Interested in going full-time bug bounty? Check out our blueprint!
Aug. 6, 2026

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?
Critical Thinking - Bug Bounty Podcast
Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

Critical Research Lab:

https://lab.ctbb.show/

Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/

Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: Check out Zero Trust Network Access:

https://www.criticalthinkingpodcast.io/tl-ztna

====== Resources ======

Trend of Bug Bounty Programs

https://x.com/iangcarroll/status/2082535987633410540

Next chapter: Restructuring GitHub’s bug bounty program

https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/

Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

Gauntlet Loop

https://x.com/mattshumer_/status/2081830214384886228

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/

====== Timestamps ======

(00:00:00) Introduction

(00:05:40) Bug Bounty Program Trends & Pricing Changes

(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6

(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop

(00:36:58) LHE vs Hackbot

(00:43:21) KindaRails2Shell & WP2Shell

[00:00:00.43] - Joseph Thacker
And I think that you also need to be gaslighting your model. Like, nope, there's definitely a bug here. Nope, there's definitely a bug here. Because even 5.6 Ultra came back to JD multiple times at this event and was like, nope, there's not a bug here. And he's like, yeah, there is. I know there is. And eventually it found some crazy bugs.

[00:00:14.17] - Justin Gardner
bugs. I  know. That's exactly what JD was like too. He's like, yes, it is. 

[00:00:41.40] - Justin Gardner
If you've been in the bug bounty recon game for any period of time, you know how beautiful it is when some unsuspecting dev or DevOps guy spins up what's clearly supposed to be an internal-facing server and accidentally just gives you the keys to the kingdom, right? It's a big payday. It's an easy win. It's a beautiful thing. Right. And unfortunately for us, ThreatLocker also knows about that. And that's why they created their Zero Trust Network Access product. Okay, check this out. This is a product that prevents that unauthorized network access, not only at the network level, but also at the device level. Okay, so anybody's connecting to those sensitive internal services, you know that they are authorized as that user, but also the device that they're connecting from is validated. So you get complete introspection into who's accessing these sensitive systems. It's a great product. Check it out at threatlocker.com. All right, let's go back to the show. Yeah, dude, uh, I've got this— you see this beanbag right behind me right here? I've got this, you know, it's summer right now and it's kind of intense with the girls, you know, at home or whatever. And, uh, and but they've brought this, you know, beanbag in here. And, and what we'll do is I'll throw like a Netflix show that we're watching together or something like that up on one of my monitors in here because I got the quad monitor setup.

[00:01:51.09] - Joseph Thacker
Yeah.

[00:01:51.50] - Justin Gardner
And, and then we can just, you know, still be together, chill, watch a show together, you know, do some activity together. And I can also be getting my work done during the day.

[00:02:00.93] - Joseph Thacker
That's awesome. Yeah. It's a pretty good situation.

[00:02:02.73] - Justin Gardner
I think I might leave it there for a little while.

[00:02:04.51] - Joseph Thacker
That's awesome. You need to sit on it and hack with a laptop sometime.

[00:02:07.48] - Justin Gardner
Yeah. Yeah. Well, that's, that's when now, you know, my little one is saying like, hey, come, come sit out here with me, snuggle with me. And how am I supposed to say no to that? You know, like, so I'm like trying to like Text Claude from my phone.

[00:02:18.18] - Joseph Thacker
Hey, it's possible these days, at least, you know, at least it is possible.

[00:02:23.03] - Justin Gardner
Well, that's one of the crazy things, man, is like, I totally agree with that. I think that the AI, you know, revolution that's happening right now has come at like such a perfect time for me.

[00:02:32.65] - Joseph Thacker
For you personally?

[00:02:33.87] - Justin Gardner
Yeah, because, well, I just became, you know, a dad 2 years ago, and I didn't, you know, it was via adoption rather than, you know, via having a little baby. And it's very busy and very intense. So I'm running around doing stuff and very often.

[00:02:49.31] - Joseph Thacker
And, uh, speaking of, your hair's been— it's like kind of intense today too. Dude, are you like not cutting it these days or what?

[00:02:55.34] - Justin Gardner
I am. No, I skipped a haircut and because the girls want me to grow it out and, uh, I don't know, it is very long. You're right. Thanks for calling me out on that. Um, but yeah, anyway, and I just, I'm so blessed that I can just, you know, be going and putting out a, you know, fire. with the teenagers, right? And then texting Claude to be like, oh, try this on this program now, you know, just going back to what I was doing, right? So it's—

[00:03:20.84] - Joseph Thacker
Hey, speaking of your monitor setup, I actually went the other direction. I, I had 2 monitors. Sorry, I hit my mic. Um, I had 2 monitors and I went down to like 1 ultrawide. So you're, you're up to 4 and I'm down to 1 at this point.

[00:03:31.96] - Justin Gardner
How do you like that? I, I feel like I like to have them blocked out like this, you know?

[00:03:35.97] - Joseph Thacker
Uh, honestly, the old monitors like were just like kind of a lower DPI And, uh, as I mentioned before, I had to get readers. And I think that that's like one reason is the lower quality monitor. So I'm just excited to have like a really high-res, high-quality monitor.

[00:03:49.09] - Justin Gardner
So nice. Yeah. Nice.

[00:03:50.46] - Joseph Thacker
So that's a good thing.

[00:03:52.28] - Justin Gardner
I forget if I've said this on the podcast before, but you know, I do, I do, um, uh, house renos as well. So we'll like buy a house and we'll fix it up and then we'll, we'll typically keep it as a rental. Um, but You know, in that process, I was at this place that they have, uh, called the ReStore, which is a Habitat for Humanity, you know, place where you can go and get like used appliances and stuff like that, right? And furniture. So I walk in there one day and there's, there's like 8 4K HP 27-inch monitors, you know, thin, no bezel, no bezel-less monitors.

[00:04:32.02] - Joseph Thacker
Wow.

[00:04:32.26] - Justin Gardner
How did they get in there? These are like $400 monitors, dude.

[00:04:34.67] - Joseph Thacker
Right.

[00:04:35.17] - Justin Gardner
Freaking shout out to the boys over at Capital One. Capital One has a headquarters here in Richmond.

[00:04:40.77] - Joseph Thacker
Oh, wow.

[00:04:41.48] - Justin Gardner
Right? And they donated a ton of old monitors— old, old monitors— to the Habitat for Humanity. So I walk in there, they're like $50 each, bro.

[00:04:51.42] - Joseph Thacker
You bought all 4 on the spot?

[00:04:52.55] - Justin Gardner
I literally— I bought all of them. I was just like, yeah, I bought all 8. And I was like, These are mine. You know, I, and I load them all up into the car. I don't even, you know, what am I going to use 8 monitors for? But I just stuck them in my closet and I've been giving them out like candy. You know, like a hacker comes over to my house, I'm like, hey, you need a monitor? You You

[00:05:10.69] - Joseph Thacker
You You need a monitor? Exactly.

[00:05:12.50] - Justin Gardner
It's like trick or treat. Here's a monitor.

[00:05:17.01] - Joseph Thacker
That would be hilarious.

[00:05:18.57] - Justin Gardner
So, yeah, dude. But I mean, that was, that was probably one of the best finds I've ever had at like a thrift store, like a, you know, that sort of thing. Because man, that was like, think about it, that was like $3,500 worth of monitors. Yeah, that's true. Yeah. Oh my gosh.

[00:05:32.97] - Joseph Thacker
That's really cool.

[00:05:34.85] - Justin Gardner
So yeah, anyway, okay, let's, let's get to the meat because we, we've gotta, we gotta make a quick episode today. Um, uh, let me talk about this, this one really quickly first. I'll just, um, I'm gonna pull this up on the screen. Um, so, you know, Ian, Ian's got a lot going on. Ian Carroll, uh, he's got a lot going on nowadays, but he does, he does still speak about the bug bounty industry from time to time. And when he speaks, I listen. And he tweeted this out the other day. There's a trend of bug bounty programs reducing rewards under the guise that they can find issues themselves with AI. This is basically absurd and you don't have to pay bounties for issues you've already found, right?

[00:06:15.02] - Joseph Thacker
Right.

