- 250
- 475 070
Critical Thinking - Bug Bounty Podcast
เข้าร่วมเมื่อ 7 ธ.ค. 2022
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
2024 Hacker Stats & 2025 Goals (Ep. 104)
Episode 104: 2024 Hacker Stats & 2025 Goals
Episode 104: In this episode of Critical Thinking - Bug Bounty Podcast Justin reflects upon the past year and walks through some of the bug bounty goals he had for 2024, and how he feels like he did. Then he sets some goals for 2025, as well as some exciting CT news for the coming year.
Follow us on twitter at: ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater & Teknogeek on twitter:
0xteknogeek
rhynorater
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Check out our new SWAG store at ctbb.show/swag!
Resources:
CTBB Full Time Guild
ctbb.show/ft (CHECK TO SEE IF LIVE)
Critical Research Lab
ctbb.show/crl
CT Episode 51 - 2024 Goals
www.criticalthinkingpodcast.io/episode-51-hacker-stats-2023-2024-goals/
Personal BB inventory and goals
ctbb.show/blog
Timestamps:
(00:00:00) introduction
(00:00:57) Critical Thinking 2025 Announcements
(00:04:21) Personal Inventory of 2024
(00:24:05) Goals for 2025
Episode 104: In this episode of Critical Thinking - Bug Bounty Podcast Justin reflects upon the past year and walks through some of the bug bounty goals he had for 2024, and how he feels like he did. Then he sets some goals for 2025, as well as some exciting CT news for the coming year.
Follow us on twitter at: ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater & Teknogeek on twitter:
0xteknogeek
rhynorater
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Check out our new SWAG store at ctbb.show/swag!
Resources:
CTBB Full Time Guild
ctbb.show/ft (CHECK TO SEE IF LIVE)
Critical Research Lab
ctbb.show/crl
CT Episode 51 - 2024 Goals
www.criticalthinkingpodcast.io/episode-51-hacker-stats-2023-2024-goals/
Personal BB inventory and goals
ctbb.show/blog
Timestamps:
(00:00:00) introduction
(00:00:57) Critical Thinking 2025 Announcements
(00:04:21) Personal Inventory of 2024
(00:24:05) Goals for 2025
มุมมอง: 3 152
วีดีโอ
Getting ANSI about Unicode Normalization (Ep. 103)
มุมมอง 1Kวันที่ผ่านมา
Episode 103: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs), as well as talk through some research about _json Juggling, cookie handling quirks, and the value of micro-blogging in general. Follow us on twitter at: ctbbpodcast We're new to this podcasting thing, so ...
Building Web Hacking Micro Agents with Jason Haddix (Ep. 102)
มุมมอง 4.4K14 วันที่ผ่านมา
Episode 102: In this episode of Critical Thinking - Bug Bounty Podcast Justin grabs Jason Haddix to help brainstorm the concept of AI micro-agents in hacking, particularly in terms of web fuzzing, WAF bypasses, report writing, and more.They discuss the importance of contextual knowledge, the cost implications, and the strengths of different LLM Models. Follow us on twitter at: ctbbp...
AI Attack Vectors - CTBB Hijacked - Rez0__ and Johann (Ep. 101)
มุมมอง 2K21 วันที่ผ่านมา
Episode 101: In this episode of Critical Thinking - Bug Bounty Podcast we’ve been hijacked! Rez0 takes control of this episode, and sits down with Johann Rehberger to discuss the intricacies of AI application vulnerabilities. They talk through the importance of understanding system prompts, and various obfuscation techniques used to bypass security measures, the best AI platforms, and the evolv...
