Day[0]: Recent Episodes

dayzerosec

A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.

View Details

In this week's episode, we discuss Microsoft's summit with vendors on their intention to lock down the Windows kernel from endpoint security drivers and possibly anti-cheats. We also talk cryptography and about the problems of nonce reuse.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/256.html

[00:00:00] Introduction

[00:01:12] Friends don’t let friends reuse nonces

[00:13:22] Serious Cryptography, 2nd Edition

[00:14:30] Taking steps that drive resiliency and security for Windows customers

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We are back and testing out a new episode format focusing more on discussion than summaries. We start talking a bit about the value of learning hacking by iterating on the same exploit and challenging yourself as a means of practicing the creative parts of exploitation. Then we dive into the recent Intel SGX fuse key leak, talk a bit about what it means, how it happened.

We are seeking feedback on this format. Particularly interested in those of you with more of a bug bounty or higher-level focus if an episode like this would still be appealing? If you want to share any feedback feel free to DM us (@__zi or @specterdev) or email us at media [at] dayzerosec.com

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/255.html

[00:00:00] Introduction

[00:04:55] Exploiting CVE-2024-20017 4 different ways

[00:22:26] Intel SGX Fuse Keys Extracted

[00:51:01] Introducing the URL validation bypass cheat sheet

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Memory corruption is a difficult problem to solve, but many such as CISA are pushing for moves to memory safe languages. How viable is rewriting compared to mitigating?

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/254.html

[00:00:00] Introduction

[00:01:12] Clarifying Scope & Short/Long Term

[00:04:28] Mitigations

[00:15:37] Safe Languages Are Falliable

[00:21:20] Weaknesses & Evolution of Mitigations

[00:29:19] Rewriting and the Iterative Process

[00:34:55] The Rewriting Scalability Argument

[00:41:43] System vs App Bugs

[00:48:46] Mitigations & Rewriting Are Not Mutually Exclusive

[00:50:25] Corporate vs Open Source

[00:54:12] Generational Change

[00:56:18] Conclusion

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Change is in the air for the DAY[0] podcast! In this episode, we go into some behind the scenes info on the history of the podcast, how it's evolved, and what our plans are for the future.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/253.html

[00:00:00] Introduction[00:01:30] Early days of the DAY[0] podcast[00:14:10] Split into bounty and binary episodes[00:21:50] Novelty focus on topic selection[00:30:47] Difficulties with the current format[00:40:18] Change[00:48:02] New direction for content[00:57:42] Conclusions & Feedback

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Bit of a lighter episode this week with a Linux Kernel ASLR bypass and a clever exploit to RCE FortiGate SSL VPN.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/252.html

[00:00:00] Introduction

[00:00:29] KASLR bypass in privilege-less containers

[00:13:13] Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762

[00:19:32] Making Mojo Exploits More Difficult

[00:22:57] Robots Dream of Root Shells

[00:27:02] Gaining kernel code execution on an MTE-enabled Pixel 8

[00:28:23] SMM isolation - Security policy reporting (ISSR)

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

In this week's bounty episode, an attack takes an XSS to RCE on Mailspring, a simple MFA bypass is covered, and a .NET CRLF injection is detailed in its FTP functionality.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/251.html

[00:00:00] Introduction

[00:00:20] Making Desync attacks easy with TRACE

[00:16:01] Reply to calc: The Attack Chain to Compromise Mailspring

[00:35:29] $600 Simple MFA Bypass with GraphQL

[00:38:38] Microsoft .NET CRLF Injection Arbitrary File Write/Deletion Vulnerability [CVE-2023-36049]

Podcast episodes are available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

In the 250th episode, we have a follow-up discussion to our "Future of Exploit Development" video from 2020. Memory safety and the impacts of modern mitigations on memory corruption are the main focus.

View Details

In this episode we have an libXPC root privilege escalation, a run-as debuggability check bypass in Android, and digital lockpicking on smart locks.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/249.html

[00:00:00] Introduction

[00:00:21] Progress OpenEdge Authentication Bypass Deep-Dive [CVE-2024-1403]

[00:05:19] xpcroleaccountd Root Privilege Escalation [CVE-2023-42942]

[00:10:50] Bypassing the “run-as” debuggability check on Android via newline injection

[00:18:09] Say Friend and Enter: Digitally lockpicking an advanced smart lock (Part 2: discovered vulnerabilities)

[00:43:06] Using form hijacking to bypass CSP

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

In this week's binary episode, Binary Ninja Free releases along with Binja 4.0, automated infoleak exploit generation for the Linux kernel is explored, and Nintendo sues Yuzu.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/248.html

[00:00:00] Introduction

[00:00:31] Binary Ninja Free

[00:10:25] K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel

[00:19:53] Glitching in 3D: Low Cost EMFI Attacks

[00:22:08] Nintendo vs. Yuzu

[00:38:32] Finding Gadgets for CPU Side-Channels with Static Analysis Tools

[00:40:12] ThinkstScapes Research Roundup - Q4 - 2023

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A shorter episode this week, featuring some vulnerabilities impacting Google's AI and a SAML auth bypass.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/247.html

[00:00:00] Introduction

[00:00:31] We Hacked Google A.I. for $50,000

[00:17:26] SAML authentication bypass vulnerability in RobotsAndPencils/go-saml [CVE-2023-48703]

[00:22:17] Exploiting CSP Wildcards for Google Domains

[00:26:11] ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

VirtualBox has a very buggy driver, PostgreSQL has an Out of Bounds Access, and lifetime issues are demonstrated in Rust in "safe" code.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/246.html

[00:00:00] Introduction

[00:00:22] cve-rs

[00:18:28] Oracle VM VirtualBox: Intra-Object Out-Of-Bounds Write in virtioNetR3CtrlVlan

[00:32:30] PostgreSQL: Array Set Element Memory Corruption

[00:35:06] Analyzing the Google Chrome V8 CVE-2024-0517 Out-of-Bounds Code Execution Vulnerability

[00:37:15] Continuously fuzzing Python C extensions

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week's episode features a cache deception issue, Joomla inherits a PHP bug, and a DOM clobbering exploit. Also covered is a race condition in Chrome's extension API published by project zero.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/245.html

[00:00:00] Introduction

[00:00:21] Cache Deception Without Path Confusion

[00:07:15] Hello Lucee! Let us hack Apple again?

[00:14:41] Joomla: PHP Bug Introduces Multiple XSS Vulnerabilities

[00:26:37] Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild

[00:38:23] chrome.pageCapture.saveAsMHTML() extension API can be used on blocked origins due to racy access check

[00:42:28] 🎮 Diving Back into Games-related Bugs!

[00:44:43] Exploiting Empire C2 Framework

[00:46:19] iMessage with PQ3: The new state of the art in quantum-secure messaging at scale

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Linux becomes a CNA and takes a stance on managing CVEs for themselves, and underutilized fuzzing strategies are discussed.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/244.html

[00:00:00] Introduction

[00:00:14] What to do about CVE numbers

  • The first article we bring up is the 2019 LWN article able Greg's talk back then. The topic itself is a more recent change actually moving forward.

