Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 147: Stupid Simple Hacking Workflow Tips

·59 min·4 clips
Justin says Kaido's command palette now handles encodings and replay-tab jumps with keyboard shortcuts.
1. Critical Thinking - Bug Bounty Podcast Episode 147 focuses on Stupid Simple Hacking Workflow Tips for faster bug bounty work. 2. Hugo Vda and Justin are the hosts, and Hugo frames the segment around efficiency while Justin keeps adding concrete tooling examples. 3. The episode asks how hackers can remove friction from repeated tasks so they test more and quit less. 4. Hugo opens with a story about his daughter Selah calling him “the one in the black shirt” and “a hacker” at a cross-country meet. 5. The hosts then shift to live hacking event workflow problems, where setup time and repeated retries slow down testing. 6. Hugo says he feels more motivated and works harder when he is hacking with other people such as Justin, Ronnie, Kieron, BuzzFact, and Pliny’s B Team Six. 7. Justin agrees that solo work is not always optimal and says automation pays dividends when a test chain is hard to reset. 8. Hugo points to Kaido’s command palette as a way to run encodings without copying into another tool. 9. Justin explains that his own Kaido workflow uses Control-K shortcuts for convert actions and may soon include named replay tabs. 10. The hosts compare these shortcuts with Burp-style workflows and with the older need to use Hackvertor for custom encodings. 11. Justin says Chrome DevTools “Edit as HTML” helps him feed more context to AI tools when CSS or layout fixes are failing. 12. He also uses that same DevTools trick to copy scope and policy text from pages that block downloading or copy-paste. 13. Hugo converts that HTML into Markdown notes so AI can reference the documents during the live event. 14. Justin describes a quick-tricks toolkit for client-side testing that includes window.open, iframe, sandbox, and redirect scripts. 15. He says that toolkit automatically hash-encodes the script so he can share the exact test state with someone else. 16. Justin then walks through a Raycast setup with commands for CVSS, Python, clipboard hex viewing, cookie redaction, JWT inspection, and OCR. 17. He also describes an MR command that does match-and-replace on clipboard text, which he uses for newline cleanup and GraphQL queries. 18. The tone stays technical, conversational, and highly tactical, with both hosts interrupting each other to compare small workflow improvements. 19. Hackers who care about faster recon, better request editing, and AI-assisted testing would get the most value from this episode. 20. Listeners looking for a polished interview arc or a beginner bug bounty intro may skip it.

As heard by us

Small tooling habits with real hacking payoff.

This episode stays close to the kind of small workflow habits that keep hacking work moving. A ThreatLocker ad read frames local challenge and SMB gating as a way to blunt port scans, then the discussion moves into CyberChef, URL encoding, and turning escaped JSON back into…

Read the full review in PlayNext →

Why you'd press play

For hackers who want fewer clicks between a messy payload and a testable request.

Read the full recommendation in PlayNext →
Listen to the show on