Its a web-exploit heavy episode impacing Apple, Hasicorp, Azure, Google, and even a DOMPurify Bypass. Then we end-off with a look into benchmarking fuzzers, and a look at the House of Muney heap exploitation technique.
[00:14:03] Memory Safe 'curl' for a More Secure Internet
[01:15:47] Bypassing DOMPurify again with mutation XSS
https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/
https://github.com/marcinguy/jquery-xss-in-html
[01:28:11] UNIFUZZ: A Holistic, Pragmatic Metrics-Driven Platform for Evaluating Fuzzers
https://github.com/unifuzz/unibench
https://github.com/unifuzz
[01:47:15] House of Muney - Leakless Heap Exploitation Technique
https://github.com/mdulin2/house-of-muney
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@DAY[0])