Interested in going full-time bug bounty? Check out our blueprint!

Videos

Sept. 19, 2024

The Untapped Bug Bounty Landscape of IoT w/ Matt Brown (Ep. 89)

Episode 89: In this episode of Critical Thinking - Bug Bounty Podcast We’re joined live by Matt Brown to talk about his journey with hacking in the IoT. We cover the specializations and challenges in hardware hacking, and Matt’s personal Methodology. Then we switch over to touch on BGA Reballing,…

View more
Sept. 18, 2024

Mariah embarrassing Justin about the first time he met Frans Rosén 😂

Plus some great tips for your first time LHE! #bugbountytips #bugbounty #bugbounties

View more
Sept. 12, 2024

News, Tools, and Writeups (Ep. 88)

Episode 88: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel tackle a whole slate of new research including a new cheat sheet for URL validation bypass from Portswigger, the introduction of Sanic DNS as a high-speed DNS resolver, xsstools, and the Dockerization of Orange Confusion…

View more
Sept. 10, 2024

Is this the ULTIMATE SWAG FLEX? 💪

#bugbountytips #bugbounty #bugbounties

View more
Sept. 9, 2024

How to dump /etc/passwd with "%3F" 🤯

#bugbountytips #bugbounty #bugbounties

View more
Sept. 8, 2024

First time at DEFCON... as a content creator!

#bugbountytips #bugbounty #bugbounties

View more
Sept. 7, 2024

Why didn't I know about THIS!?

#bugbountytips #bugbounty #bugbounties

View more
Sept. 5, 2024

'Hacker Wife' Mariah Gardner on Bug Bounty Mentality and Relationships (Ep. 87)

Episode 87: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with none other than his wife Mariah to talk about Bug Bounty from the perspective of a Significant Other. They share how they’ve traversed travel and Live Hacking Events, household chores, hobbies, goals, rewards, as…

View more
Sept. 4, 2024

The MISSING PLUGIN for API Testing!

View more
Aug. 31, 2024

Why is note taking SO BAD!?

View more
Aug. 29, 2024

Why are hackers so SCRAPPY?

View more
Aug. 29, 2024

The X-Correlation between Frans & RCE - Research Drop (Ep. 86)

Episode 86: In this episode of Critical Thinking - Bug Bounty Podcast Frans blows Justin’s mind with a sneak peak of his new presentation. Note: This is a little different from our normal episode, and video is recommended. So head over to ctbb.show/yt if you feel like you’re missing something.…

View more
Aug. 22, 2024

Practical Applications of DEFCON 32 Web Research (Ep. 85)

Episode 85: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel talk through some of the research coming out of DEFCON, mainly from the PortSwigger team. Web timing attacks, cache exploitation, and exploits related to email protocols are all featured. Plus we also talk some fun…

View more
Aug. 15, 2024

0xLupin & Takeaways from Google's Las Vegas BugSwat (Ep. 84)

Episode 84: In this episode of Critical Thinking - Bug Bounty Podcast, Justin is joined by Roni Carta (@0xLupin) to discuss their MVH win at the recent Google LHE, and share some technical observations they had with the target and the event. Follow us on twitter at: @ctbbpodcast We're new…

View more
Aug. 10, 2024

Hacking your first IoT device

Wanna dive into IoT device research? Grab a device, hook it up with UART or JTAG, and start poking around. Try some tricks like glitching or looking for sneaky firmware backdoors to get in. Here's a quick rundown. #bugbountytips #bugbounty #bugbounties

View more
Aug. 9, 2024

Surviving last-minute patches in Pwn2Own!

Pwn2Own competitions can be a cruel mistress but there are ways to prepare for the worst.

View more
Aug. 8, 2024

Brainstorming Proxy Plugins (Ep.83)

Episode 83: In this episode of Critical Thinking - Bug Bounty Podcast Joel and Justin are brainstorming new features and improvements for Caido, such as the implementation of a 403 bypassing workflow, a text expander, Tracing Cookies, and more. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting…

View more
Aug. 7, 2024

STOP overriding debug functions. Use this DevTools secret instead.

Instead of manually modifying debug functions, Matan sets log points to capture function arguments, providing more visibility and simplifying the process. Here's how to add log points with a right-click in DevTools.

View more
Aug. 6, 2024

This JS function = XSS as a Service!

Learn how Matan uses JavaScript imports to fetch and execute files, transforming traditional XSS exploits into a single-line process. #bugbountytips #bugbounty #bugbounties

View more
Aug. 5, 2024

DISGUSTINGLY AMAZING vuln leaves me (almost) speechless!

Matan Berson ingeniously uses self-XSS to manipulate cookies and hijack browser sessions. Learn how he cleared cookies, set redirect cookies with payloads, and achieved successful login redirections by exploiting path variables for session fixation.

View more
Aug. 4, 2024

Mind-blowing debugging trick!

Genius debugging technique: writing scripts inside conditional breakpoints! Learn how to inject code directly into breakpoints for quick checks, making debugging super efficient. This eye-opening trick will revolutionize how you use conditional breakpoints.

View more
Aug. 1, 2024

Muscle up your bug bounty game (literally)!

If you wanna do cool shit, you gotta put in the reps. Also... check out the biceps on Justin! 😂

View more
Aug. 1, 2024

Part-Time Bug Bounty (Ep. 82)

Episode 82: In this episode of Critical Thinking - Bug Bounty Podcast Joel Margolis discusses strategies and tips for part-time bug bounty hunting. He covers things like finding (and enforcing) balance, picking programs and goals, and streamlining your process to optimize productivity. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new…

View more
July 26, 2024

This vuln keeps Justin awake at night!

If CSS injection keeps you up at night, you're not alone. Get in touch with Justin and you can start a club or get help or something.

View more