Critical Thinking - Bug Bounty Podcast

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS


Listen Later

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Service in Claude.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe.

Use code CTBB040126, and get a 10% bonus on your bounty for any AI vulnerability which is mapped to the OWASP LLM top 10.

Valid on Adobe Acrobat Web - AI Assistant / PDF Spaces / Content Creation and presentation features using Express

Adobe Express AI Assistant. 

Valid through April 1st, 2026


Also we have a Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag!


====== Resources ======

Cloudflare Zero-day

https://fearsoff.org/research/cloudflare-acme


Turning List-Unsubscribe into an SSRF/XSS Gadget

https://security.lauritz-holtmann.de/post/xss-ssrf-list-unsubscribe/


Breaking Multi-Tenant Isolation in Heroku Postgres

https://allistair.sh/blog/breaking-heroku-postgres/


Parse and Parse: MIME Validation Bypass to XSS via Parser Differential

https://lab.ctbb.show/research/parse-and-parse-mime-validation-bypass-to-xss-via-parser-differential


Claude Magic String Denial of Service

https://x.com/Frichette_n/status/2013988503336415522


From WebView to Remote Code Injection

https://djini.ai/from-webview-to-remote-code-injection/


DOM XSS Is Not Dead: The Rise of Polyglot Payloads

https://blogs.jsmon.sh/dom-xss-is-not-dead-the-rise-of-polyglot-payloads/


====== Timestamps ======

(00:00:00) Introduction

(00:06:17) Cloudflare Zero-day & Turning List-Unsubscribe into an SSRF/XSS Gadget

(00:16:57) Breaking Multi-Tenant Isolation in Heroku Postgres & CTBB Research

(00:25:46) Claude Magic String Denial of Service & From WebView to Remote Code Injection

...more
View all episodesView all episodes
Download on the App Store

Critical Thinking - Bug Bounty PodcastBy Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

  • 5
  • 5
  • 5
  • 5
  • 5

5

53 ratings


More shows like Critical Thinking - Bug Bounty Podcast

View all
Radiolab by WNYC Studios

Radiolab

43,977 Listeners

StarTalk Radio by Neil deGrasse Tyson

StarTalk Radio

14,353 Listeners

Hacked by Hacked

Hacked

188 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,008 Listeners

The Vergecast by The Verge

The Vergecast

3,718 Listeners

Risky Business by Risky Business Media

Risky Business

373 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,026 Listeners

Click Here by Recorded Future News

Click Here

417 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,093 Listeners

The Indicator from Planet Money by NPR

The Indicator from Planet Money

9,561 Listeners

The Jordan Harbinger Show by Jordan Harbinger

The Jordan Harbinger Show

11,990 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

My First Million by Hubspot Media

My First Million

2,667 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

16,447 Listeners