Justin Gardner

@rhynorater.bsky.social

Christian | Full-time Bug Bounty Hunter | Host @ctbbpodcast.bsky.social | Advisor @caido.io | 3x LHE MVH | 🗣️ English, 日本語

Yo, new big thing: Shift. AI seamlessly integrated into your HTTP proxy. Use cases: "Take this JS and build the JSON request body" "Fill in these IDs from my notes - UserA" "Create a match and replace rule to turn on this feature flag" "Generate a wordlist with all HTTP Verbs"

I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions. I'm not gonna recite them again here, but today a new condition came up: No Content-Type header -> no CSRF restrictions Same-site: None POST = CSRF The research:

Alright, new platform so I'm going to start sharing some things that I'm excited about to keep the momentum flowing! Rn, I think the 403 Bypasser Caido plugin from Bebiks is freaking amazing. This is a tool to automate the bypassing of walled-off endpoints. This plugin does 3 things right:

Bild