Mapping Hacking

http://dday.us/2021/10/09/Mapyourhacking.html

Timestamps: (00:00:00) Introduction

(00:03:01) Douglas Day’s infosec and LHE intro

(00:10:42) Evolution and philosophy of collaboration

(00:23:08) Balancing Collaboration and Money

(00:29:43) Recap of 100 Short Bug Bounty Rules

(00:37:15) Bug-hunting Methodology

(00:45:45) Using match and replace to find new endpoints in bug hunting

(00:49:07) Exploiting Intercom widgets

(00:52:35) Facing Failure and enjoying the journey

(00:57:00) Managing work-life balance

(01:05:55) Auth-Z testing and documentation

(01:12:25) Vulnerabilities in applications

(01:17:05) Mapping Hacking Sessions

Up next
Oct 9
Episode 143: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!
Episode 143: In this episode of Critical Thinking - Bug Bounty Podcast Justin brings Brandyn back to announce him as our newest co-host. We chat about recent LHE experiences, and then break down some news. Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and sugges ... Show More
1h 4m
Oct 2
Episode 142: Gr3pme's Full-Time Hunting Journey Update, Insane AI research, And Some Light News
Episode 142: In this episode of Critical Thinking - Bug Bounty Podcast Rez0 and Gr3pme join forces to discuss Websocket research, Meta’s $111750 Bug, PROMISQROUTE, and the opportunities afforded by going full time in Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGo ... Show More
54m 50s
Sep 25
Episode 141: Hacking the Pod - Google Docs 0-day & React CreateElement Exploits with Nick Copi (7urb0)
Episode 141: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Nick Copi to talk about CSPT, React, CSS Injections and how Nick hacked the pod.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any f ... Show More
1h 23m
Recommended Episodes
Jan 2024
Introducing On This Day in Working Class History: A new daily podcast from WCH
Introducing a brand-new daily podcast from the team at WCH. On This Day in Working Class History will be a brief reminder each morning of our collective struggles for a better world which have taken place on this date in history. Launching on 1 February on a trial basis, each epi ... Show More
2m 32s
Feb 2024
🔒 Exploring English Vocabulary: Remote Working with Lindsay
Subscriber-only episodeE186: 🎙️  Welcome to another Bonus Episode, Plus Members! Thank you for tuning in once again. Today, we're delving into the nitty-gritty of some vocabulary discussed in my recent chat with Lindsay in Episode 185: Native English Conversation: Remote Working ... Show More
10 m
Feb 2024
E167: Nvidia smashes earnings (again), Google's Woke AI disaster, Groq's LPU breakthrough & more
(0:00) Bestie intros: Banana boat! (2:34) Nvidia smashes expectations again: understanding its terminal value and bull/bear cases in the context of the history of the internet (27:26) Groq's big week, training vs. inference, LPUs vs. GPUs, how to succeed in deep tech (49:37) Goog ... Show More
1h 20m
Feb 2024
Microsoft's New Direction with Copilot, Data Management & Retention, Tech Skills Shortage
The Transformation Ground Control podcast covers a number of topics important to digital and business transformation. This episode covers the following topics and interviews: Microsoft’s New Direction with Copilot, Q&A (Darian Chwialkowski, Third Stage Consulting) Data Management ... Show More
1h 54m
Feb 2024
730: Own Your Own PaaS
Scott and Wes talk about the benefits of owning your own PaaS (platform as a service), the main alternatives in the space, and ways to make passion projects more financially viable. Show Notes 00:00 Welcome to Syntax! 01:12 Brought to you by Sentry.io. 01:56 What is a PaaS? NGINX ... Show More
57m 58s
Feb 2024
Episode 119 - Dart Squad (Ft. 1Dime)
You are listening to this episode 1 week after it was released. To get episodes on time check out our Patreon!  Episode 120 is already available there: https://www.patreon.com/TheDeprogram Check out his work here:Controlled Opposition video: https://www.youtube.com/watch?v=7uPevW ... Show More
1h 16m
Feb 2024
TIP609: Fooled by Randomness by Nassim Taleb
On today’s episode, Clay reviews Nassim Taleb’s book – Fooled by Randomness.Nassim Taleb is a Lebanon-born American mathematician and statistician whose work concerns problems of randomness, probability, and uncertainty. He’s very well known for his popular books, including The B ... Show More
1 h
Feb 2024
Ultra-Niche Positioning: How to Find Success By Going SUPER Narrow
I’m so f*cking happy to announce that ​my book, Stand The F*ck Out, is officially available for PURCHASE​! To buy the book—and more!—DIRECTLY from us and support our small business, go to: https://book.stfo.ioFree Shipping Worldwide • Ripped Apart by 70+ Marketers • Money-Back Gu ... Show More
57m 59s
Nov 2023
Milli Vanilli Unsynced w/Luke & Patrick - Just Shoot It 399
Director Luke Korem is back on the pod! Matt & Oren chat with him and editor Patrick Berry about their new Paramount+ documentary, Milli Vanilli! Matt's Endorsement: Cuisinart Digital Gooseneck KettleOren's Endorsement: Polycam's Room ModeLuke's Endorsement: Nekteck Shiatsu Neck ... Show More
1h 5m