<description>&lt;p&gt;Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!&lt;/p&gt;&lt;p&gt;Follow us on twitter at: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast"&gt;https://x.com/ctbbpodcast&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Got any ideas and suggestions? Feel free to send us any feedback here: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="mailto:info@criticalthinkingpodcast.io"&gt;info@criticalthinkingpodcast.io&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Shoutout to&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"&gt; YTCracker&lt;/a&gt; for the awesome intro music!&lt;/p&gt;&lt;p&gt;====== Links ======&lt;/p&gt;&lt;p&gt;Follow your hosts Rhynorater, rez0 and gr3pme on X: &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater"&gt;https://x.com/Rhynorater&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__"&gt;https://x.com/rez0__&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme"&gt;https://x.com/gr3pme&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Ways to Support CTBBPodcast ======&lt;/p&gt;&lt;p&gt;Hop on the CTBB Discord at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord"&gt;https://ctbb.show/discord&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.&lt;/p&gt;&lt;p&gt;You can also find some hacker swag at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch"&gt;https://ctbb.show/merch&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec"&gt;https://ctbb.show/tl-ec&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== This Week in Bug Bounty ======&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/reports/3027461"&gt;Cache Overflow on Cloudflare&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Resources ======&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/"&gt;Breaking Oracle’s Identity Manager&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://hx01.me/hailcsv.htm"&gt;Who Needs a Blind XSS?&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://lab.ctbb.show/research/asp-net-mvc-view-engine-search-patterns"&gt;ASP.NET MVC View Engine Search Patterns&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/p-e-w/heretic"&gt;Heretic&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://docs.google.com/presentation/d/1UOcryh9c7zJ0UnnLwqRLFIyfU5LxSRRRt10c17dV8tI/edit?slide=id.g2d6dd8819b6_0_20#slide=id.g2d6dd8819b6_0_20"&gt;Lesser known techniques for large-scale subdomain enum&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://bughunters.google.com/learn/invalid-reports/google-products/4655949258227712/antigravity-known-issues#known-issues"&gt;Antigravity – Known Issues&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://bugbountydaily.com/"&gt;Bug Bounty Daily&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/caido-community/surf"&gt;Caido version of AssetNote Surf&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Timestamps ======&lt;/p&gt;&lt;p&gt;(00:00:00) Introduction&lt;/p&gt;&lt;p&gt;(00:09:47) Breaking Oracle’s Identity Manager &amp;amp; Who Needs a Blind XSS?&lt;/p&gt;&lt;p&gt;(00:20:37) &lt;a target="_blank" rel="noopener noreferrer nofollow" href="http://ASP.NET"&gt;ASP.NET&lt;/a&gt; MVC View Engine Search Patterns &amp;amp; Heretic&lt;/p&gt;&lt;p&gt;(00:29:04) Lesser known techniques for large-scale subdomain enum&lt;/p&gt;&lt;p&gt;(00:35:29) Gemini 3 &amp;amp; Antigravity.&lt;/p&gt;&lt;p&gt;(00:45:57) Bug Bounty Daily  &lt;/p&gt;&lt;p&gt;(00:52:42) Surf for Caido&lt;/p&gt;</description>

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration

NOV 27, 202557 MIN
Critical Thinking - Bug Bounty Podcast

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration

NOV 27, 202557 MIN

Description

<p>Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec">https://ctbb.show/tl-ec</a></p><p>====== This Week in Bug Bounty ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/reports/3027461">Cache Overflow on Cloudflare</a></p><p>====== Resources ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/">Breaking Oracle’s Identity Manager</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://hx01.me/hailcsv.htm">Who Needs a Blind XSS?</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://lab.ctbb.show/research/asp-net-mvc-view-engine-search-patterns">ASP.NET MVC View Engine Search Patterns</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/p-e-w/heretic">Heretic</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://docs.google.com/presentation/d/1UOcryh9c7zJ0UnnLwqRLFIyfU5LxSRRRt10c17dV8tI/edit?slide=id.g2d6dd8819b6_0_20#slide=id.g2d6dd8819b6_0_20">Lesser known techniques for large-scale subdomain enum</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://bughunters.google.com/learn/invalid-reports/google-products/4655949258227712/antigravity-known-issues#known-issues">Antigravity – Known Issues</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://bugbountydaily.com/">Bug Bounty Daily</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/caido-community/surf">Caido version of AssetNote Surf</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:09:47) Breaking Oracle’s Identity Manager &amp; Who Needs a Blind XSS?</p><p>(00:20:37) <a target="_blank" rel="noopener noreferrer nofollow" href="http://ASP.NET">ASP.NET</a> MVC View Engine Search Patterns &amp; Heretic</p><p>(00:29:04) Lesser known techniques for large-scale subdomain enum</p><p>(00:35:29) Gemini 3 &amp; Antigravity.</p><p>(00:45:57) Bug Bounty Daily </p><p>(00:52:42) Surf for Caido</p>