Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)

Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)

Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe. Earn more for AI bugs with Adobe’s new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-research


Also don’t forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.

Expires June 30, 2026.


====== This Week in Bug Bounty ======

Scaling Bug Bounty triage in the AI era

(https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai)


The AI impact: a triager’s perspective

https://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective


====== Resources ======

Sling Selectors - The Key to Unlocking AEM's Attack Surface

https://greenjam.co.uk/blog/sling-selectors/


Just a Moment CTF

https://poc.greenjam.co.uk/just-a-moment.html


General XSS jquery .text()

https://poc.greenjam.co.uk/text-xss.html


URL XXS Challenge

https://poc.greenjam.co.uk/url-xss.html


====== Timestamps ======

(00:00:00) Introduction

(00:04:35) Background and AEM Bug

(00:17:40) Sling Selectors & the Tech Stack

(00:38:14) Permissions & Apache Sling Resolution

(01:01:37) The Bugs & AEM Red Flags

(01:31:55) Moment in Time CTF

(01:40:38) General XSS jquery .text()

(01:45:45) URL XXS Challenge

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(192)

Episode 192: Building Amazing Proof-of-Concepts with AI

Episode 192: Building Amazing Proof-of-Concepts with AI

Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestio...

17 Sep 26min

Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions....

10 Sep 37min

Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They als...

3 Sep 33min

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what h...

27 Aug 1h 14min

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.F...

20 Aug 41min

Episode 187: Are Live Hacking Events even worth it?

Episode 187: Are Live Hacking Events even worth it?

Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.Foll...

13 Aug 42min

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop....

6 Aug 58min

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow...

30 Juli 1h 23min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-veckans-ai
rss-ai-med-jonas-benjamin
rss-technokratin
rss-en-ai-till-kaffet
bli-saker-podden
natets-morka-sida
rss-sakerhetspodcasten
rss-digitala-influencer-podden
developers-mer-an-bara-kod
rss-snacka-om-ai
rss-it-sakerhetspodden
hej-bruksbil
 och-bilen-gar-bra
bilar-med-sladd