logo
episode-header-image
Dec 2023
51m 33s

Episode 49: Getting Live Hacking Event I...

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
About this episode

Episode 49: In this episode of Critical Thinking - Bug Bounty Podcast, Justin Gardner is once again joined by Nagli to discuss some of their recent hacking discoveries. They talk about finding and exploiting a backup file in an ASP.NET app, discovering vulnerabilities through Swagger files, and debating the vulnerability of a specific ‘undisclosed’ domain. Then they reflect on 2023’s Live Hacking Event circuit, and preview what’s to come in 2024’s.

This episode sponsored by Wordfence! Wordfence recently launched a game-changer of a bug bounty program with ALL WordPress plugins over 50k installs are in-scope. They are currently paying 6.25x their normal bounty amounts, and have agreed to give CT listeners a 10% bonus on top of that! If you wanna pop some crits and see those bounties roll in, head over to https://ctbb.show/wf for more info and keep an eye on the CTBB Discord for inspiration/collabs.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

------ Ways to Support CTBBPodcast ------

Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Today’s Guest

Episode Resources:

Shockwave

Why So Serial

New LHE Standards Dropped

Timestamps:

(00:00:00) Introduction

(00:02:37) wwwroot .zip Hack Recap

(00:13:44) Swagger File Hack Recap

(00:18:27) Undisclosed URL Hack Recap

(00:24:29) 2023 LHE Circut Recap

(00:37:14) 2024 LHE Preview and New Standards

(00:47:22) Bug Bounty Motivation

Up next
Nov 20
Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains
<p>Episode 149: In this episode of Critical Thinking - Bug Bounty Podcast The DEFCON videos are up, and Justin and Joseph talk through some of their favorites.</p><p>Follow us on <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">X</a></p><p>Go ... Show More
1h 2m
Nov 13
Episode 148: MCP Hacking Guide
Episode 148: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us a crash course on Model Context Protocol.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io ... Show More
32m 26s
Nov 6
Episode 147: Stupid Simple Hacking Workflow Tips
Episode 147: In this episode of Critical Thinking - Bug Bounty Podcast we're talking tips and tricks that help us in hacking that we really should’ve learned sooner.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback ... Show More
58m 48s
Recommended Episodes
Feb 2024
TIP609: Fooled by Randomness by Nassim Taleb
On today’s episode, Clay reviews Nassim Taleb’s book – Fooled by Randomness. Nassim Taleb is a Lebanon-born American mathematician and statistician whose work concerns problems of randomness, probability, and uncertainty. He’s very well known for his popular books, including The ... Show More
1 h
Nov 2023
Sports Podcasting On A National Level
“Think of our NFL network, it’s 38 podcasts. To source 38 podcasts, you don’t want eight different publishers and 38 different onboarding calls and invoices - it can be a nightmare. So for us, we like to just make it as easy for an advertiser as possible to activate with those mi ... Show More
44m 24s
Feb 2024
#723: In Case You Missed It: January 2024 Recap of "The Tim Ferriss Show"
<p><strong><em>This episode is brought to you by&nbsp;</em></strong><a href="https://go.tim.blog/5-bullet-friday-1/?utm_source=timblog&amp;utm_medium=timblog&amp;utm_campaign=podcast-sponsorship" rel="noopener noreferrer" target="_blank"><strong><em>5-Bullet Friday</em></strong>< ... Show More
48m 19s
Dec 2024
David Goggins: Transforming Pain into Power - Motivational Insights
David Goggins: Transforming Pain into Power - Motivational Insights Get inspired and motivated every morning with our podcast, featuring insights from successful individuals on changing your mindset and achieving your goals. Don't miss out on this opportunity to start your day o ... Show More
7m 2s
Feb 2024
Episode 702 | "Cutting Diamonds"
<p>In the latest episode, the JBP starts with music including their reactions to Jeezy's Tiny Desk performance (16:38), J. Cole's freestyle (28:38), and the streaming games artists are playing after French Montana drops six versions of 'Mac & Cheese 5' (38:18). Wendy Williams has ... Show More
3h 5m
Feb 2024
Ultra-Niche Positioning: How to Find Success By Going SUPER Narrow
<p></p><p><strong>I've just launched a </strong><a href="https://www.youtube.com/channel/UCdNXaHHVnVntg5gpveB-5_Q"><strong>new YouTube channel</strong></a><strong>!! The concept? </strong>I take real businesses struggling to stand the f*ck out, provide my positioning/branding/lea ... Show More
58m 5s
Feb 2024
The Suffolk Strangler / Steve Wright - Part 2
<p>PLEASE LISTEN TO <strong>‘SEASON 8 - EPISODE 44’ </strong>FOR PART ONE OF THIS TWO-PART CASE. The bodies of five vulnerable women who went missing from the streets of Ipswich were found over a ten-day period.&nbsp;Suffolk Police launched the most extensive investigation in the ... Show More
1 h
Nov 2023
Milli Vanilli Unsynced w/Luke & Patrick - Just Shoot It 399
<p>Director Luke Korem is back on the pod! Matt &amp; Oren chat with him and editor Patrick Berry about their new Paramount+ documentary, Milli Vanilli! </p><br><p>Matt's Endorsement: Cuisinart Digital Gooseneck Kettle</p><p>Oren's Endorsement: Polycam's Room Mode</p><p>Luke's En ... Show More
1h 5m