Critical Thinking - Bug Bounty Podcast Podcast Por Justin Gardner (Rhynorater) & Joseph Thacker (Rez0) arte de portada

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

De: Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Escúchala gratis

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Episodios
  • Episode 138: Caido Tools and Workflows
    Sep 4 2025

    Episode 138: In this episode of Critical Thinking - Bug Bounty Podcast We’re talking Caido tools and workflows. Justin gives us a list of some of the Caido tools that have caught his interest, as well as how he’s using them.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== This Week in Bug Bounty ======

    Meet YesWeHack at ROOTCON 2025

    https://www.yeswehack.com/page/meet-yeswehack-at-rootcon-2025

    New Dojo challenge featuring a Local File Inclusion in a Ruby application

    https://dojo-yeswehack.com/challenge-of-the-month/dojo-44?utm_source=sponsor&utm_medium=challenge&utm_campaign=dojo-44

    AI Red Teaming CTF

    https://ctf.hackthebox.com/event/details/ai-red-teaming-ctf-ai-gon3-rogu3-2604

    ====== Resources ======

    Web Security Labs

    http://caido.rhynorater.com

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:32) Common filters & command palette in EvenBetter

    (00:06:49) Notes++

    (00:09:28) Shift Agents and Drop

    (00:15:34) Workflows

    Más Menos
    23 m
  • Episode 137: How We Do AI-Assisted Whitebox Review, New CSPT Gadgets, and Tools from SLCyber
    Aug 28 2025

    Episode 137: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gardner and Joseph Thacker reunite to talk about AI Hacking Assistants, CSPT and cache deception, and a bunch of tools like ch.at, Slice, Ebka, and more.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== This Week in Bug Bounty ======

    Vulnerability vectors: SQL injection for Bug Bounty hunters

    Mozilla VPN Clients: RCE via file write and path traversal

    ====== Resources ======

    Cache Deception + CSPT:

    dig @ch.at

    Searchlight Cyber Tools

    Slice

    Ebka-Caido-AI

    postMessage targetOrigin bypass

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:01:26) Claude, Gemini, and Hacking Assistants

    (00:11:08) AI Safety

    (00:18:09) CSPT

    (00:23:26) ch.at, Slice, Ebka, & Searchlight Cyber Tools

    (00:45:19) postMessage targetOrigin bypass

    Más Menos
    49 m
  • Episode 136: Hacking Cluely, AI Prod Sec, and How To Not Get Sued with Jack Cable
    Aug 21 2025

    Episode 136: In this episode of Critical Thinking - Bug Bounty Podcast, Joseph Thacker sits down with Jack Cable to get the scoop on a significant bug in Cluely’s desktop application, as well as the resulting drama. They also talk about Jack’s background in government cybersecurity initiatives, and the legal risks faced by security researchers.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor - ThreatLocker. Checkout ThreatLocker Detect! https://www.criticalthinkingpodcast.io/tl-detect

    Today’s Guest: https://x.com/jackhcable?lang=en

    ====== This Week in Bug Bounty ======

    Nullcon Berlin

    https://www.yeswehack.com/page/yeswehack-live-hacking-nullcon-berlin-2025?utm_source=sponsor&utm_medium=blog&utm_campaign=lhe-nullcon-berlin

    BB Bulletin #15

    https://www.linkedin.com/pulse/bug-bounty-bulletin-15-yes-we-hack-dntue/

    2x Bounty on Grab

    https://hackerone.com/grab?type=team

    ====== Resources ======

    Corridor

    https://corridor.dev/

    disclose.io

    https://disclose.io/

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:33) Cluely Bug, Government involvement, & Disclosed.io

    (00:12:33) AI in security & Corridor.dev

    (00:29:23) Cluely Bug Fallout & Ethics of hacking outside of Programs

    (00:41:20) Shift Agents

    Más Menos
    51 m
Todas las estrellas
Más relevante  
as someone who is still very new to the industry, I like listening to this podcast as I find the information very useful

great information

Se ha producido un error. Vuelve a intentarlo dentro de unos minutos.