[00:26:50] Bug - Double free on dcm\_dataset\_insert · Issue #82 · ImagingDataCommons/libdicom

[00:31:48] Buffer Overflow Vulnerabilities in KiTTY Start Duplicated Session Hostname (CVE-2024-25003) & Username (CVE-2024-25004)Variables

[00:38:35] Underutilized Fuzzing Strategies for Modern Software Testing

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

In this bounty episode, some straightforward bugs were disclosed in GhostCMS and ClamAV, and Portswigger publishes their top 10 list of web hacking techniques from 2023.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/243.html

[00:00:00] Introduction

[00:02:15] Ghost CMS Stored XSS Leading to Owner Takeover [CVE-2024-23724]

[00:16:07] ClamAV Not So Calm [CVE-2024-20328]

[00:21:00] Top 10 web hacking techniques of 2023

[00:44:46] Hacking a Smart Home Device

[00:48:15] Cloud cryptography demystified: Amazon Web Services

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Google makes some changes to their kCTF competition, and a few kernel bugs shake out of the LogMeIn and wlan VFS drivers.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/242.html

[00:00:00] Introduction

[00:00:29] Netfilter Tables Removed from kCTF

[00:20:23] LogMeIn / GoTo LMIInfo.sys Handle Duplication

[00:27:20] Several wlan VFS read handlers don't check buffer size leading to userland memory corruption

[00:32:35] International Journal of Proof-of-Concept or Get The Fuck Out (PoC||GTFO) - 0x22

[00:34:15] Exploring AMD Platform Secure Boot

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

DEF CON moves venues, the Canadian government moves to ban Flipper Zero, and some XSS issues affect Microsoft Whiteboard and Meta's Excalidraw.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/241.html

[00:00:00] Introduction

[00:00:33] DEF CON was canceled.

[00:16:42] Federal action on combatting auto theft

[00:39:03] Jenkins Arbitrary File Leak Vulnerability, CVE-2024-23897, Can Lead To RCE

[00:43:27] Back to the (Clip)board with Microsoft Whiteboard and Excalidraw in Meta (CVE-2023-26140)

[00:52:26] SSRF on a Headless Browser Becomes Critical!

[00:59:04] ChatGPT Account Takeover - Wildcard Web Cache Deception

[01:05:14] Differential testing and fuzzing of HTTP servers and proxies

[01:10:14] Hunting for Vulnerabilities that are ignored by most of the Bug Bounty Hunters

[01:19:38] Analyzing AI Application Threat Models

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Libfuzzer goes into maintenance-only mode and syslog vulnerabilities plague some vendors in this week's episode.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/240.html

[00:00:00] Introduction

[00:00:20] LibFuzzer in Maintainence-only Mode

[00:11:41] Heap-based buffer overflow in the glibc's syslog() [CVE-2023-6246]

[00:26:33] Hunting for ~~Un~~authenticated n-days in Asus Routers

[00:34:44] Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution

[00:35:51] Chaos Communication Congress (37C3) recap

[00:36:51] GitHub - google/oss-fuzz-gen: LLM powered fuzzing via OSS-Fuzz.

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we have a crazy crypto fail where some Android devices had updates signed by publicly available private keys, as well as some Docker container escapes.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/239.html

[00:00:00] Introduction

[00:00:22] Missing signs: how several brands forgot to secure a key piece of Android

[00:13:37] ModSecurity: Path Confusion and really easy bypass on v2 and v3

[00:21:24] runc process.cwd & leaked fds container breakout [CVE-2024-21626]

[00:24:23] Buildkit GRPC SecurityMode Privilege Check [CVE-2024-23653]

[00:27:49] Jumpserver Preauth RCE Exploit Chain

[00:43:49] 500$: MFA bypass By Race Condition

[00:49:52] HTTP Downgrade attacks with SmuggleFuzz

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week's binary episode features a range of topics from discussion on Pwn2Own's first automotive competition to an insane bug that broke ASLR on various Linux systems. At the lower level, we also have some bugs in UEFI, including one that can be used to bypass Windows Hypervisor Code Integrity mitigation.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/238.html

[00:00:00] Introduction

[00:02:40]

37C3: Unlocked

  • media.ccc.de

[00:08:15] Zero Day Initiative — Pwn2Own Automotive 2024 - Day One Results

[00:16:35] ASLRn’t: How memory alignment broke library ASLR

[00:22:47] Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)

[00:26:33] PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack.

[00:31:10] Hunting down the HVCI bug in UEFI

[00:35:51] A Deep Dive into V8 Sandbox Escape Technique Used in In-The-Wild Exploit

[00:37:32] Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution - Exodus Intelligence

[00:38:38] OffSec EXP-401 Advanced Windows Exploitation (AWE) - Course Review

[00:44:56] Dumping GBA ROMs from Sound

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A packed episode this week as we cover recent vulnerabilities from the last two weeks, including some IDORs, auth bypasses, and a HackerOne bug. Some fun attacks such as a resurface of IDN Homograph Attacks and timing attacks also appear.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/237.html

[00:00:00] Introduction

[00:02:59]

37C3: Unlocked

  • media.ccc.de

[00:09:00] Ivanti's Pulse Connect Secure Auth Bypass and RCE

[00:19:47] [HackerOne] View Titles of Private Reports with pending email invitation

[00:23:58] 1 Program, 4 Business Logic Bugs and Cashing in 2300$.

[00:33:32] Global site selector authentication bypass

[00:42:55] IDN Homograph Attack - Reborn of the Rare Case

[00:50:53] PII Disclosure At theperfumeshop.com/register/forOrder

[00:54:40] [darkhttpd] timing attack and local leak of HTTP basic auth credentials

[01:02:42] Ransacking your password reset tokens

[01:08:11] Worse than SolarWinds: Three Steps to Hack Blockchains, GitHub, and ML through GitHub Actions

[01:10:41] Crypto Gotchas!

[01:13:37] Web LLM attacks

[01:15:13] Improving LLM Security Against Prompt Injection

[01:16:17] Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise

[01:17:37] Kubernetes Scheduling And Secure Design

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A bit of a game special this week, with a Counter-Strike: Global Offensive vulnerability and an exploit for Factorio. We also have a Linux kernel bug and a Chromecast secure-boot bypass with some hardware hacking mixed in.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/236.html

[00:00:00] Introduction

[00:00:25] Exploring Counter-Strike: Global Offensive Attack Surface

[00:26:22] Exploiting a Factorio Buffer Overflow

[00:31:46] io_uring: __io_uaddr_map() handles multi-page region dangerously

[00:39:25] Chromecast with Google TV (1080P) Secure-Boot Bypass

[00:51:58] exploits.club

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A short bounty episode featuring some logical bugs in Apache OFBiz, a GitLab Account Takeover, and an unauthenticated RCE in Adobe Coldfusion.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/235.html

[00:00:00] Introduction

[00:00:20] SonicWall Discovers Critical Apache OFBiz Zero-day

[00:11:40] [GitLab] Account Takeover via password reset without user interactions

[00:24:05] Unauthenticated RCE in Adobe Coldfusion [CVE-2023-26360]

[00:35:08] No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

[00:36:45] How we made $120k bug bounty in a year with good automation

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week's highly technical episode has discussion around the exploitation of a libwebp vulnerability we covered previously, memory tagging (MTE) implementation with common allocators, and an insane iPhone exploit chain that targeted researchers.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/234.html

[00:00:00] Introduction

[00:02:35] PagedOut Issue 3

[00:05:14] GPSd NTRIP Stream Parsing access violation vulnerability

[00:08:25] Exploiting the libwebp Vulnerability, Part 1: Playing with Huffman Code

[00:30:01] Strengthening the Shield: MTE in Heap Allocators

[00:37:40] Operation Triangulation - What you get when you attack iPhones of Researchers

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Kicking off 2024 with a longer episode as we talk about some auditing desktop applications (in the context of some bad reports to Edge). Then we've got a couple fun issues with a client-side path traversal, and a information disclosure due to a HTTP 307 redirect. A bunch of issues in PandoraFSM, and finally some research about parser differentials in SMTP leading to SMTP smuggling (for effective email spoofing).

