התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות


Episode 97: Bcrypt Hash Input Truncation & Mobile Device Threat Modeling
Manage episode 450134185 series 3435922
Episode 97: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel jump into some cool news items, including a recent Okta Bcrypt vulnerability, insights into crypto bugs, and some intricacies of Android and Chrome security. They also explore the latest research from Portswigger on payload concealment techniques, and the introduction of the Lightyear tool for PHP exploits.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
------ Ways to Support CTBBPodcast ------
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Today’s Sponsor - ThreatLocker: Check out Network Control!
https://www.criticalthinkingpodcast.io/tl-nc
And AssetNote: Check out their ASMR board (no not that kind!)
Resources
Android Web Attack Surface Writeups
Concealing payloads in URL credentials
Dumping PHP files with Lightyear
Limit maximum number of filter chains
Timestamps
(00:00:00) Introduction
(00:02:43) Okta Release and bcrypt
(00:10:26) Android Web Attack Surface Writeups
(00:20:21) More Portswigger Research
(00:28:29) Lightyear and PHP filter chains
(00:35:09) Dom-Explorer
(00:45:24) The JSON Debate
(00:49:59) Notes plugin for Burp and Caido
119 פרקים
Manage episode 450134185 series 3435922
Episode 97: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel jump into some cool news items, including a recent Okta Bcrypt vulnerability, insights into crypto bugs, and some intricacies of Android and Chrome security. They also explore the latest research from Portswigger on payload concealment techniques, and the introduction of the Lightyear tool for PHP exploits.
Follow us on twitter at: @ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
------ Links ------
Follow your hosts Rhynorater & Teknogeek on twitter:
https://twitter.com/0xteknogeek
https://twitter.com/rhynorater
------ Ways to Support CTBBPodcast ------
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Today’s Sponsor - ThreatLocker: Check out Network Control!
https://www.criticalthinkingpodcast.io/tl-nc
And AssetNote: Check out their ASMR board (no not that kind!)
Resources
Android Web Attack Surface Writeups
Concealing payloads in URL credentials
Dumping PHP files with Lightyear
Limit maximum number of filter chains
Timestamps
(00:00:00) Introduction
(00:02:43) Okta Release and bcrypt
(00:10:26) Android Web Attack Surface Writeups
(00:20:21) More Portswigger Research
(00:28:29) Lightyear and PHP filter chains
(00:35:09) Dom-Explorer
(00:45:24) The JSON Debate
(00:49:59) Notes plugin for Burp and Caido
119 פרקים
כל הפרקים
×
1 Episode 119: Abusing Iframes from a client-side hacker 33:54

1 Episode 118: Hacking Happy Hour: 0days on Tap and SQLi Shots 58:29

1 Hacking AI Series: Vulnus ex Machina - Part 1 32:20

1 Episode 116: Auth Bypasses and Google VRP Writeups 26:48

1 Episode 115: Mentee to Career Hacker - Mokusou (So Sakaguchi) 1:40:58

1 Episode 114: Single Page Application Hacking Playbook 1:22:25

1 Episode 113: Best Technical Takeaways from Portswigger Top 10 2024 1:29:19

1 Episode 112: Interview with Ciarán Cotter (MonkeHack) - Critical Lab Researcher and Full-time Hunter 1:07:37

1 Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu 1:49:15

1 Episode 110: Oauth Gadget Correlation and Common Attacks 49:41

1 Episode 109: Creative Recon - Alternative Techniques 1:01:42

1 Episode 108: How to Hack Salesforce, ServiceNow, and Other SaaS Products With Aaron Costello 1:31:08

1 Episode 107: Bypassing Cross-Origin Browser Headers 1:06:17

1 Episode 106: Announcing our new cohost... 58:10

1 Episode 105: Best Critical Thinking Moments from 2024 2:17:47
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.