<description>&lt;p&gt;Episode 156: In this episode of Critical Thinking - Bug Bounty Podcast we answer some fantastic questions from over at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="http://bugbounty.forum"&gt;bugbounty.forum&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Follow us on twitter at: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast"&gt;https://x.com/ctbbpodcast&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Got any ideas and suggestions? Feel free to send us any feedback here: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="mailto:info@criticalthinkingpodcast.io"&gt;info@criticalthinkingpodcast.io&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Shoutout to&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"&gt; YTCracker&lt;/a&gt; for the awesome intro music!&lt;/p&gt;&lt;p&gt;====== Links ======&lt;/p&gt;&lt;p&gt;Follow your hosts Rhynorater, rez0 and gr3pme on X:&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater"&gt;https://x.com/Rhynorater&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__"&gt;https://x.com/rez0__&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme"&gt;https://x.com/gr3pme&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Ways to Support CTBBPodcast ======&lt;/p&gt;&lt;p&gt;Hop on the CTBB Discord at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord"&gt;https://ctbb.show/discord&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.&lt;/p&gt;&lt;p&gt;You can also find some hacker swag at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch"&gt;https://ctbb.show/merch&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;====== Resources ======&lt;/p&gt;&lt;p&gt;Critical Thinking Lab&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="http://lab.ctbb.show"&gt;lab.ctbb.show&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Cross-Site ETag Length Leak&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.arkark.dev/2025/12/26/etag-length-leak"&gt;https://blog.arkark.dev/2025/12/26/etag-length-leak&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Clawdbot&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/clawdbot/clawdbot/"&gt;https://github.com/clawdbot/clawdbot/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Post from Steve Caldwell&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/moreconfetti/status/2006494133159162008"&gt;https://x.com/moreconfetti/status/2006494133159162008&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Timestamps ======&lt;/p&gt;&lt;p&gt;(00:00:00) Introduction&lt;/p&gt;&lt;p&gt;(00:00:58) Crit Lab update&lt;/p&gt;&lt;p&gt;(00:04:36) Cross-Site ETag Length Leak&lt;/p&gt;&lt;p&gt;(00:13:26) Clawdbot&lt;/p&gt;&lt;p&gt;(00:16:56) Will bug hunting become obsolete, LHE invitations, and Fulltime vs Part time?&lt;/p&gt;&lt;p&gt;(00:30:52) 10 bugs at $5k or 1 bug at $5k, CTBB Background, &amp;amp; Future Plans&lt;/p&gt;&lt;p&gt;(00:38:32) Mentoring, Conquering Classes, and what angles we implement from the podcast&lt;/p&gt;&lt;p&gt;(00:49:27) Best approach on new targets, tips for making 500k in a year, AI/Vibecoding &amp;amp; Human in the Loop&lt;/p&gt;&lt;p&gt;(00:59:07) Mentally mapping the target, anti-patterns that waste time, and BB beliefs that were wrong.&lt;/p&gt;&lt;p&gt;(01:10:12) Tackling small scope, staying on one program, picking up after a break, &amp;amp; moving on&lt;/p&gt;&lt;p&gt;(01:17:41) Invisible elements that make the difference between $2k and $20k&lt;/p&gt;</description>

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Episode 156: Chill AMA from bugbounty.forum

JAN 8, 202683 MIN
Critical Thinking - Bug Bounty Podcast

Episode 156: Chill AMA from bugbounty.forum

JAN 8, 202683 MIN

Description

<p>Episode 156: In this episode of Critical Thinking - Bug Bounty Podcast we answer some fantastic questions from over at <a target="_blank" rel="noopener noreferrer nofollow" href="http://bugbounty.forum">bugbounty.forum</a></p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X:</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>You can also find some hacker swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>====== Resources ======</p><p>Critical Thinking Lab</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="http://lab.ctbb.show">lab.ctbb.show</a></p><p>Cross-Site ETag Length Leak</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.arkark.dev/2025/12/26/etag-length-leak">https://blog.arkark.dev/2025/12/26/etag-length-leak</a></p><p>Clawdbot</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/clawdbot/clawdbot/">https://github.com/clawdbot/clawdbot/</a></p><p>Post from Steve Caldwell</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/moreconfetti/status/2006494133159162008">https://x.com/moreconfetti/status/2006494133159162008</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:00:58) Crit Lab update</p><p>(00:04:36) Cross-Site ETag Length Leak</p><p>(00:13:26) Clawdbot</p><p>(00:16:56) Will bug hunting become obsolete, LHE invitations, and Fulltime vs Part time?</p><p>(00:30:52) 10 bugs at $5k or 1 bug at $5k, CTBB Background, &amp; Future Plans</p><p>(00:38:32) Mentoring, Conquering Classes, and what angles we implement from the podcast</p><p>(00:49:27) Best approach on new targets, tips for making 500k in a year, AI/Vibecoding &amp; Human in the Loop</p><p>(00:59:07) Mentally mapping the target, anti-patterns that waste time, and BB beliefs that were wrong.</p><p>(01:10:12) Tackling small scope, staying on one program, picking up after a break, &amp; moving on</p><p>(01:17:41) Invisible elements that make the difference between $2k and $20k</p>