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/233.html

[00:00:00] Introduction

[00:10:25] Browser Security Bugs that Aren’t - #1: Local Attacks

[00:22:10] The power of Client-Side Path Traversal: How I found and escalated 2 bugs through “../”

[00:32:30] instipod DuoUniversalKeycloakAuthenticator challenge information disclosure vulnerability

[00:38:25] Technical Advisory – Multiple Vulnerabilities in PandoraFMS Enterprise

[00:45:07] SMTP Smuggling - Spoofing E-Mails Worldwide

[01:16:20] Catching OpenSSL misuse using CodeQL

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A bit of a rambling episode to finish off 2023, we talk about some Linux kernel exploitation research (RetSpill) then get into several vulnerabilities. A type confusion in QNAP QTS5, a JavaScriptCore bug in Safari, and several issues in Steam's Remote Play protocol.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/232.html

[00:00:00] Introduction

[00:02:00] RetSpill - Igniting User-Controlled Data to Burn Away Linux Kernel Protections

[00:12:23] QNAP QTS5 – /usr/lib/libqcloud.so JSON parsing leads to RCE

[00:19:53] Safari, Hold Still for NaN Minutes!

[00:31:00] Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A mix of issues this week, not traditionally bounty topics, but there are some lessons that can be applied. First is a feature, turned vulnerability in VS Code which takes a look at just abusing intentional functionality. Several XOS bugs with a web-console. A Sonos Era 100 jailbreak which involves causing a particular call to fail, a common bug path we've seen before, and some discussion about doing fast DNS rebinding attacks against Chrome and Safari.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/231.html

[00:00:00] Introduction

[00:01:00] It’s not a Feature, It’s a Vulnerability

[00:13:40] Multiple Vulnerabilities In Extreme Networks ExtremeXOS

[00:24:06] Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100

[00:30:08] Tricks for Reliable Split-Second DNS Rebinding in Chrome and Safari

[00:46:02] Apache Struts2 文件上传漏洞分析(CVE-2023-50164) - 先知社区

[00:48:49] Blind CSS Exfiltration: exfiltrate unknown web pages

[00:51:11] Finding that one weird endpoint, with Bambdas

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A Samsung special this week, starting off with two Samsung specific vulnerabilities, one in the baseband chip for code execution. And a stack based overflow in the RILD service handler parsing IPC calls from the baseband chip for a denial of service. Lastly a Mali GPU driver use-after-free.Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/230.html[00:00:00] Introduction[00:00:27] Humble Tech Book Bundle: Hacking 2023 by No Starch[00:08:15] CVE-2023-21517: Samsung Baseband LTE ESM TFT Heap Buffer Overflow[00:18:10] CVE-2023-30644: Samsung RIL Stack Buffer Overflow[00:24:58] Arm Mali r44p0: UAF by freeing waitqueue with elements on it[00:31:55] A Detailed Look at Pwn2Own Automotive EV Charger HardwareThe DAY[0] Podcast episodes are streamed live on Twitch twice a week: -- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities -- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.We are also available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosecYou can also join our discord: https://discord.gg/daTxTK9

View Details

This week brings up a pretty solid variety of issues. Starting off with some cookie smuggling (and other cookie attacks) which presents some interesting research I hadn't really looked for before that has some potential. Then an AI alignment evasion to leak training data. Not the most interesting attack but it appears to open up some other ideas for further research. A MacOS desktop issue (for a $30k bounty), and some home assistant issues.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/229.html

[00:00:00] Introduction

[00:00:25] Humble Tech Book Bundle: Hacking 2023 by No Starch

[00:06:58] Cookie Bugs - Smuggling & Injection

[00:17:21] Extracting Training Data from ChatGPT

[00:32:22] lateralus (CVE-2023-32407) - a macOS TCC bypass

[00:37:35] Securing our home labs: Home Assistant code review

[00:45:16] TRAP; RESET; POISON; - Taking over a country Kaminsky style

[00:47:04] Exploiting XPath Injection Weaknesses

[00:47:42] Deep dive into the new Amazon EKS Pod Identity feature

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week kicks off with a a V8 misoptimization leading to out-of-bounds access, an unprotected MSR in Microsoft's Hypervisor allowing corruption of Hypervisor code. We also take a quick look at a 2021 CVE with an integer underflow leading to an overflow in the Windows Kernel low-fragmentation heap, and finally an interesting information leak due to the kernel not clearing a sensitive register.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/228.html

[00:00:00] Introduction

[00:00:56] Spot the Vuln - Beyond the Grave

[00:04:00] Chrome V8 Hole Exploit

[00:15:57] How I found Microsoft Hypervisor bugs as a by-product of learning

[00:33:13] Exploitation of a kernel pool overflow from a restrictive chunk size [CVE-2021-31969]

[00:44:13] That's FAR-out, Man

[00:47:38] Money Tree

[00:50:21] How to voltage fault injection

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we've got a few relatively simple bugs to talk about along with a discussion about auditing and manually analysis for vulnerabilities.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/227.html

[00:00:00] Introduction

[00:00:23] Introducing the Microsoft Defender Bounty Program

[00:04:26] Tapping into a telecommunications company’s office cameras

[00:07:47] CrushFTP Critical Vulnerability CVE-2023-43177 Unauthenticated Remote Code Execution

[00:17:22] [Kubernetes] Ingress nginx annotation injection causes arbitrary command execution

[00:24:38] Testing for audits: there is no spoon

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Last week we brought you several Windows bugs, this week we are talking Linux kernel vulnerabilities and exploitation. We start off looking at a weird but cool CPU bug, Reptar, then we get into nftables, io_uring, and talk about a newer mitigations hitting Linux 6.6 that randomizes the caches allocations end up in.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/226.html

[00:00:00] Introduction

[00:00:21] Reptar

[00:11:56] One shot, Triple kill: Pwning all three Google kernelCTF instances with a single 1-day Linux vulnerability

[00:31:09] Conquering the memory through io_uring - Analysis of CVE-2023-2598

[00:38:00] Exploring Linux's New Random Kmalloc Caches

[00:48:09] ThinkstScapes Quarterly - 2023.Q3

[00:49:34] CacheWarp

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week has an interesting mix of issues, starting with a pretty standard template inject. Then we get into a Windows desktop issue, a TOCTOU in how the Mark-of-the-Web would be applied to file extracted from an archive, a privilege escalation from a Chrome extension, and a bit of a different spin on what you could do with a prompt injection.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/225.html

[00:00:00] Introduction

[00:00:26] Magento Template Engine, a story of CVE-2022-24086

[00:06:57] In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584

[00:24:50] Google Cloud Vertex AI - Data Exfiltration Vulnerability Fixed in Generative AI Studio

[00:30:40] Uncovering a crazy privilege escalation from Chrome extensions

[00:47:49] Content Providers and the potential weak spots they can have

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We've got a few Windows bugs this week, but first a fun off-by-one null-byte write. Then we jump into a containerized registry escape, a browser escape with a very simple bug buried deep in the browser, and a kernel bug.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/224.html

[00:00:00] Introduction

[00:00:20] Spot the Vuln - Minimax

[00:05:00] Weston Embedded uC-HTTP HTTP Server Host header parsing memory corruption vulnerability

[00:14:49] Windows Kernel containerized registry escape through integer overflows in VrpBuildKeyPath and other weaknesses

[00:20:04] Escaping the sandbox: A bug that speaks for itself

[00:37:07] Exploiting Windows Kernel Wild Copy With User Fault Handling [CVE-2023–28218]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Just a few issues this week, a Mastodon normalization issue leading to the potential to impersonate another account. Then we have a more complex chain starting again with a normalization leading to a fairly interesting request smuggling (CL.0 via malformed content-type header) and cache poisoning to leak credentials. Finally a crypto issue with a signature not actually being a signature.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/223.html

[00:00:00] Introduction

[00:00:23] Usurping Mastodon instances - mastodon.so/cial [CVE-2023-42451]

[00:09:59] From Akamai to F5 to NTLM... with love.