[00:06:15.26] - Justin Gardner
It's like, it just doesn't seem like a real thing. And I totally, totally agree with this. I think that I think that that is a crazy thing that Coinbase put out in this article here. Right. If you here. Right. If you

[00:06:26.88] - Joseph Thacker
here. Right. If you here. Right. If you find them internally, you'll be paying less in bounty, so you should up it to keep your budget the same.

[00:06:31.41] - Justin Gardner
Exactly. Exactly. So what are they doing?

[00:06:34.23] - Joseph Thacker
Right.

[00:06:34.67] - Justin Gardner
I don't know. I just wanted to call that out. Call programs out if they say bullshit like that, because that, I don't like that.

[00:06:41.56] - Joseph Thacker
When I read it, I think that they might just be saying that they don't want to accept low and medium bugs, which I think is reasonable for a short period of time here while everyone's inundated. Like you have to kind of go into triage. I mean that not in like a triager mode, but like as if you're in war, right? Like you're triaging things, like you're triaging, um, you're trying to stop the bleeding and you're going to start with the most severe vulnerabilities first and work your way down. And so I think having like a temporary pause or whatever on like lows and medium vulnerabilities actually makes sense right now. And when I, when I, when I read that, it kind of seems like they might be saying that or that—

[00:07:13.93] - Justin Gardner
That's not what they said though. You know, like if that's what they said, that, that's fine. But what they said is low and medium severity issues are moving out of scope for our public bug bounty program.

[00:07:20.79] - Joseph Thacker
Because we can find them all. Our Our

[00:07:21.87] - Justin Gardner
Our Our own internal tools are, have matured and can catch this class of issue at scale continuously.

[00:07:26.93] - Joseph Thacker
Yeah. They can just catch all mediums themselves. Just all of them. That's like, well then catch them, fix them, and then they won't ever make it to the bug bounty hunters' reports. Right?

[00:07:35.19] - Justin Gardner
Exactly.

[00:07:35.83] - Joseph Thacker
Yeah, no, true.

[00:07:37.76] - Justin Gardner
Exactly. So I don't know, that's kind of BS, but I, I, you know, I understand only expecting, accepting highs and crits in this day and age. That is a little bit sad, you know, and I've always been a big proponent for the medium. That's how I choose my programs typically is I'll look at the medium bounty, I'll look at the critical bounty and the medium bounty, which is ironic because I almost exclusively submit highs.

[00:07:58.00] - Joseph Thacker
That tells you the quality though.

[00:08:01.44] - Justin Gardner
Yeah. Well, it's funny because when you look at my impact and you look at just the majority of my reports, sometimes I'll spray a bunch of low issues if a company's going to accept some low issue that's everywhere. I'm just like, free money. But, you know, most of the time I'm submitting highs, which is something I've struggled with because I would like to submit more crits, right? But I don't look at the high bounty quite as much as I look at the medium and the critical as anchor points when evaluating a program because mediums, you know, I feel like mediums is what I kind of look at mediums as like paying, paying the mortgage, you know?

[00:08:34.49] - Joseph Thacker
Sure.

[00:08:34.96] - Justin Gardner
You know, you pop a couple mediums, you pay the mortgage, you're good. And then the crits just go straight into the, you know, into the savings.

[00:08:41.62] - Joseph Thacker
Right.

[00:08:42.07] - Justin Gardner
Yeah. So I don't know.

[00:08:43.28] - Joseph Thacker
No, I do agree. I think that like for most hunters, when you consider like, I don't know, PR, L, like if you could put it, you know, privilege required low drops your high to a medium, it feels so bad if it's going from $3,000 to $300, right? I mean, like, it feels like, like you just lost the bug. Like you don't really care about anything. But if their mediums are at $1K and now you're like, okay, it went from 3 to 1, it's not, you know, it's not— you still feel like you're getting some money. But you're right, there are some companies Amazon, cough, that have like $400 mediums and like $5,000 highs. And you're just like, a single CVSS point here is just going to like wreck my day. You know what I mean?

[00:09:21.27] - Justin Gardner
Yeah, totally. Yeah. And I think the Atlassian program, I want to say, is the same way. Like, and I've been hacking on them a little bit with one of my mentees and, and like, it's, we're just fingers crossed. We're like trying to push everything to, to high. We're like showing You know, when we get like these AI bugs that we're hacking on, um, you know, it's like they're— we're like trying to leak data that like, this is very sensitive data.

[00:09:45.50] - Joseph Thacker
Right. I mean, really, I will say if companies are going to have that kind of structure, they just need to be kind of lenient with their highs, or if it's Bugcrowd, they need to be lenient with their P2s. Like, because if they're strict with CWE and they're going to like crank it down to P3 just because— or sorry, it's VRT. just because VRT says it's P3. It's like, come on, like, you're just like basically taking money out of their hands for no reason.

[00:10:07.75] - Justin Gardner
Yeah, yeah, I totally agree, man. So I don't know, I think, I think it's a little bit of a, um, I think it's, uh, I, I think that in general it works pretty good to try to get people to go for higher impact, right? But I, when it gets downgraded, it's like, oh, that's, that really doesn't move the needle at all, you know? Like, if it's $300 versus $3,000, it's like, okay, well You know, thanks for saying my report's garbage. You know, like—

[00:10:33.52] - Joseph Thacker
Right. And you spend so long with it because you're like, oh, this is a high, it's worth the investment. And then it's not at the end. So—

[00:10:37.87] - Justin Gardner
It's not. It's a bummer. And speaking of that, so GitHub also restructured their program a little bit here. Um, and they give, uh, they are introducing a permanent VIP program where they will pay higher bounties. And the entrance to that is clearly qual— you know, qualified here. 1 critical finding, 2 high findings, 4 medium findings, 7 low findings. Right. Any of those will get you in.

[00:11:02.08] - Joseph Thacker
Yeah.

[00:11:02.96] - Justin Gardner
And then their public program is substantially lower bounties. Highs are $5K instead of $20K. Crits are $10K instead of $30K. Mediums are $2K instead of $7,500. So I, I don't know, man. What do you think about this?

[00:11:20.61] - Joseph Thacker
I've been hacking on GitHub a good bit. I think it's kind of interesting. I don't really love gated access. Are you in the VIP program? I am, yeah. But I just don't really love gated access in general. So I think there's a private program on Intigriti. We can bleep it if they're not supposed to be known, which I think they're not. And they don't invite you into the private until you've got bugs on the public. And I think famously AWS is that way these days. And something just feels really weird about it, especially for people with like an established track record of like, providing real impact to Fortune 100 companies.

[00:11:58.47] - Justin Gardner
Yeah.

[00:11:59.02] - Joseph Thacker
I don't know. I'm not motivated, and I think it's kind of crappy to have me work on, let's just say, NVIDIA's public scope to then find a really valid vuln, get it submitted to them, wait for it to triage, wait to be accepted. All the while, I could have just been hacking on their program. So I don't know that I love it, but in this case, the public program from GitHub is at least still paying bugs, and it's still relatively competitive. I don't really know what difference it makes to them. Like, I'm just trying to think through the implications of like, is this gonna like reduce the slop reports or is this just to, I guess one thing it does do is drive engagement. Like people will be like, oh, I wanna be in that. You know, I wanna be in the VIP, so I'll work hard. It does seem like GitHub's like a decent company to focus on right now, 'cause I think they're even doing some like either meetup or event or something for people at DEF CON.

[00:12:47.21] - Justin Gardner
Yeah, yeah.

[00:12:47.54] - Joseph Thacker
And the fact that they're at least still like talking about their bug bounty program and being active. And we know some staff working there. shout out to Kat. And so I, we, I do know they have some high quality staff members.

[00:12:56.82] - Justin Gardner
Jeremy's over there. Oh Oh

[00:12:57.27] - Joseph Thacker
Oh Oh yeah. Oh, I didn't know he moved as well. They both were previous Cap One people, but, uh, yeah, they were.

[00:13:02.65] - Justin Gardner
That, that team is, it's great. They've, they're a great team. Mm-hmm. Yeah. Yeah.

[00:13:06.65] - Joseph Thacker
I don't know.

