Critical Thinking - Bug Bounty Podcast
@ctbbpodcast
Followers
19K
Following
2K
Statuses
2K
A 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
getting intimate with your app
Joined December 2022
Lol, browser 0-days dropping in the cool-research channel on the CTBB discord. Shoutout to @slonser_ @ViniSilvaCa @kevin_mizu @ryotkak @serverinspector and the rest of the squad for contributing ❤️
0
5
104
6. Enumerate objects and data fields: since object names are often customised, you may not be able to blindly guess them. However, schema exports and analysing _api/ calls in the front-end can help identify useful queries. Aaron’s research found over 1 million exposed healthcare records due to these misconfigurations. Understanding Power Pages’ access controls and API structure is key to identifying and reporting similar vulnerabilities. Check out the full research here by @ConspiracyProof:
0
0
5
Days like these remind us why we do what we do. Happy to see another 2 top hackers join our ranks @0xacb @x1m_martijn ❤️
1
1
32
Pro tip: When testing ServiceNow, hit the kb_knowledge table’s text field with the filterText parameter. If display_value comes back **null**, the field exists—you just need to find the right one to read. @ConspiracyProof has pulled plenty of passwords and tokens this way. If it sounds cool, you should check the full thing:
0
1
15
Almost every company is using third-party SaaS tools, and in this latest episode, we have a legend in the SaaS security space & AppOmni Researcher @ConspiracyProof give us the low-down on how to attack SalesForce, ServiceNow, and MS Power Pages.
0
6
46
Windows ANSI-to-Unicode conversions can break apps! Best-fit mappings may misinterpret characters (¥ → \\), creating unexpected bugs. Always make sure to test these encoding edge cases for vulnerabilities! (credit: @orange_8361 and @_splitline_)
2
47
315