Episode 130: Minecraft Hacks to Google Hacking Star - Valentino

Episode 130: Minecraft Hacks to Google Hacking Star - Valentino

Episode 130: In this episode of Critical Thinking - Bug Bounty Podcast Justin is joined by Valentino, who shares his journey from hacking Minecraft to becoming a Google hunter. He talks us through several bugs, including an HTML Sanitizer bypass and .NET deserialization, and highlights the hyper creative approaches he tends to employ.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater and Rez0 on Twitter:

https://x.com/Rhynorater

https://x.com/rez0__

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker - Patch Management

https://www.criticalthinkingpodcast.io/TL-patch-management

Today’s Guest: Valentino - https://blog.3133700.xyz/

====== Resources ======

JMX Manager

Stored XSS in reclamos

Command Injection in Vertex AI

whitepaper-net-deser.pdf

free-after-use.go

A Journey Into Finding Vulnerabilities in the PMB Library Management System

emulated-register_globals.php

====== Timestamps ======

(00:00:00) Introduction

(00:02:38) JMXProxy Bug Story

(00:09:46) Intro to Valentino

(00:29:08) HTML Sanitizer bypass on MercadoLibre

(00:37:16) Command injection in Vertex AI

(00:44:10) .NET deserialization, & Argument injection to LFR, & Free after use

(00:51:33) Luck, creativity, and evolution as Hacker

(00:59:31) Issues in file extension validation components, Emulated register_globals, & AI Hacking

Jaksot(161)

Episode 41: Mini Masterclass: Attack Vector Ideation

Episode 41: Mini Masterclass: Attack Vector Ideation

Episode 41: In this episode of Critical Thinking - Bug Bounty Podcast, Justin takes a break from his busy travel schedule to walk us through a few of his Attack Vector formulation strategies. We’re ke...

19 Loka 202317min

Episode 40: Bug Bounty Mentoring

Episode 40: Bug Bounty Mentoring

Episode 40: In this episode of Critical Thinking - Bug Bounty Podcast, it’s all about mentorships! Justin sits down with Kodai and So, two hackers he helped mentor, to discuss what worked and what did...

12 Loka 20231h 31min

Episode 39: The Art of Architectures

Episode 39: The Art of Architectures

Episode 39: In this episode of Critical Thinking - Bug Bounty Podcast, We're catching up on news, including new override updates from Chrome, GPT-4, SAML presentations, and even a shoutout from Live O...

5 Loka 20231h 21min

Episode 38: Mobile Hacking Maestro: Sergey Toshin

Episode 38: Mobile Hacking Maestro: Sergey Toshin

Episode 38: In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome mobile hacking maestro Sergey Toshin (aka @bagipro). We kick off with Sergey sharing his unexpected jou...

28 Syys 202343min

Episode 37: Tokyo Hacking & Interview with 0xLupin

Episode 37: Tokyo Hacking & Interview with 0xLupin

Episode 37: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by none other than Lupin himself! We recap the Tokyo LHE and the lessons we learned from it before diving into his le...

21 Syys 20231h 15min

Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports

Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports

Episode 36: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel take a break from LHE prep to answer questions about the ethics of bug bounty and share their recent bug finds. W...

14 Syys 20231h 3min

Episode 35: King of Collaboration: Douglas Day

Episode 35: King of Collaboration: Douglas Day

Episode 35: In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome Douglas Day, a bug bounty hunter known for his unique methodologies and collaborative spirit. We talk a...

7 Syys 20231h 25min

Episode 34: Program vs Hacker Debate

Episode 34: Program vs Hacker Debate

Episode 34: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel have both beaten COVID and now square off against each other in a mega-debate representing hackers and program ma...

31 Elo 20232h 10min