[00:33:36] Our Pwn2Own journey against time and randomness (part 2)

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

As memory tagging (MTE) finally comes to a consumer device, we talk about how it may impact vulnerability research and exploit development going forward. Then we get into a few vulnerabilities including a DNS response parsing bug on the Wii U, an Adobe Acrobat bug that was exploited by a North Korean APT, and a CPU bug (iTLB Multihit).

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/222.html

[00:00:00] Introduction

[00:00:23] Hexacon 2023 Talks

[00:02:48] First handset with MTE on the market

[00:24:15] Exploiting DNS response parsing on the Wii U

[00:33:11] Adobe Acrobat PDF Reader RCE when processing TTF fonts [CVE-2023-26369

[00:46:18] iTLB multihit

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Kicking off the week with a bit of Pwn2Own drama, then taking a look at an OAuth attack against Grammarly and a couple other sites, a fun little polyglot file based attack, and Citrix Bleed, a snprintf information disclosure vulnerability on the web.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/221.html

[00:00:00] Introduction

[00:01:24] Wyze Cam v3 - Pwn2Own Drama

[00:17:57] Oh-Auth - Abusing OAuth to take over millions of accounts

[00:30:55] Exploiting Healthcare Servers with Polyglot Files [CVE-2023-33466]

[00:41:06] Citrix Bleed: Leaking Session Tokens with CVE-2023-4966

[00:49:25] Hacking a Silent Disco

[00:50:43] DOM-based race condition: racing in the browser for fun

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Diving right into some binary exploitation issues this week. Starting wtih a look at a rare sort of curl vulnerability where a malicious server could compromise a curl user. Then we take a look at a pretty straight-forward type confusion in Windows kernel code, and an integer underflow in Safari with some questionable exploitation. Ending the episode with some thoughts on how impactful grsecurity's "constify" mitigation could be.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/220.html

[00:00:00] Introduction

[00:00:14] How I made a heap overflow in curl

[00:17:32] Critically close to zero (day): Exploiting Microsoft Kernel streaming service

[00:30:34] Story of an innocent Apple Safari copyWithin gone (way) outside [CVE-2023-38600]

[00:38:10] CONSTIFY: Fast Defenses for New Exploits

[00:46:53] An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit

[00:47:40] Getting RCE in Chrome with incomplete object initialization in the Maglev compiler

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We've got a mix of topics this week, started with a bit of discussion around the recent Rapid Reset denial of service attack, before diving into a few vulnerabilities. A Node "permissions" module escape due to having a fail-open condition when unexpected but supported types are passed in. Then we talk about some common AWS Cognito issues, a fun little privilege escalation in Confluence, and a log injection bug leading to RCE.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/219.html

[00:00:00] Introduction

[00:00:15] HTTP/2 Rapid Reset Attack [CVE-2023-44487]

[00:04:35] [Node] Path traversal through path stored in Uint8Array

[00:09:44] Attacking AWS Cognito with Pacu

[00:14:33] Privilege Escalation Vulnerability in Confluence Data Center and Server [CVE-2023-22515]

[00:21:15] Not Your Stdout Bug - RCE in Cosmos SDK

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

View Details

Some complex and confusing vulnerabilities as we talk about the recent WebP 0day and the complexities of huffman coding. A data-only exploit to escape a kCTF container, the glibc LPE LOONY_TUNABLES, and a Chrome TurboFan RCE.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/218.html

[00:00:00] Introduction

[00:00:40] Expanding our exploit reward program to Chrome and Cloud

[00:06:10] The WebP 0day

  • We do somewhat downplay this issue due to the difficulty of exploiting it. But to be clear, it was exploited in the wild on Apple devices, so it exploitable. We're more downplaying the panic that came up around it. It is still a serious issue that should be patched.

[00:34:00] Escaping the Google kCTF Container with a Data-Only Exploit

[00:44:49] Local Privilege Escalation in the glibc's ld.so [CVE-2023-4911]

[01:01:27] Getting RCE in Chrome with incorrect side effect in the JIT compiler

[01:08:03] Behind the Shield: Unmasking Scudo's Defenses

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we've got some fun issues, including a WinRAR processing bug that results in code execution due (imo) to a filename adjustment when extracting that isn't performed consistently. A MyBB admin-panel RCE, fairly privileged bug but I think the bug pattern could appear elsewhere and is something to watch out for, And several silly issues in a "next-gen" firewall, including source disclosures and RCEs from the login page.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/217.html

[00:00:00] Introduction

[00:01:17] Analysis of CVE-2023-38831 Zero-Day vulnerability in WinRAR

[00:13:32] Yet More Unauth Remote Command Execution Vulns in Firewalls

[00:29:02] MyBB Admin Panel RCE [CVE-2023-41362]

[00:44:55] How to build custom scanners for web security research automation

[00:46:33] Exploiting HTTP Parsers Inconsistencies

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A binary summer-recap episode, looking at some vulnerabilities and research put out over the summer. Talking about what TPM really offers when it comes to full-disk encryption, some thoughts on AI in the fuzzing loop. Then into some cool bugs, kicking off with some ARM Memory Tagging Extension vulnerabilities, a -fstack-protector implementation failure and bypass, and then a look at a Android exploit that was found in-the-wild.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/216.html

[00:00:00] Introduction

[00:01:50] Spot the Vuln - Only One Domain

[00:04:46] AI-Powered Fuzzing: Breaking the Bug Hunting Barrier

[00:15:00] Summary: MTE As Implemented

[00:38:21] TPM provides zero practical security

[00:47:30] CVE-2023-4039: GCC’s -fstack-protector fails to guard dynamic stack allocations on ARM64

[00:55:30] Analyzing a Modern In-the-wild Android Exploit

[01:07:31] Various Vulnerabilities in Huawei Trustlets

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We are back, and talking about our summer with a lengthy discussion about our DEF CON experiences before getting into some favorite issues from the summer. Including a neat twist on a PHP security feature that might be using in your bug bounty chains. A look at classic crypto issue (unauthenticated encrypted blobs), and an easily missed caching issue.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/215.html

[00:00:00] Introduction

[00:02:15] Summer Recap - HardwearIO

[00:11:51] Summer Recap - DEF CON

[00:49:20] CVE-2020-19909 is everything that is wrong with CVEs

[00:58:40] PHP servers drop any header if the header has "\r" [@OctagonNetworks]

[01:03:10] Encrypted Doesn't Mean Authenticated: ShareFile RCE [CVE-2023-24489]

[01:11:40] How Private Cache Can Lead to Mass Account Takeover

[01:15:20] From Terminal Output to Arbitrary Remote Code Execution

[01:16:37] Mashing Enter to bypass full disk encryption with TPM, Clevis, dracut and systemd

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

BugBounty #BugHunting #InfoSec #CyberSec #Podcast

Continue? (y/N) n

2023/09/26 00:57:09 [1] Set Start Time and Offset

2023/09/26 00:57:09 [2] Download and Convert Episode

2023/09/26 00:57:09 [3] Youtube Stuff

2023/09/26 00:57:09 [4] Print Episode

2023/09/26 00:57:09 [5] Create Blog Post

Selection: 4

2023/09/26 00:57:11 215 - DEF CON, HardwearIO, Broken Caching, and Dropping Headers [Bug Bounty Podcast]

[bounty] DEF CON, HardwearIO, Broken Caching, and Dropping Headers

============================================

We are back, and talking about our summer with a lengthy discussion about our DEF CON experiences before getting into some favorite issues from the summer. Including a neat twist on a PHP security feature that might be using in your bug bounty chains. A look at classic crypto issue (unauthenticated encrypted blobs), and an easily missed caching issue.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/215.html

[00:00:00] Introduction

[00:02:15] Summer Recap - HardwearIO

[00:11:51] Summer Recap - DEF CON

[00:49:20] CVE-2020-19909 is everything that is wrong with CVEs

[00:58:40] PHP servers drop any header if the header has "\r" [@OctagonNetworks]

[01:03:10] Encrypted Doesn't Mean Authenticated: ShareFile RCE [CVE-2023-24489]

[01:11:40] How Private Cache Can Lead to Mass Account Takeover

[01:15:20] From Terminal Output to Arbitrary Remote Code Execution

[01:16:37] Mashing Enter to bypass full disk encryption with TPM, Clevis, dracut and systemd

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we've got a handful of low-level vulns, VM-escape, Windows EoP, and a single IPv6 packet leading to a kernel panic/denial of service, and one higher-level issue with a bug chain in CS:GO.

