More discussion about election hacking with Voatz undergoing a more complete security assessment, we also discuss a few interesting web attacks and end with a good discussion about a new code-reuse mitigation: Hurdle.
[00:07:32] Pwn2Own Results
[01:08:12] Don't Clone That Repo: Visual Studio Code^2 Execution
https://github.com/doyensec/VSCode_PoC_Oct2019/
https://github.com/doyensec/VSCode_PoC_Oct2019/blob/master/.vscode/settings.json
https://github.com/doyensec/VSCode_PoC_Oct2019/commit/19b4687259bd5d1821525a3ebbe6aa76618359c3#diff-62b00de1d62bb867ef03dec7057712f1R50
[01:19:58] JavaScript without parentheses using DOMMatrix
https://portswigger.net/web-security/cross-site-scripting/contexts/lab-javascript-url-some-characters-blocked
[01:24:21] Hurdle: Securing Jump Instructions Against Code Reuse Attacks
https://www.youtube.com/watch?v=qFWTZ2zZ1XQ
http://se.ri0.us/2020-03-23-110829182-9e1b1.png
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@DAY[0])