Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our personal takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if Smart People Ever Say They’re Smart.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker – Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26

https://ztw.com/


====== Resources ======

InsertScript - XSS Challenge Solution

https://insert-script.blogspot.com/2020/03/xss-challenge-solution-refresh-header.html


InsertScript - Redirect AuthHeader

https://www.insert-script.com/examples/redirectAuthHeader/send.html


CRLF injection on a 302 redirect

https://x.com/0xdef1ant/status/2009040359482118500


Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover

https://ysamm.com/uncategorized/2025/01/13/capig-xss.html


Arcanum Hack Tips

https://github.com/Arcanum-Sec/hack_tips


Trail of Bits Releases Claude Skills

https://x.com/dguido/status/2011541318229533063


what a $55,000 bug can look like

https://x.com/the_IDORminator/status/2007480636244697237


Pwning Claude Code in 8 Different Ways

https://flatt.tech/research/posts/pwning-claude-code-in-8-different-ways/


Do Smart People Ever Say They’re Smart?

https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/



====== Timestamps ======

(00:00:00) Introduction

(00:04:18) Technical takeaways from CT Charity Hackalong

(00:22:21) InsertScript POCs & Rez0 and teknogeek's IOT Adventures

(00:32:16) CRLF injection on a 302 redirect & Multiple XSS in Meta

(00:41:00) Trail of Bits, what a $55,000 bug can look like, & Pwning Claude Code

(00:54:16) Do Smart People Ever Say They’re Smart?



Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(188)

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.F...

20 Aug 41min

Episode 187: Are Live Hacking Events even worth it?

Episode 187: Are Live Hacking Events even worth it?

Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.Foll...

13 Aug 42min

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop....

6 Aug 58min

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow...

30 Juli 1h 23min

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hac...

23 Juli 1h 13min

Episode 183: PortSwigger Research Impossible XSS SOLVED

Episode 183: PortSwigger Research Impossible XSS SOLVED

Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’...

16 Juli 1h 14min

Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some Graph...

9 Juli 39min

Episode 181: Bug Bounty Singularity

Episode 181: Bug Bounty Singularity

Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestion...

2 Juli 52min

Populärt inom Teknik

uppgang-och-fall
market-makers
rss-elektrikerpodden
 och-bilen-gar-bra
rss-laddstationen-med-elbilen-i-sverige
bli-saker-podden
rss-technokratin
rss-en-ai-till-kaffet
rss-uppgang-och-fall
skogsforum-podcast
hej-bruksbil
gubbar-som-tjotar-om-bilar
bilar-med-sladd
rss-milpodden
natets-morka-sida
klocksnack-tillsammans-med-nymans-ur-1851
rss-fabriken-2
rss-veckans-ai
elbilsveckan
developers-mer-an-bara-kod