
Sign up to save your podcasts
Or


Episode 7: In this episode of Critical Thinking - Bug Bounty Podcast we talk about PortSwigger's Top 10 Web Hacking Techniques of 2022 (link below), some drama surrounding TruffleSecurity's XSS Hunter, and, as always, some great bug bounty tips.
Sorry if the audio is a little rough around the edges this time, should be better than ever next time.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
PortSwigger's Top 10 Web Hacking Techniques of 2022:
https://portswigger.net/research/top-10-web-hacking-techniques-of-2022
Ian Carroll Cookie Monster:
https://github.com/iangcarroll/cookiemonster
Frans Rosen's postMessage Tracker Chrome Extension:
https://github.com/fransr/postMessage-tracker
Notes from Justin on postMessages:
https://rhynorater.github.io/postMessage-Braindump
Frans Rosen's research on nginx misconfiguration that are similar to #6:
https://blog.detectify.com/2020/11/10/common-nginx-misconfigurations/
"Mount" Wycheproof 😂:
https://github.com/google/wycheproof
https://en.wikipedia.org/wiki/Mount_Wycheproof
Nathan Davison - Abusing Hop-by-Hop headers:
https://nathandavison.com/blog/abusing-http-hop-by-hop-request-headers
Awesome example of client-side path traversal:
https://erasec.be/blog/client-side-path-manipulation/
Joohoi Ffuf 2.0:
https://infosec.exchange/@joohoi/109806822104162973
FeroxBuster:
https://github.com/epi052/feroxbuster
By Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)5
5353 ratings
Episode 7: In this episode of Critical Thinking - Bug Bounty Podcast we talk about PortSwigger's Top 10 Web Hacking Techniques of 2022 (link below), some drama surrounding TruffleSecurity's XSS Hunter, and, as always, some great bug bounty tips.
Sorry if the audio is a little rough around the edges this time, should be better than ever next time.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
PortSwigger's Top 10 Web Hacking Techniques of 2022:
https://portswigger.net/research/top-10-web-hacking-techniques-of-2022
Ian Carroll Cookie Monster:
https://github.com/iangcarroll/cookiemonster
Frans Rosen's postMessage Tracker Chrome Extension:
https://github.com/fransr/postMessage-tracker
Notes from Justin on postMessages:
https://rhynorater.github.io/postMessage-Braindump
Frans Rosen's research on nginx misconfiguration that are similar to #6:
https://blog.detectify.com/2020/11/10/common-nginx-misconfigurations/
"Mount" Wycheproof 😂:
https://github.com/google/wycheproof
https://en.wikipedia.org/wiki/Mount_Wycheproof
Nathan Davison - Abusing Hop-by-Hop headers:
https://nathandavison.com/blog/abusing-http-hop-by-hop-request-headers
Awesome example of client-side path traversal:
https://erasec.be/blog/client-side-path-manipulation/
Joohoi Ffuf 2.0:
https://infosec.exchange/@joohoi/109806822104162973
FeroxBuster:
https://github.com/epi052/feroxbuster

43,837 Listeners

14,353 Listeners

187 Listeners

2,011 Listeners

3,722 Listeners

371 Listeners

1,028 Listeners

418 Listeners

8,077 Listeners

9,556 Listeners

12,004 Listeners

175 Listeners

2,660 Listeners

139 Listeners

16,525 Listeners