Interested in going full-time bug bounty? Check out our blueprint!

Videos

Feb. 29, 2024

Our Take on PortSwigger's Top 10 Web Hacking Techniques of 2023 (Ep. 60)

Episode 60: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel review the Portswigger Research list of top 10 web hacking techniques of 2023. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io…

View more
Feb. 27, 2024

This bug is SO CLUTCH! Client-side path traversal via open redirect.

Why? Because who's expecting malicious input to come back from a fetch request that they sent to their own API!? Watch the full episode here: ctbb.show/59

View more
Feb. 25, 2024

How I use gadgets to stay motivated in bug hunting!

I know how hard it is to stay motivated when you've been hacking for days and haven't found anything. Here's my tip:

View more
Feb. 24, 2024

We've got an EXCITING announcement!

We've got an exciting announcement...

View more
Feb. 22, 2024

How to turn math.random into math(NOT)random by calculating the seed!

How to turn math.random into math(NOT)random by calculating the seed! Watch the full episode with Youssef Sammouda here: ctbb.show/58

View more
Feb. 22, 2024

Bug Bounty Gadget Hunting & Hacker's Intuition (Ep. 59)

Episode 59: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel discuss the concept of gadgets and how they can be used to escalate the impact of vulnerabilities. We talk through things like HTML injection, image injection, CRLF injection, web cache deception, leaking window location, self-stored…

View more
Feb. 20, 2024

Youssef confuses the triage team with this Scroll to Text Fragment exploitation!

Stored XSS? "Easy". SQL Injection? "Piece of cake". Manipulating page encoding for Scroll to Text Fragment exploitation? "Uhhhh... Can you hold?". Youssef throws more triage curveballs at us in this episode: https://loom.ly/ovfwWUc

View more
Feb. 18, 2024

Client-side race condition via postMessage with Youssef Sammouda (Ep. 58)

Client-side race condition via postMessage: 1. Initiate asynchronous request. 2. Before response, use postMessage to change origin. 3. Manipulated origin gains trust. ...you know where this is going. Youssef explains all in Ep. 58: https://loom.ly/ovfwWUc

View more
Feb. 17, 2024

Youssef hasn't duped in like 6 years! HOW!?

His creativity is next level and he hasn't duped in like 6 years! @samm0uda shares some crazy stories about race conditions, exploiting hash change events, and leveraging scroll to text fragments. Watch this episode now: https://loom.ly/ovfwWUc

View more
Feb. 15, 2024

Youssef Sammouda - Client-Side & ATO War Stories (Ep. 58)

Episode 58: In this episode of Critical Thinking - Bug Bounty Podcast we finally sit down with Youssef Samouda and grill him on his various techniques for finding and exploiting client-side bugs and postMessage vulnerabilities. He shares some crazy stories about race conditions, exploiting hash change events, and leveraging scroll…

View more
Feb. 8, 2024

Episode 57: Live Hacking Event Inside Scoop - H1-305

Episode 57: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel are live from Miami, and recap their experience and share takeaways from the live hacking event. They highlight the importance of paying attention to client-side routing and the growing bug class of client-side path traversal.…

View more
Feb. 1, 2024

Using Data Science to win Bug Bounty - Mayonaise (aka Jon Colston) (Ep. 56)

Episode 56: In this episode of Critical Thinking - Bug Bounty Podcast, Justin sits down with Jon Colston to discuss how his background in digital marketing and data science has influenced his hunting methodology. We dive into subjects like data sources, automation, working backwards from vulnerabilities, applying conversion funnels to…

View more
Jan. 25, 2024

Popping WordPress Plugins - Methodology Brain dump (Ep. 55)

Episode 55: In this episode of Critical Thinking - Bug Bounty Podcast, Justin is joined by Wordpress Security Researcher Ram Gall to discuss both functionality and vulnerabilities within Wordpress Plugins. Follow us on twitter Send us any feedback here: Shoutout to https://twitter.com/realytcracker for the awesome intro music! ====== Links ======…

View more
Jan. 18, 2024

White Box Formulas - Vulnerable Coding Patterns (Ep. 54)

