{"podcast":{"title":"Critical Thinking - Bug Bounty Podcast","slug":"critical-thinking-bug-bounty-podcast-5951018","podcast_index_feed_id":5951018,"rss_url":"https://feeds.cohostpodcasting.com/y3zHW5ae","website_url":"https://criticalthinkingpodcast.io","image_url":"https://files.cohostpodcasting.com/quill-file-prod/8d5e4388-13f4-45c8-b82f-aff313a5ac76/shows/194e9190-c8b8-49a9-a30a-6fae125dfd3f/cover-art/original_ef591a0cfb81593cfd0c1795273d6d1f.jpg","author":"Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)","episode_count":179,"summary":"A \"by Hackers for Hackers\" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.","last_synced_at":"2026-06-18T18:20:31.324885+00:00","page_url":"https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018"},"episode":{"title":"Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS","slug":"episode-171-path-scoped-cookie-hacks-with-uppercase-post-based-raw-protobuf-xss","published_at":"2026-04-23T09:00:00+00:00","page_url":"https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-171-path-scoped-cookie-hacks-with-uppercase-post-based-raw-protobuf-xss","show_page_url":"https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018","url":"https://criticalthinkingpodcast.io","audio_url":"https://audio-delivery.cohostpodcasting.com/audio/8d5e4388-13f4-45c8-b82f-aff313a5ac76/episodes/d7dc9562-d21d-4f16-b44a-9a08afcfe2ee/episode.mp3","summary":"Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp; https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ &nbsp; ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today's Sponsor: Check out ThreatLocker Ringfencing https://www.criticalthinkingpodcast.io/tl-rf ====== Resources ====== The ultimate Bug Bounty guide to OS command injection vulnerabilities https://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&amp;utm_medium=youtube&amp;utm_campaign=article-os-command-injection Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&amp;utm_medium=youtube&amp;utm_campaign=article-wordpress-bypass-plugin Aituglo featured on YWH https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st https://ekoparty.org/ekoparty-m…","meta_description":"Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking,…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1364,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-171-path-scoped-cookie-hacks-with-uppercase-post-based-raw-protobuf-xss/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-171-path-scoped-cookie-hacks-with-uppercase-post-based-raw-protobuf-xss.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}