Critical Thinking - Bug Bounty Podcast

by Justin Gardner (Rhynorater) & Joel Margolis (teknogeek)

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Podcast episodes

  • Season 1

  • Episode 38: Mobile Hacking Maestro: Sergey Toshin

    Explicit

    Episode 38: Mobile Hacking Maestro: Sergey Toshin

    Explicit

    Episode 38: In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome mobile hacking maestro Sergey Toshin (aka @bagipro). We kick off with Sergey sharing his unexpected journey into mobile security, and how he rose to become the number one hacker in both Google Play Security and Samsung Bug Bounty programs. We then delve into the evolving perception of mobile bugs, a myriad of new and existing attack vectors, and discuss Sergey's creation of mobile security company Oversecured. You’re going to want to make time for this one!Follow us on twitter at: @ctbbpodcastWe're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!------ Links ------Follow your hosts Rhynorater & Teknogeek on twitter:https://twitter.com/0xteknogeekhttps://twitter.com/rhynoraterToday's Guest:https://twitter.com/_bagiproOversecuredhttps://oversecured.com/Oversecured Bloghttps://blog.oversecured.com/jadxhttps://github.com/skylot/jadx'Golden Android Techniques'https://hackerone.com/reports/431002Timestamps:(00:00:00) Introduction(00:01:28) Sergey Toshin’s hacking journey and achievements(00:08:20) Mobile hacking: Devices and attack vectors(00:12:35) Using Jadx(00:15:40) The creation of Oversecured(00:23:10) The Oversecured Blog and Sharing Information(00:28:08) New Spheres and Strategies of Mobile Hacking(00:35:13) Tips for getting into Mobile Hacking

  • Episode 37: Tokyo Hacking & Interview with 0xLupin

    Explicit

    Episode 37: Tokyo Hacking & Interview with 0xLupin

    Explicit

    Episode 37: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by none other than Lupin himself! We recap the Tokyo LHE and the lessons we learned from it before diving into his legendary journey into security research and bug bounty. We also talk collaboration of all kinds: pair hacking, joining a team, and starting a business together. We even touch on some great tools that can collaborate with each other! This was a fun one, and we don't want you to miss it!Follow us on twitter at: @ctbbpodcastWe're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!------ Links ------Follow your hosts Rhynorater & Teknogeek on twitter:https://twitter.com/0xteknogeekhttps://twitter.com/rhynoraterToday’s Guest:https://twitter.com/0xLupinLupin and Holmeshttps://landh.tech/JSWZLhttps://jswzl.io/Cursorhttps://cursor.so/Clairvoyancehttps://github.com/nikitastupin/clairvoyanceTweet about Command Injectionshttps://twitter.com/win3zz/status/1703702550372078074James Kettle article on security researchhttps://portswigger.net/research/so-you-want-to-be-a-web-security-researcherTimestamps:(00:00:00) Introduction(00:01:00) Lessons learned from the latest LHE(00:09:30) JSWZL and the Cursor Combo(00:19:15) The Legend of Lupin(00:34:35) Code and Collaborating(00:38:48) Requests, Automation, and Testing(00:50:28) Joel's Helper scripts(00:52:50) Teamwork and Pair Hacking(00:57:29) Tips for learning to Hack(01:00:35) UUID and CTF(01:08:35) Dynamics of Collaboration with French Team

  • Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports

    Explicit

    Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports

    Explicit

    Episode 36: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel take a break from LHE prep to answer questions about the ethics of bug bounty and share their recent bug finds. We talk Iframes, mobile intercept proxies, open redirects, and that time Justin got shot at…Follow us on twitter at: @ctbbpodcastWe're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!------ Links ------Follow your hosts Rhynorater & Teknogeek on twitter:https://twitter.com/0xteknogeekhttps://twitter.com/rhynoraterTimeshifter:https://www.timeshifter.com/Tweet about Google Open Redirecthttps://twitter.com/Rhynorater/status/1697357773690818844 Tweet about XSS Exploitation https://twitter.com/Rhynorater/status/1698059391700701424 Request Minimizerhttps://portswigger.net/bappstore/cc16f37549ff416b990d4312490f5fd1Timestamps:(00:00:00) Introduction(00:02:45) Hacker One LHE Preview(00:05:40) Is Bug Bounty Inherently Ethical(00:19:25) Ethics of Going out of scope(00:27:56) Justin’s story of getting shot at(00:30:22) Setting up a mobile intercept proxy(00:33:40) How to approach a new target(00:40:30) Google Open Redirect(00:43:35) Recent XSS Exploitation(00:46:28) ATO Trick(00:50:25) Joel’s Bug Report(00:55:40) Justin’s Bug Report

