
Sign up to save your podcasts
Or
Episode 47: In this episode of Critical Thinking - Bug Bounty Podcast, the holidays are fast approaching, and Justin and Joel discuss some of the struggles of getting back into the hacking groove during and after breaks. We also celebrate the newly launched Critical Thinking Discord Community before diving into Iframe Sandwhiches, JS Hoisting, CSP Bypasses, and a host of new tools, techniques, and tangents.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
------ Ways to Support CTBBPodcast ------
Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.
Hop on the CTBB Discord at https://ctbb.show/discord!
ThankUNext
jswzl
Rapid API
SSRF Utility tool by Bebiks
Tweet from Johan Carlsson
Burp Extension from Google VRP
Justin's Tweet about JS Hoisting
Bypass CSP Using WordPress
How to trick CSP in letting you run whatever you want
Timestamps:
(00:00:00) Introduction
(00:01:58) Overcoming Bug Bounty struggles and getting back into the hacking groove
(00:07:46) Taking notes and sticking to one program
(00:14:50) Critical Thinking Discord, Community highlights, and Competition vs Collaboration
(00:22:25) Secondary context bugs and Automationism
(00:28:42) ThankUNext and Client-side Paths
(00:33:45) Tool Tangents: Jswzl, Caido, Postman, and Rapid API
(00:46:49) New SSRF Utility tool by Bebiks and the continuing evolution of hacking tools
(00:51:45) Iframe Sandwiches
(00:58:54) News Items
(01:06:12) JS Hoisting
(01:15:05) CSP Bypasses
5
4545 ratings
Episode 47: In this episode of Critical Thinking - Bug Bounty Podcast, the holidays are fast approaching, and Justin and Joel discuss some of the struggles of getting back into the hacking groove during and after breaks. We also celebrate the newly launched Critical Thinking Discord Community before diving into Iframe Sandwhiches, JS Hoisting, CSP Bypasses, and a host of new tools, techniques, and tangents.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
------ Ways to Support CTBBPodcast ------
Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.
Hop on the CTBB Discord at https://ctbb.show/discord!
ThankUNext
jswzl
Rapid API
SSRF Utility tool by Bebiks
Tweet from Johan Carlsson
Burp Extension from Google VRP
Justin's Tweet about JS Hoisting
Bypass CSP Using WordPress
How to trick CSP in letting you run whatever you want
Timestamps:
(00:00:00) Introduction
(00:01:58) Overcoming Bug Bounty struggles and getting back into the hacking groove
(00:07:46) Taking notes and sticking to one program
(00:14:50) Critical Thinking Discord, Community highlights, and Competition vs Collaboration
(00:22:25) Secondary context bugs and Automationism
(00:28:42) ThankUNext and Client-side Paths
(00:33:45) Tool Tangents: Jswzl, Caido, Postman, and Rapid API
(00:46:49) New SSRF Utility tool by Bebiks and the continuing evolution of hacking tools
(00:51:45) Iframe Sandwiches
(00:58:54) News Items
(01:06:12) JS Hoisting
(01:15:05) CSP Bypasses
363 Listeners
633 Listeners
372 Listeners
174 Listeners
1,008 Listeners
313 Listeners
387 Listeners
926 Listeners
7,810 Listeners
141 Listeners
187 Listeners
308 Listeners
120 Listeners
4 Listeners
33 Listeners