Episode 54: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel are back with news items and new projects. Joel shares about his personal scraping project to gather data on bug bounty programs and distribution Next, they announce the launch of HackerNotes, a podcast companion that…

View more
Jan. 11, 2024

500k/yr as Full-Time Bug Hunter & Content Creator - Nahamsec (Ep. 53)

Episode 53: In this episode of Critical Thinking - Bug Bounty Podcast,we’re joined by none other than NahamSec. We start by discusses the challenges he faced on his journey in bug bounty hunting and content creation, including personal struggles and the pressure of success.We also talk about finding balance and…

View more
Jan. 4, 2024

Best Technical Content from Year 1 of CTBB Podcast (Ep. 52)

Episode 52: In this episode of Critical Thinking - Bug Bounty Podcast we're going back and highlighting some of the best technical moments from the past year! Hope you enjoy this best of 2023 Supercut! Follow us on twitter at: @ctbbpodcast We're new to this podcasting thing, so feel free…

View more
Dec. 28, 2023

Hacker Stats 2023 & 2024 Goals (Ep. 51)

Episode 51: In this episode of Critical Thinking - Bug Bounty Podcast, Justin and Joel are back for the last episode of 2023. We discuss some noteworthy news items including a Hacker One Crit, Caido updates, and some Blind CSS. Then we dive into our own personal ‘Hackers Wrapped’ recap…

View more
Dec. 21, 2023

Mathias "Fall in a well" Karlsson - Bug Bounty Prophet (Ep. 50)

Episode 50: In this episode of Critical Thinking - Bug Bounty Podcast, Justin catches up with hacking master Mathias Karlsson, and talks about burnout, collaboration, and the importance of specialization. Then we dive into the technical details of MXSS and XSLT, character encoding, and give some predictions of what Bug…

View more
Dec. 14, 2023

Getting Live Hacking Event Invites & Bug Bounty Collab with Nagli (Ep. 49)

Episode 49: In this episode of Critical Thinking - Bug Bounty Podcast, Justin Gardner is once again joined by Nagli to discuss some of their recent hacking discoveries. They talk about finding and exploiting a backup file in an ASP.NET app, discovering vulnerabilities through Swagger files, and debating the vulnerability…

View more
Dec. 7, 2023

MVH, DEFCON Black Badge, Googler Sam Erb (Ep. 48)

Episode 48: In this episode, joined by the spectacular Sam Erb, Google Security Engineer and DEFCON Black Badge winner. We talk about the importance of understanding how systems work to find vulnerabilities, and how his engineering background influences his hunting style and methodologies. Then we jump over to his Career…

View more
Nov. 30, 2023

CSP Research, Iframe Hopping, and Client-side Shenanigans (Ep. 47)

Episode 47: In this episode of Critical Thinking - Bug Bounty Podcast, the holidays are fast approaching, and Justin and Joel discuss some of the struggles of getting back into the hacking groove during and after breaks. We also celebrate the newly launched Critical Thinking Discord Community before diving into…

View more
Nov. 23, 2023

The SAML Ramble (Ep. 46)

Episode 46: In this episode of Critical Thinking - Bug Bounty Podcast, Justin is deep diving the topic of SAML (Security Assertion Markup Language), and walks through what it is and why it can be intimidating, before going over some key attack vectors to look for. Then he closes out…

View more
Nov. 16, 2023

The OG Bug Bounty King - Frans Rosen (Ep. 45)

In this episode of Critical Thinking - Bug Bounty Podcast, we're thrilled to welcome Frans Rosén, an OG bug bounty hunter and co-founder of Detectify. We kick off with Frans sharing his journey bug bounty and security startups, before diving headfirst into a host of his blog posts. We also…

View more
Nov. 9, 2023

URL Parsing & Auth Bypass Magic (Ep. 44)

Episode 44: In this episode of Critical Thinking - Bug Bounty Podcast, the topic is URL structure, and Justin and Joel break down the elements that make up a URL and some common tips and tricks surrounding them which allow for all sorts of bypasses. We also round out the…

View more