Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 156: Chill AMA from bugbounty.forum

·1 hr 23 min
1. Critical Thinking - Bug Bounty Podcast Episode 156 is an AMA built around bugbounty.forum questions and a technical writeup on cross-site ETag length leaks. 2. Justin and his co-host Joseph lead the discussion, and ArcArc is named as the researcher behind the SecCon CTF writeup they dissect. 3. The episode asks what bug bounty hunters should do as AI agents, live hacking events, and new browser-side leak primitives keep changing the field. 4. The hosts announce an update to the Crit Research Lab exclusivity agreement that now allows researchers to host their work on their own blog after 30 days. 5. They explain that Crit Research Lab pays researchers, hosts the research, covers it on the podcast, and offers extra distribution through lab.ctbb.show. 6. Justin points to a “little exploit gadget” from the Critical Thinkers chat: using x-Safari-https when only the protocol-specific part of an open redirect is under control. 7. He says the trick can help with AI vulnerabilities that rely on Sec-Fetch-Site checks and can move a browser into Safari with different client-side restrictions. 8. The main technical segment covers ArcArc’s cross-site ETag length leak, which depends on the ETag changing length by one byte when a hex-encoded size crosses a boundary. 9. They describe using CSRF to create many notes in a victim session, changing the response size enough to flip the ETag length. 10. They then explain how the reflected ETag value becomes an If-None-Match request header on the next request, which can push the request over Node.js’s 16 KB header limit. 11. A 431 status code versus a 200 response becomes the signal, and the browser history API behavior is used to tell which response occurred cross-origin. 12. Justin calls the result a way to leak an entire flag with a one-byte difference in a header, and the writeup is described as a SecCon CTF challenge with one solve. 13. The first AMA question asks whether bug hunting will become obsolete in five to ten years because of AI agents, and both hosts say the field will be more competitive but not gone. 14. They argue that AI lowers the barrier to entry for beginners and also helps hackers build tools, while bug bounty still offers resume value, money, live events, and flexibility. 15. They also suggest that if bug bounty disappeared, it would affect many industries at once rather than uniquely destroying bug bounty. 16. Another topic is live hacking events, where the advice is to specialize in a program, target larger Fortune 20-style companies, or become a useful plus one through high-signal collaboration. 17. The hosts contrast bug counts and bug severity, saying that ten bugs at $500 each can build a better program profile, while one $5,000 bug carries more prestige and often more respect. 18. Justin describes CTBB’s origin as wanting to capture the live-hacking-event conversations with top-tier hunters, and he says the show is now a weekly content obligation alongside full-time hunting. 19. The tone is conversational and technical, with fast back-and-forth explanations, practical career advice, and occasional joking about cold symptoms and AI replacing the host. 20. People who want bug bounty tactics, career advice, and browser leak primitives will get the most from this episode, while listeners wanting a polished narrative or light entertainment may skip it.

As heard by us

A candid bug bounty conversation about why CTBB exists, how it has performed, and what it aims to deliver each week.

The episode opens with a cold start and some easy banter before settling into a very human bug bounty conversation. It begins with a Crit Research Lab policy update, then moves into why CTBB was started, how profitable it has been, and the aim of leaving listeners with one…

Read the full review in PlayNext →

Why you'd press play

You want a candid bug bounty conversation about how CTBB started, what it aims to do, and why the host still keeps shipping it weekly.

Read the full recommendation in PlayNext →
Listen to the show on