『Episode 183: PortSwigger Research Impossible XSS SOLVED』のカバーアート

Episode 183: PortSwigger Research Impossible XSS SOLVED

Episode 183: PortSwigger Research Impossible XSS SOLVED

無料で聴く

ポッドキャストの詳細を見る
Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== This Week in Bug Bounty ======How LLMs are changing Bug Bounty Interview serieshttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglohttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynoraterhttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare====== Resources ======$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainhttps://whoareme.com/blog/cspt-account-takeover-2fa-bypass/Two Bypasses for Chrome’s Sanitizer APIhttps://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/Documenting the impossible: Unexploitable XSS labshttps://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labsGitLost: How We Tricked GitHub’s AI Agent into Leaking Private Reposhttps://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/Chaining Razor SSTI into RCE via Reflection and Runtime Stringshttps://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/====== Timestamps ======(00:00:00) Introduction(00:06:07) AI Features Are Just Tech Features(00:20:02) CSPT to full Account Takeover & Other Chains(00:35:27) Sanitizer API for Chrome and Firefox(00:46:57) Solving PortSwigger's Impossible Lab & GitLost(01:01:19) SSTI into RCE via Reflection
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません