Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 140: Crit Research Lab Update & Client-Side Tricks Galore

·58 min·3 clips
Jorian's write-up shows how XSS inside a web worker can jump back to the main domain with blobs.
1. Critical Thinking - Bug Bounty Podcast Episode 140 focuses on the research lab update, client-side tricks, and AI-tool security. 2. Justin leads the show, and the recurring bug-bounty discussion matters because he frames the episode around live hacking, research, and community submissions. 3. The episode asks what the research lab is now for, and the answer is a public channel for micro research, write-ups, and bug reports. 4. Jorian's article, "Exploiting Web Workers XSS with Blobs," is used as the first lab example. 5. The hosts describe a universal chain that starts with XSS inside a web worker and ends with a blob URL, drag-and-drop payload, and main-domain impact. 6. They say the technique uses browser APIs such as fetch, postMessage, indexedDB, caches, and the blob API. 7. The lab relaunch includes submissions through ctbb.show and a research-lab button at the top of the site. 8. Micro research is described as one to eight paragraphs, with payouts of 20 to 50 dollars. 9. Full write-ups are listed at 100 to 250 dollars, mega research at 500 dollars, and bug write-ups at 50 dollars. 10. The hosts also explain that accepted submissions get posted on the site, covered on the pod, and shared in the CTBB Discord research channel. 11. HackerOne's new Hacker Milestone Rewards program comes up next, including points and rewards for newer hackers. 12. The hosts say the first five duplicate reports for a vulnerability are eligible for points under that program. 13. A listener-facing plug for Santera from Bug Crowd invites experienced hackers to reach out for interviews, articles, and panel discussions. 14. The conversation returns to client-side security with a YesWeHack write-up on cross-site request forgery and same-site cookie nuances. 15. They stress that content type, multipart encoding, and same-site behavior can change whether a CSRF is possible. 16. The Grafana write-up by jewbobs is cited as an example of using a fetch request with `text/plain; anything you want`. 17. The browser discussion then covers quirks mode, CSS injection, and frame counting as a way to build a conditional cross-site leak. 18. The tone is conversational and technical, with long back-and-forth explanations, interruptions, and examples from live hacking events. 19. Hackers who like web exploitation, browser quirks, and AI security tooling will get the most from it. 20. Listeners looking for a tightly edited, nontechnical narrative will probably skip it.

As heard by us

AI-assisted bug hunting, verbose API feedback, and a classic cookie-prefix flaw.

It follows the thread of AI-assisted bug hunting from start to finish, with shift agents and Cloud Code applied to APIs that return far too much detail. That gives the piece a practical edge, and the cookie-prefix vulnerability near the end adds a clear security payoff.

Read the full review in PlayNext →

Why you'd press play

Want to let Claude grind through prompt loops while you keep hunting the bug?

Read the full recommendation in PlayNext →
Listen to the show on