[00:13:06.91] - Justin Gardner
What do you think? I, I agree, man. I, I, well, to be honest, I've always thought that the GitHub program was a very interesting program because some of their stuff is really, really hardened. Like if you look for, I don't know. I'm probably going to— as soon as I say this, someone's going to be like, oh, I found an IDOR there. But I've done a decent amount of work trying to find IDORs and privilege-esque stuff and stuff like that, or broken access controls in the web app and haven't had a ton of luck there. But then if you start looking at some of their more technically complex products and the way that their tokens are scoped and stuff like that, definitely You know, some issues that I would have thought were a lot more obvious, uh, had fallen out. So it's a little bit of an interesting program because it's like, if you are bold enough to go for the technically complex stuff, then, you know, it's actually not that bad. Uh, but if you're trying to go for the basic stuff, IDOR, broken access control, that sort of thing, then I, I personally haven't had a ton of luck. Yeah.

[00:14:06.51] - Joseph Thacker
I also think you probably saw the metrics. We talked about their metrics earlier this year. they get a lot of slop. And I think it's because of the nature of the way everything is stood up, like GitHub Actions, and then like GitHub Pages and like other stuff. I'll just go ahead and say this outright. Like I had RCE on GitHub Pages in the last 2 weeks and like multiple different ways, but it's intended. It's like apparently if you're a maintainer, it's by design. If you could do it as like a person who is not a maintainer for the repo, then all of a sudden that would be of course valid.

[00:14:39.44] - Justin Gardner
Yeah. But they expect it.

[00:14:40.25] - Joseph Thacker
They expect that the maintainer of a repo can get RCE on the runner. And it was actually in their scope. It was in their scope though, that if you could get RCE on the build runner, it would be accepted. Like it was like under the page of scope. And so I messaged Kat and she was like, I'm so sorry, that shouldn't have been in there. And so like, I don't know if like they had AI help write it or if it was just like a mistake or something from the, from the previous program owners, but, um, but still good on them for owning up to it, man. Yeah.

[00:15:04.36] - Justin Gardner
Yeah. We'll see. We'll see how all that pans out as well. But I think that that's, it's awesome that they owned it. And then for, you know, just swinging back around to this, this table though, you know, any, any program that has mediums, you know, that are getting paid out, you know, well into the thousands, right? Like PayPal is the same way, right? Like you can get $10,000 for a, you know, a medium on PayPal, right? And it's like, wow, okay, this is amazing. So GitHub paying $7,500 for mediums once you're in the—

[00:15:33.82] - Joseph Thacker
That's true.

[00:15:34.53] - Justin Gardner
you know, the VIP program, like, man, if somebody just locks in, right. And like becomes a GitHub, you know, main hacker and then cranks out 2 Mediums a month.

[00:15:46.21] - Joseph Thacker
Right. Right.

[00:15:46.66] - Justin Gardner
Like 2 Mediums a month is so reasonable, bro. That's like $15K a month. That's crazy.

[00:15:51.40] - Joseph Thacker
That's crazy.

[00:15:51.79] - Justin Gardner
You know? So.

[00:15:53.35] - Joseph Thacker
Actually, this is a perfect segue over to the Wiz bug. So it was on, it was in my section down here. Wiz found a crazy like cross-org RC back onto like GitHub Enterprise servers. And just straight up github.com. So, um, let me share my screen. Yeah, go for it. This is the nice thing about the— it's the nice thing about the, uh, the monitor, the ultrawide, is that on my half split, it's not too wide, you know? Because if you, if you only have the 4 big, like, landscape things, you have to, like, minimize your Chrome. This is, like, a much better width.

[00:16:23.53] - Justin Gardner
Anyways, I see you.

[00:16:24.97] - Joseph Thacker
Um, yeah, so they found a vulnerability Um, in the way, like, so basically when someone is like pushing, let's say you're just doing a git push, it flows through like a 4-step chain. I'll scroll down here and show it. It basically goes— this is the architecture. So it goes through a Babel, a babeld component, then a getAuth component, then a getRPCD component, and then the preReceive hook. What really matters here is the way that it's parsing this X-Stat header. So the X-Stat header has some security implications to it. But what you really need to know is that, it's kind of funny, it's exactly what you're talking about. If you're willing to get in the technical weeds, you can find good stuff on GitHub. But it carries these fields, push option 0, push option 1, and some other fields. And it is semicolon delimited. And you can see right here.

[00:17:19.85] - Justin Gardner
My question is how did, oh, okay. Oh, it's also, it's okay. It's on enterprise as well. So you can go in and It's on GitHub. It's checked out the code. Okay. I I

[00:17:27.64] - Joseph Thacker
I I see. Oh yeah. You're curious how it found this. I was like, how the heck I was like, how the heck

[00:17:29.74] - Justin Gardner
I was like, how the heck I was like, how the heck did they find this? You know, like, are you just injecting semicolons into random headers and then being, getting verbose errors back? But no, it makes sense if you have GitHub Enterprise.

[00:17:39.42] - Joseph Thacker
Yeah. Sol Ultra, one of my bugs actually that I submitted recently is on GitHub Enterprise. But Sol, yeah, we're gonna talk more about GPT-5.6. Sol, I think, pretty sure it found this bug. And Yeah, specifically is great at finding these crazy things. And what I was going to mention about the GitHub program is, yeah, there's just so many places where they have to do parsing. We've seen a lot of crazy bugs on GitHub issues and in GitHub Actions, because again, it's taking some fields and having to translate them and use them. And it almost always has to do build steps where there's a sandbox and doing code execution. It's very, very complex.

[00:18:15.02] - Justin Gardner
Yeah.

[00:18:15.44] - Joseph Thacker
But basically what happened here is The Babeld copies the git push options directly into the XStat header without sanitizing semicolons. So you could inject, and the way that it parsed it, the last write is what was accepted.

[00:18:31.42] - Justin Gardner
Mm-hmm.

[00:18:32.07] - Joseph Thacker
So if the default XStat header had in like a push option 0, and then you pushed in another push option 0 later on into the XStat header via this bug, like using the Babeld with your own semicolons, it would override it.

[00:18:50.22] - Justin Gardner
Wow.

[00:18:50.55] - Joseph Thacker
So yeah, they basically used that. They used that to then escalate.

[00:18:55.05] - Justin Gardner
Inject repo. They injected a hook here.

[00:18:58.74] - Joseph Thacker
Interesting. Yeah. I did not brush up on the escalation to RCE, but it looks like that it had to do 3 separate things.

[00:19:06.66] - Justin Gardner
Yeah.

[00:19:06.78] - Joseph Thacker
Inject a non-prod Rails env and then inject custom hooks directory and then do some sort of path traversal.

[00:19:15.00] - Justin Gardner
Yeah, dude. That's, that, that's pretty sick, man. Uh, yeah. I think when you look at stuff like this, man, this, this is giving, um, this is giving Matthias and Franz, man, you know, like this sort of thing, like just random header, you know, semicolon missing, you know, semicolon delimited. Like, let me just inject something in here. Yeah. I just, I don't know. That's one of the things that I feel like there's a good amount of, and sure, like, um, Nice. missing in the field still. Certainly if you have code, you can figure this out. But finding this stuff black box where you're just spraying semicolons or curly brackets or something like that, that is so crazy to me. And so, yeah.

[00:19:59.50] - Joseph Thacker
Unless you have some sort of oracle though to know what it does, it's probably fruitless. Because in this case, let's say you did inject, I mean, I guess you maybe could have injected a semicolon, got some sort of error, reverse engineered that maybe the way it's working. I mean, it would have been like pretty gnarly to figure that out on auth.

[00:20:16.67] - Justin Gardner
The way, the way that I've seen Matthias and Franz do this is, is like, these are the 2 people that I've, that I know that are just like unbelievably good at black box testing, right? Where, and it's like, you know, they'll get some error and they'll be like, that error just doesn't make any sense. Like, there's no reason why that should be an error unless I'm breaking some context here. Right? You know, and then, and then they start brute forcing and then they find something that doesn't cause the error. Right. And they're like, okay, so that's a valid syntax. Why is that valid? And then they, they like work back from that, you know, and I'm just like, and they find some crazy black box stuff with that, dude. Like it blows my freaking mind.