This is our final episode until September 25th as we will be heading off on our regular summer break.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/214.html

[00:00:00] Introduction

[00:01:12] Spot the Vuln - Reference Check

[00:06:56] Exploiting VMware Workstation at Pwn2Own Vancouver [CVE-2023-20869/20870]

[00:17:44] CS:GO: From Zero to 0-day

[00:30:27] CVE-2022-41073: Windows Activation Contexts EoP

[00:38:37] Linux IPv6 Route of Death 0day

[00:46:36] Google Chrome V8 ArrayShift Race Condition Remote Code Execution

[00:47:46] Specter Will Give Hardwear.IO PS5 Talk

[00:49:11] Resources while we are on bread

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Another bug bounty podcast, another set of vulnerabilities. Starting off with a desktop info-disclosure in KeePass2 that discloses master passwords to attackers (with a high-level of access). A couple Jellyfin bugs resulting in an RCE chain, and a pretty classic crypto issue that allowed for renting luxury cars for extremely cheap.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/213.html

[00:00:00] Introduction

[00:02:48] KeePass2 Password Disclosure

[00:10:10] Peanut Butter Jellyfin Time

[00:19:14] Abusing Time-Of-Check Time-Of-Use (TOCTOU) Race Condition Vulnerabilities in Games, Harry Potter Style

[00:22:19] Discovering a Hidden Security Loophole: Rent luxury Cars for a Single Dollar

[00:27:00] Bug bounties are broken – the story of “i915” bug, ChromeOS + Intel bounty programs, and beyond

[00:35:28] Resources while we are on break

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we we've got a neat little printer corruption, a probably unexploitable stockfish bug, though we speculate about exploitation a bit. Then into a VirtualBox escape bug, and an Andreno "vulnerability".

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/212.html

[00:00:00] Introduction

[00:01:31] Spot the Vuln - To Upload or Not To Upload

[00:05:25] The printer goes brrrrr, again!

[00:09:34] [Stockfish] Increase MAX_MOVES to prevent buffer overflow and stack corruption

[00:27:53] Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991

[00:37:09] Qualcomm Adreno/KGSL: secure buffers are addressable by all GPU users

[00:43:37] RET2ASLR - Leaking ASLR from return instructions

[00:46:13] Apple Fails to Fully Reboot iOS Simulator Copyright Case

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

More bug bounty style bugs, but you'd be forgiven reading that title thinking we had a low-level focus this episode. We got some awesome bugs this week though from tricking Dependabot and abusing placeholder values, an IIS auth bypass. Ending off with a kernel bug (OverlayFS) and a VM escape (Parallels Desktop)

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/211.html

[00:00:00] Introduction

[00:00:28] Dependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot

[00:12:39] Placeholder for Dayzzz: Abusing placeholders to extract customer informations

[00:19:40] Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3

[00:33:44] PwnAssistant - Controlling /home's via a Home Assistant RCE

[00:39:26] The OverlayFS vulnerability [CVE-2023-0386]

[00:44:01] Escaping Parallels Desktop with Plist Injection

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

BugBounty #BugHunting #InfoSec #CyberSec #Podcast

View Details

This week we go a bit deeper than normal and look at some low level TPM attacks to steal keys. We've got a cool attack that lets us leak a per-chip secret out of the TPM one byte at a time, and a post about reading Bitlocker's secret off the SPI bus. Then we talk about several Shannon baseband bugs disclosed by Google's Project Zero.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/210.html

[00:00:00] Introduction

[00:01:14] Spot the Vuln - Sanitize Now or Later

[00:03:50] faulTPM: Exposing AMD fTPMs’ Deepest Secret

[00:18:33] Stealing the Bitlocker key from a TPM

[00:24:01] Shannon Baseband: Integer overflow when reassembling IPv4 fragments

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We open up this weeks bug bounty podcast with a discussion about Google's recent support for passkeys, tackling some misunderstanding about what they are and how open the platform is. Also some talk towards the end about potential vulnerabilities to look out for. Then we dive into the vulnerabilities for the week, involving bypassing phone validation in OpenAI, a bad origin check enabling abuse of a permissive CORS policy, and an order of operations issue breaking the purpose of sanitization in Oracle's Opera.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/209.html

[00:00:00] Introduction

[00:02:43] So long passwords, thanks for all the phish

[00:23:49] OpenAI Allowed “Unlimited” Credit on New Accounts

[00:28:53] A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF...

[00:44:28] Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera

[00:52:16] Testing Zero Touch Production Platforms and Safe Proxies

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Not a lot of interesting binary exploitation topics for this week, we've got a DHCPv6 service vuln, and a fun idea to use a timing side-channel to improve exploit stability. Then we end with a discussion about Rust coming the Windows operating system, what Rust means for the future of exploit development and vulnerability research and the value of memory corruption in Windows.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/208.html

[00:00:00] Introduction

[00:00:17] Spot the Vuln - Organizational Issues

[00:09:21] RCE in the Microsoft Windows DHCPv6 Service [CVE-2023-28231]

[00:12:29] PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique

[00:22:16] Rust and the future of VR

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

On this weeks bug bounty podcast we take a look at a few interesting issues. While they are all patched, there is reason to believe they'd all creep up in other applications too. First up is an RCE due to nested use of an escaped string. Second a fgets loop that doesn't account for long lines. A XML signature verification tool with a deceptive interface, and last a look at how Bash's privileged mode can backfire.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/207.html

[00:00:00] Introduction

[00:00:31] Analysis of Pre-Auth RCE in Sophos Web Appliance [CVE-2023-1671]

[00:07:16] Git Arbitrary Configuration Injection [CVE-2023-29007]

[00:11:41] Redash SAML Authentication Bypass

[00:18:51] Bash Privileged-Mode Vulnerabilities in Parallels Desktop and CDPATH Handling in MacOS

[00:29:38] Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO

[00:34:37] [cPanel] Finding XSS in a million websites [CVE-2023-29489]

[00:35:20] Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score [CVE-2023-1767]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week's binary exploitation episode has some pretty solid bugs.A string escaping routine that goes out of bounds, a web-based information disclosure. And a couple kernel issues, one in the Windows registry, a logical bug leading to memory corruption, and an AppleSPU out of bounds access.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/206.html

[00:00:00] Introduction

[00:00:30] Reversing the AMD Secure Processor (PSP) - Part 1: Design and Overview

[00:01:15] Spot the Vuln - Left-over Spaces

[00:05:03] Shell in the Ghost: Ghostscript CVE-2023-28879 writeup

[00:17:16] SecurePwn Part 2: Leaking Remote Memory Contents [CVE-2023-22897]

