# #558: Top 4 Web hacking demos for aspiring hackers (with labs and CTF) Page: https://stenobird.com/podcast/david-bombal-5315180/558-top-4-web-hacking-demos-for-aspiring-hackers-with-labs-and-ctf Text version: https://stenobird.com/podcast/david-bombal-5315180/558-top-4-web-hacking-demos-for-aspiring-hackers-with-labs-and-ctf.md Podcast: [David Bombal](https://stenobird.com/podcast/david-bombal-5315180) Published: 2026-03-16T13:47:27+00:00 Episode link: https://soundcloud.com/davidbombal/558-top-4-web-hacking-demos Audio file: https://feeds.soundcloud.com/stream/2284685441-davidbombal-558-top-4-web-hacking-demos.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/david-bombal-5315180/episodes/558-top-4-web-hacking-demos-for-aspiring-hackers-with-labs-and-ctf Duration seconds: 1512 ## Resource Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Are you looking to get into bug bounty hunting but feel overwhelmed or worried the field is oversaturated? In this video, full-time bug bounty hunter Justin Gardner shares a realistic, actionable guide to web hacking for beginners. We dive straight into the practical side with five live demonstrations of common web vulnerabilities—all done using just your browser and DevTools. Justin explains how Insecure Direct Object Reference (IDOR), Broken Access Controls, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) work in the real world, including stories of finding these exact bugs on major platforms like Google. After the demos, we tackle the biggest questions new hackers have: Is there still money to be made in 2026? How has AI changed the landscape? And what is the exact roadmap to landing your first bounty? Justin breaks down his "200-hour rule" for learning, why you need to get comfortable with failing, and the best resources (like HackerOne and PortSwigger) to help you launch your cybersecurity career today. // Labs and more here: // Labs: https://ztw.ctbb.show/ More labs: https://labs.cai.do/ And more labs: https://portswigger.net/web-security // Justin Gardner’s SOCIAL // YouTube: / @criticalthinkingpodcast LinkedIn: / rhynorater X: https://x.com/Rhynorater GitHub: https://rhynorater.github.io/aboutme/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davi… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/david-bombal-5315180/episodes/558-top-4-web-hacking-demos-for-aspiring-hackers-with-labs-and-ctf/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/david-bombal-5315180/558-top-4-web-hacking-demos-for-aspiring-hackers-with-labs-and-ctf.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.