Interested in going full-time bug bounty? Check out our blueprint!

Videos

May 18, 2023

Source Review Part 2: Audit Code, Earn Bounties (Ep. 19)

In this episode of Critical Thinking - Bug Bounty Podcast we further discuss some tips and tricks for finding vulns once you’ve got source code and some banger tweets/tools that popped up in our feed this week. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting thing, so…

View more
May 11, 2023

Source Review: Audit Code, Earn Bounties (Ep. 18)

Episode 18: In this episode of Critical Thinking - Bug Bounty Podcast, we dive into everything source-code related: how to get source-code and what to do with it once you have. This episode is packed with great examples of successful source code review, tips on how to review code yourself,…

View more
May 4, 2023

Live Chat with Legendary Hackers in LA (Ep. 17)

In this episode of Critical Thinking - Bug Bounty Podcast we talk with five legendary hackers about some of their favorite bugs. Live. From LA. Corben Leo “Lorben CEO” @hacker_ https://twitter.com/hacker_ Sam “ZLZ” “ZOZL” “The King” Curry @samwcyo https://twitter.com/samwcyo Frans “The Legend” Rosen @fransrosen https://twitter.com/fransrosen Jonathan “Doc” Bouman @JonathanBouman https://twitter.com/JonathanBouman…

View more
April 20, 2023

The Hacker's Toolkit (Ep. 16)

In this episode of Critical Thinking, we talk about the hacker’s toolkit. Joel and Justin talk about their VPS setup, go-to hacking tools, most often used Linux commands, and the ways they duct tape all of these together for the big hacks. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new…

View more
April 13, 2023

Gal Nagli: The Israeli Million-Dollar Hacker (Ep. 15)

In this episode of Critical Thinking - Bug Bounty Podcast we talk with the latest Million-Dollar bug bounty hunter: @naglinagli . He talks about his climb from $1,000 in bounties to $1,000,000, recon tips and tricks, and some bug reports that made the news and landed him the "Best Bug"…

View more
April 6, 2023

Mobile Hacking: Dynamic Analysis using Frida (Ep. 14)

Episode 14: In this episode of Critical Thinking we talk about Dynamic Analysis within Mobile Hacking and a bunch of random hacker stuff. It's a good time. Enjoy the pod. Follow us on Twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting thing, so feel free to send us any feedback…

View more
March 30, 2023

Acropalypse Now (Ep. 13)

Episode 13: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to determine if a bug bounty program is good or not from the policy page. We also cover some news including Acropalypse, ZDI's Pwn2Own Competition, Node's Request library's SSRF Bypass, and a new scanning…

View more
March 23, 2023

Jason Haddix: From Hacker to CISO (Ep. 12)

In this episode of Critical Thinking - Bug Bounty Podcast we talk with Jason Haddix (aka jhaddix) about his eclectic hacking techniques, Hacker to Hacker CISO life, and some crazy vulns he found. This episode is chock full of awesome tips so give it a good listen! Follow us on…

View more
March 16, 2023

CV$$, Web Cache Deception, and SSTI (Ep. 11)

In this episode of Critical Thinking - Bug Bounty Podcast we talk about CVSS (the good, the bad, and the ugly), Web Cache Deception (an underrated vuln class) and a sick SSTI Joel and Fisher (https://twitter.com/Regala_) found. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting thing, so…

View more
March 9, 2023

The Life of a Full Time Bug Bounty Hunter (Ep. 10)

In this episode of Critical Thinking - Bug Bounty Podcast we talk about what its like to be a full-time bug bounty hunter, a tonne of bug bounty news, and some great report summaries from Justin’s two mentees: Kodai and Soma. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to…

View more
March 2, 2023

Headless Browser SSRF + NEW TOOL RELEASE! (Ep. 9)

Episode 9: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Headless Browser SSRf and drop a tool called RebindMultiA. Joel also walks us through a web3 bug and we cover some bug bounty news from the past week. As always, we drop some bug bounty…

View more
Feb. 22, 2023

PostMessage Exploits and CSS Injection (Ep. 8)

Episode 8: In this episode of Critical Thinking - Bug Bounty Podcast we drop some critical bugs which leak raw credit card info. We also discuss some CSS Injection & PostMessage related techniques. It's a short one but a good one! Don't miss it! Follow us on twitter at: @ctbbpodcast…

View more
Feb. 16, 2023

PortSwigger Top 10, TruffleSec Drama, and more (Ep. 7)

In this episode of Critical Thinking - Bug Bounty Podcast we talk about PortSwigger's Top 10 Web Hacking Techniques of 2022, some drama surrounding TruffleSecurity's XSS Hunter, and, as always, some great bug bounty tips. Sorry if the audio is a little rough around the edges this time, should be…

View more