TIL: Array.fromAsync([1],alert)
19.12.2024 15:54
π 12
π 5
π¬ 0
π 0
Beautiful use of an irregular comment.
12.12.2024 17:59
π 1
π 0
π¬ 1
π 0
Web Challenge
33:
joaxcar.com/xss/self.htm...
12.12.2024 17:46
π 1
π 0
π¬ 2
π 0
Wow this rocks
12.12.2024 17:37
π 1
π 0
π¬ 0
π 0
8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking (Ep. 100)
YouTube video by Critical Thinking - Bug Bounty Podcast
If y'all wanna catch the 100th episode, you can find it here:
www.youtube.com/watch?v=ANYt...
06.12.2024 16:11
π 2
π 0
π¬ 0
π 0
Shoutout to Sentinel Studio's Richard and Christian for great quality and consistency on production.
Shoutout to gr3pme and Yujilik for killing it with the HackerNotes and HackerTLDR.
Shoutout to HackerContent for helping us manage our socials.
06.12.2024 16:11
π 2
π 1
π¬ 1
π 0
We released our 100th episode of
@ctbbpodcast.bsky.social yesterday - really proud of the whole CTBB team! We're sad to be losing @teknogeek.io, but very hopeful for future of the pod!
We're going to lean more into the discord community and keep producing HQ technical content in 2025.
06.12.2024 16:11
π 18
π 1
π¬ 4
π 0
Chills
06.12.2024 15:40
π 1
π 0
π¬ 0
π 0
Yo, new big thing: Shift.
AI seamlessly integrated into your HTTP proxy.
Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"
06.12.2024 15:38
π 11
π 5
π¬ 1
π 1
Program Managerβs Guide To Running a Successful Bug Bounty Program
How to run a bug bounty program hackers will love to hack on.
We spend a lot of time talking to the hackers, but today, we're dropping a goodie for the program managers!
Here are our top tips for running a kickass bug bounty program.
See the matrix at the end for high impact to hackers, low effort changes.
blog.criticalthinkingpodcast.io/p/program-ma...
04.12.2024 16:16
π 6
π 3
π¬ 0
π 0
Bash tip: hit ctrl+x then ctrl+e to edit your current command in $EDITOR, write and quit to run it
03.12.2024 18:15
π 37
π 6
π¬ 2
π 1
Flatt Security XSS Challenge - Writeup | maitai's blog
If you are interested in client-side hacking and browser quirks I strongly recommend going through this writeup by @maitai.bsky.social!
It was also cool to collab w/ him on the second chall π€πΏπ€π»
blig.one/2024/11/29/f...
30.11.2024 06:20
π 13
π 7
π¬ 0
π 0
Wait, how does this work? Do you mean href=//yourdomain? Or is there some way to make that reach out to your domain?
29.11.2024 23:57
π 0
π 0
π¬ 1
π 0
Pro-tip: gron is awesome for diffing JSON π₯°
github.com/tomnomnom/gron
29.11.2024 23:29
π 104
π 29
π¬ 3
π 0
This is the content I came to Blue sky for
29.11.2024 01:13
π 4
π 0
π¬ 1
π 0
Very nice one!
28.11.2024 16:23
π 1
π 0
π¬ 0
π 0
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
YouTube video by Critical Thinking - Bug Bounty Podcast
This week we've got a rare episode that is also a bit more beginner friendly!
0xLupin (of Lupin and Holmes) and @rhynorater.bsky.social breakdown some of the hacker mentality that really caused some breakthrough in their hacker growth.
Check it out!
youtu.be/yxc2jVKE-jo
28.11.2024 15:06
π 31
π 9
π¬ 0
π 0
Character length
28.11.2024 12:48
π 1
π 0
π¬ 0
π 0
I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions.
I'm not gonna recite them again here, but today a new condition came up:
No Content-Type header -> no CSRF restrictions
Same-site: None
POST
= CSRF
The research:
27.11.2024 16:55
π 41
π 5
π¬ 4
π 0
3. It provides introspection
The reason why many hackers prefer to do everything manually because they don't trust the tools to do as good of a job as they would. Bebiks was able to solve this issue by providing very clean introspection into what the plugin is doing.
27.11.2024 15:01
π 3
π 0
π¬ 1
π 0
2. AI assisted customization
The difficult thing about implementing your own methodology is it takes time and effort. Bebiks was able to greatly reduce the friction of this by allowing for natural language prompting to integrate custom 403 bypass techniques into the app.
27.11.2024 15:01
π 2
π 0
π¬ 1
π 0
1. Implement your own methodology
This plug-in allows you to take your own 403 bypassing methodology and automate it easily. Elite hackers love this because they can take what makes them special as hackers and automated easily.
Plus it has sensible defaults.
27.11.2024 15:01
π 2
π 0
π¬ 1
π 0
Alright, new platform so I'm going to start sharing some things that I'm excited about to keep the momentum flowing!
Rn, I think the 403 Bypasser Caido plugin from Bebiks is freaking amazing.
This is a tool to automate the bypassing of walled-off endpoints.
This plugin does 3 things right:
27.11.2024 15:01
π 37
π 8
π¬ 3
π 0
Great times with these gents
27.11.2024 14:43
π 9
π 0
π¬ 0
π 0
Take your time, brother! You got this!
27.11.2024 14:43
π 1
π 0
π¬ 0
π 0