Artwork

Indhold leveret af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0). Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0) eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration

57:20
 
Del
 

Manage episode 521444933 series 3435922
Indhold leveret af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0). Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0) eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

https://ctbb.show/tl-ec

====== This Week in Bug Bounty ======

Cache Overflow on Cloudflare

====== Resources ======

Breaking Oracle’s Identity Manager

Who Needs a Blind XSS?

ASP.NET MVC View Engine Search Patterns

Heretic

Lesser known techniques for large-scale subdomain enum

Antigravity – Known Issues

Bug Bounty Daily

Caido version of AssetNote Surf

====== Timestamps ======

(00:00:00) Introduction

(00:09:47) Breaking Oracle’s Identity Manager & Who Needs a Blind XSS?

(00:20:37) ASP.NET MVC View Engine Search Patterns & Heretic

(00:29:04) Lesser known techniques for large-scale subdomain enum

(00:35:29) Gemini 3 & Antigravity.

(00:45:57) Bug Bounty Daily

(00:52:42) Surf for Caido

  continue reading

151 episoder

Artwork
iconDel
 
Manage episode 521444933 series 3435922
Indhold leveret af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0). Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Justin Gardner (Rhynorater) & Joseph Thacker (Rez0), Justin Gardner (Rhynorater), and Joseph Thacker (Rez0) eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

https://ctbb.show/tl-ec

====== This Week in Bug Bounty ======

Cache Overflow on Cloudflare

====== Resources ======

Breaking Oracle’s Identity Manager

Who Needs a Blind XSS?

ASP.NET MVC View Engine Search Patterns

Heretic

Lesser known techniques for large-scale subdomain enum

Antigravity – Known Issues

Bug Bounty Daily

Caido version of AssetNote Surf

====== Timestamps ======

(00:00:00) Introduction

(00:09:47) Breaking Oracle’s Identity Manager & Who Needs a Blind XSS?

(00:20:37) ASP.NET MVC View Engine Search Patterns & Heretic

(00:29:04) Lesser known techniques for large-scale subdomain enum

(00:35:29) Gemini 3 & Antigravity.

(00:45:57) Bug Bounty Daily

(00:52:42) Surf for Caido

  continue reading

151 episoder

Alle episoder

×
 
Loading …

Velkommen til Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Hurtig referencevejledning

Lyt til dette show, mens du udforsker
Afspil