Critical Thinking - Bug Bounty Podcast

Episode 75: *Rerun* of The OG Bug Bounty King - Frans Rosen


Listen Later

Episode 75: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel are sick, So instead of a new full episode, we're going back 30 episodes to review.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

------ Ways to Support CTBBPodcast ------

Hop on the CTBB Discord at https://ctbb.show/discord!

Today's Guest: https://twitter.com/fransrosen

Detectify

Discovering s3 subdomain takeovers

https://labs.detectify.com/writeups/hostile-subdomain-takeover-using-heroku-github-desk-more/

bucket-disclose.sh

https://gist.github.com/fransr/a155e5bd7ab11c93923ec8ce788e3368

A deep dive into AWS S3 access controls

Attacking Modern Web Technologies

Live Hacking like a MVH

Account hijacking using Dirty Dancing in sign-in OAuth flows

Timestamps:

(00:00:00) Introduction

(00:11:41) Franz Rosen's Bug Bounty Journey and Detectify

(00:20:21) Pseudo-code, typing, and thinking like a dev

(00:27:11) Hunter Methodologies and automationists

(00:42:31) Time on targets, Iteration vs. Ideation

(00:58:01) S3 subdomain takeovers

(01:11:53) Blog posting and hosting motivations

(01:20:21) Detectify and entrepreneurial endeavors

(01:36:41) Attacking Modern Web Technologies

(01:52:51) postMessage and MessagePort

(02:05:00) Live Hacking and Collaboration

(02:20:41) Account Hijacking and OAuth Flows

(02:35:39) Hacking + Parenthood

...more
View all episodesView all episodes
Download on the App Store

Critical Thinking - Bug Bounty PodcastBy Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

  • 5
  • 5
  • 5
  • 5
  • 5

5

53 ratings


More shows like Critical Thinking - Bug Bounty Podcast

View all
Hacked by Hacked

Hacked

186 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

288 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,005 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,026 Listeners

Smashing Security by Graham Cluley

Smashing Security

319 Listeners

Click Here by Recorded Future News

Click Here

417 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,069 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

965 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Day[0] by dayzerosec

Day[0]

10 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

140 Listeners

Bug Bounty Reports Discussed by Grzegorz Niedziela

Bug Bounty Reports Discussed

4 Listeners