<p><span style="background-color: transparent;">Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, &amp; Magic String Denial of Service in Claude.</span></p><p><br></p><p><span style="background-color: transparent;">Follow us on twitter at: </span><a href="https://x.com/ctbbpodcast" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ctbbpodcast</a></p><p><span style="background-color: transparent;">Got any ideas and suggestions? Feel free to send us any feedback here: </span><a href="mailto:info@criticalthinkingpodcast.io" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">info@criticalthinkingpodcast.io</a></p><p><span style="background-color: transparent;">Shoutout to</span><a href="https://twitter.com/realytcracker" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);"> YTCracker</a><span style="background-color: transparent;"> for the awesome intro music!</span></p><p><br></p><p><span style="background-color: transparent;">====== Links ======</span></p><p><span style="background-color: transparent;">Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp;</span></p><p><a href="https://x.com/Rhynorater" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/Rhynorater</a></p><p><a href="https://x.com/rez0__" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/rez0__</a></p><p><a href="https://x.com/gr3pme" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/gr3pme</a></p><p><br></p><p><span style="background-color: transparent;">Critical Research Lab:</span></p><p><a href="https://lab.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://lab.ctbb.show/</a><span style="background-color: transparent;">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">====== Ways to Support CTBBPodcast ======</span></p><p><span style="background-color: transparent;">Hop on the CTBB Discord at </span><a href="https://ctbb.show/discord" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/discord</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</span></p><p><br></p><p><span style="background-color: transparent;">You can also find some hacker swag at </span><a href="https://ctbb.show/merch" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/merch</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">Today’s Sponsor: Adobe.</span></p><p><span style="background-color: transparent;">Use code CTBB040126, and get a 10% bonus on your bounty for any AI vulnerability which is mapped to the OWASP LLM top 10.</span></p><p><span style="background-color: transparent;">Valid on Adobe Acrobat Web - AI Assistant / PDF Spaces / Content Creation and presentation features using Express</span></p><p><span style="background-color: transparent;">Adobe Express AI Assistant.&nbsp;</span></p><p><span style="background-color: transparent;">Valid through April 1st, 2026</span></p><p><br></p><p><span style="background-color: transparent;">Also we have a Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag!</span></p><p><br></p><p><span style="background-color: transparent;">====== Resources ======</span></p><p><span style="background-color: transparent;">Cloudflare Zero-day</span></p><p><span style="background-color: transparent;">https://fearsoff.org/research/cloudflare-acme</span></p><p><br></p><p><span style="background-color: transparent;">Turning List-Unsubscribe into an SSRF/XSS Gadget</span></p><p><span style="background-color: transparent;">https://security.lauritz-holtmann.de/post/xss-ssrf-list-unsubscribe/</span></p><p><br></p><p><span style="background-color: transparent;">Breaking Multi-Tenant Isolation in Heroku Postgres</span></p><p><span style="background-color: transparent;">https://allistair.sh/blog/breaking-heroku-postgres/</span></p><p><br></p><p><span style="background-color: transparent;">Parse and Parse: MIME Validation Bypass to XSS via Parser Differential</span></p><p><span style="background-color: transparent;">https://lab.ctbb.show/research/parse-and-parse-mime-validation-bypass-to-xss-via-parser-differential</span></p><p><br></p><p><span style="background-color: transparent;">Claude Magic String Denial of Service</span></p><p><span style="background-color: transparent;">https://x.com/Frichette_n/status/2013988503336415522</span></p><p><br></p><p><span style="background-color: transparent;">From WebView to Remote Code Injection</span></p><p><span style="background-color: transparent;">https://djini.ai/from-webview-to-remote-code-injection/</span></p><p><br></p><p><span style="background-color: transparent;">DOM XSS Is Not Dead: The Rise of Polyglot Payloads</span></p><p><span style="background-color: transparent;">https://blogs.jsmon.sh/dom-xss-is-not-dead-the-rise-of-polyglot-payloads/</span></p><p><br></p><p><span style="background-color: transparent;">====== Timestamps ======</span></p><p><span style="background-color: transparent;">(00:00:00) Introduction</span></p><p><span style="background-color: transparent;">(00:06:17) Cloudflare Zero-day &amp; Turning List-Unsubscribe into an SSRF/XSS Gadget</span></p><p><span style="background-color: transparent;">(00:16:57) Breaking Multi-Tenant Isolation in Heroku Postgres &amp; CTBB Research</span></p><p><span style="background-color: transparent;">(00:25:46) Claude Magic String Denial of Service &amp; From WebView to Remote Code Injection</span></p>

Critical Thinking - Bug Bounty Podcast

[email protected] (Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme))

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

FEB 5, 202645 MIN
Critical Thinking - Bug Bounty Podcast

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

FEB 5, 202645 MIN

Description

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Service in Claude.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: Adobe.Use code CTBB040126, and get a 10% bonus on your bounty for any AI vulnerability which is mapped to the OWASP LLM top 10.Valid on Adobe Acrobat Web - AI Assistant / PDF Spaces / Content Creation and presentation features using ExpressAdobe Express AI Assistant. Valid through April 1st, 2026Also we have a Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag!====== Resources ======Cloudflare Zero-dayhttps://fearsoff.org/research/cloudflare-acmeTurning List-Unsubscribe into an SSRF/XSS Gadgethttps://security.lauritz-holtmann.de/post/xss-ssrf-list-unsubscribe/Breaking Multi-Tenant Isolation in Heroku Postgreshttps://allistair.sh/blog/breaking-heroku-postgres/Parse and Parse: MIME Validation Bypass to XSS via Parser Differentialhttps://lab.ctbb.show/research/parse-and-parse-mime-validation-bypass-to-xss-via-parser-differentialClaude Magic String Denial of Servicehttps://x.com/Frichette_n/status/2013988503336415522From WebView to Remote Code Injectionhttps://djini.ai/from-webview-to-remote-code-injection/DOM XSS Is Not Dead: The Rise of Polyglot Payloadshttps://blogs.jsmon.sh/dom-xss-is-not-dead-the-rise-of-polyglot-payloads/====== Timestamps ======(00:00:00) Introduction(00:06:17) Cloudflare Zero-day & Turning List-Unsubscribe into an SSRF/XSS Gadget(00:16:57) Breaking Multi-Tenant Isolation in Heroku Postgres & CTBB Research(00:25:46) Claude Magic String Denial of Service & From WebView to Remote Code Injection