logo
episode-header-image
Jan 2024
3 h

Episode 52: Best Technical Content from ...

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
About this episode

Episode 52: In this episode of Critical Thinking - Bug Bounty Podcast we're going back and highlighting some of the best technical moments from the past year! Hope you enjoy this best of 2023 Supercut!

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

------ Ways to Support CTBBPodcast ------

Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Timestamps:

(00:00:00) Introduction

(00:02:55) Episode 26: Meta tags and base tags in HTML

(00:15:20) Episode 27: Client-side path traversal

(00:23:18) Episode 27: Cookie bombing + cookie jar overflow

(00:35:47) Episode 44: Cross environment authentication bugs

(00:43:17) Episode 47: The open-faced Iframe Sandwich

(00:50:19) Episode 47: js hoisting and classic Joel nerdsnipe

(00:58:28) Episode 29: Sean Yeoh on Subdomains vs IP in recon

(01:04:05) Episode 30: Shubs on reversing enterprise software

(01:24:58) Episode 30: Shubs on building out a recon flow

(01:29:36) Episode 30: Shubs on Hacking IIS Servers

(01:36:45) Episode 37: 0xLupin on smart JavaScript analysis tools

(01:45:42) Episode 45: Frans Rosen On App cache, Service workers cookie stuffing, and postMessage

(02:15:02) Episode 50: Mathias Karlsson on XSLT and MXSS

(02:39:26) Episode 27: Assetnote's sharefile RCE

(02:48:18) Episode 31: Perforce RCE

(02:53:48) Episode 48: Sam Erb's XSLT bug story

(02:58:47) Final thoughts and Special Thanks

Up next
Nov 20
Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains
<p>Episode 149: In this episode of Critical Thinking - Bug Bounty Podcast The DEFCON videos are up, and Justin and Joseph talk through some of their favorites.</p><p>Follow us on <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">X</a></p><p>Go ... Show More
1h 2m
Nov 13
Episode 148: MCP Hacking Guide
Episode 148: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us a crash course on Model Context Protocol.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io ... Show More
32m 26s
Nov 6
Episode 147: Stupid Simple Hacking Workflow Tips
Episode 147: In this episode of Critical Thinking - Bug Bounty Podcast we're talking tips and tricks that help us in hacking that we really should’ve learned sooner.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback ... Show More
58m 48s
Recommended Episodes
Sep 14
455: The Chicken Killer | The Official Podcast
Get 25% off HelixSleep sitewide: go to https://www.helixsleep.com/official Get 25% off your Fitbod subscription or try the app for free: go to https://www.fitbod.me/official Get additional episodes and bonus content with early access (try now with 7 DAYS FREE): go to https://www. ... Show More
1h 41m
Sep 22
Episode 83: Learn and Teach American English with Maestro Sersea Podcast
Episode 83: Learn and Teach American English with Maestro Sersea PodcastIn this episode we cover:InterjectionsEmotions VocabularyEmotions Dialogues and Comprehension Visit our official podcast website, https://rss.com/podcasts/americanenglish/ for prior episodes and links to all ... Show More
19m 33s
Aug 2024
100th Episode Extravaganza
In this bonus episode we celebrate a major milestone, the 100th episode of our podcast! We talk about some of the listeners' favorite moments of the first 99 episodes of the podcast, and our favorite moments from all the episodes of Bluey that we've talked about so far. Our liste ... Show More
41m 48s
Mar 2025
Episode 172 - Car Go Vroom
<p>Brief history of a tool that changed the world.</p><p>You are listening to this episode 1 week after it was released. To get episodes on time, up to 2 exclusive episodes a month, discord access, merch discounts and plenty more - check out our Patreon - https://www.patreon.com/ ... Show More
1h 17m
Sep 2023
Episode 074: Management of Advanced Stage Diffuse Large B-Cell Lymphoma (DLBCL)
<p class="" style="white-space:pre-wrap;">This week, we continue our conversation about DLBCL, this time focusing our attention on the management of early stage disease. </p><p class="" style="white-space:pre-wrap;">In this week’s episode, we delve into the management of advance ... Show More
36m 4s
Sep 5
Episode 197 - Deep State Epstein Shenanigans (Ft. Alan Macleod)
<p>From the Maxwell family tree to IDF corporate espionage - we&apos;re joined by Alan to discuss some of his latest articles on all things Elite.</p><p>You are listening to this episode 1 week after it was released. To get episodes on time, up to 2 exclusive episodes a month, di ... Show More
1h 42m
Sep 2020
Collaborative Article Writing (Episode 75)
<p>Claire, Kacy, and guests Miranda and Christina discuss their work collaborating on writing an academic article, with additional tips for student writers to keep in mind!</p><br><p>Resources mentioned:</p><br><p>WriteCast Episode 8 (Rebroadcast as episode 48):<a href="https://a ... Show More
13m 38s
Jul 2017
464. How I make episodes of the podcast (Part 1)
<p>Talking about the creative side of making podcast episodes, including some thoughts on how to come up with ideas and how to speak in front of an audience. Watch out for various phrases with 'get' during the episode.</p> <p>Episode page on teacherluke.co.uk <a href= "http://wp. ... Show More
1h 16m
Aug 14
Live from Big Sky Dev Con: Code Debates, Content Insights, and What's Next for Web Development
Live from Big Sky Dev Con, Robbie is joined by Aaron Francis, Ken Wheeler, and Typecraft to discuss HTML and CSS programming status, React’s future, app security failures, NPM’s weak spots, content creation hooks, survival tech fantasies, and balancing big tech ambitions with fam ... Show More
50m 55s