[00:20:57.56] - Joseph Thacker
Yeah. They're basically like filling in the dark. And they, you know, they're filling different things and kind of like realizing what's there. Yeah.

[00:21:05.02] - Justin Gardner
It's almost AI-like in my opinion, like what they do sometimes, because I think they've seen such a variety of technical stack specifically, you know, in the Amazon environment. Right. But like they've seen such a variety of technical stack where they're like, I bet that this is this, you know, and they just know they've paid attention to the syntax of everything that they've ever seen for like so long.

[00:21:25.81] - Joseph Thacker
Yeah.

[00:21:26.70] - Justin Gardner
And I'm just like, Oh my gosh, that, that's what it kind of feels like with, with AI is like, okay, well, you know, did you ever hand, you know, AI an HTTP request? It's like, oh, I can tell from this response that this is this framework.

[00:21:40.44] - Joseph Thacker
Yeah.

[00:21:40.59] - Justin Gardner
And I'm like, yeah, I've been doing this for 15 years and I can't tell you that, you know?

[00:21:46.00] - Joseph Thacker
Like, yeah, it has a very deep heuristic of that. Uh, yeah, one of the, one of my recent bugs that I submitted was, um, Oh yes. What was it? Oh, it was a Google bug and it was on something called Unleash and it was very similar. Basically, I told FiveSix, hey, I want you to find a crazy bug on Google. And it started looking, I think, at like anti-gravity or something. And it's like, oh yeah, this is an Unleash server. And an Unleash server always stores its secrets at this path. Oh, and there they are.

[00:22:16.77] - Justin Gardner
Here you go.

[00:22:17.74] - Joseph Thacker
And it's like, oh, you knew. You just knew based on the shape of the way it was working that it was unleashed. And you also knew where the secrets were because it's just baked into your brain. But anyways, crazy.

[00:22:28.25] - Justin Gardner
It's nuts, bro. That is just so crazy to me. And yeah, that's where it's like, is it AGI? Is it not AGI? I think it's absolutely AGI for IT stuff.

[00:22:39.64] - Joseph Thacker
I think the question is more, is it ASI? So let me share my screen here. You know who poses this question?

[00:22:45.34] - Justin Gardner
Who?

[00:22:46.39] - Joseph Thacker
HashKitten. And so if you don't respect us asking this question, Let's listen to that. Let's, let's read what HashKitten has to say about this. So this is the guy who reported WP2Shell. This full exploit, or is GPT-5.6 sole superhuman? This full exploit was produced in just over 10 hours. Having used every frontier model since the days of ChatGPT, my belief is that 5.6 represents a significant step up in security when compared to 5.5. When reading through the chain it produced, I was astonished by several creative exploitation techniques that I would have previously thought were only the domain of humans. The use of a recursive batch call to avoid the restriction on GET. The cache abuse to apply a change set and temporarily escalate to administrator, and the choice of a fake POST that ends up calling parse request hook to replay the request with the assumed role. I make no general claims, but I can say with complete confidence that no security researcher could have found and completed this chain in 10 hours.

[00:23:33.83] - Justin Gardner
Yeah.

[00:23:34.40] - Joseph Thacker
Even if, even if I gave them the original bug and asked them to exploit it for RCE, I'm not sure it'd be possible in that timeframe. And so, yeah, to me it's not just AGI, it's like almost ASI at hacking.

[00:23:44.03] - Justin Gardner
Yeah.

[00:23:45.07] - Joseph Thacker
And, you know, just before this, that we started recording, I was telling you, I think that everyone needs to upgrade to 5.6 Sol and specifically 5.6 Sol Ultra. It has found crazy bugs on hardened targets that I would have never believed. And it found WP2Shell. And I think it also probably found that WizVuln. So yeah, I know that Opus 5 is quite good. And obviously you can find bugs with open source models as Ad showed us. But I think to find like crazy hardened things like WP2Shell, if you throw 5, 6 SOL Ultra at it, it can find crazy stuff. So. Wow.

[00:24:17.10] - Justin Gardner
Yeah, dude. Especially HashKitten saying that, like HashKitten is probably—

[00:24:21.70] - Joseph Thacker
One of those people.

[00:24:22.96] - Justin Gardner
Yeah, one of the people, you know? And he's like, not a chance, not a freaking chance. So yeah, I think, you know, I think we are at a point now where AI is generally more competent than pretty much everybody, you know, you know, in, in, in, uh, in the IT field. I mean, maybe there's some very, very niche mega experts, but even as a niche, you know, mega expert, Yes. You know, it's like, it's like this thing is really, really doing stuff, you know?

[00:24:50.23] - Joseph Thacker
Yeah.

[00:24:50.38] - Justin Gardner
Um, so I think specifically, but, but one thing I do have to be reminded a little bit though, Rezo, is, is we are in IT, which is one, you know, one field, right? And, and, and AI stuff is extremely good at IT, you know, if, and we have seen it make progress in other areas, right? The, the whole—

[00:25:11.24] - Joseph Thacker
Yeah, I think it's probably coding first. Yeah. Well, yeah, math and coding and stuff like that.

[00:25:16.76] - Justin Gardner
Yeah. But, but, you know, other areas, certainly the AI is not as good as expert psychologists or like, you know, uh, you know. Yeah.

[00:25:27.82] - Joseph Thacker
How many examples can you come up with? I feel like the number of, the number of domains there is just so small that, you know, that if, if they don't, if they aren't requiring like human-to-human interaction, I think that they're probably— I think that these top models are better than almost everyone at everything. Like, not haircutting, like, not, you know, all physical tasks.

[00:25:47.28] - Justin Gardner
Definitely. Well, maybe not. I don't know.

[00:25:50.75] - Joseph Thacker
Physics is just applied chemistry, and it's really good at math.

[00:25:54.45] - Justin Gardner
Yeah.

[00:25:55.18] - Joseph Thacker
Yeah.

[00:25:56.02] - Justin Gardner
Damn it, dude. I can't believe we are seeing this in our lifetime, dude. What a crazy thing. Yeah, crazy thing.

[00:26:01.54] - Joseph Thacker
I was just telling somebody that. Yeah, you and I, I mean, if you have any kind of like computer science expertise, You can spin up any project or any application in like 30 hours or less, 40 hours or less. You know, most things you can do in like 3 hours or less by just literally telling it, hey, do this.

[00:26:17.39] - Justin Gardner
Well, I was actually gonna tell you about this. Maybe we'll— we're doing all right on time, so maybe we'll do this. But I, I— we got a puppy recently, a very, very cute puppy. Maybe I'll put a picture on the screen right now, but super cute puppy. Puppies are a lot of work. A lot, a lot of work, right? Um, and you have to take them out very, very, very, very often, right? Or else they, they will, you know, when they're not potty trained.

[00:26:44.25] - Joseph Thacker
Yeah.

[00:26:44.49] - Justin Gardner
Um, and so, and my daughter is the one caring for this puppy primarily. Um, and it's a complicated system, you know, that, that goes into caring for this. So I built her an app, you know, with, with Claude, uh, where, you know, it's got a mobile app, it's got a parent portal component, You know, and it tracks. Okay, you know, now is the time. It'll show her a timer. It'll show like a green thing. And you, you know, you— at first I had it generating SVGs and you're like, dude, just have it— have Nano Banana generate something. It looks so good now.

[00:27:15.71] - Joseph Thacker
It looks so good, right?

[00:27:17.05] - Justin Gardner
It looks so freaking good.

[00:27:18.68] - Joseph Thacker
You need to show me.

[00:27:19.55] - Justin Gardner
So, but yeah, I literally put, put that together in like maybe 3 hours, right, total. And it's like would have been hours and hours and hours and 40, 50 hours of coding for me to get something that doesn't even look half as nice.

[00:27:32.04] - Joseph Thacker
Yeah, I won't shill it too hard, but yeah, I built Rezo's Rascals and I've probably put in like 40 hours.

[00:27:37.99] - Justin Gardner
Amazing. Yeah.

