logo
episode-header-image
Dec 2023
51m 33s

Episode 49: Getting Live Hacking Event I...

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
About this episode

Episode 49: In this episode of Critical Thinking - Bug Bounty Podcast, Justin Gardner is once again joined by Nagli to discuss some of their recent hacking discoveries. They talk about finding and exploiting a backup file in an ASP.NET app, discovering vulnerabilities through Swagger files, and debating the vulnerability of a specific ‘undisclosed’ domain. Then they reflect on 2023’s Live Hacking Event circuit, and preview what’s to come in 2024’s.

This episode sponsored by Wordfence! Wordfence recently launched a game-changer of a bug bounty program with ALL WordPress plugins over 50k installs are in-scope. They are currently paying 6.25x their normal bounty amounts, and have agreed to give CT listeners a 10% bonus on top of that! If you wanna pop some crits and see those bounties roll in, head over to https://ctbb.show/wf for more info and keep an eye on the CTBB Discord for inspiration/collabs.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

------ Ways to Support CTBBPodcast ------

Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Today’s Guest

Episode Resources:

Shockwave

Why So Serial

New LHE Standards Dropped

Timestamps:

(00:00:00) Introduction

(00:02:37) wwwroot .zip Hack Recap

(00:13:44) Swagger File Hack Recap

(00:18:27) Undisclosed URL Hack Recap

(00:24:29) 2023 LHE Circut Recap

(00:37:14) 2024 LHE Preview and New Standards

(00:47:22) Bug Bounty Motivation

Up next
Oct 9
Episode 143: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!
Episode 143: In this episode of Critical Thinking - Bug Bounty Podcast Justin brings Brandyn back to announce him as our newest co-host. We chat about recent LHE experiences, and then break down some news. Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and sugges ... Show More
1h 4m
Oct 2
Episode 142: Gr3pme's Full-Time Hunting Journey Update, Insane AI research, And Some Light News
Episode 142: In this episode of Critical Thinking - Bug Bounty Podcast Rez0 and Gr3pme join forces to discuss Websocket research, Meta’s $111750 Bug, PROMISQROUTE, and the opportunities afforded by going full time in Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGo ... Show More
54m 50s
Sep 25
Episode 141: Hacking the Pod - Google Docs 0-day & React CreateElement Exploits with Nick Copi (7urb0)
Episode 141: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Nick Copi to talk about CSPT, React, CSS Injections and how Nick hacked the pod.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any f ... Show More
1h 23m
Recommended Episodes
Feb 2024
🔒 Exploring English Vocabulary: Remote Working with Lindsay
Subscriber-only episodeE186: 🎙️  Welcome to another Bonus Episode, Plus Members! Thank you for tuning in once again. Today, we're delving into the nitty-gritty of some vocabulary discussed in my recent chat with Lindsay in Episode 185: Native English Conversation: Remote Working ... Show More
10 m
Feb 2024
TIP609: Fooled by Randomness by Nassim Taleb
On today’s episode, Clay reviews Nassim Taleb’s book – Fooled by Randomness.Nassim Taleb is a Lebanon-born American mathematician and statistician whose work concerns problems of randomness, probability, and uncertainty. He’s very well known for his popular books, including The B ... Show More
1 h
Nov 2023
Sports Podcasting On A National Level
“Think of our NFL network, it’s 38 podcasts. To source 38 podcasts, you don’t want eight different publishers and 38 different onboarding calls and invoices - it can be a nightmare. So for us, we like to just make it as easy for an advertiser as possible to activate with those mi ... Show More
44m 24s
Feb 2024
#723: In Case You Missed It: January 2024 Recap of "The Tim Ferriss Show"
This episode is brought to you by 5-Bullet Friday, my very own email newsletter.Welcome to another episode of The Tim Ferriss Show, where it is my job to deconstruct world-class performers to tease out the routines, habits, et cetera that you can apply to your own life. This is a ... Show More
48m 19s
Dec 2024
David Goggins: Transforming Pain into Power - Motivational Insights
David Goggins: Transforming Pain into Power - Motivational InsightsGet inspired and motivated every morning with our podcast, featuring insights from successful individuals on changing your mindset and achieving your goals. Don't miss out on this opportunity to start your day of ... Show More
10m 2s
Feb 2024
Episode 702 | "Cutting Diamonds"
In the latest episode, the JBP starts with music including their reactions to Jeezy’s Tiny Desk performance (16:38), J. Cole’s freestyle (28:38), and the streaming games artists are playing after French Montana drops six versions of ‘Mac & Cheese 5’ (38:18). Wendy Williams has be ... Show More
3h 5m
Feb 2024
Ultra-Niche Positioning: How to Find Success By Going SUPER Narrow
I’m so f*cking happy to announce that ​my book, Stand The F*ck Out, is officially available for PURCHASE​! To buy the book—and more!—DIRECTLY from us and support our small business, go to: https://book.stfo.ioFree Shipping Worldwide • Ripped Apart by 70+ Marketers • Money-Back Gu ... Show More
57m 59s
Feb 2024
The Suffolk Strangler / Steve Wright - Part 2
PLEASE LISTEN TO ‘SEASON 8 - EPISODE 44’ FOR PART ONE OF THIS TWO-PART CASE. The bodies of five vulnerable women who went missing from the streets of Ipswich were found over a ten-day period. Suffolk Police launched the most extensive investigation in the force's history, and wit ... Show More
1 h
Nov 2023
Milli Vanilli Unsynced w/Luke & Patrick - Just Shoot It 399
Director Luke Korem is back on the pod! Matt & Oren chat with him and editor Patrick Berry about their new Paramount+ documentary, Milli Vanilli! Matt's Endorsement: Cuisinart Digital Gooseneck KettleOren's Endorsement: Polycam's Room ModeLuke's Endorsement: Nekteck Shiatsu Neck ... Show More
1h 5m
Jan 2025
President Trump Pardons January 6 Defendants in Sweeping Clemency Action
President Trump Pardons January 6 Defendants in Sweeping Clemency ActionSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info. 
24m 53s