Episode 93: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Dr. Jonathan Bouman to discuss his unique journey as both a Hacker and a Healthcare Professional. We talk through how he balances his dual careers, some ethical considerations of hacking in the context of healthcare, and highlight some experiences he’s had with Amazon's bug bounty program.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to https://twitter.com/ctbbpodcast for the awesome intro music!

====== Links ======
Find the Hackernotes: https://blog.criticalthinkingpodcast.io/
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater

====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Today’s Sponsor - AssetNote. Listen to their podcast https://www.criticalthinkingpodcast.io/sspod

Today’s Guest:
Dr. Jonathan Bouman: https://x.com/JonathanBouman

Resources:
https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github

Filesender Github
https://github.com/filesender/filesender/blob/development/templates/exception.php

Filesender 0-day writeup:
https://medium.com/@jonathanbouman/cve-2024-45186-unauthenticated-ssti-bug-in-filesender-exposes-mysql-s3-credentials-and-other-463a9efc1478

Remote Code execution at ws1.aholdusa.com
https://medium.com/@jonathanbouman/remote-code-execution-at-ws1-aholdusa-com-compromising-logins-of-ahold-delhaize-usa-employees-c7c9aca7e05d

APK-MITM
https://github.com/niklashigi/apk-mitm

Hacking Dutch healthcare system
https://medium.com/@jonathanbouman/bricks-huisarts-v2-3-12-94166-vulnerable-to-executable-uploads-in-e-consultation-send-by-patients-631f6152cf8e

Fitness YouTube Channels
https://www.youtube.com/channel/UCpQ34afVgk8cRQBjSJ1xuJQ

https://www.youtube.com/@BullyJuice

Timestamps
(00:00:00) Introduction
(00:07:28) Medicine and Hacking
(00:19:36) Hacking on Amazon
(00:34:33) Collaboration and consistency
(00:44:13) SSTI Methodology
(01:06:10) iOS Hacking Methodology
(01:13:23) Hacking Healthcare
(01:32:19) Health tips for hacking