44 subscribers
Player FM 앱으로 오프라인으로 전환하세요!
Episode 110: Oauth Gadget Correlation and Common Attacks
Manage episode 466438775 series 3435922
Episode 110: In this episode of Critical Thinking - Bug Bounty Podcast we hit some quick news items including a DOMPurify 3.2.3 Bypass, O3 mini updates, and a cool postLogger Chrome Extension. Then, we hone in on OAuth vulnerabilities, API keys, and innovative techniques hackers use to exploit these systems.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to https://x.com/realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater and Rez0 on Twitter:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== Resources ======
Jason Zhou's post about O3 mini
Live Chat Blog #2: Cisco Webex Connect
nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover
Account Takeover using SSO Logins
====== Timestamps ======
(00:00:00) Introduction
(00:01:44) DOMPurify 3.2.3 Bypass
(00:06:37) O3 mini
(00:10:29) Ophion Security: Cisco Webex Connect
(00:15:54) Discord Community News
(00:19:12) postLogger Chrome Extension
(00:21:04) Common OAuth Vulnerabilities & Lessons learned from Google’s APIs
117 에피소드
Manage episode 466438775 series 3435922
Episode 110: In this episode of Critical Thinking - Bug Bounty Podcast we hit some quick news items including a DOMPurify 3.2.3 Bypass, O3 mini updates, and a cool postLogger Chrome Extension. Then, we hone in on OAuth vulnerabilities, API keys, and innovative techniques hackers use to exploit these systems.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to https://x.com/realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater and Rez0 on Twitter:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== Resources ======
Jason Zhou's post about O3 mini
Live Chat Blog #2: Cisco Webex Connect
nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover
Account Takeover using SSO Logins
====== Timestamps ======
(00:00:00) Introduction
(00:01:44) DOMPurify 3.2.3 Bypass
(00:06:37) O3 mini
(00:10:29) Ophion Security: Cisco Webex Connect
(00:15:54) Discord Community News
(00:19:12) postLogger Chrome Extension
(00:21:04) Common OAuth Vulnerabilities & Lessons learned from Google’s APIs
117 에피소드
모든 에피소드
×
1 Episode 115: Mentee to Career Hacker - Mokusou (So Sakaguchi) 1:40:58

1 Episode 114: Single Page Application Hacking Playbook 1:22:25

1 Episode 113: Best Technical Takeaways from Portswigger Top 10 2024 1:29:19

1 Episode 112: Interview with Ciarán Cotter (MonkeHack) - Critical Lab Researcher and Full-time Hunter 1:07:37

1 Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu 1:49:15

1 Episode 110: Oauth Gadget Correlation and Common Attacks 49:41

1 Episode 109: Creative Recon - Alternative Techniques 1:01:42

1 Episode 108: How to Hack Salesforce, ServiceNow, and Other SaaS Products With Aaron Costello 1:31:08

1 Episode 107: Bypassing Cross-Origin Browser Headers 1:06:17

1 Episode 105: Best Critical Thinking Moments from 2024 2:17:47

1 Episode 103: Getting ANSI about Unicode Normalization 1:00:30
플레이어 FM에 오신것을 환영합니다!
플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.