8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking (Ep. 100)
มุมมอง 3.6Kหลายเดือนก่อน
8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking (Ep. 100)
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
มุมมอง 10Kหลายเดือนก่อน
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
Team 82 Sharon Brizinov - The Live Hacking Polymath (Ep. 98)
มุมมอง 2.4Kหลายเดือนก่อน
Team 82 Sharon Brizinov - The Live Hacking Polymath (Ep. 98)
Bcrypt Hash Input Truncation & Mobile Device Threat Modeling (Ep. 97)
มุมมอง 1.1Kหลายเดือนก่อน
Bcrypt Hash Input Truncation & Mobile Device Threat Modeling (Ep. 97)
Cookies & Caching with MatanBer (Ep. 96)
มุมมอง 2K2 หลายเดือนก่อน
Cookies & Caching with MatanBer (Ep. 96)
Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side (Ep. 95)
มุมมอง 2.4K2 หลายเดือนก่อน
Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side (Ep. 95)
Zendesk Fiasco & the CTBB Naughty List (Ep. 94)
มุมมอง 1.8K2 หลายเดือนก่อน
Zendesk Fiasco & the CTBB Naughty List (Ep. 94)
A Chat with Dr. Bouman - Life as a Hacker and a Doctor (Ep.93)
มุมมอง 3K2 หลายเดือนก่อน
A Chat with Dr. Bouman - Life as a Hacker and a Doctor (Ep.93)
SAML XPath Confusion, Chinese DNS Poisoning, and AI Powered 403 Bypasser (Ep. 92)
มุมมอง 2.1K2 หลายเดือนก่อน
SAML XPath Confusion, Chinese DNS Poisoning, and AI Powered 403 Bypasser (Ep. 92)
Zero to LHE in 9 Months (feat gr3pme) (Ep. 91)
มุมมอง 5K3 หลายเดือนก่อน
Zero to LHE in 9 Months (feat gr3pme) (Ep. 91)
5k Clickjacking, Encryption Oracles, and Cursor for PoCs (Ep. 90)
มุมมอง 1.9K3 หลายเดือนก่อน
5k Clickjacking, Encryption Oracles, and Cursor for PoCs (Ep. 90)
The Untapped Bug Bounty Landscape of IoT w/ Matt Brown (Ep. 89)
มุมมอง 2.6K3 หลายเดือนก่อน
The Untapped Bug Bounty Landscape of IoT w/ Matt Brown (Ep. 89)
'Hacker Wife' Mariah Gardner on Bug Bounty Mentality and Relationships (Ep. 87)
มุมมอง 4.2K4 หลายเดือนก่อน
'Hacker Wife' Mariah Gardner on Bug Bounty Mentality and Relationships (Ep. 87)
The X-Correlation between Frans & RCE - Research Drop (Ep. 86)
มุมมอง 7K4 หลายเดือนก่อน
The X-Correlation between Frans & RCE - Research Drop (Ep. 86)
Practical Applications of DEFCON 32 Web Research (Ep. 85)
มุมมอง 2.5K4 หลายเดือนก่อน
Practical Applications of DEFCON 32 Web Research (Ep. 85)
0xLupin & Takeaways from Google's Las Vegas BugSwat (Ep. 84)
มุมมอง 1.5K4 หลายเดือนก่อน
0xLupin & Takeaways from Google's Las Vegas BugSwat (Ep. 84)
Crushing Client-Side on Any Scope with MatanBer (Ep. 81)
มุมมอง 7K5 หลายเดือนก่อน
Crushing Client-Side on Any Scope with MatanBer (Ep. 81)
Pwn2Own VS H1 Live Hacking Event (feat SinSinology) (Ep. 80)
มุมมอง 4.6K5 หลายเดือนก่อน
Pwn2Own VS H1 Live Hacking Event (feat SinSinology) (Ep. 80)
The State of CSS Injection - Leaking Text Nodes & HTML Attributes (Ep. 79)
มุมมอง 1.8K5 หลายเดือนก่อน
The State of CSS Injection - Leaking Text Nodes & HTML Attributes (Ep. 79)
Less Writing, More Hacking - Reporting Efficiency Techniques (Ep.78)
มุมมอง 1.8K6 หลายเดือนก่อน
Less Writing, More Hacking - Reporting Efficiency Techniques (Ep.78)
Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated (Ep.77)
มุมมอง 3.9K6 หลายเดือนก่อน
Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated (Ep.77)
Match & Replace - HTTP Proxies' Most Underrated Feature (Ep. 76)
มุมมอง 2.6K6 หลายเดือนก่อน
Match & Replace - HTTP Proxies' Most Underrated Feature (Ep. 76)
*Rerun* of The OG Bug Bounty King - Frans Rosen (Ep. 75)
มุมมอง 2.4K6 หลายเดือนก่อน
*Rerun* of The OG Bug Bounty King - Frans Rosen (Ep. 75)
:)
❤
First strategy: Focus on one target company, spending time familiarizing myself with all of its products, keeping up with updates, and hunting for various vulnerabilities in those. Secondly strategy: Cast a wider net, learning new techniques or exploitation methods, or analyzing newly disclosed vulnerabilities, and then perform broad scans or manual testing across multiple targets on bug bounty platforms. Which of these two strategies is better?
