Episode 39: The Art of Architectures

Episode 39: The Art of Architectures

Episode 39: In this episode of Critical Thinking - Bug Bounty Podcast, We're catching up on news, including new override updates from Chrome, GPT-4, SAML presentations, and even a shoutout from Live Overflow! Then we get busy laying the groundwork on a discussion of web architecture. better get started on this one, cause we're going to need a part two!

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

CT shoutout from Live Overflow

https://www.youtube.com/watch?v=3zShGLEqDn8

Chrome Override updates

https://developer.chrome.com/blog/new-in-devtools-117/#overrides

GPT-4/AI Prompt Injection

https://x.com/rez0__/status/1706334160569213343?s=20 & https://x.com/evrnyalcin/status/1707298475216425400?s=20

Caido Releases Pro free for students

https://twitter.com/CaidoIO/status/1707099640846250433

Or, use code ctbbpodcast for 10% of the subscription price

Aleksei Tiurin on SAML hacking

https://twitter.com/antyurin/status/1704906212913951187

Account Takeover on Tesla

https://medium.com/@evan.connelly/post-account-takeover-account-takeover-of-internal-tesla-accounts-bc720603e67d

Joseph

https://portswigger.net/bappstore/82d6c60490b540369d6d5d01822bdf61

Cookie Monster

https://github.com/iangcarroll/cookiemonster

HTMX

https://htmx.org/

Timestamps:

(00:00:00) Introduction

(00:04:40) Shoutout from Live Overflow

(00:06:40) Chrome Overrides update

(00:08:48) GPT-4V and AI Prompt Injection

(00:14:35) Caido Promos

(00:15:40) SAML Vulns

(00:17:55) Account takeover on Tesla, and auth token from one context in a different context

(00:24:30) Testing for vulnerabilities in JWT-based authentication

(00:28:07) Web Architectures

(00:32:49) Single page apps + a rest API

(00:45:20) XSS vulnerabilities in single page apps

(00:49:00) Direct endpoint architecture

(00:55:50) Content Enumeration

(01:02:23) gRPC & Protobuf

(01:06:08) Microservices and Reverse Proxy

(01:12:10) Request Smuggling/Parameter Injections

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(192)

Episode 192: Hackbot Proof-of-Concept Skill Creation

Episode 192: Hackbot Proof-of-Concept Skill Creation

Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestio...

17 Sep 26min

Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions....

10 Sep 37min

Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They als...

3 Sep 33min

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what h...

27 Aug 1h 14min

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.F...

20 Aug 41min

Episode 187: Are Live Hacking Events even worth it?

Episode 187: Are Live Hacking Events even worth it?

Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.Foll...

13 Aug 42min

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop....

6 Aug 58min

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow...

30 Juli 1h 23min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-veckans-ai
rss-ai-med-jonas-benjamin
rss-technokratin
rss-en-ai-till-kaffet
bli-saker-podden
natets-morka-sida
rss-sakerhetspodcasten
rss-digitala-influencer-podden
developers-mer-an-bara-kod
rss-snacka-om-ai
rss-it-sakerhetspodden
hej-bruksbil
 och-bilen-gar-bra
bilar-med-sladd