Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 144: Google’s Top AI Hackers: Busfactor and Monke

October 16, 2025·53 min·3 clips
He turns one `postMessage` flaw into prototype pollution, a custom WebSocket server, and session takeover.
1. Critical Thinking - Bug Bounty Podcast Episode 144 follows Kieran and Vitor Bus Factor after a Google live hacking event in Mexico. 2. Kieran hosts the episode, and Vitor Bus Factor appears as a guest bug hunter whose Google event collaboration with Kieran mattered because it produced 16 reports and a second-place finish. 3. The episode asks what made their Google collaboration work and why Vitor shifted from server-side hunting into front-end bugs and AI-focused event work. 4. Vitor opens with a client-side exploit chain against a huge company's in-house support chat, not Intercom, and says the agent could access the customer side but not the reverse. 5. He says the first flaw was a missing origin check on `postMessage`, which led him into the unified JavaScript and eventually to `JSON.parse` followed by `Object.assign`. 6. Vitor describes that combination as textbook prototype pollution, but says the useful breakthrough came from a deep config property and a string branch in the code. 7. He then changes a version value in the config and makes the chat connect to his own server instead of `chat.company.com`, giving him control of the WebSocket messages. 8. Vitor says he had to build a malicious server using the same libraries the target used, including `socket.js`, before the exploit path would work. 9. The chain ends with XSS, a `window.open`, and then an iframe sandwich that lets him obtain the authentication token and take over a session. 10. Kieran says the bug became critical, applied across every product page, and earned a 50% bonus because the program treated the chain as unusually severe. 11. Vitor says he had been hunting for bug bounty only a year and a half total, with his first bounty about a year earlier and his full-time switch only three months before the interview. 12. He explains that his background is developer work and then SRE, which made client-side code review feel natural rather than abstract. 13. Vitor says he spent a full year hunting server-side bugs before seeing Justin's client-side-heavy community and realizing front-end work could produce chains like CSPT to XSS. 14. He describes client-side hunting as reading minified JavaScript, using debugger breakpoints, and feeling like he is doing white-box review instead of fuzzing in the dark. 15. Kieran says the Google event pushed them toward AI because the event rewards and bonuses favored that area, while Vitor says he had never touched AI before the event. 16. The two describe how they ignored some client-side rabbit holes, focused on the event's AI targets, and still found 16 reports with 14 valid results. 17. The discussion about full-time bug bounty is practical and workmanlike, with both hosts talking about prioritization, routine, and the mental cost of bouncing between programs. 18. Vitor says ADHD makes it hard to stay locked in, so he uses exercise, pomodoro sessions, and weekly adjustment instead of forcing the same plan every day. 19. People who like Google live hacking events, client-side exploit chains, and full-time bug bounty routines will get the most from this episode. 20. People looking for a short, nontechnical overview or a story without code detail should probably skip it.
Listen to the show on