JR0ch17 accidentally discovered a bug in an OAuth flow where sending constant requests to the token refresh endpoint without a refresh token or authentication, could grant an access token during another user's login process!
Here's a WEIRD RACE CONDITION BUG for y'all!
Join the Email List
Email has been submitted.
Recent Episodes
- Episode 192: Hackbot Proof-of-Concept Skill Creation
- Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens
- Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?
- Episode 189: What Happened to HackerOne with Joel Margolis
- Episode 188: DEFCON 34 Hotel Room Debrief
- Episode 187: Are Live Hacking Events even worth it?
- Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?
- Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026
- Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
- See all →