ctbbpodcast Profile Banner
Critical Thinking - Bug Bounty Podcast Profile
Critical Thinking - Bug Bounty Podcast

@ctbbpodcast

Followers
19K
Following
2K
Statuses
2K

A 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.

getting intimate with your app
Joined December 2022
Don't wanna be here? Send us removal request.
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
30 days
Useful links: - Our Discord: - Our Critical Thinkers Tier (MasterClasses, Exclusive Tools, 0-day -> bug bounty services, MUCH more): - Our Full-time Bug Hunter's Guild (application only):
Tweet media one
0
5
28
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
22 hours
Cookie bombing, of course. hahah
1
3
38
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
2 days
HackerNotes for this week is here! Head over to our blog to check out the latest stuff we talked about on the pod in a readable format:
0
2
20
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
3 days
Just get intimate with the app...
1
0
35
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
4 days
Lol, browser 0-days dropping in the cool-research channel on the CTBB discord. Shoutout to @slonser_ @ViniSilvaCa @kevin_mizu @ryotkak @serverinspector and the rest of the squad for contributing ❤️
Tweet media one
0
5
104
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
4 days
New episode is out! In this episode we cover the recent DeepSeek incident, some industry news and a deep dive into some Creative Recon Techniques:
0
6
36
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
4 days
6. Enumerate objects and data fields: since object names are often customised, you may not be able to blindly guess them. However, schema exports and analysing _api/ calls in the front-end can help identify useful queries. Aaron’s research found over 1 million exposed healthcare records due to these misconfigurations. Understanding Power Pages’ access controls and API structure is key to identifying and reporting similar vulnerabilities. Check out the full research here by @ConspiracyProof:
0
0
5
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
5 days
Days like these remind us why we do what we do. Happy to see another 2 top hackers join our ranks @0xacb @x1m_martijn ❤️
Tweet media one
1
1
32
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
6 days
Pro tip: When testing ServiceNow, hit the kb_knowledge table’s text field with the filterText parameter. If display_value comes back **null**, the field exists—you just need to find the right one to read. @ConspiracyProof has pulled plenty of passwords and tokens this way. If it sounds cool, you should check the full thing:
0
1
15
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
8 days
If you wanna get your hands on the MasterClass, hop into the discord and subscribe to the Critical Thinkers tier. The full recording will drop later today.
0
1
21
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
11 days
Almost every company is using third-party SaaS tools, and in this latest episode, we have a legend in the SaaS security space & AppOmni Researcher @ConspiracyProof give us the low-down on how to attack SalesForce, ServiceNow, and MS Power Pages.
0
6
46
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
12 days
Windows ANSI-to-Unicode conversions can break apps! Best-fit mappings may misinterpret characters (¥ → \\), creating unexpected bugs. Always make sure to test these encoding edge cases for vulnerabilities! (credit: @orange_8361 and @_splitline_)
Tweet media one
2
47
315
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
14 days
Read more here:
0
0
8
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
16 days
Agentic models, better prompts, and privacy-first workflows can transform your AI game. Learn more by watching the episode with Jason Haddix:
0
0
9