Episodes

  • Episode 105: Best Critical Thinking Moments from 2024
    Jan 9 2025

    Episode 105: In this episode of Critical Thinking - Bug Bounty Podcast we're back with another Best-of episode recapping some of our top moments of 2024.

    Follow us on twitter at: @ctbbpodcast

    Ssend us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Rez0 on twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Check out our new SWAG store at https://ctbb.show/swag!

    Today’s Sponsor - ThreatLocker. Check out their Elevation Control! https://www.criticalthinkingpodcast.io/tl-ec

    Resources

    Episode 53

    ctbb.show/53

    Episode 59

    ctbb.show/59

    Episode 65

    ctbb.show/65

    Episode 69

    ctbb.show/69

    Episode 80

    ctbb.show/80

    Episode 81

    ctbb.show/81

    Episode 86

    ctbb.show/86

    Episode 87

    ctbb.show/87

    Episode 91

    ctbb.show/91

    Episode 93

    ctbb.show/93

    Episode 99

    ctbb.show/99

    Timestamps

    (00:00:00) Introduction

    (00:03:59) Episode 53

    (00:17:12) Episode 59

    (00:32:45) Episode 65

    (00:48:08) Episode 69

    (01:02:37) Episode 80

    (01:18:09) Episode 81

    (01:28:59) Episode 86

    (01:41:04) Episode 87

    (01:54:48) Episode 91

    (02:01:48) Episode 93

    (02:09:37) Episode 99

    Show More Show Less
    2 hrs and 18 mins
  • Episode 104: 2024 Hacker Stats & 2025 Goals
    Jan 2 2025

    Episode 104: In this episode of Critical Thinking - Bug Bounty Podcast Justin reflects upon the past year and walks through some of the bug bounty goals he had for 2024, and how he feels like he did. Then he sets some goals for 2025, as well as some exciting CT news for the coming year.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Rez0 on X:

    https://x.com/rhynorater

    https://x.com/rez0__

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Check out our new SWAG store at https://ctbb.show/swag!

    Resources

    CTBB Full Time Guild

    ctbb.show/ft

    Critical Research Lab

    ctbb.show/crl

    CT Episode 51 - 2024 Goals

    https://www.criticalthinkingpodcast.io/episode-51-hacker-stats-2023-2024-goals/

    Personal BB inventory and goals

    https://ctbb.show/blog

    Timestamps

    (00:00:00) introduction

    (00:00:57) Critical Thinking 2025 Announcements

    (00:04:21) Personal Inventory of 2024

    (00:24:05) Goals for 2025

    Show More Show Less
    29 mins
  • Episode 103: Getting ANSI about Unicode Normalization
    Dec 26 2024

    Episode 103: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs), as well as talk through some new research and the value of micro-blogging in general.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord!

    We offer Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Check out our new SWAG store!

    Join our Shift waitlist!

    Today’s Sponsor - ThreatLocker. Check out their Elevation Control! https://www.criticalthinkingpodcast.io/tl-ec

    Resources

    _json Juggling Attack

    Cross-Site POST Requests Without a Content-Type Header

    Worst Fit

    Orange Tsai on Worst Fit

    Handling Cookies is a Minefield

    Terminal DiLLMa

    XS-Leaking flags with CSS: A CTFd 0day

    Hacking Back the AI-Hacker

    Johann Computer use demo

    How I Became The Most Valuable Hacker

    Timestamps

    (00:00:00) Introduction

    (00:01:39) _json Juggling Attack and Cross-Site POST Requests Without a Content-Type Header

    (00:10:55) Worst Fit and Unicode Mapping

    (00:20:08) Handling Cookies is a Minefield

    (00:28:11) Terminal DiLLMa & CTFd 0day

    (00:41:18) Hacking Back the AI-Hacker

    (00:47:30) Becoming Most Valuable Hacker

    Show More Show Less
    1 hr and 1 min
  • Episode 102: Building Web Hacking Micro Agents with Jason Haddix
    Dec 19 2024

    Episode 102: In this episode of Critical Thinking - Bug Bounty Podcast Justin grabs Jason Haddix to help brainstorm the concept of AI micro-agents in hacking, particularly in terms of web fuzzing, WAF bypasses, report writing, and more.They discuss the importance of contextual knowledge, the cost implications, and the strengths of different LLM Models.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Check out our new SWAG store at https://ctbb.show/swag!

