Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 163: Best Technical Takeaways from Portswigger Top 10 2025

·1 hr 8 min·4 clips
Chrome's connection pool cap of 256 requests and six per origin becomes a binary-search leak for cross-origin hosts.
1. Critical Thinking - Bug Bounty Podcast Episode 163 focuses on PortSwigger Top 10 2025 web hacking techniques. 2. Hosts Justin and Joseph split the research and explain why the 2025 write-ups are hard to cover in audio. 3. The episode asks which findings matter most for bug bounty hunters in real targets. 4. Georgian's OffensiveCon 25 talk on parser differentials appears first and centers on JavaScript, Erlang, Java, Go, Python, and YAML. 5. The hosts describe duplicate role parameters where one parser sees an empty array and another sees 'admin'. 6. They also cover a double Authorization header setup with a fake none-signed JWT and a real bearer token. 7. YAML binary tags, merge behavior, and truthy strings like yes, no, true, and false become another parser-differential theme. 8. The Chrome connection pool segment uses a 256-request cap and six requests per origin as the basis for a timing leak. 9. The attacker fills the pool, triggers a cross-origin request, and compares which request gets the freed slot first. 10. The result is a binary-search method for extracting a subdomain or distinguishing redirect destinations such as admin and regular users. 11. The HTTP/2 CONNECT write-up by Flomb is framed as a different attack surface from HTTP/1 CONNECT. 12. The hosts explain that HTTP/2 multiplexing allows multiple CONNECT tunnels on one connection. 13. They describe a Go scanner that uses CONNECT to reach arbitrary IPs and ports and returns 200 or 503 depending on success. 14. Xero's Next.js research gets a detailed revisit because it produced multiple reports and six-figure bounty total. 15. The hosts emphasize the '__next_data_request' query parameter and the 'X-Next-Route-Matches' header as the key control points. 16. They note the accept-encoding header trick that lets a tester check cache behavior without impacting browsers that always send that header. 17. Piotr Bazydlo's 93-page .NET paper is summarized as a proxy and WSDL issue with HTTP client casting quirks. 18. The hosts say a FileWebRequest path can skip HTTP setup, write XML to disk, leak NTLM credentials through UNC paths, and become a web shell. 19. The tone is technical, fast-paced, and often side-by-side, with Justin and Joseph interrupting each other to unpack dense implementation details. 20. Viewers who like framework bugs, parser mismatches, and client-side leaks will get the most value from this episode.

As heard by us

Dense PortSwigger research, turned into practical bug-hunting takeaways.

This episode takes PortSwigger's 2025 top ten web hacking techniques and turns them into bug-hunting lessons without losing the technical weight.

Read the full review in PlayNext →

Why you'd press play

PortSwigger 2025's web-hacking techniques, translated by two bug hunters.

Read the full recommendation in PlayNext →
Listen to the show on