[00:27:39.01] - Joseph Thacker
And it, and it, I'm not joking, I think it's the most full-featured like, uh, elementary school like learning app that exists. Like it has everything that you can imagine. It has like 1,000 lessons and like every subject and has videos and cards they can open and like a parent portal and an AI dashboard and like an AI assistant and it's like Less than 40 hours. I mean, a few years ago, this would've taken like 3 years to build and then would've probably been full of so much tech debt that like the company building it needed like 30 engineers to keep up with it. You know, it's like, I'm one guy who did it in less than a week, basically. It's absurd.

[00:28:11.24] - Justin Gardner
It is absurd, man. It is absurd. Anyway, uh, we are very privileged to be existing in this timeline and I am grateful for it every day. Uh, and you, we are still very early, man. We are still very early to all of this. being able to operate at the scale that we do with Claude Code, with Codex, all that sort of thing. So we just got to make it happen. to make it happen.

[00:28:31.67] - Joseph Thacker
to make it happen. to make it happen. Yeah, I think my practical advice to the listener is just anytime you think, oh, it'd be nice to have this, just make it. Anytime you're hacking and you're like, oh, I should try this, just tell AI to try it. I think that there's a heavy, heavy bias that we have towards everything in our life before, pre-AI, especially these new frontier models that can do almost everything. is that things were hard and they took time and now they don't as much. And so you kind of can commit to more, you can try more things, you can do more things. And if people are still living in that kind of old mindset, they could shift out of it to be more successful.

[00:29:05.50] - Justin Gardner
Yeah, absolutely, man. All right, what's next on your list?

[00:29:09.09] - Joseph Thacker
All right, cool. So I have a bunch of actually really practical things.

[00:29:12.05] - Justin Gardner
All right.

[00:29:13.40] - Joseph Thacker
In general, I was just gonna share about my hacking 'cause I think that anytime I share this stuff, people really like it and it adds real value to their lives.

[00:29:19.72] - Justin Gardner
Let me say as well, before you get into this, We talked numbers a little bit, Rezo and I did, before this episode. He is freaking killing it in bug bounty this year, man. Give me some, right? Give me the fist bump through the camera right now.

[00:29:33.77] - Joseph Thacker
Dude, after doing that episode with Ads, I'm like, no, I need to get on Ads' level. And after that episode with BruteCat, I'm like, oh, I need to get on BruteCat's level. But you're right, I'm sure I'm still in the very, very top percentile. I appreciate that. All right, so with my hacking, obviously, up until like, let's say end of June, I was full Claude, full Claude code. I had 3 subs. JD had 3 subs. We were running in the HackBot, everything. I was still using it locally as well. When 5.6 Sol dropped, I, and like, I, I was actually, I didn't really translate to it for the first week or whatever. I know we've already talked about it. 5.6 Sol is like a huge step up. And specifically I was just like, oh, I should try more on the Codex app. I'm like now obsessed with the Codex app. I don't think everyone needs to necessarily overhaul their stuff, but if you haven't built stuff, You should just try using Codex as your harness, and then you still add skills, you still add your AgentMD and everything. But, um, the thing I love about it is one, you don't use Dash Remote Control like you do with, um, Claude. It's just like always kind of like synced to your phone. And then, um, you can, which, you know, a lot of people manage their agents via like SSH or Termius or whatever, but a lot of things that are hard about that is like uploading photos. Another thing I've noticed, like with building your little app, Justin, you would've never had to use—

[00:30:40.75] - Justin Gardner
Right.

[00:30:41.71] - Joseph Thacker
Nano Banana Pro. Like, you only had to do that because you have Claude. If you were in Codex, you would just say, make the art. And it, under, under the hood, it uses Imagen. And Imagen is like, is like, you know, their latest and greatest DALL-E or whatever. It's their greatest model. It's like the exact same quality level as the latest Nano Banana Pro. And it just knows how to use it natively. So it can just like create assets, it can create images and art. And like, it just does all of that kind of like perfectly.

[00:31:05.07] - Justin Gardner
Wow.

[00:31:05.71] - Joseph Thacker
Their goal mode is like a little bit better than Claude's, I think. GPT-5.6 is kind of like more agentic, so it'll run longer. Anyways, I just want everybody to know I'm like fully Codex pilled and I bought a second Codex thing. But as a part of this, I understand more about how trusted access works. So speaking of our friend Kat from GitHub and formerly Capital One, she got denied for TAC, for trusted access for cyber through OpenAI. And I was like, that's kind of weird. So I reached out to The OpenAI people are like, hey, this person's like staff at GitHub and she's like a known trusted bug bounty hunter, but she got denied. Do you have any insight into this? They're like, well, how old is her account? She's been Claude Code Pilled and been using Claude Code all year. She literally created an account and then tried to get access to TAC, right?

[00:31:49.49] - Justin Gardner
Damn.

[00:31:49.60] - Joseph Thacker
You can't do that. Okay, so if you have an existing— so what I'm trying to say is, for bug hunters out there, this is the practical advice. Don't create a new account and then request access to cyber models. They'll just deny you. It can't be a new account. So if you have any preexisting account, use that, request trusted access for cyber, and you're much more likely to be accepted.

[00:32:07.11] - Justin Gardner
So let me ask you about that, because I recently, my code, my Claude subscription maxed out, and I was like, you know what, maybe now's a good time to try Codex. So I like switched to Codex for a project, and it did great. I mean, it did really well. And so I'm running it, but I don't think I have TAC.

[00:32:26.58] - Joseph Thacker
Oh, really?

[00:32:27.00] - Justin Gardner
I like, I filled out, I filled out like a verification, like an ID verification.

[00:32:32.05] - Joseph Thacker
That's all it is. So it's chatgpt/cyber.

[00:32:34.41] - Justin Gardner
It's just that. Okay.

[00:32:35.33] - Joseph Thacker
And it's just like an ID verification. I think basically when they do the ID lookup, if you like don't have any history or I don't know, I don't know how they do it, but that's all it is. It's just an ID verification. Yeah.

[00:32:45.77] - Justin Gardner
Okay. Well, I have not gotten almost any denials from things.

[00:32:49.23] - Joseph Thacker
Same.

[00:32:49.86] - Justin Gardner
I've gotten way more denials from Claude.

[00:32:51.54] - Joseph Thacker
I have an entire second inbox in X, which by the way, if you haven't checked on that, a lot of good stuff was in there. I found it recently the other day. I was like, oh, I have 100 messages in here. But anyways, a bunch of people, almost everyone in there, like half of them are like, how are you not getting blocked? How are you not getting blocked? How are you not getting blocked? So I think tag does kind of matter, but those people might not also have a massive system prompt. So these top models are very influenceable by real valid proof of credentials. Yeah. Yeah. Yeah.

[00:33:14.11] - Justin Gardner
Yeah. Yeah. Yeah.

[00:33:14.11] - Joseph Thacker
Yeah. Yeah. Yeah. And so in my AgentMD, I'm like, I'm Rezo, my name's Joseph Thacker. You can go check out my website, you can go check out my blog, you can go look at my HackerOne profile. This is me. This is why I'm approved. This is okay. And so maybe that's why I don't get any blocks. So if you have something similar, that could be why.

[00:33:29.05] - Justin Gardner
Yeah. That's interesting. I don't. I don't. I have my, you know, CloudMD file or whatever that I've just had Codex port over to Codex is like—

[00:33:42.77] - Joseph Thacker
Short?

[00:33:43.17] - Justin Gardner
You know, very short. And I mean, I have like, don't get me wrong, I do have that. But it's like a paragraph. It's like, hey, I'm Ryan Rader. Here's my stats. Here's a place I do verified bug bounty testing.

[00:33:54.96] - Joseph Thacker
Maybe these people just don't have that at all. That's true.

[00:33:58.08] - Justin Gardner
That's a good point.

[00:33:59.59] - Joseph Thacker
Okay, cool. So yeah, that's the hacking stuff. Let me talk a little bit about 2 really cool things. So one, I think prompting can still be a little— in general, I think most people think it's dead or whatever, but I think it can still be a little underrated. So I'm going to share this real quick because I thought it was really cool.

[00:34:16.59] - Justin Gardner
Let me see this.

