Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

·59 min·3 clips
A postMessage race condition was beaten by opening a popup window with width and height parameters.
1. Critical Thinking - Bug Bounty Podcast episode 158 recaps a 10-hour charity hack-along in the CTPB Discord and a set of client-side bug-bounty takeaways. 2. The hosts are Justin and Kieran, who split the recap between live-hacking logistics and postMessage and iframe exploitation details. 3. The episode asks what live narration, partial-auth states, and browser permission edge cases reveal about practical bug hunting. 4. The charity hack-along used five people in roughly two-hour shifts, and the hosts say it was harder than expected to narrate hacking while reading chat. 5. Justin says his brain felt like "absolute spaghetti" while switching between talking, reading chat, and coordinating with other co-hosts. 6. The team names Monke, XSS Doctor, Buss Factor, Rezo, and Yuji as contributors to the event. 7. They say Doc did prep work, found scope, built a threat model, and sussed most of the exploit before Justin closed it out. 8. The recap says the group submitted two reports from those first two sections and expected a third full exploit to be submitted soon. 9. One takeaway covers a postMessage-based race condition where an iframe gets initialized from a top-level page and an attacker-controlled page races its own message into place. 10. The workaround they describe uses window.open with width and height parameters so Chrome keeps both windows sufficiently active for rapid message delivery. 11. Another takeaway comes from a SaaS login flow that routes one email address to Okta and leaves a partial-auth state when a second email is used. 12. Justin says he pulled API endpoints and single-page-app endpoints to fuzz them with partial cookies and bearer tokens tied to that mixed-auth state. 13. The hosts say the SaaS company had been acquired by a parent SaaS company, and the profile-management path stayed logged in as the partial-auth identity. 14. A later segment covers a code pattern where a message is accepted if it comes from a specific window reference or if it has a secret value. 15. Justin points out that if the secret is not yet initialized, loose comparison can leave it as undefined and let messages pass through. 16. They also discuss browser-permission delegation, especially when an iframe uses the allow attribute for microphone and camera inside a page that already has those permissions. 17. The hosts say that behavior let an attacker-controlled iframe inherit access and potentially record audio or capture a picture. 18. Tone-wise, the episode is conversational and technical, with long back-and-forth explanations, interruptions, and frequent "dude"-style banter. 19. Listeners who like client-side bug bounty tactics and live hack-along logistics will get the most value. 20. Listeners looking for polished storytelling or non-technical recap material may skip it.
Listen to the show on