Episode
Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs
- Published
- Jan 22, 2026
- Duration seconds
- 3510
- Processing state
not_requested- Canonical source
- https://criticalthinkingpodcast.io
Actions
POST https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-158-10hr-marathon-hack-along-recap-300k-client-side-bugs/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-158-10hr-marathon-hack-along-recap-300k-client-side-bugs.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our personal takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if Smart People Ever Say They’re Smart. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: [email protected] Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26 https://ztw.com/ ====== Resources ====== InsertScript - XSS Challenge Solution https://insert-script.blogspot.com/2020/03/xss-challenge-solution-refresh-header.html InsertScript - Redirect AuthHeader https://www.insert-script.com/examples/redirectAuthHeader/send.html CRLF injection on a 302 redirect https://x.com/0xdef1ant/status/2009040359482118500 Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover https://ysamm.com/uncategorized/2025/01/13/capig-xss.html Arcanum Hack Tips https://github.com/Arcanum-Sec/hack_tips Trail of Bits Releases Claude Skills https://x.com/dguido/status/2011541318229533063 what a $55,000 bug can look like https://x.com/the_IDORminator/statu…