Episode 20: Hacker Brain Hacks - Overcoming Bug Bounty's Mental Tolls

Episode 20: Hacker Brain Hacks - Overcoming Bug Bounty's Mental Tolls

Episode 20: In this episode of Critical Thinking - Bug Bounty Podcast, we dive into the world of "hacker brain hacks'' and overcoming challenges in bug bounty hunting. We discuss custom word lists, the rising popularity of Caido as a potential Burp Suite replacement, and Cloudflared tunnels for hosting POCs. We also tackle the mental aspects of bug bounty hunting, from procrastination to imposter syndrome, and share tips for staying motivated and avoiding burnout. Don't miss this episode packed with valuable insights and advice for both beginners and seasoned bug bounty hunters!

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

Caido:

https://caido.io

Tweet from D3mondev on Sequence Diagram:

https://twitter.com/d3mondev/status/1660803152755453952

Sequence diagram software:

https://sequencediagram.org

Timestamps:

(00:00:00) Introduction

(00:02:36) "Sequence Diagram": Sequence mapping for PoCs

(00:04:10) "SubReconGPT": AI and GPT in Bug Bounty Hacking

(00:08:30) "Caido": A Potential Replacement for Burp Suite

(00:11:34) HackerOne's New Features

(00:13:00) Cloudflared Tunnels for Red Team Assessments and Payload Hosting

(00:16:07) Mental challenges in Bug Bounty Hunting

(00:17:50) Procrastination Education: Letting fear of failure drive you into always learning, never doing.

(00:22:46) Analysis Paralysis: Starting with Bug Bounty Programs vs VDPs

(00:27:07) Automation Obsession: "When you're hacking, hack. When you're automating, automate."

(00:14:34) Imposter Syndrome: You may not be the best, but you're not the worst either.

(00:31:55) Motivation Deprivation: Stay curious, and set tiered goals

(00:36:07) Automation Obsession pt2: Do we need to say it again?

(00:37:25) Reconnaissance Cognizance: Spending too much time on recon and not enough time on hacking

(00:40:00) Bad Rabbit Holes, RIP Your Goals: Identifying good and bad rabbit holes

(00:46:01) Set Your Goal Poles: Setting specific goals for yourself.

(00:48:29) Impact Lacked: Fixating on something that's funky, but simply doesn’t really have impact

(00:51:00) The Burn-out turn-out: Mending, maintenance, and finding identity and self-worth outside hacking

(00:58:19) Responsibility Volatility: Balancing Responsibilities and Freedom as a Bug Bounty Hunter

(01:00:30) Payout Phase-out: Don't stop once you've found one bug.

(01:02:04) Report on URN Injection

Episoder(166)

Episode 102: Building Web Hacking Micro Agents with Jason Haddix

Episode 102: Building Web Hacking Micro Agents with Jason Haddix

Episode 102: In this episode of Critical Thinking - Bug Bounty Podcast Justin grabs Jason Haddix to help brainstorm the concept of AI micro-agents in hacking, particularly in terms of web fuzzing, WAF...

19 Des 20241h 2min

Episode 101: CTBB Hijacked: Rez0__ on AI Attack Vectors with Johann Rehberger

Episode 101: CTBB Hijacked: Rez0__ on AI Attack Vectors with Johann Rehberger

Episode 101: In this episode of Critical Thinking - Bug Bounty Podcast we’ve been hijacked! Rez0 takes control of this episode, and sits down with Johann Rehberger to discuss the intricacies of AI app...

12 Des 202451min

Ep 100 - 8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking

Ep 100 - 8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking

Episode 100: In this episode of Critical Thinking - Bug Bounty Podcast we have a mixed bag. We celebrate 100 episodes of Critical Thinking, but also bid farewell to Joel, who will be leaving the show ...

5 Des 20241h 41min

Episode 99: Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty

Episode 99: Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty

Episode 99: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Roni dissect an old thread of Justin's talking about how best to start bug bounty with the goal of making $100k in the ...

28 Nov 20241h 42min

Episode 98: Team 82 Sharon Brizinov - The Live Hacking Polymath

Episode 98: Team 82 Sharon Brizinov - The Live Hacking Polymath

Episode 98: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gardner sits down with Sharon,to discuss his journey from early iOS development to leading a research team at Claroty. They...

21 Nov 20241h 43min

Episode 97: Bcrypt Hash Input Truncation & Mobile Device Threat Modeling

Episode 97: Bcrypt Hash Input Truncation & Mobile Device Threat Modeling

Episode 97: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel jump into some cool news items, including a recent Okta Bcrypt vulnerability, insights into crypto bugs, and some ...

14 Nov 202453min

Episode 96: Cookies & Caching with MatanBer

Episode 96: Cookies & Caching with MatanBer

Episode 96: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with Matanber to hit some stuff we ran out of time on last episode. We talk about advanced cookie parsing techniques an...

7 Nov 202449min

Episode 95: Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side

Episode 95: Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side

Episode 95: In this episode of Critical Thinking - Bug Bounty Podcast In this episode, Justin is joined by MatanBer to delve into the intricacies of browser extensions. We talk about the structure and...

31 Okt 20241h 56min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
smart-forklart
elektropodden
nasjonal-sikkerhetsmyndighet-nsm
energi-og-klima
rss-ki-praten
rss-impressions-2
fornybaren
shifter
tomprat-med-gunnar-tjomlid
rss-heis
rss-ai-forklart
rss-alt-vi-kan
rss-alt-som-gar-pa-strom
pedagogisk-intelligens
rss-praktisk-proptech
rss-fjorsilkebris-podcast
rss-anleggspraten