Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND

·1 hr 12 min·4 clips
A random Yahoo SSRF became a $180,000 payout and a Nissan GTR.
1. Critical Thinking - Bug Bounty Podcast centers on Tommy DeVoss, Yahoo SSRF bypasses, Python Pitfalls, and his black-hat history. 2. Hosts frame Tommy as a bug bounty legend and a personal influence on their own hacker origin story. 3. The episode asks what Tommy actually learned from early hacking, prison, and bug bounty work that still matters today. 4. A brief This Week in Bug Bounty segment covers Alex Broomans' article called Python Pitfalls and its path-handling quirks. 5. The hosts discuss os.path.join, where an absolute path like /etc/passwd can override /user/uploads. 6. They also cover urllib.parse.urljoin, where http://evil.com can replace http://example.com when the second argument is absolute. 7. The episode mentions pickle deserialization as another topic inside the Python article. 8. A Google Cloud VRP announcement offers an extra reward, cash or swag, if listeners mention the podcast in rewarded reports through the end of April. 9. Tommy says his favorite bug is a Yahoo SSRF from 2018 that paid for his GTR. 10. He describes being in Las Vegas, waiting for a friend named Steve, and opening HackerOne reports instead of starting a new target. 11. He says Yahoo used a blacklist rather than an allow list, and that distinction mattered for the bypass. 12. He explains that encoding only the first octet of 169.254.169.254 in octal still reached the AWS metadata endpoint. 13. He says the same trick worked on every Yahoo SSRF he had reported over the previous three years. 14. He filed 18 new reports, each tied to a unique location, and says Yahoo paid $10,000 per report. 15. Four days later, he flew back to Richmond and went to the dealership to claim the GTR. 16. Tommy links that experience to a broader lesson about revisiting old reports when time is short and systems have changed. 17. He says he first learned about the AWS metadata server at AWS re:Invent in Washington, D.C., while sitting next to his friend Josh. 18. The interview style is casual and memory-driven, with Tommy and the hosts interrupting each other to fill in old details. 19. Listeners who like bug bounty tactics, SSRF tricks, and hacker origin stories will get the most from it. 20. Listeners seeking a tight technical tutorial without personal history may skip it.

As heard by us

A loose but useful bug bounty episode that pairs Python reminders with hacker history and community energy.

This episode blends community news with a practical look at Alex Broomans's Python Pitfalls piece, then turns to old hacker stories about fake IDs, busted crews, and an expulsion in 2000 that led to a month in New Mexico with other hackers.

Read the full review in PlayNext →

Why you'd press play

You want the backstory behind how this bug bounty world grew into a tight-knit community.

Read the full recommendation in PlayNext →
Listen to the show on