I'm trying to understand this - What you and Joel said are true to a certain extent... but wouldn't this be applicable to other instances of applications like Facebook (fbconnect) only because the application creator decided to open specific links that are either affiliated to that application or want the application workflow pivot from one application to another? Happens in certain cases where you want to open instances of those applications like clicking a TH-cam link from internet browser and playing the video in the application vs playing the video in browser.
Bruh Shubs bug so outta pocket 💀
This is so real
Lol "young and invincible" 😎
Been there, done that 😎
intro music is cool
1:13:56 🔥😂
Appreciate man thanks for all you do
I feel you. You wish there were 40 hours per day, so that you could do 8 hours of work, 12 hours of sleep & misc stuff and 20 hours of pure CySec: 10 hours bug bounty, 10 hours research & learning.
Thanks for sharing your insights. Ready and motivated to get back into the hunt as a part timer. Need to accomplish some professional goals that I set for myself but again really motivated to dive back in.
Temp home and revert home that’s a great idea Awesome pod as usual
Nice job on 2024 goals! Bug bounty guild and research group sounds cool 👀
Very useful tips. Thanks for sharing!
collab with @yshahinzadeh (thezodd in hackerone)
Hello Mr. Rhynorater, I wanted to say that your videos are inspiring! Thank you for what you are doing for the community!
Appreciate y’all so much! Looking forward to an amazing 2025 for us all! 🎉
Just wanted to say thank you so much for all the effort you put into this Podcast and the community. It's been my main source of motivation these last few months going through two CS50 courses to get my CS fundamentals down, to the point where I am now finally in a situation where I can justify making a full time attempt at your "1 year to 100k" plan this year! Absolutely love the idea of a full-time BB community and I'm looking forward to applying once I (hopefully) clear the 50% requirement sometime this year!
What was the crypto bug ??
half a mil? good goal ;)
🎉🎉
Doing god's work. Thanks Justin
i wish it was more in example video instead of just talk
Me too
why i have no idea what they're talking about but I been hacking for a year
I'm watching it on the end of this year to make a new beginning tomorrow 🎉🎉
In burp you an use the CMAR extension, Conditional Match and Replace.
Please help me recover my funds
1st!! Love the intro tune dudes.
Can you please Share This person using extension for xss..
What is the chrome plugin called you are talking about at the end?
I strongly believe that AI is not going to replace or work against us Hackers but, more so work side by side with us as a extention awesome tool , or a cyber buddy that would not only make it easier 8n some scenarios but also instresting as technology advances , that to me is awesome. Awesome educational videos Jason 😊
Absolute banger of a video
Yum.yum..
0:54 the same thing i reported on Roblox this year, the mitigation was simple: Replace shell commands with libraries or built-in functions of the programming language xD
We need CTFs around this to understand better
🫀
More Jason!
checkmate!
If it is Jason I m definitely downloading it and watching it over and over again
✋️ will Ai become just another tool or will it offload/replace workers??
Convoluted linear algebra will not offload and replace workers. Start studying less doomism.
What are those Discord servers called?
I FUCKING hate AI
no man it's end of bug bounty field AI will takeover nooooooooooooooooooooooooooooooo
Nah, tgeres gonna be manual hunters that dont use ai a houndred years from now
well there are bugs that require manual testing but how just how advance will ai become
Btw this is not some hatress toward you just I hate seei g people telling this we human created computers we created ai so it's just a tool rather than a replacement if you see yourself as an easy replacement then you are good give us brain to think and achieve unimaginable with consistency and work and nothing was granted with such present animal or things.end
Ai is just billions of data arranged .and god say if you can escape from the ranges of all sky's and earth do it you will not without a magesty.(The magesty mean science ) Tell me why god didn't say dear ai .go to the ai and ask it that question how can I escape... If will show you some result from shitty website from 2015 taking about some random thing that don't have relation with this
FIRST! 💜
#DD man i am fan of you and your mindset.
❤
Great episode
48:15😂
Very informative