
Sign up to save your podcasts
Or


Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
Intigriti is providing free Burp Pro for Hackers!
https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence
====== Resources ======
Django-allauth Account Takeover (ZeroPath Audit)
https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities
CVE-2025-4144: Cloudflare Workers PKCE Bypass
https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9
CVE-2025-54576: OAuth2-Proxy Auth Bypass
https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass
====== Timestamps ======
(00:00:00) Introduction
(00:02:16) OAuth 2.0 Standards
(00:12:08) Agent to Agent Communication
(00:17:19) CVE Case studies
By Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)5
5353 ratings
Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
Intigriti is providing free Burp Pro for Hackers!
https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence
====== Resources ======
Django-allauth Account Takeover (ZeroPath Audit)
https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities
CVE-2025-4144: Cloudflare Workers PKCE Bypass
https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9
CVE-2025-54576: OAuth2-Proxy Auth Bypass
https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass
====== Timestamps ======
(00:00:00) Introduction
(00:02:16) OAuth 2.0 Standards
(00:12:08) Agent to Agent Communication
(00:17:19) CVE Case studies

43,837 Listeners

14,353 Listeners

187 Listeners

2,011 Listeners

3,722 Listeners

371 Listeners

1,028 Listeners

418 Listeners

8,077 Listeners

9,556 Listeners

12,004 Listeners

175 Listeners

2,660 Listeners

139 Listeners

16,525 Listeners