  • Episode 35: King of Collaboration: Douglas Day

    Explicit

    Episode 35: King of Collaboration: Douglas Day

    Explicit

    Episode 35: In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome Douglas Day, a bug bounty hunter known for his unique methodologies and collaborative spirit. We talk about his approach to finding new endpoints in applications, his ingenious technique of exploiting Intercom widgets, and collaboration preferences and tips at LHEs. We also touch on the struggle of justifying hobbies that don't generate income and the importance of finding enjoyment in the process.We hope you enjoy this episode as much as we did!Follow us on twitter at: @ctbbpodcastWe're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!------ Links ------Follow your hosts Rhynorater & Teknogeek on twitter:https://twitter.com/0xteknogeekhttps://twitter.com/rhynoraterToday’s Guest:https://twitter.com/ArchAngelDDayhttps://hackerone.com/the_arch_angelhttps://bugcrowd.com/arch_angel100 Short Bug Bounty Ruleshttps://twitter.com/ArchAngelDDay/status/1661924038875435008Blog about Intercomhttps://dday.us/2021/11/03/h1vendorATO.htmlBlog about Mapping Hackinghttp://dday.us/2021/10/09/Mapyourhacking.htmlTimestamps: (00:00:00) Introduction(00:03:01) Douglas Day’s infosec and LHE intro(00:10:42) Evolution and philosophy of collaboration(00:23:08) Balancing Collaboration and Money(00:29:43) Recap of 100 Short Bug Bounty Rules(00:37:15) Bug-hunting Methodology(00:45:45) Using match and replace to find new endpoints in bug hunting(00:49:07) Exploiting Intercom widgets(00:52:35) Facing Failure and enjoying the journey(00:57:00) Managing work-life balance(01:05:55) Auth-Z testing and documentation(01:12:25) Vulnerabilities in applications(01:17:05) Mapping Hacking Sessions

  • Episode 34: Program vs Hacker Debate

    Explicit

    Episode 34: Program vs Hacker Debate

    Explicit

    Episode 34: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel have both beaten COVID and now square off against each other in a mega-debate representing hackers and program managers respectively. Among the topics included are Disclosures, Dupes, Zero-Day Policy, payouts, budgets, Triage and Retesting. So, if you want blood-pumping, insult-hurling opinion-invalidating debate…then maybe look somewhere else. But if a thought-provoking discussion about bug bounty is more your style, then take a seat and get ready!Follow us on twitter at: @ctbbpodcastWe're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!------ Links ------Follow your hosts Rhynorater & Teknogeek on twitter:https://twitter.com/0xteknogeekhttps://twitter.com/rhynoraterPrompt Injection Primer for Engineershttps://twitter.com/rez0__/status/1695078576104833291 Portswigger on XSShttps://twitter.com/PortSwiggerRes/status/1691812241375424983Gunner Andrews talkhttps://www.youtube.com/watch?v=aaDe1ADh5KM Jhaddix live training Givawayhttps://tbhmlive.com/ctbb.show/giveawayNew Websitectbb.showFight music composed by Dayn Leonardsonhttps://www.daynleo.com/Timestamps:(00:00:00) Introduction(00:02:00) Joel’s DEFCON Recap(00:04:45) Prompt Injection Primer for Engineers by Rez0(00:07:00) Portswigger Research and XSS(00:08:36) Gunnar Andrews' talk on serverless architecture(00:10:10) ‘Bug Hunter Methodology’ Course GiveawayThe Debate(00:13:34) Zero-Day Policy and Payment for Vulnerabilities(00:25:40) Disclosure(00:33:52) Dupes (00:51:23) CVSS(01:02:25) Budgets and Payouts(01:15:00) Triage and Retesting(01:34:55) Withholding Reports(01:41:50) Root Cause Analysis(01:52:25) Interacting with hacker reports from a security standpoint.(01:58:50) Internal Activity on a Report(02:01:15) Cost of running Bug Bounty Programs and LHE’s