Justin Gardner's Avatar

Justin Gardner

@rhynorater

Christian | Full-time Bug Bounty Hunter | Host @ctbbpodcast.bsky.social | Advisor @caido.io | 3x LHE MVH | πŸ—£οΈ English, ζ—₯本θͺž

848
Followers
108
Following
25
Posts
27.11.2024
Joined
Posts Following

Latest posts by Justin Gardner @rhynorater

Preview
UL NO. 463 | Launching 2025, US Soldier Data Leak, AI Agents Emerge, China's Global Spy Network, Robotaxis Now Safer Than Humans Navigating AI's impact on work, the rise of transnational threats, a grim new reality in air travel, and how to harness the chaos of 2025 for personal and professional growth

πŸš€ This week's UL is live!

Featuring:

🌐 Launching 2025
πŸ“‚ US soldier data leak
πŸ€– AI agents begin to emerge
πŸ‡¨πŸ‡³ China’s global spy network revealed
πŸš• Robotaxis now safer than human drivers
newsletter.danielmiessler.com/p/ul-463

07.01.2025 19:52 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

TIL: Array.fromAsync([1],alert)

19.12.2024 15:54 πŸ‘ 12 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0

Beautiful use of an irregular comment.

12.12.2024 17:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Web Challenge

33:
joaxcar.com/xss/self.htm...

12.12.2024 17:46 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Wow this rocks

12.12.2024 17:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking (Ep. 100)
8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking (Ep. 100) YouTube video by Critical Thinking - Bug Bounty Podcast

If y'all wanna catch the 100th episode, you can find it here:
www.youtube.com/watch?v=ANYt...

06.12.2024 16:11 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Shoutout to Sentinel Studio's Richard and Christian for great quality and consistency on production.

Shoutout to gr3pme and Yujilik for killing it with the HackerNotes and HackerTLDR.

Shoutout to HackerContent for helping us manage our socials.

06.12.2024 16:11 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

We released our 100th episode of
@ctbbpodcast.bsky.social yesterday - really proud of the whole CTBB team! We're sad to be losing @teknogeek.io, but very hopeful for future of the pod!

We're going to lean more into the discord community and keep producing HQ technical content in 2025.

06.12.2024 16:11 πŸ‘ 18 πŸ” 1 πŸ’¬ 4 πŸ“Œ 0

Chills

06.12.2024 15:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
SHIFT - AI-Powered Hacking Supercharge your proxy with AI-powered automation. Join the waitlist for early access to SHIFT.

Shift is currently in closed beta. If you'd like to get on the waiting list, sign up here: shiftwaitlist.com

06.12.2024 15:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Shift Demo - JS->JSON Use Loom to record quick videos of your screen and cam. Explain anything clearly and easily – and skip the meeting. An essential tool for hybrid workplaces.

Recorded a demo for y'all to check out, you can find it here.
The longer version is on the website below.
www.loom.com/share/1ed8f9...

06.12.2024 15:38 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Yo, new big thing: Shift.
AI seamlessly integrated into your HTTP proxy.

Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"

06.12.2024 15:38 πŸ‘ 11 πŸ” 5 πŸ’¬ 1 πŸ“Œ 1
Preview
Program Manager’s Guide To Running a Successful Bug Bounty Program How to run a bug bounty program hackers will love to hack on.

We spend a lot of time talking to the hackers, but today, we're dropping a goodie for the program managers!

Here are our top tips for running a kickass bug bounty program.

See the matrix at the end for high impact to hackers, low effort changes.

blog.criticalthinkingpodcast.io/p/program-ma...

04.12.2024 16:16 πŸ‘ 6 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Bash tip: hit ctrl+x then ctrl+e to edit your current command in $EDITOR, write and quit to run it

03.12.2024 18:15 πŸ‘ 37 πŸ” 6 πŸ’¬ 2 πŸ“Œ 1
Flatt Security XSS Challenge - Writeup | maitai's blog

If you are interested in client-side hacking and browser quirks I strongly recommend going through this writeup by @maitai.bsky.social!
It was also cool to collab w/ him on the second chall πŸ€œπŸΏπŸ€›πŸ»
blig.one/2024/11/29/f...

30.11.2024 06:20 πŸ‘ 13 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0

Wait, how does this work? Do you mean href=//yourdomain? Or is there some way to make that reach out to your domain?

29.11.2024 23:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

Pro-tip: gron is awesome for diffing JSON πŸ₯°

github.com/tomnomnom/gron

29.11.2024 23:29 πŸ‘ 104 πŸ” 29 πŸ’¬ 3 πŸ“Œ 0

This is the content I came to Blue sky for

29.11.2024 01:13 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Very nice one!

28.11.2024 16:23 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99) YouTube video by Critical Thinking - Bug Bounty Podcast

This week we've got a rare episode that is also a bit more beginner friendly!

0xLupin (of Lupin and Holmes) and @rhynorater.bsky.social breakdown some of the hacker mentality that really caused some breakthrough in their hacker growth.

Check it out!
youtu.be/yxc2jVKE-jo

28.11.2024 15:06 πŸ‘ 31 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0

Character length

28.11.2024 12:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Cross-Site POST Requests Without a Content-Type Header / nastystereo.com

nastystereo.com/security/cro...

27.11.2024 16:55 πŸ‘ 11 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions.

I'm not gonna recite them again here, but today a new condition came up:

No Content-Type header -> no CSRF restrictions
Same-site: None
POST
= CSRF

The research:

27.11.2024 16:55 πŸ‘ 41 πŸ” 5 πŸ’¬ 4 πŸ“Œ 0
Preview
GitHub - bebiksior/Caido403Bypasser: 403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates. 403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates. - bebiksior/Caido403Bypasser

Good shit, y'all. Give it a download.

github.com/bebiksior/Ca...

27.11.2024 15:01 πŸ‘ 15 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

3. It provides introspection

The reason why many hackers prefer to do everything manually because they don't trust the tools to do as good of a job as they would. Bebiks was able to solve this issue by providing very clean introspection into what the plugin is doing.

27.11.2024 15:01 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

2. AI assisted customization

The difficult thing about implementing your own methodology is it takes time and effort. Bebiks was able to greatly reduce the friction of this by allowing for natural language prompting to integrate custom 403 bypass techniques into the app.

27.11.2024 15:01 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

1. Implement your own methodology

This plug-in allows you to take your own 403 bypassing methodology and automate it easily. Elite hackers love this because they can take what makes them special as hackers and automated easily.

Plus it has sensible defaults.

27.11.2024 15:01 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Alright, new platform so I'm going to start sharing some things that I'm excited about to keep the momentum flowing!

Rn, I think the 403 Bypasser Caido plugin from Bebiks is freaking amazing.

This is a tool to automate the bypassing of walled-off endpoints.

This plugin does 3 things right:

27.11.2024 15:01 πŸ‘ 37 πŸ” 8 πŸ’¬ 3 πŸ“Œ 0

Great times with these gents

27.11.2024 14:43 πŸ‘ 9 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Take your time, brother! You got this!

27.11.2024 14:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0