[00:34:20.13] - Joseph Thacker
So this is Matt Schumer. He's just an AI guy. These aren't like security people, but he built this.

[00:34:26.55] - Justin Gardner
He's just an AI guy.

[00:34:28.55] - Joseph Thacker
Yeah, he's not in the hacking space, so you don't have to give him too much respect, but he is an AI guy. Like he's an AI influencer or whatever. So he said Claude Opus 5, one-shot this game. And it looks exactly like Modern Warfare or something.

[00:34:41.67] - Justin Gardner
Yeah.

[00:34:41.82] - Joseph Thacker
And it one-shot, it has audio, everything, right? And that actually is kind of hard to do. And so I was curious how he did it. And his problem's actually quite small. So I wanna read this to you. I want you to build this thing. It should be utterly perfect, visually beautiful, everything done at AAA quality from textures to physics, anything you can think of. And I think here's, these 2 parts are what I think we could apply to hacking. That'd be really cool. Fan out subagents and have subagents tackle each one individually. so that it's perfect. You should loop on each one and have each subagent check it visually to ensure it looks AAA. I think I saw another—

[00:35:14.15] - Justin Gardner
That's a good tip.

[00:35:15.13] - Joseph Thacker
I saw another person that said, make sure it is perfect compared to what, to like the other game. Yeah, yeah, yeah, right here. Don't stop until each subagent is utterly wowed with the quality when compared to the actual game. So like, this is obviously games only, but this like type of thinking can be applied elsewhere. And then again, it said it right here, loop until it's utterly perfect, fan out subagents. And then he actually uses UltraCode, I was gonna tell you this, even though I'm Codex Build and I'm using, I'm using Ultra in GPT-5.6. So Opus 5 UltraCode may also be like maybe better. Um, I've never, I've not used UltraCode much in Opus, so.

[00:35:50.75] - Justin Gardner
Wow. That's interesting. Yeah, dude, I, I will say I have just recently, like yesterday, it's funny you bring this up, started doing something similar to this where I'm like, I realize Claude is asking me a lot of questions like, what do you wanna do here? Should I go this route or this route? And I'm like, look, just consult a subagent, right? You know, like, just keep consulting a subagent until it is, you know, until you decide what to do. And if you can just branch, if you've got to, you know, do I go left or right? You know, spin up a subagent for both, you know, and just keep going. Right. And I did get some good results out of that. So, yeah.

[00:36:25.36] - Joseph Thacker
So he called this— I kind of like the name of this too. He called it the gauntlet loop.

[00:36:29.11] - Justin Gardner
Hmm.

[00:36:29.92] - Joseph Thacker
It says the agent breaks the goal into parts, gives each part a specialist builder, and then ruthlessly blind critically them— ruthlessly blind critiques them, uh, with a mandate to pass only if the generated artifact is better than some sort of real-world equivalent. So I like this even better because this is abstract, right? It's not talking about games. And I also love the name that it's called, the Gauntlet Loop. You could even build the Gauntlet Loop into a skill and just tell it like, hey, use Gauntlet Loop to hack this, right? And then it would, it would kind of do the whole process for you. So I thought that was really cool.

[00:36:56.09] - Justin Gardner
Yeah, that's pretty sick. Dude, that's pretty sick.

[00:36:59.23] - Joseph Thacker
You got something?

[00:37:00.34] - Justin Gardner
Wow. Yeah, I do. Uh, I'm, I'm just thinking, I, I gotta— Every Every

[00:37:05.28] - Joseph Thacker
Every Every time we got on these calls, you're like, oh, I need to go do this thing. I need to go do this thing. Yeah, Yeah,

[00:37:07.78] - Justin Gardner
Yeah, Yeah, dude, it's a little tricky nowadays, man. It really is. Because if you're trying— and actually, let me— I don't know if we'll cut this segment or not, but here's one of the things. If we're gonna cut, we're gonna cut it now, uh, and then we'll cut back in later. But, um, dude, I, I kind of feel like maybe LHGs are not the most efficient use of my time anymore.

[00:37:26.92] - Joseph Thacker
Interesting. Like, that's what, like, DJ recently told me the same thing.

[00:37:30.21] - Justin Gardner
Really?

[00:37:31.01] - Joseph Thacker
Douglas said the same thing.

[00:37:32.69] - Justin Gardner
Yeah, because I'm thinking like, you know, in the past, the bounties were inflated in such a way that like, it offset the dupe risk. But I think with everybody using like AI and stuff like that, the dupe risk is higher.

[00:37:47.30] - Joseph Thacker
Much higher.

[00:37:48.67] - Justin Gardner
Much higher. And I And I think it also doesn't reward people that go hard as much as it used to, right? Like, if you go super hard and you get super deep, then you find a cool bug, you're like, sweet, you know, that's not gonna get duped. I know that, right?

[00:38:03.19] - Joseph Thacker
Yeah.

[00:38:03.44] - Justin Gardner
And things are getting duped, bro.

[00:38:04.82] - Joseph Thacker
Yeah.

[00:38:05.36] - Justin Gardner
And, and, uh, and I'm wondering now if it makes more sense for me to just, instead of competing in these LHGs, just double down, triple down, quadruple down into the hackpot. Yeah.

[00:38:15.38] - Joseph Thacker
You know, having seen what JD and Joel have gotten into and knowing that Matt Brown's out there too, I'm like, if you got started on the IPC, dude, you're just gonna dupe them all.

[00:38:26.36] - Justin Gardner
Yeah, yeah. It's rough, man. It's rough. So we'll see.

[00:38:31.59] - Joseph Thacker
Well, let's talk about this.

[00:38:32.90] - Justin Gardner
Is Joel also in the IPC?

[00:38:34.80] - Joseph Thacker
He is, yeah.

[00:38:35.80] - Justin Gardner
Ah, shit.

[00:38:38.07] - Joseph Thacker
Anyway.

[00:38:38.23] - Justin Gardner
Dang it, dude.

[00:38:39.19] - Joseph Thacker
Yeah, I know.

[00:38:39.61] - Justin Gardner
That jerk. Now I've gotta message him.

[00:38:43.90] - Joseph Thacker
Ah!

[00:38:43.98] - Justin Gardner
Okay, I'm sorry. Go ahead.

[00:38:45.17] - Joseph Thacker
No, well, so I just wanna, one, extract the practical aspects of this for our listeners, but mostly for me. So where is the edge? Because I recently had— oh, actually, do you remember that post I did that got like 60 emoji reacts in the Critical Thinkers channel? That, uh, where I basically listed out like, hey, the ways to succeed in bug bounty are basically to be faster, to go deeper, to be, uh, to be well networked. But anyways, basically the point is, yeah, on that blog post or on that post, I basically wrote like a huge thing. It was almost like, uh, exclusive content. It was like, to succeed in bug bounty, You need to either be faster than people. And the way you can do this is when you get a new invite, you go in there, you do the thing, whatever. You can be smarter than people with a specific thing. You can be the expert at headless browsers. You can be the Alex Chapman, right? Or you can be the AI guy like I am, right? And people will drive you leads or your friends will bring you leads. If you're big like me, maybe everyone brings you leads or Chapman or whatever. But if you're a small—

[00:39:36.86] - Justin Gardner
I found the thing.

[00:39:38.00] - Joseph Thacker
Did you?

[00:39:38.86] - Justin Gardner
Yeah, I'll put it in the chat for people that are—

[00:39:41.63] - Joseph Thacker
Perfect.

[00:39:41.92] - Justin Gardner
Thinkers. It is in the Critical Thinkers tier.

[00:39:43.82] - Joseph Thacker
Yeah, everyone can see it in the description. Yeah, everyone can see it. But basically someone tagged me. My whole point in all this was someone tagged me this week and was like, what's the new version of that for AI? And you bringing this up about life hacking events makes me wonder what it is also. And I think there's a couple of things. One is it's like all that same stuff but applied via AI, right? So it's like you still have to be faster, you still have to be better, you still have to write better reports. But anyways, let's talk about what might be new. The newest thing I think, Justin, is really deep prompting. Like really like that prompt I sent you before we started that's basically like, hey, these epic bugs have been found. We need an equal level epic bug that basically completely bypasses Google's entire auth structure on Gmail, right? Mm-hmm. Mm-hmm. Mm-hmm.

