<p><span style="background-color: transparent;">Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCs</span></p><p><br></p><p><span style="background-color: transparent;">Follow us on twitter at: </span><a href="https://x.com/ctbbpodcast" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ctbbpodcast</a></p><p><span style="background-color: transparent;">Got any ideas and suggestions? Feel free to send us any feedback here: </span><a href="mailto:info@criticalthinkingpodcast.io" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">info@criticalthinkingpodcast.io</a></p><p><span style="background-color: transparent;">Shoutout to</span><a href="https://twitter.com/realytcracker" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);"> YTCracker</a><span style="background-color: transparent;"> for the awesome intro music!</span></p><p><br></p><p><br></p><p><span style="background-color: transparent;">====== Links ======</span></p><p><span style="background-color: transparent;">Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp;</span></p><p><a href="https://x.com/Rhynorater" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/Rhynorater</a></p><p><a href="https://x.com/rez0__" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/rez0__</a></p><p><a href="https://x.com/gr3pme" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/gr3pme</a></p><p><br></p><p><span style="background-color: transparent;">Critical Research Lab:</span></p><p><a href="https://lab.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://lab.ctbb.show/</a><span style="background-color: transparent;">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">Need a Pentest? We just launched CTBB Pentests!</span></p><p><a href="https://pentest.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://pentest.ctbb.show/</a></p><p><br></p><p><span style="background-color: transparent;">Hack full time? Check out the Full-Time Hunter’s Guild!</span></p><p><a href="https://ctbb.show/fthg" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/fthg</a></p><p><br></p><p><span style="background-color: transparent;">====== Ways to Support CTBBPodcast ======</span></p><p><span style="background-color: transparent;">Hop on the CTBB Discord at </span><a href="https://ctbb.show/discord" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/discord</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</span></p><p><br></p><p><span style="background-color: transparent;">You can also find some hacker swag at </span><a href="https://ctbb.show/merch" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/merch</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">Today's Sponsor: Check out Zero Trust Cloud Access from ThreatLocker</span></p><p><a href="https://www.criticalthinkingpodcast.io/tl-ztca" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.criticalthinkingpodcast.io/tl-ztca</a></p><p><br></p><p><span style="background-color: transparent;">====== Resources ======</span></p><p><span style="background-color: transparent;">Another day, another universal linux LPE</span></p><p><a href="https://x.com/v12sec/status/2054491454064746629" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/v12sec/status/2054491454064746629</a></p><p><br></p><p><span style="background-color: transparent;">ZDI Drama</span></p><p><a href="https://x.com/ryotkak/status/2052881664909660521" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ryotkak/status/2052881664909660521</a></p><p><br></p><p><span style="background-color: transparent;">Orange Tsai Bug on Edge</span></p><p><a href="https://x.com/thezdi/status/2054868495888777266" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/thezdi/status/2054868495888777266</a></p><p><br></p><p><span style="background-color: transparent;">Chompie's Exploit in NV Container Toolkit</span></p><p><a href="https://x.com/chompie1337/status/2054882193055601140" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/chompie1337/status/2054882193055601140</a></p><p><br></p><p><span style="background-color: transparent;">GitHub Security April bug bounty stats</span></p><p><a href="https://x.com/GitHubSecurity/status/2054274356403138932" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/GitHubSecurity/status/2054274356403138932</a></p><p><br></p><p><span style="background-color: transparent;">====== Timestamps ======</span></p><p><span style="background-color: transparent;">(00:00:00) Introduction</span></p><p><span style="background-color: transparent;">(00:02:14) q param prompt injection &amp; Mobile CSPT</span></p><p><span style="background-color: transparent;">(00:14:17) Admin API Key MegaCrit</span></p><p><span style="background-color: transparent;">(00:17:13) Hackbots</span></p><p><span style="background-color: transparent;">(00:37:10) Pretty POCs and ZDI Drama</span></p><p><span style="background-color: transparent;">(00:44:48) GitHub Security April Stats</span></p>

Critical Thinking - Bug Bounty Podcast

[email protected] (Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme))

Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama

MAY 21, 202649 MIN
Critical Thinking - Bug Bounty Podcast

Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama

MAY 21, 202649 MIN

Description

Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access from ThreatLockerhttps://www.criticalthinkingpodcast.io/tl-ztca====== Resources ======Another day, another universal linux LPEhttps://x.com/v12sec/status/2054491454064746629ZDI Dramahttps://x.com/ryotkak/status/2052881664909660521Orange Tsai Bug on Edgehttps://x.com/thezdi/status/2054868495888777266Chompie's Exploit in NV Container Toolkithttps://x.com/chompie1337/status/2054882193055601140GitHub Security April bug bounty statshttps://x.com/GitHubSecurity/status/2054274356403138932====== Timestamps ======(00:00:00) Introduction(00:02:14) q param prompt injection & Mobile CSPT(00:14:17) Admin API Key MegaCrit(00:17:13) Hackbots(00:37:10) Pretty POCs and ZDI Drama(00:44:48) GitHub Security April Stats