    Today’s Guest - https://x.com/Jhaddix

    Resources

    Keynote: Red, Blue, and Purple AI - Jason Haddix

    https://www.youtube.com/watch?v=XHeTn7uWVQM

    Attention in transformers,

    https://www.youtube.com/watch?v=eMlx5fFNoYc

    Shift

    https://shiftwaitlist.com/

    The Darkest Side of Bug Bounty

    https://www.youtube.com/watch?v=6SNy0u6pYOc

    Timestamps

    (00:00:00) Introduction

    (00:01:25) Micro-agents and Weird Machine Tricks

    (00:11:05) Web fuzzing with AI

    (00:18:15) Brainstorming Shift and micro-agents

    (00:34:40) Strengths of different AI Models, and using AI to write reports

    (00:54:21) The Darkest Side of Bug Bounty

    Show More Show Less
    1 hr and 3 mins
  • Episode 101: CTBB Hijacked: Rez0__ on AI Attack Vectors with Johann Rehberger
    Dec 12 2024

    Episode 101: In this episode of Critical Thinking - Bug Bounty Podcast we’ve been hijacked! Rez0 takes control of this episode, and sits down with Johann Rehberger to discuss the intricacies of AI application vulnerabilities. They talk through the importance of understanding system prompts, and various obfuscation techniques used to bypass security measures, the best AI platforms, and the evolving landscape of AI security.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Sponsor - ThreatLocker. Check out their Elevation Control! https://www.criticalthinkingpodcast.io/tl-ec

    Today’s Guest: https://x.com/wunderwuzzi23

    Resources

    Johann's blog

    https://embracethered.com/blog/

    zombais

    https://embracethered.com/blog/posts/2024/claude-computer-use-c2-the-zombais-are-coming/

    Copirate

    https://embracethered.com/blog/posts/2024/m365-copilot-prompt-injection-tool-invocation-and-data-exfil-using-ascii-smuggling/

    Timestamps

    (00:00:00) Introduction

    (00:01:59) Biggest things to look for in AI hacking

    (00:11:58) Best AI companies to hack on

    (00:15:59) URL Redirects and Obfuscation Techniques

    (00:24:05) Copirate

    (00:35:50) prompt injection guardrails and threats

    Show More Show Less
    51 mins
  • Ep 100 - 8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking
    Dec 5 2024

    Episode 100: In this episode of Critical Thinking - Bug Bounty Podcast we have a mixed bag. We celebrate 100 episodes of Critical Thinking, but also bid farewell to Joel, who will be leaving the show as a co-host, but returning as guest. Then we hear from a bunch of friends about their 'best bug of the year', before capping the episode with the announcement of a new AI tool we've been working on!

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Resources

    Delorean

    https://github.com/jselvi/Delorean

    Shift

    shiftwaitlist.com

    Timestamps

    (00:00:00) Introduction

    (00:07:32) Nagli

    (00:19:09) Shubs

    (00:35:00) Matt Brown

    (00:39:42) Matanber

    (00:57:52) Douglas Day

    (01:05:18) Alex Chapman

    (01:15:02) Nahamsec

    (01:25:45) Rez0

    (01:28:20) Shift Announcement

    Show More Show Less
    1 hr and 42 mins
  • Episode 99: Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty
    Nov 28 2024

    Episode 99: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Roni dissect an old thread of Justin's talking about how best to start bug bounty with the goal of making $100k in the first year.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Sponsor - AssetNote: Check out their ASMR board (no not that kind!)

    https://assetnote.io/asmr

    Today’s Guest - https://x.com/0xLupin

    Resources

    Justin's Twitter Thread

    https://x.com/Rhynorater/status/1699395452481769867

    Timestamps

    (00:00:00) Introduction

    (00:03:00) Web Fundamentals Education

    (00:46:01) Threat Modeling and Hacking Goals

    (01:18:58) Vuln Types and finding Specialization

    Show More Show Less
    1 hr and 43 mins
  • Episode 98: Team 82 Sharon Brizinov - The Live Hacking Polymath
    Nov 21 2024

    Episode 98: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gardner sits down with Sharon,to discuss his journey from early iOS development to leading a research team at Claroty. They address the differences between HackerOne and Pwn2Own, and talk through some intricacies of IoT security, and some less common IoT attack surfaces.

    Follow us on twitter at: @ctbbpodcast

    We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ------ Links ------

    Follow your hosts Rhynorater & Teknogeek on twitter:

    https://twitter.com/0xteknogeek

    https://twitter.com/rhynorater

    ------ Ways to Support CTBBPodcast ------

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    Today’s Sponsor - ThreatLocker: Check out Network Control!

    https://www.criticalthinkingpodcast.io/tl-nc

    And AssetNote: Check out their ASMR board (no not that kind!)

    https://assetnote.io/asmr

    Today’s Guest: https://sharonbrizinov.com/

    Resources

    The Claroty Research Team

    https://claroty.com/team82

    Pwntools

    https://github.com/Gallopsled/pwntools

    Scan My SMS

    http://scanmysms.com

    Gotta Catch 'Em All: Phishing, Smishing, and the birth of ScanMySMS

    https://www.youtube.com/watch?v=EhNsXXbDp3U

    Timestamps

    (00:00:00) Introduction

    (00:03:31) Sharon's Origin Story

    (00:21:58) Transition to Bug Bounty and Pwn2Own vs HackerOne

    (00:47:05) IoT/ICS Hacking Methodology

    (01:10:13) Cloud to Device Communication

    (01:18:15) Bug replication and uncommon attack surfaces

    (01:30:58) Documentation tracker, reCaptcha bypass, and ScanMySMS

    Show More Show Less
    1 hr and 44 mins