Practical Applications of DEFCON 32 Web Research (Ep. 85)

Опубликовано: 27 Июнь 2026
на канале: Critical Thinking - Bug Bounty Podcast
2,718
90

Episode 85: In this episode of Critical Thinking - Bug Bounty Podcast
Justin and Joel talk through some of the research coming out of DEFCON, mainly from the PortSwigger team. Web timing attacks, cache exploitation, and exploits related to email protocols are all featured. Plus we also talk some fun Apache hacks from Orange Tsai

Follow us on twitter at:   / ctbbpodcast  

We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]

Shoutout to   / realytcracker   for the awesome intro music!

====== Links ======
Find the Hackernotes: https://blog.criticalthinkingpodcast.io/
Follow your hosts Rhynorater & Teknogeek on twitter:
  / 0xteknogeek  
  / rhynorater  

====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!

Check out our new SWAG store at https://ctbb.show/swag!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Today’s Sponsor - ThreatLocker
https://www.criticalthinkingpodcast.i...

Resources
Listen to the whispers
https://portswigger.net/research/list...

Splitting the email atom
https://portswigger.net/research/spli...

Gotta cache 'em all
https://portswigger.net/research/gott...

HTTP Garden
https://github.com/narfindustries/htt...

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
https://blog.orange.tw/2024/08/confus...

Trusted API Types
https://developer.mozilla.org/en-US/d...

Untrusted Types
https://github.com/filedescriptor/unt...

Timestamps:
(00:00:00) Introduction
(00:09:45) 'Listen to the whispers'
(00:30:03) 'Splitting the email atom'
(00:58:42) 'Gotta cache 'em all'
(01:21:03) 'Confusion Attacks'