For members-only perks and exclusive content, join our Discord server!

Videos

April 17, 2024

Breaking the auth flow using "?" to terminate the redirect URI!

Used a "?" before "@" to terminate an OAuth flow redirect URI, control the redirect location, and leak the oauth code.

View more
April 15, 2024

Hacking a Korean MMO for 3 MILLION DOLLARS worth of in-game purchases!

Sam Curry explains how he found a bug in a video game where he could set the price of a $500 in-game package to a penny.

View more
April 14, 2024

Popping Teslas with Secondary PT and JavaScript's intparse() - just Sam Curry shit.

How Sam Curry gained access to someone else's Tesla via an integer parsing bug!

View more
April 13, 2024

Sam doing his thing and generating infinite money with a request replay attack LOL 3mm *shakes head*

Sam Curry shares how he hacked a casino slot machine to generate an unlimited balance.

View more
April 11, 2024

The story of how Sam Curry got detained at an airport!?

Just one of his many crazy stories from last week!

View more
April 11, 2024

CDN-CGI Research, Intent To Ship, and Louis Vuitton (Ep. 66)

Episode 66: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel discuss the recent YesWeHack Louis Vuitton LHE, the importance of failure as growth in bug bounty, and Justin shares his research on CDN CGI. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting…

View more
April 7, 2024

Got paid 150% for a bug by adding more visual impact!?

Got paid 150% of what a bug normally gets paid just by adding more visual impact through answering these 3 questions: 1. How would the payload be distributed? 2. How it would be exploited once the user clicks on the link etc? 3. How could it be wormed?

View more
April 6, 2024

DOM Purify Type Confusion by @slonser_

DOM Purify Type Confusion by @slonser_ How? 1. DOM Purify converts XML tags to HTML comment tags 2. Leaving the closing bracket empty, escapes to an HTML context allowing for onerror="alert(1)" and other fun stuff!

View more
April 4, 2024

Words of wisdom from Naffy (@nnwakelam)

If you do these two things well and with any kind of volume or repetition, you should be finding things!

View more
April 4, 2024

Motivation and Methodology with Sam Curry (Zlz) (Ep. 65)

Episode 65: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with Sam Curry to discuss the ethical considerations and effectiveness of hacking, the importance of good intent, and the enjoyment Sam derives from pushing the boundaries to find bugs. He shares stories of his experiences,…

View more
April 2, 2024

Exploiting .NET Remoting via a header!?

Exploiting HTTP request verb confusion via the __RequestVerb header to leak .NET remoting URLs.

View more
March 28, 2024

Is this the best tool JHaddix has EVER built!?

Jason explains how he built his self proclaimed best ever tool - SecGPT.

View more
March 28, 2024

.NET Remoting, CDN Attack Surface, and Recon vs Main App (Ep. 64)

Episode 64: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Justin and Joel delve into .NET remoting and how it can be exploited, a recent bypass in the Dom Purify library and some interesting functionality in the Cloudflare CDN-CGI endpoint. They also touch on the…

View more
March 26, 2024

Finding unknown apex domains using dig, whoisXML API and grep.

Jason explains how he used a few simple tools to find 12 apex domains that no other hunters knew about!

View more
March 24, 2024

Taking things out of the too hard basket to find bugs!

Signing up to developer programs, creating bank accounts and joining reseller programs, are awesome ways to gain additional app functionality that most people can't be bothered to go through!

View more
March 23, 2024

JHaddix inspects webhooks to catch bugs!

Jason Haddix explains why webhooks and integrations are a great starting place to look for bugs.

View more
March 22, 2024

Smuggling sensitive data via CSS injection and sequential import chaining.

Recently smuggled some sensitive data via CSS injection and sequential import chaining!

View more
March 21, 2024

Episode 63: JHaddix Returns

Episode 63: In this episode of Critical Thinking - Bug Bounty Podcast we welcome back Jason Haddix (From Episode 12) to talk about some updates to his The Bug Hunter's Methodology, as well as his own personal life and hacking journey. We talk about the start of his new company,…

View more
March 20, 2024

Dropping cookie bombs for full ATO!

This exploit is da bomb: Exploiting cookie bombing for session hijacking!

View more
March 18, 2024

iFrame Hijacking via window.open

Discovered an iFrame hijack using window.open and two iframes that allowed me to do some fun postMessage stuff.

View more
March 17, 2024

Here's a WEIRD RACE CONDITION BUG for y'all!

JR0ch17 accidentally discovered a bug in an OAuth flow where sending constant requests to the token refresh endpoint without a refresh token or authentication, could grant an access token during another user's login process!

View more
March 16, 2024

This is the FUNNIEST blind XSS story I've heard!

lollll JR0ch17 ruins a guy's day when a year old blind XSS payload finally pops... via a complaint sent to an internal email system about JR0ch17's behaviour.

View more
March 14, 2024

Exploiting DOMPurify with Meta Tag and Redirects for OAuth Token Leakage with JR0ch17.

This one deserves a golf clap for sure.

View more
March 14, 2024

Frontend Language Oddities (Ep. 62)

Episode 62: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel are back with some additional research resources that didn’t make the Portswigger Top-Ten, but that are worth looking at. Follow us on twitter at: https://twitter.com/ctbbpodcast Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout…

View more