Interested in going full-time bug bounty? Check out our blueprint!

Videos

Feb. 20, 2025

(Ep 111) How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu Episode 111: In this episode of Critical Thinking - Bug Bounty Podcast Justin interviews Kevin Mizu to showcase his knowledge regarding DOMPurify and its misconfigurations. We walk through some of Kevin’s research, highlighting things like Dangerous allow-lists and…

View more
Feb. 19, 2025

[Bug Drop] XSSDoctor's Sick XSS Chain

We're going a bit outside the normal posts for CTBB Podcast today, and we're gonna give you a taste of what our premium content on Discord feels like. This time, we've got an AMAZING bug from XSSDoctor. If you'd like to get your hands on the lab for this one,…

View more
Feb. 13, 2025

(Ep. 110) Oauth Gadget Correlation and Common Attacks

Episode 110: In this episode of Critical Thinking - Bug Bounty Podcast we hit some quick news items including a DOMPurify 3.2.3 Bypass, O3 mini updates, and a cool postLogger Chrome Extension. Then, we hone in on OAuth vulnerabilities, API keys, and innovative techniques hackers use to exploit these systems.…

View more
Feb. 9, 2025

Cookie bombing, of course! hahah

#hacking #bugbounty #bugbountytips #websecurity #infosec #cookies #cookiebombing #SAASsecurity

View more
Feb. 7, 2025

Just get intimate with the app

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
Feb. 6, 2025

(Ep. 109) Creative Recon - Alternative Techniques

Episode 109: In this episode of Critical Thinking - Bug Bounty Podcast we start off with a quick recap of some of the DeepSeek Drama that’s been going down, and discuss AI in CAPTCHA and 2FA as well. Then we switch to cover some other news before settling in to…

View more
Feb. 5, 2025

Exploiting SAAS Misconfigurations

#hacking #bugbounty #bugbountytips #websecurity #infosec #saas

View more
Jan. 30, 2025

(Ep. 108) How to Hack Salesforce, ServiceNow, and Other SaaS Products With Aaron Costello

Episode 108: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph bring on Aaron Costello to discuss SaaS security and misconfigurations as a bug class. He also gives some in-depth examples from Salesforce, ServiceNow, and Power Pages. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas…

View more
Jan. 23, 2025

Bypassing Cross-Origin Browser Headers (Ep. 107)

Episode 107: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph are tackling the subject of cross-origin security headers. They also cover some news items including Google’s OAuth login flaw, RAINK, and gift card hacking. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions?…

View more
Jan. 16, 2025

Announcing our new cohost... (Ep. 106)

Episode 106: In this episode of Critical Thinking - Bug Bounty Podcast we are pleased to announce our new co-host of the podcast: Joseph Thacker Aka Rez0! We discuss Joseph's transition to full-time bug bounty hunting, his goals, and what he’s looking forward to bringing to the pod. We also…

View more
Jan. 8, 2025

Best Moments of 2024 on the Pod (Ep. 105)

Episode 105: In this episode of Critical Thinking - Bug Bounty Podcast we're back with another Best-of episode recapping some of our top moments of the year. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout…

View more
Jan. 4, 2025

The Secret to Knowing What (and When) to Learn!

#bugbountytips #bugbounty #bugbounties

View more
Jan. 2, 2025

Concealing payloads in URL credentials

#bugbountytips #bugbounty #bugbounties

View more
Jan. 2, 2025

2024 Hacker Stats & 2025 Goals (Ep. 104)

Episode 104: 2024 Hacker Stats & 2025 Goals Episode 104: In this episode of Critical Thinking - Bug Bounty Podcast Justin reflects upon the past year and walks through some of the bug bounty goals he had for 2024, and how he feels like he did. Then he sets some…

View more
Dec. 30, 2024

Missing browser prompts = BIG bounties

#bugbountytips #bugbounty #bugbounties

View more
Dec. 28, 2024

This Bcrypt thing is insane.

#bugbountytips #bugbounty #bugbounties

View more
Dec. 27, 2024

Getting ANSI about Unicode Normalization (Ep. 103)

Episode 103: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs), as well as talk through some research about _json Juggling, cookie handling quirks, and the value of micro-blogging in general. Follow us…

View more
Dec. 27, 2024

Getting ANSI about Unicode Normalization (Ep. 103)

Episode 103: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs), as well as talk through some research about _json Juggling, cookie handling quirks, and the value of micro-blogging in general. Follow us…

View more
Dec. 26, 2024

XSS via the shared cache in service workers (with Matan Berson)

#bugbountytips #bugbounty #bugbounties

View more
Dec. 26, 2024

Getting ANSI about Unicode Normalization (Ep. 103)

Episode 103: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs), as well as talk through some research about _json Juggling, cookie handling quirks, and the value of micro-blogging in general. Follow us…

View more
Dec. 24, 2024

The character that broke Safari's cookies.

#bugbountytips #bugbounty #bugbounties

View more
Dec. 22, 2024

Have you heard of the cookie value-to-key trick!?

#bugbountytips #bugbounty #bugbounties

View more
Dec. 20, 2024

Chrome extensions 101 with Justin and Matan

#bugbountytips #bugbounty #bugbounties

View more
Dec. 19, 2024

Building Web Hacking Micro Agents with Jason Haddix (Ep. 102)

Episode 102: In this episode of Critical Thinking - Bug Bounty Podcast Justin grabs Jason Haddix to help brainstorm the concept of AI micro-agents in hacking, particularly in terms of web fuzzing, WAF bypasses, report writing, and more.They discuss the importance of contextual knowledge, the cost implications, and the strengths…

View more