Critical Thinking - Bug Bounty Podcast
Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Overview
Episodes

Details

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Recent Episodes

Episode 156: Chill AMA from bugbounty.forum
JAN 8, 2026
Episode 156: Chill AMA from bugbounty.forum
<p>Episode 156: In this episode of Critical Thinking - Bug Bounty Podcast we answer some fantastic questions from over at <a target="_blank" rel="noopener noreferrer nofollow" href="http://bugbounty.forum">bugbounty.forum</a></p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X:</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>====== Resources ======</p><p>Critical Thinking Lab</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="http://lab.ctbb.show">lab.ctbb.show</a></p><p>Cross-Site ETag Length Leak</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.arkark.dev/2025/12/26/etag-length-leak">https://blog.arkark.dev/2025/12/26/etag-length-leak</a></p><p>Clawdbot</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/clawdbot/clawdbot/">https://github.com/clawdbot/clawdbot/</a></p><p>Post from Steve Caldwell</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/moreconfetti/status/2006494133159162008">https://x.com/moreconfetti/status/2006494133159162008</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:00:58) Crit Lab update</p><p>(00:04:36) Cross-Site ETag Length Leak</p><p>(00:13:26) Clawdbot</p><p>(00:16:56) Will bug hunting become obsolete, LHE invitations, and Fulltime vs Part time?</p><p>(00:30:52) 10 bugs at $5k or 1 bug at $5k, CTBB Background, &amp; Future Plans</p><p>(00:38:32) Mentoring, Conquering Classes, and what angles we implement from the podcast</p><p>(00:49:27) Best approach on new targets, tips for making 500k in a year, AI/Vibecoding &amp; Human in the Loop</p><p>(00:59:07) Mentally mapping the target, anti-patterns that waste time, and BB beliefs that were wrong.</p><p>(01:10:12) Tackling small scope, staying on one program, picking up after a break, &amp; moving on</p><p>(01:17:41) Invisible elements that make the difference between $2k and $20k</p>
play-circle icon
83 MIN
Episode 155: 2025 Hacker Stats & 2026 Goals
JAN 1, 2026
Episode 155: 2025 Hacker Stats & 2026 Goals
<p>Episode 155: In this episode of Critical Thinking - Bug Bounty Podcast Justin, Joseph, and Brandyn reflect on last year of Bug Bounty, and list their goals and predictions for what 2026 holds.</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>====== Resources ======</p><p>2024 Hacker Stats &amp; 2025 Goals</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-104-2024-hacker-stats-2025-goals">https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-104-2024-hacker-stats-2025-goals</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:02:08) 2025 Full Time Hunting Retrospective</p><p>(00:10:19) Most Fulfilling Moments and Bugs</p><p>(00:17:56) Satisfaction with 2025 Stats</p><p>(00:45:28) Automation, Organization, and Collaboration</p><p>(00:48:55) Time and Motivation</p><p>(01:08:01) Goals and Predictions for Bug Bounty in 2026</p>
play-circle icon
92 MIN
Episode 154: Starting a Pentesting Company on Top of Bug Bounty
DEC 25, 2025
Episode 154: Starting a Pentesting Company on Top of Bug Bounty
<p>Episode 154: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn talk through the transition from Bug Bounty hunting to Pentesting. We cover diversifying income streams, the challenges of pricing for Pentests, legal considerations, and what Bug Hunters can bring to the Pentesting world</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:03:36) Starting a Pentesting Company </p><p>(00:12:25) Advantages of Pentesting as a Bug Bounty Hunter</p><p>(00:29:03) Pricing, Sales, and knowing your Market/Worth</p><p>(00:36:21) Compliance in Pentests &amp; Rapid-Fire Takaways</p>
play-circle icon
41 MIN
Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown
DEC 18, 2025
Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown
<p>Episode 153: In this episode of Critical Thinking - Bug Bounty Podcast Matt Brown returns to talk with us about hacking robots, IOT hackbots, and his Zero-to-Hero Hardware Hacking Guide.</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>Today’s Guest: Matt Brown</p><ul><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/nmatt0">https://x.com/nmatt0</a></li><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/BrownFineSecurity/iothackbot">https://github.com/BrownFineSecurity/iothackbot</a></li></ul><p>====== Resources ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.amazon.com/KeeYees-Analyzer-Device-Channel-Arduino/dp/B07K6HXDH1">KeeYees USB Logic Analyzer Device</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://saleae.com/logic">Saleae logic analyzer</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.amazon.com/stores/XGecu/page/ACADF4DC-D4D0-4162-BDAF-566A7CF73D5F">XGecu</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.youtube.com/playlist?list=PLoFdAHrZtKkhcd9k8ZcR4th8Q8PNOx7iU">Hardware Hacking Tutorial by Make Me Hack</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://wrongbaud.github.io/posts/router-teardown/">UART and SPI firmware extraction</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://youtu.be/B0Wi2EP-BCY">UART Root Shell on Linux Router</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://youtu.be/pogUY9jH3sw">UART Shell Jail and Unlocked Bootloader</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://youtu.be/Su4MTlgDfzI">Chinese IP Camera Firmware Extraction</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://youtu.be/IkXbuF7_VPk">Chip-Off Firmware Extraction</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:01:22) Incremental Session Token Story and Matt Brown Intro </p><p>(00:10:42) Hardware Bug Bounty Scene &amp; AI on Devices</p><p>(00:24:30) Hacking Human Robot</p><p>(00:41:33) Zero-to-Hero Hardware Hacking Guide</p><p>(01:01:47) IOT Hackbot</p>
play-circle icon
76 MIN
Episode 152: GeminiJack and Agentic Security with Sasi Levi
DEC 11, 2025
Episode 152: GeminiJack and Agentic Security with Sasi Levi
<p>Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>CHeck out our New Christmas Swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec">https://ctbb.show/tl-ec</a></p><p>And Noma Security! <a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/">https://noma.security/</a></p><p>Today’s Guest: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103">https://x.com/sasi2103</a></p><p>====== This Week in Bug Bounty ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/vercel_platform_protection?type=team">Vercel Platform Protection</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/cramforce/status/1998072892391592195?s=20">Dedicated HackerOne program for Vercel WAF</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://yeswehack.com/programs?scopeType%5B%5D=open-source&amp;page=1">YesWeHack Open Source Programs</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.yeswehack.com/learn-bug-bounty/android-recon-bug-bounty-guide">Android recon for Bug Bounty hunters</a></p><p>====== Resources ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103/status/608349038778437632">Sasi's Tweet from 2015</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/">ForcedLeak: AI Agent risks exposed in Salesforce AgentForce</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://danielmiessler.com/blog/is-prompt-injection-a-vulnerability">Is Prompt Injection a Vulnerability?</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:09:16) Google Vertex AI Bug</p><p>(00:29:28) Sasi's Background and Bug Bounty Journey</p><p>(00:38:55) Resources for AI and Agentic Security Methodology</p><p>(00:50:34) ForcedLeak</p><p>(01:02:06) Is Prompt Injection a Vuln?</p>
play-circle icon
81 MIN