[00:21:50] Windows Kernel insufficient validation of new registry key names in transacted NtRenameKey

[00:30:38] CVE-2022-32917: AppleSPU out of bounds write

[00:34:11] Compromising Garmin's Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine

[00:35:27] The Fuzzing Guide to the Galaxy: An Attempt with Android System Services

[00:36:51] Stepping Insyde System Management Mode

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

For this week's bug bounty podcast We start off with a bit of a unique auth bypass in a firewall admin panel. We've also got a couple desktop-based software bugs, with a Docker Desktop privilege escalation on windows, and a chfn bug. We've also got a couple escalation techniques, one for Azure environments, and another trick for exploiting semi-controlled file-writes.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/205.html

[00:00:00] Introduction

[00:00:32] SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication [CVE-2023-22620]

[00:08:41] Abusing Linux chfn to Misrepresent etc passwd [CVE-2023-29383]

[00:14:39] Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2

[00:22:42] From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys

[00:25:52] Pretalx Vulnerabilities: How to get accepted at every conference

[00:34:07] LLM Hacker's Handbook

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We start with a hardware/glitching attack against the Wii U, then lets talk about integer overflows. We've got three integer overflows this week that lead to buffer overflows in different ways.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/204.html

[00:00:00] Introduction

[00:00:19] Spot the Vuln - Easy as ABC

[00:06:18] de_Fuse, the One True Pwn

[00:15:31] SonicWall Out Of Bounds Write DoS

[00:26:43] Windows bluetooth vulnerability exploit [CVE-2022-44675]

[00:28:52] Windows bluetooth vulnerability exploit [CVE-2022-44675]

[00:30:06] Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Some fun issues this week as we explore code execution in Synthetics Recorder stemming from a comment in the code. An auth bypass in Pentaho leading to RCE via SSTI, car theft via CAN bus message injection, and how to become a cluster admin from a compromised pod in AWK Elastic Kubernetes Service.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/203.html

[00:00:00] Introduction

[00:00:30] [Elastic] Synthetics Recorder: Code injection when recording website with malicious content

[00:02:45] [Elastic] Synthetics Recorder: Code injection when recording website with malicious content

[00:06:32] Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server

[00:13:47] CAN Injection: keyless car theft

[00:23:48] Privilege escalation in AWS Elastic Kubernetes Service (EKS)

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Just a few bugs this week, a classic buffer overflow because of an unbounded copy in SNIProxy. mast1c0re Part 2 with a few more easy vulnerability but some more complex and difficult exploitation. And a Samsung NPU in-the-wild double free.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/202.html

[00:00:00] Introduction

[00:00:24] Spot The Vuln - Operational Set

[00:03:37] SNIProxy wildcard backend hosts buffer overflow vulnerability

[00:08:17] mast1c0re Part 2 - Compiler Attack

[00:21:46] Samsung NPU device driver double free in Android [CVE-2022-22265]

[00:41:52] CodeQL zero to hero part 1: the fundamentals of static analysis for vulnerability research

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Some audio issues this week, sorry for the ShareX sound. But we have a few interesting issues. A curl quirk that it might be useful to be aware of, Azure Pipelines vulnerability abusing attacker controlled logging. A look at a pretty classic Android/mobile bug, and a crazy auth misconfiguration (BingBang).

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/201.html

[00:00:00] Introduction

[00:00:39] The curl quirk that exposed Burp Suite and Google Chrome

[00:03:33] Exploiting prototype pollution in Node without the filesystem

[00:05:37] Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack

[00:11:27] Attacking Android Antivirus Applications

[00:20:59] BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Its our 200th episode, and we've got some stats from our first 200 episodes. Then we talk some Pwn2Own policy changes, a couple memeable overflows, and some new anti-ROP mitigations on OpenBSD.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/200.html

[00:00:00] Introduction

[00:00:52] Spot the Vuln - Just a Coupon

[00:04:56] 200th Episode

[00:14:52] Pwn2Own Vancouver 2023 - The Full Schedule

[00:23:26] WellinTech KingHistorian SORBAx64.dll RecvPacket integer conversion vulnerability

[00:28:23] ARM TrustZone: pivoting to the secure world

[00:34:33] Synthetic Memory Protections - An update on ROP mitigations

[00:57:51] Vulnerabilities 1002: C-Family Software Implementation Vulnerabilities

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We are back with more discussion about applying AI/ChatGPT to security research, but before that we have a few interesting vulnerabilities. An OTP implementation that is too complex for its own good, a directory traversal leading to a guest to host VM escape, and server-side mime-sniffing.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/199.html

[00:00:00] Introduction

[00:00:31] Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research

[00:07:45] Story of a Beautiful Account Takeover

[00:14:06] Parallels Desktop Toolgate Vulnerability

[00:18:50] Golang Server-Side MIME Sniff

[00:25:55] InjectGPT: the most polite exploit ever

[00:32:36] ChatGPT: The Right Tool for the Job?

[00:40:38] GPT Trick Golf

[00:49:19] [HackerOne] Arbitrary Remote Leak via ImageMagick [CVE-2022-44268]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We've got a pretty nice root/super-use check bypass in XNU this week, and a sort of double fetch issue in Intel's SMM leading to a potential privilege escalation into the Management system. We've also got a few meme-able Shannon Baseband issues and some tough to exploit out of bound reads in MIT Kerberos V5.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/198.html

[00:00:00] Introduction

[00:00:27] Spot the Vuln - The Right Context

[00:02:52] Discussion: Using GPT-4 to Spot Vulnerabilities in Code (and SecGPT)

[00:11:05] A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM

[00:19:32] Out-of-Bounds Read in the MIT Kerberos V5 (krb5) library

[00:25:35] XNU: NFSSVC root check bypass; use after free due to insufficient locking in upcall worker threads

[00:32:36] XNU: NFSSVC root check bypass; use after free due to insufficient locking in upcall worker threads

[00:36:35] Shannon Baseband: Intra-object overflow in NrmmMsgCodec when decoding Service Area List

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Recovering data from a cropped image (thanks to an undocumented API change, bypassing an origin check with an emoji, and a trivial SSRF filter bypass all in this week's bug bounty podcast.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/197.html

[00:00:00] Introduction

[00:00:32] SSRF Cross Protocol Redirect Bypass

[00:08:08] EmojiDeploy: Smile! Your Azure Web Service Got RCE’d ._.

[00:20:43] Multiple vulnerabilities in Apollo Configuration Management System [CVE-2023-25569, CVE-2023-25570]

[00:29:00] Exploiting aCropalypse: Recovering Truncated PNGs

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Some simple, but interesting vulnerabilities. A use-after-free because of wrong operation ordering, an interesting type confusion, an integer underflow and some OOB access in TPM 2.0 reference code.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/196.html

[00:00:00] Introduction

[00:00:27] Spot the Vuln - Just be Positive

[00:03:42] oss-sec: Linux kernel: CVE-2023-1118: UAF vulnerabilities in "drivers/media/rc" directory

[00:07:56] oss-sec: CVE-2023-1076: Linux Kernel: Type Confusion hardcodes tuntap socket UID to root

[00:11:21] GitHub - fuzzingrf/openbsd_tcpip_overflow: OpenBSD remote overflow

[00:14:36] Chat Question: What Language is Most Effective for Writing These Types of Exploits

[00:18:22] Vulnerabilities in the TPM 2.0 reference implementation code

[00:28:19] Chat Question: Skillset for Exploit Dev as part of a Red Team

[00:33:40] Espressif ESP32: Glitching The OTP Data Transfer

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A few varied issues this week, exploiting an apparently unexploitable CRLF injection, organization secrets exposure in GitHub, and a Jenkins XSS.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/195.html

[00:00:00] Introduction

[00:00:25] Abusing Hop-by-Hop Header to Chain A CRLF Injection Vulnerability

[00:04:26] HubSpot Full Account Takeover in Bug Bounty

[00:12:22] Unauthorized access to organization secrets in GitHub

[00:17:39] CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE

[00:26:37] Firefly: a smart black-box fuzzer for web applications testing

[00:29:27] EJS - Server Side Prototype Pollution gadgets to RCE

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Just one vulnerability this week about hacking the Nintendo DSi browser, but we have a good discussion about fuzzing and a new paper "autofz".