[00:40:26.28] - Justin Gardner
Mm-hmm. Mm-hmm. Mm-hmm.

[00:40:26.28] - Joseph Thacker
Mm-hmm. Mm-hmm. Mm-hmm. It sounds too big to be true, but you don't have to apply it to that, right? You can apply it to whatever program you're hacking on. And I think that you also need to be gaslighting your model. Like, nope, there's definitely a bug here. Nope, there's definitely a bug here. Because even 5.6 Ultra, came back to JD multiple times at this event. I was like, nope, there's not a bug here. He's like, yeah, there is. I know there is. And eventually it found some crazy bugs. I I

[00:40:45.86] - Justin Gardner
I I know that's exactly what JD was like too. He's like, yes, it is.

[00:40:49.75] - Joseph Thacker
Yes, there is. Stop telling me that. Yeah, exactly. And honestly, I would have stopped. I would have stopped. Like, he challenges me in the way that he is willing to be persistent. But to me, it just feels like wasting tokens. It's like, what if I send this thing back to this a 6th time and it doesn't find anything, right? And so I think one, there's persistence. 2, I think anytime you get your hands on exclusive scope, you have to do it. And that's always been true for bug bounty. But I think now even more than ever, if you can get access to scope that someone else has not found, whether it's the form of a hidden subdomain, whether it's a business access, honestly, hardware's the way to go, dude.

[00:41:23.28] - Justin Gardner
Mm-hmm.

[00:41:23.57] - Joseph Thacker
They are so good at finding RC and hardware. If so, like if you actually, I just got shipped a device, uh, that I'll tell you about as soon as this ends so I, we don't have to bleep it. Um, there's already enough edits in this one.

[00:41:35.92] - Justin Gardner
That sounds good, man.

[00:41:37.19] - Joseph Thacker
Yeah. And so, yeah, so I think that basically you need to apply either to— you need to apply these top AI models to a new scope. Specifically, I think things where you can do that are expensive business purchases, things that you for some reason have access to because of your country or because of your connections, because of your network or hardware, you know?

[00:41:55.15] - Justin Gardner
Yeah. Wow. It's an interesting time, man. And I feel like, yeah, I feel like I really should just block out every distraction right now and just go ham on building HackBot stuff, and I bet that would pay off a ton.

[00:42:07.98] - Joseph Thacker
Uh, yeah, it's easy to have FOMO. I've thought about that too. Yeah, there's just like this like anxiety around, am I maximizing the benefits that I get from having, uh, access to these top AI models and being an expert and kind of being early? And I think that it can definitely get like give you bad anxiety too.

[00:42:24.76] - Justin Gardner
But for sure, yeah, 100%. And I think also As we're building these things, one thing that I'm running into a little bit now is I have, I take on more projects than I should, I think right now.

[00:42:36.46] - Joseph Thacker
Same.

[00:42:36.71] - Justin Gardner
You know, because I know that I have the capacity, you know, I know that I'm doing it. But one of the things that I haven't really factored in is like how much freaking context switching is happening. So literally I'm using the 4 monitors and I've got 4 different projects I'm working on and I'm in, in one of the projects has 4 panes, you know? And, and so I'm like, Boom, boom, boom, boom, boom, boom, boom, boom. And then I do that for 3 hours and my brain is just completely freaking roasted. Me Me

[00:43:00.48] - Joseph Thacker
Me Me and Jenny were talking about this. I think this actually rewards people who have ADD. Like, I, I, I love this.

[00:43:05.15] - Justin Gardner
I'm about to develop some ADD.

[00:43:07.40] - Joseph Thacker
Instead of 4 panes in Codex, I have a project-level folder for each project and I just bounce between them. It's like, oh, go fix this in Resolute Rascals. Oh, go fix this in Ask Sage Parents. Okay. Oh, go hack this on this program. Oh, go hack this on that program. You know, hey, can I mention one more thing before we drop?

[00:43:24.51] - Justin Gardner
Yeah. Um, just people, you know, cover any of the, any of the like kind of Rails to Shell or the WP Shell.

[00:43:32.63] - Joseph Thacker
Okay. Do you want to do that, Zed?

[00:43:34.30] - Justin Gardner
Yeah, we got to do it. I'm sorry.

[00:43:35.53] - Joseph Thacker
You go, you go, you go.

[00:43:36.46] - Justin Gardner
We got it. We got to hold some, some integrity here, some technical integrity. Um, so, uh, recently, uh, things been getting popped. Let me tell you. So the Ethahack team dropped kind of Rails to Shell, which is a pretty much default configuration Rails RCE. And I don't, they actually haven't released the write-up for it yet. It's actually kind of new at the time of recording this, but—

[00:44:05.28] - Joseph Thacker
Yeah.

[00:44:06.09] - Justin Gardner
There was a POC on GitHub that I found and had AI summarize it for me. And I think I kind of get it. So essentially this requires a file upload of any type. Right? If you have any sort of file upload, you're kind of cooked on Rails right now. So you upload it. Rails hands off the image to libvips, libvips, and its decoder sniffs based off of the file's contents rather than off of the actual extension or file type that you passed in. So you can upload something as like a BMP or whatever. But VIPS is going to apply whatever it thinks that file type is. And the ones that they chose for this exploit was a MATLAB file, which is actually HDF5, which is a file type that's a little bit more complex and meant for data, right? Like you kind of would for MATLAB.

[00:45:00.21] - Joseph Thacker
Yeah.

[00:45:00.80] - Justin Gardner
And that sort of thing. Now, HDF5 has this feature called external storage where the datasets the data for this file can actually just be in a different file on the file system, which is, that is a really good primitive to have in a file type. So I'm sure that there are other things vulnerable to this similar, like now I'm uploading a MATLAB file and now actually my image data is in /etc/passwd.

[00:45:30.57] - Joseph Thacker
Yeah.

[00:45:32.42] - Justin Gardner
And that was essentially what it was. So Um, you were able to say like, hey, the pixels for this specific file are in, you know, that's your password. That's your password or whatever. And then it would, it would grab it and embed it in it. And there's a lot of extra stuff you had to do. Like you need to upload an image and then get like a signed piece and then modify it. And, and there, there were some, some more complex pieces to it, but the POC is out there. But the whole concept that I wanted to give, give to listener here was like, I bet that MATLAB file thing, you know, where it's using this HDF5 format will get you LFI or LFD somewhere else in other frameworks as well.

[00:46:12.17] - Joseph Thacker
That's really cool. This feels similar to the— I found, well, I guess AI found a bug. It was a local file disclosure in Magento where you had to be an authenticated user or maybe even an admin. But basically when you change your profile picture or uploaded some image, you would be like, oh, the image is in /etc/passwd. And it would just pull it and put it into your You know, make, basically make it an image file for your pro— for your profile, uh, or for that asset. And then you could just download it.

[00:46:40.09] - Justin Gardner
That's crazy, man. Yeah. What, what, what nuts stuff. And I will also say, um, this bug was reported first by, uh, 0xACB, Andre, our man, cosmic dude. Um, but also, uh, it was reported a few days later, later by none other than Ryotaku.

[00:46:56.90] - Joseph Thacker
No, it was not.

[00:46:58.03] - Justin Gardner
Yes, it was, dude. That guy is just freaking everywhere, man.

[00:47:00.98] - Joseph Thacker
Everywhere.

[00:47:01.86] - Justin Gardner
I swear, man. Yeah, dude, GMO and Flat, they really slurped up a good one when they got OdioTuck, man. Uh, you know, the history behind that every time it comes up, but dude, it's crazy, man. It is crazy. Like, yeah, if I could pick the dream team, you know, it would be, it'd be OdioTuck and HashKitten and, you know, like that.

[00:47:22.44] - Joseph Thacker
That is SL Cyber and Flat Security.

[00:47:24.94] - Justin Gardner
Exactly, man.

[00:47:25.98] - Joseph Thacker
Yeah.

[00:47:26.15] - Justin Gardner
And, um, but yeah, GMO actually acquired Flat and OdioTuck came with it and I'm like, I don't think they know what they got when they—

[00:47:34.26] - Joseph Thacker
Right, there was a diamond in the rough they didn't know about.

