Interested in going full-time bug bounty? Check out our blueprint!
Sept. 24, 2026

Episode 193: Browser Logic Errors & XS-Leaks with Jorian Woltjer

Episode 193: Browser Logic Errors & XS-Leaks with Jorian Woltjer
Episode 193: Browser Logic Errors & XS-Leaks with Jorian Woltjer
Critical Thinking - Bug Bounty Podcast
Episode 193: Browser Logic Errors & XS-Leaks with Jorian Woltjer

Episode 193: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Jorian Woltjer to talk through his Bug Bounty journey and all the crazy research he’s done for the Critical Thinking Lab.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


====== Resources ======

Cache key injection: Smuggling poison through the door

https://www.yeswehack.com/lab/research-cache-key-injection


====== Resources ======

XS-Leaks

https://xsleaks.dev/


Solving an ORB mystery

https://lab.ctbb.show/research/solving-an-orb-mystery


Research Review #24: Solving an ORB mystery (J0R1AN)

https://www.youtube.com/watch?v=TpXccQbOb48


Stopping Redirects

https://lab.ctbb.show/research/stopping-redirects


Ethical Hacker Groep Nederland

https://www.youtube.com/playlist?list=PL-cT3O--POR-ElvSufpZ1oPfyocmWYeos


====== Timestamps ======

(00:00:00) Introduction

(00:04:19) CTFd status code XS-Leak

(00:18:05) Jorian's Journey & Solving an ORB mystery

(00:33:39) Stopping Redirects

(00:58:55) DNS Rebinding in the browser

(01:08:47) Popunder: weak password prompt

(01:24:33) Declarative partial updates