Discover
Critical Thinking - Bug Bounty Podcast
Critical Thinking - Bug Bounty Podcast
Author: Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Subscribed: 525Played: 12,443Subscribe
Share
© Critical Thinking Podcast
Description
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
192 Episodes
Reverse
Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Privileged Access Managementhttps://www.criticalthinkingpodcast.io/tl-pam====== This Week in Bug Bounty ======LHE at Ekoparty, open to all Ekoparty Attendeeshttps://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfihttps://www.youtube.com/watch?v=MYK9-66qe6w====== Resources ======Get Justin’s exclusive masterclass for more informationhttps://www.ctbb.show/discord====== Timestamps ======(00:00:00) Introduction(00:05:33) PoC Creation Goals & Formats(00:15:01) Nuts and Bolts of Python & HTML Files
Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!====== This Week in Bug Bounty ======How to use Codex for Bug Bounty research: explore broadly, validate rigorouslyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-codex====== Resources ======Herdrhttps://herdr.dev/====== Timestamps ======(00:00:00) Introduction(00:02:43) Rez0's Sick Caching Bug(00:11:38) Hackbot Scale & Hardware Spend(00:19:16) Stretching your Subscriptions(00:27:53) Herdr.dev & LHE's with Total Bounty Pools
Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Privileged Access Managementhttps://www.criticalthinkingpodcast.io/tl-pam====== This Week in Bug Bounty ======Web Fuzzing for Hackershttps://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackersWhen fear no longer holds you back. Interview with Ryan Bonnerhttps://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatusSteve’s Maturity Frameworkhttps://x.com/SteveHernandezM/status/2094398761946493107====== Timestamps ======(00:00:00) Introduction(00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties(00:18:30) Amount vs. Impact(00:25:42) Ideal Work Day and Focus State
Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest - Joel Magolishttps://x.com/0xteknogeek====== This Week in Bug Bounty ======Kara Sprague’s Statement:“I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.” Kara Sprague, CEO, HackerOne Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit pluginhttps://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-codeClaude Kithttps://github.com/yeswehack/claude-kit====== Resources ======What Happened to HackerOne?https://blog.teknogeek.io/posts/what-happened-to-hackerone/Watch our episode with Alex Ricehttps://www.youtube.com/watch?v=Pa4wWv_ONjM====== Timestamps ======(00:00:00) Introduction(00:04:18) The early days: LHE's, Covid, and the rise of AI(00:17:20) HSM Program, HAI, and resource allocation(00:36:41) Sales Incentivisation(00:46:10) AI and Researcher Reports Data(00:54:38) How Can H1 Revive its Old Self(01:02:40) Triage
Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!Today’s Guests:https://x.com/7urb01https://x.com/busf4ctor====== This Week in Bug Bounty ======YesWeHack is introducing Credits to combat AI slop reportshttps://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits====== Timestamps ======(00:00:00) Introduction(00:03:45) DEFCON Event Reactions and Takeaways(00:12:56) Bus & Turbo Talk Overviews(00:21:53) Event Bugs