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/194.html

[00:00:00] Introduction

[00:00:27] Spot the Vuln - Checking your Numbers

[00:03:23] autofz: Automated Fuzzer Composition at Runtime

[00:14:52] Alex Plaskett - Fuzzing Insights

[00:23:08] Hacking the Nintendo DSi Browser

[00:29:56] Espressif ESP32: Breaking HW AES with Electromagnetic Analysis

[00:32:08] Finding 10x+ Performance Improvements in C++ with CodeQL – Part 2/2 on Combining Dynamic and Static Analysis for Performance Optimisation

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This episode covers a lot of ground, from an insecure OAuth flow (Booking.com) to a crazy JSON injection and fail-open login system (DataHub) to hacking Bluetooth smart locks (Megafeis-palm). And even a new ImageMagick trick for a local file read.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/193.html

[00:00:00] Introduction

[00:00:26] Traveling with OAuth - Account Takeover on Booking.com

[00:13:25] Megafeis-palm: Exploiting Vulnerabilities to Open Bluetooth SmartLocks

[00:22:46] GitHub Security Lab audited DataHub: Here's what they found

[00:33:43] ImageMagick: The hidden vulnerability behind your online images

[00:38:49] CI/CD secrets extraction, tips and tricks

[00:39:30] A New Vector For “Dirty” Arbitrary File Write to RCE

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Just a couple issues this week, a cache coherency issue because the functions used to flush changes were not implemented on AARCH64. The second was using the "world's worst fuzzer" to find some bugs. Dumb fuzzer, but it worked.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/192.html

[00:00:00] Introduction

[00:00:24] Spot the Vuln - Targeting

[00:06:16] Vulnerability Reward Program: 2022 Year in Review

  • Correction: I mistakenly thought Google's Bug Hunter University was older than it is. It was started in 2021.

[00:12:56] The code that wasn't there: Reading memory on an Android device by accident

[00:22:37] Using the “World’s Worst Fuzzer” To Find A Kernel Bug In The FiiO M6

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Parameter pollution for an auth bypass, SQL injection in an ORM, CRLF injection for a WAF bypass...this episode has a great mix of issues.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/191.html

[00:00:00] Introduction

[00:00:26] OpenEMR - Remote Code Execution in your Healthcare System

[00:10:13] Vulnerability write-up - "Dangerous assumptions"

[00:18:05] Chat Question: How do we find topics for the podcast?

[00:19:22] Exploiting Parameter Pollution in Golang Web Apps

[00:24:10] Using CRLF Injection to Bypass a Web App Firewall

[00:34:17] Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week we talk about more Rust pitfalls, and fuzzing cURL. Then we have a couple bugs, one involving messing with the TCP stack to reach the vulnerable condition.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/190.html

[00:00:00] Introduction

[00:00:27] Spot the Vuln - Insecure by Default

[00:02:20] cURL audit: How a joke led to significant findings

[00:09:45] Rustproofing Linux (Part 4/4 Shared Memory)

[00:11:25] Rustproofing Linux (Part 4/4 Shared Memory)

[00:17:22] Exploiting a remote heap overflow with a custom TCP stack

[00:34:20] mast1c0re: Part 3 - Escaping the emulator

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A variety episode this week with some bad cryptography in PHP and Azure, information disclosure in suid binaries, request smuggling in HAProxy, and some research on testing for server-side prototype pollution.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/189.html

[00:00:00] Introduction

[00:00:22] PHP :: Sec Bug #81744 :: Password_verify() always return true with some hash

[00:11:25] Readline crime: exploiting a SUID logic bug

[00:18:05] Azure B2C Crypto Misuse and Account Compromise

[00:24:32] BUG/CRITICAL: http: properly reject empty http header field names · haproxy/haproxy@a8598a2

[00:27:23] Server-side prototype pollution: Black-box detection without the DoS

[00:30:47] ThinkstScapes 2022.Q4

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Few discussions this week, from using ASAN for effectively, to vulnerabilities in Rust code, and some discussion about exploiting the OpenSSH double free.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/188.html

[00:00:00] Introduction

[00:00:31] Spot the Vuln - Too Soft

[00:04:19] One Weird Trick to Improve Bug Finding With ASAN

[00:08:27] Rustproofing Linux (Part 2/4 Race Conditions)

[00:22:39] OpenSSH Pre-Auth Double Free Writeup & PoC [CVE-2023-25136]

[00:34:14] mast1c0re: Part 2 - Arbitrary PS2 code execution

[00:42:39] All about UndefinedBehaviorSanitizer

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Bit slow this week, so we talk about the Top Web-hacking techniques of 2022, and some TruffleSec/XSS Hunter drama before so we cover a blockchain verification bug, and a simple path traversal to SSTI and RCE chain.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/187.html

[00:00:00] Introduction

[00:00:32] Top 10 web hacking techniques of 2022

[00:06:30] TruffleSec/XSSHunter Drama

[00:15:33] Binance Smart Chain Token Bridge Hack

[00:24:01] Insecure path join to RCE via SSTI [CVE-2023-22855]

[00:29:06] Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation)

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

First, we take a look at some positive changes to OSS Fuzz, then we dive into some vulnerabilities. This includes an XNU heap out-of-bounds write vulnerability, a Chrome heap-based overflow vulnerability, and an out-of-bounds read in cmark-gfm that, while probably not exploitable, is still intriguing.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/186.html

[00:00:00] Introduction

[00:00:22] Spot the Vuln - The Great String Escape

[00:03:03] Taking the next step: OSS-Fuzz in 2023

[00:09:48] XNU Heap Underwrite in dlil.c [CVE-2023-23504]

[00:19:10] Chrome heap buffer overflow in validating command decoder [CVE-2022-4135]

[00:26:19] Out-of-bounds read in cmark-gfm [CVE-2023-22485]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Is it possible to escalate a self-XSS into an account takeover? Perhaps, we take a look at some potential options by abusing single-sign on. Then we take a look at a few Facebook/Meta authentication issues, and a deserialization trick to increase the usable classes in PHP.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/185.html

[00:00:00] Introduction

[00:00:21] Single-Sign On Gadgets: Escalate (Self-)XSS to Account Takeover

[00:11:11] Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing

[00:14:00] DOM-XSS in Instant Games due to improper verification of supplied URLs

[00:18:55] Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation

[00:29:33] Unserializable, but unreachable: Remote code execution on vBulletin

[00:34:54] Lexmark MC3224adwe RCE exploit

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Discussion heavy episode this week, talking about KASAN landing on Windows, shuffling gadgets to make ROP harder, and a paper about automatic exploit primitive discovery.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/184.html

[00:00:00] Introduction

[00:00:26] Spot the Vuln - Just the Data

[00:04:20] Introducing kernel sanitizers on Microsoft platforms

[00:14:54] Fun with Gentoo: Why don't we just shuffle those ROP gadgets away?