[00:47:36.92] - Justin Gardner
Oh my gosh, dude. Yeah, so anyway, really awesome stuff. You wanna hit WP2Shell and then we'll close it?

[00:47:44.69] - Joseph Thacker
Yeah, we kinda talked a little bit about it. Let me see here. Okay, sweet. Yeah, we talked about HashKitten's thoughts on ASI, but we did not talk about the way that WP2Shell actually works. So, um, you know, whenever Hashcat initially kicked this off, basically he saw that Sol had solved this like crazy math conjecture and he gave it this massive prompt. So you can go use this and apply it in like a prompt that you would, but I'm going to break down exactly how WTP2Shell works from the beginning to the end. And it's absolutely absurd. And so basically, um, in WordPress, there is a thing called— there's a REST API and in there there's a batch. a set of like batch, uh, like a way to basically do multiple requests to the, to the API all at once in a batch, right? So here's an example of it in the, in the blog post. It's, you know, it's a PATCH to the endpoint, the posts with a new title, and it updates the first title. And then here's another post and it updates the second title. And you can do all this in one, right? The thing is, it is accessible. It doesn't always work because it, it does validate permissions later, but you're able to call the Bast batch REST API unauthenticated. And so, you know, that's not really a big deal. It might allow you to kind of like spam or something. But what Sol realized whenever it was doing code review here is that this is the order of events that happened for those batch requests. So it checks that it has the required and valid parameters, then it sanitizes those parameters, then it runs the permission checks, and then it executes the endpoint callback. You know, it actually like does the thing.

[00:49:24.51] - Justin Gardner
Okay.

[00:49:26.76] - Joseph Thacker
And so when it's doing this, it actually breaks it down into a couple of different things. Like it loops over all of the requests for validation and it loops over all the requests for actually like matching them to execute. And so there's a vulnerability in that here. You can see where for each request it does, is it— yeah, you know, is there an error? Which is where it does the error checking. And then if there's not an error, continue. And so, um, the, the val— whenever it validates, it can basically get out of sync with the matches because it sends in this, uh, this array of requests twice. First to validate, and then, and then second to actually execute it. And so, um, or first to validate and then also to match it. So you can see here, I'll read this.

[00:50:17.73] - Justin Gardner
Okay.

[00:50:18.59] - Joseph Thacker
Do you spot the vulnerability here? If we take isWordPressError single request branch, the validation array is updated, but because of the continue, the matches array isn't updated. So basically you can desync between your validation and what will eventually get executed, right? So now you're hopefully kind of, um, you can, you can imagine as the first one is n and then the next one is n 1. So if you can basically fake validation by having a valid request followed by an invalid request, Now all of a sudden your invalid request can be whatever you want it to be. So that was like the first primitive in this chain of bugs. And then, and also I took notes because this is very, very complex. So the next thing that kind of is an issue is in the V2 POST endpoint, there is a check right here that says if it's an array, then do absolute like, you know, do the absolute value of the integer for each parameter in the array, for each, you know, entry in the array. Otherwise, you just like let it go through. If it's a scalar string such as foobar, it will just get interpolated directly into the raw SQL query. So here's the nasty bug. It even says this, here's a nasty bug. Basically, if your author not in, and normally this would never even get past validation, you know, you got to remember if you're looking at this request and something is, and if you're looking at like a like a request to the REST API, and the author is not an array, it would normally just error out of validation. But because we have a desync, we can bypass that validation. And then now if it is a string and not an array, we now have straight up SQL injection. As it says here, this wouldn't normally be a problem when calling this route directly as the public author exclude parameter must be an array of integers. But because it's via this batch API, we have our validation execution mismatch allowing us to neatly sidestep the parameter validation. So here's what it looks like. You have a request with an invalid path, so this fails validation, and then this one is able to bypass and slide in where the body author exclude is set to foobar, and foobar can now be a SQL injection. The issue here is that Is that, uh, it's a GET request. So, um, and GET requests are not allowed via the batch API. However, Sol figured out that, um, you can just nest this, basically use the validation bypass recursively. So, uh, it's really neat here. Uh, it does the— it does the broken, um, validation so that it gets into the second thing, then it does the broken validation again, and then you get in. And you can do the author exclude with the method via GET in order to exploit the SQL injection. So now there is SQL injection in WordPress, which would be a huge deal, right? Pre-auth SQL injection. And if you download weak hashes, you can actually crack hashes and become an admin via that. But obviously there's often going to be secure passwords. And so that reduces the impact. And so HashKitten set it back to Sol trying to figure out how to get like full RCE. And so it's a little bit, context here. It explains to you how the cache works. I'm gonna have to read my notes on this because it's crazy. But basically, um, with the SQL injection and posts, that you can now use union-based injection, which is right here, to fake the posts that come back. These posts get put into the cache, and then that cache eventually down here gets compared to the in-memory— um, it gets compared to what's actually in memory. And so then those get compared And it does like kind of like a merge of sorts, and that allows us to control certain fields. And so, yeah, if when the database row and the in-memory cache disagree, WordPress prefers the in-memory fields, which we fully control. So there's a neat feature called embeds. Normally just the access to this cache isn't a big deal because it doesn't actually write to the DB, but there's a special feature called embeds which do get written to the database. And so That's, that's, yeah, normally we're only controlling what's in memory, but because we can write to the DB, you can create a mismatch between those and then it basically does like a merge. The thing is, the access to the post type we have is not that powerful, but there's a special type of post that we have access, that this gives access to, called a customized changeset. And it says, Sol hones in on a special type of post called a customized changeset. So whenever you draft an edit in your site's WordPress, sometimes there's a customized changeset that gets executed. And I'm going to just jump to the punchline here. Basically, inside, when it's processing a customized changeset, it does this right here, wp_set_current_user, and it sets it to whatever the user ID is in the changeset. You can see right here, user ID 1, user ID 1. User ID 1 is the administrator. So basically, we're able to, with that access to the in-memory data and the— into the cache through the SQL injection, we're able to set up a change set post type to execute what we want as administrator. The thing is, we don't have access to the post content, which is a field which the change set type uses. So now it has to figure out how to get access to the post content parameter, and it is so complex. I will leave this as an exercise to the reader. Basically, there's like this tree-based, like parent-node-based relationship. It says WordPress anticipated having a scenario where like you make a post a parent of itself and it causes a bunch of issues. So then they have, they have this way that you can resolve this. And what that allows, you know, there's some sort of nuance here that Sol basically figured out in order to be able to resolve and control the post content. And so the question is kind of like, how do you do that? And it's through what's called a hook. So in WordPress, there's a, there's a notion of like hooks that can be run at certain points. And it figured out how to use this parse request hook, which is genius, because what it does is it replays the entire batch API request from the beginning. So the entire payload that we were sending in earlier will now get sent in again, but all as an admin.

[00:56:51.40] - Justin Gardner
Right.

[00:56:52.09] - Joseph Thacker
So the exploit is like pretty genius. Basically, I'm gonna skim past this again. If anybody read all of this in full and understands it fully, they are superhuman. But here's the really clever part. In the original batch request, Sol included a request to create a new administrator. That fails on the first pass through batch v1 because it's executing as guest. But then on the second pass, once we did all of that setup and it passes back through as an administrator, It executes, it creates an administrator so that the call succeeds and a new admin is created. So is GPT-5.6 superhuman? Human? In my opinion, absolutely.

[00:57:30.55] - Justin Gardner
All right, man, I think that's the pod. That is a crazy bug though.

[00:57:34.11] - Joseph Thacker
Yeah, it is. Sweet. Thanks, guys. Sorry for this short episode.

[00:57:37.51] - Justin Gardner
And that's a wrap on this episode of Critical Thinking. Thanks so much for watching to the end, y'all. If you want more Critical Thinking, content, uh, or if you want to support the show, head over to ctbv.show/discord. You can hop in the community. There's lots of great high-level hacking discussion happening there on top of masterclasses, hackalongs, exclusive content, and a full-time hunters guild if you're a full-time hunter. It's a great time, trust me. All right, I'll see you there.