GLOBAL CSP BYPASS using HTMX triggers and unsafe-eval!?
.@avlidienbrunn blew our minds with his latest HTMX research including this tasty CSP bypass. See Twitter for payload.
.@avlidienbrunn blew our minds with his latest HTMX research including this tasty CSP bypass. See Twitter for payload.
Shots fired on the pod last week on whether programs are incentivised NOT to pay. #infosec #bugbounty #bugbounties #cybersecurity #criticalthinking #CTBBpodcast #bugbountytips #bugbountyhunters #hacking #hackers
Joel getting fired up about the leaderboard problem in bug bounties. #infosec #bugbounty #bugbounties #cybersecurity #criticalthinking #CTBBpodcast #bugbountytips #bugbountyhunters #hacking #hackers
Episode 68: In this episode of Critical Thinking - Bug Bounty Podcast Mathias is back with some fresh HTMX research, including CSP bypass using HTMX triggers, converting client-side response header injection to XSS, bypassing HTMX disable, and the challenges of using HTMX in larger applications and the potential performance trade-offs.…
Things getting spicy on the pod when the VDP debate cropped up! #infosec #bugbounty #bugbounties #cybersecurity #criticalthinking #CTBBpodcast #bugbountytips #bugbountyhunters #hacking #hackers
Engineering blogs can be a gold mine of juicy info about a company's internal infrastructure, how it works, how it communicates and even problems they're encountering! Pretty much no one reads them... until now!
Joel dropped some truth bombs on the pod last week! Here's one of 'em!
Set up a Discord channel so we know what the Blink Dev Google Group are up to. Whenever they post about new features they're planning to ship, we'll know!
Here's one y'all been waiting for: @CaidoIO is dropping global workflows this week!
Episode 67: In this episode of Critical Thinking - Bug Bounty Podcast we deep-dive on the topic of Vulnerability Disclosure Programs (VDPs) and whether they are beneficial or not. We also touch on the topic of leaderboard accuracy, and continue the Program VS Hacker debate regarding allocating funds for bounties.…
Used a "?" before "@" to terminate an OAuth flow redirect URI, control the redirect location, and leak the oauth code.
Sam Curry explains how he found a bug in a video game where he could set the price of a $500 in-game package to a penny.
How Sam Curry gained access to someone else's Tesla via an integer parsing bug!
Sam Curry shares how he hacked a casino slot machine to generate an unlimited balance.
Just one of his many crazy stories from last week!
Episode 66: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel discuss the recent YesWeHack Louis Vuitton LHE, the importance of failure as growth in bug bounty, and Justin shares his research on CDN CGI. Follow us on twitter at: https://twitter.com/ctbbpodcast We're new to this podcasting…
Got paid 150% of what a bug normally gets paid just by adding more visual impact through answering these 3 questions: 1. How would the payload be distributed? 2. How it would be exploited once the user clicks on the link etc? 3. How could it be wormed?
DOM Purify Type Confusion by @slonser_ How? 1. DOM Purify converts XML tags to HTML comment tags 2. Leaving the closing bracket empty, escapes to an HTML context allowing for onerror="alert(1)" and other fun stuff!
If you do these two things well and with any kind of volume or repetition, you should be finding things!
Episode 65: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with Sam Curry to discuss the ethical considerations and effectiveness of hacking, the importance of good intent, and the enjoyment Sam derives from pushing the boundaries to find bugs. He shares stories of his experiences,…
Exploiting HTTP request verb confusion via the __RequestVerb header to leak .NET remoting URLs.
Jason explains how he built his self proclaimed best ever tool - SecGPT.
Episode 64: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Justin and Joel delve into .NET remoting and how it can be exploited, a recent bypass in the Dom Purify library and some interesting functionality in the Cloudflare CDN-CGI endpoint. They also touch on the…
Jason explains how he used a few simple tools to find 12 apex domains that no other hunters knew about!