Artwork

Innhold levert av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek). Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek) eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.
Player FM - Podcast-app
Gå frakoblet med Player FM -appen!

Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans

1:31:52
 
Del
 

Manage episode 386721900 series 3435922
Innhold levert av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek). Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek) eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.

Episode 47: In this episode of Critical Thinking - Bug Bounty Podcast, the holidays are fast approaching, and Justin and Joel discuss some of the struggles of getting back into the hacking groove during and after breaks. We also celebrate the newly launched Critical Thinking Discord Community before diving into Iframe Sandwhiches, JS Hoisting, CSP Bypasses, and a host of new tools, techniques, and tangents.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

------ Ways to Support CTBBPodcast ------

Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.

Hop on the CTBB Discord at https://ctbb.show/discord!

ThankUNext

jswzl

Rapid API

SSRF Utility tool by Bebiks

Tweet from Johan Carlsson

Burp Extension from Google VRP

Justin's Tweet about JS Hoisting

Bypass CSP Using WordPress

How to trick CSP in letting you run whatever you want

Timestamps:

(00:00:00) Introduction

(00:01:58) Overcoming Bug Bounty struggles and getting back into the hacking groove

(00:07:46) Taking notes and sticking to one program

(00:14:50) Critical Thinking Discord, Community highlights, and Competition vs Collaboration

(00:22:25) Secondary context bugs and Automationism

(00:28:42) ThankUNext and Client-side Paths

(00:33:45) Tool Tangents: Jswzl, Caido, Postman, and Rapid API

(00:46:49) New SSRF Utility tool by Bebiks and the continuing evolution of hacking tools

(00:51:45) Iframe Sandwiches

(00:58:54) News Items

(01:06:12) JS Hoisting

(01:15:05) CSP Bypasses

  continue reading

93 episoder

Artwork
iconDel
 
Manage episode 386721900 series 3435922
Innhold levert av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek). Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av Justin Gardner (Rhynorater) & Joel Margolis (teknogeek), Justin Gardner (Rhynorater), and Joel Margolis (teknogeek) eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.

Episode 47: In this episode of Critical Thinking - Bug Bounty Podcast, the holidays are fast approaching, and Justin and Joel discuss some of the struggles of getting back into the hacking groove during and after breaks. We also celebrate the newly launched Critical Thinking Discord Community before diving into Iframe Sandwhiches, JS Hoisting, CSP Bypasses, and a host of new tools, techniques, and tangents.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

------ Ways to Support CTBBPodcast ------

Sign up for Caido using the referral code CTBBPODCAST for a 10% discount.

Hop on the CTBB Discord at https://ctbb.show/discord!

ThankUNext

jswzl

Rapid API

SSRF Utility tool by Bebiks

Tweet from Johan Carlsson

Burp Extension from Google VRP

Justin's Tweet about JS Hoisting

Bypass CSP Using WordPress

How to trick CSP in letting you run whatever you want

Timestamps:

(00:00:00) Introduction

(00:01:58) Overcoming Bug Bounty struggles and getting back into the hacking groove

(00:07:46) Taking notes and sticking to one program

(00:14:50) Critical Thinking Discord, Community highlights, and Competition vs Collaboration

(00:22:25) Secondary context bugs and Automationism

(00:28:42) ThankUNext and Client-side Paths

(00:33:45) Tool Tangents: Jswzl, Caido, Postman, and Rapid API

(00:46:49) New SSRF Utility tool by Bebiks and the continuing evolution of hacking tools

(00:51:45) Iframe Sandwiches

(00:58:54) News Items

(01:06:12) JS Hoisting

(01:15:05) CSP Bypasses

  continue reading

93 episoder

Tüm bölümler

×
 
Loading …

Velkommen til Player FM!

Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.

 

Hurtigreferanseguide

Copyright 2024 | Sitemap | Personvern | Vilkår for bruk | | opphavsrett