[00:25:14] Detecting Exploit Primitives Automatically for Heap Vulnerabilities on Binary Programs

[00:35:44] Armed to Boot: an enhancement to Arm's Secure Boot chain

[00:37:24] Pwning the all Google phone with a non-Google bug

[00:39:01] AMD SP Loader

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Starting off the week strong we have a CSS injection turned full-read SSRF, and a MyBB exploit chain from XSS to server-side code injection. And we've got a couple auth token disclosures to end off the episode.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/183.html

[00:00:00] Introduction

[00:00:22] Unleashing the power of CSS injection: The access key to an internal API

[00:06:50] MyBB <= 1.8.31: Remote Code Execution Chain

[00:18:53] Client-Side SSRF to Google Cloud Project Takeover [Google VRP]

[00:24:38] Account Takeover in KAYAK

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities  and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Null-dereferences might not be too exploitable on a lot of systems, what about the handling of a null-dereference. We cover a great Project Zero post on the topic, then look at a type confusion in Windows COM, a Nintendo buffer overflow, and several memory corruptions in git, highlighting their unique primitives and potential exploitability.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/182.html

[00:00:00] Introduction

[00:01:14] Spot the Vuln - Resolution

[00:03:38] Exploiting null-dereferences in the Linux kernel

[00:15:31] Type confusion in Windows COM+ Event System Service [CVE-2022-41033]

[00:22:57] Information and PoC about the ENLBufferPwn vulnerability

[00:28:11] Git security vulnerabilities announced

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We've got a cloud focused episode this week, starting with a logging bypass in AWS CloudTrail, a SSH Key injection, and cross-tenant data access in Azure Cognitive Search.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/181.html

[00:00:00] Introduction

[00:00:25] Undocumented API allows CloudTrail bypass

[00:06:00] Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434)

[00:14:53] SSH key injection in Google Cloud Compute Engine [Google VRP]

[00:19:08] Chat Question: Why is Cross-Site Scripting called That

[00:22:36] Cross-tenant network bypass in Azure Cognitive Search

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

An Apple-focused episode this week, with a trivial iPod Nano BootRom exploit, and a WebKit Use-after-free. We also have a really cool XNU Virutal Memory bug, strictly a race condition and a logic differential between two alternate paths resulting in bypassing copy-on-write protection. We also handle a few questions from chat, how much reverse engineering is necessary for vuln research, how much programming knowledge is required, and a bit about AI's applicability to reverse engineering.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/180.html

[00:00:00] Introduction

[00:00:18] Spot the Vuln - An Exceptional Login

[00:02:39] wInd3x, the iPod Bootrom exploit 10 years too late

[00:09:14] XNU VM copy-on-write bypass due to incorrect shadow creation logic during unaligned vm_map_copy operations [CVE-2022-46689]

[00:17:52] [WebKit] Use-after-free of RenderMathMLToken in CSSCrossfadeValue::crossfadeChanged

[00:21:46] Chat Question: How Important is Reverse Engineering to Vuln Research

[00:40:33] Learning eBPF exploitation

[00:41:23] [Chrome] Analyzing and Exploiting CVE-2018-17463

[00:42:40] Off-By-One Security - The Process of Reversing and Exploit Complex Vulnerabilities w/Chompie1337

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week kicks off with another look at client-side path traversal attacks, this time with some more case-studies. Then we get into some mobile issues, one a cool desync between DER processors resulting in an iOS privilege escalation. The other a Bundle processing issue in Android that provides an almost use-after-free like primitive but in Java.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/179.html

[00:00:00] Introduction

[00:00:27] Full Team Takeover

[00:04:20] Fetch Diversion

[00:13:39] Practical Example Of Client Side Path Manipulation

[00:17:50] DER Entitlements: The (Brief) Return of the Psychic Paper

[00:30:47] Privilege escalation to system app via LazyValue using Parcel after recycle() [CVE-2022-20452]

[00:47:38] Critical Thinking - A Bug Bounty Podcast by Justin Gardner (Rhynorater)

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Just a few issues this week, but some solid exploitation. A Kernel UAF, IoT, and a bhyve escape.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/178.html

[00:00:00] Introduction

[00:00:35] Spot the Vuln - Internal Externals

[00:06:35] Escaping from bhyve

[00:13:14] Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg

[00:29:28] MeshyJSON: A TP-Link tdpServer JSON Stack Overflow

[00:42:19] Survey of security mitigations and architectures, December 2022

[00:45:25] Abusing RCU callbacks with a Use-After-Free read to defeat KASLR

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities  and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

First episode of the new year, and we've got some cool stuff. Several authentication issues and "class pollution" in Python.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/177.html

[00:00:00] Introduction

[00:00:31] ReDoS "vulnerabilities" and misaligned incentives

[00:17:14] Web Hackers vs. The Auto Industry

[00:37:19] Prototype Pollution in Python

  • Correction: We discuss a bit of a disagreement regarding calling the issue "Prototype Pollution" in Python, turns out we missed the fact the author calls it "Class Pollution" in the actual article which is a more fitting name.

[00:50:26] [MK8DX] Improper verification of Competition creation allows to create "Official" competitions

[00:56:36] 0 click Facebook Account Takeover and Two-Factor Authentication Bypass

[01:01:18] How SAML works and some attacks on it

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

In this episode, we discuss the discovery of a type confusion in Internet Explorer's JScript. We also explore a fun exploit strategy for a low-level memory management bug in the Linux kernel and delve into several issues in Huawei's Secure Monitor that enable code execution in the secure world.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/176.html

[00:00:00] Introduction

[00:00:30] Spot the Vuln - Update All The Things

[00:06:02] Type confusion in Internet Explorer's JScript9 engine [CVE-2022-41128]

[00:14:48] Exploiting CVE-2022-42703 - Bringing back the stack attack

[00:29:01] Huawei Secure Monitor Vulnerabilities

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Is Pwn2Own worth it for bug bounty hunters? A handful of trivial command injections, and some awesome WAF bypasses.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/175.html

[00:00:00] Introduction

[00:00:34] Pwn2Own Toronto 2022 - Results

[00:10:31] Cool vulns don't live long - Netgear and Pwn2Own

[00:15:03] The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022

[00:26:54] Abusing JSON-Based SQL to Bypass WAF

[00:26:54] RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass

[00:37:25] Abusing JSON-Based SQL to Bypass WAF

[00:46:47] OTP Leaking Through Cookie Leads to Account Takeover

[00:50:47] ChatGPT bid for bogus bug bounty is thwarted

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Will AI be your next vuln research assistant? ... Maybe? We also talk about a stack-based overflow in ping and a Huawei hypervisor vuln.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/174.html

[00:00:00] Introduction

[00:00:41] Spot the Vuln - A Nice Choice

[00:03:49] ChatGPT - AI for Vuln Research?

[00:21:46] Memory Safe Languages in Android 13

[00:31:28] [FreeBSD] Stack overflow in ping

[00:40:59] Huawei Security Hypervisor Vulnerability

[00:45:09] Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals

[00:45:16] Chrome Browser Exploitation, Part 2: Introduction to Ignition, Sparkplug and JIT Compilation via TurboFan

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A variety of issues this week, DOM Clobbering, argument injection, a filesystem race condition, cross-site scripting, and a normalization-based auth bypass.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/173.html

[00:00:00] Introduction

[00:00:41] Humble Tech Book Bundle: The Art of Hacking by No Starch Press

[00:03:23] Hijacking service workers via DOM Clobbering

[00:11:14] Grafana RCE via SMTP server parameter injection

[00:16:33] Race condition in snap-confine's must_mkdir_and_open_with_perms() [CVE-2022-3328]

[00:23:56] XSS on account.leagueoflegends.com via easyXDM

[00:32:41] [Hyundai] Remotely control the locks, engine, horn, headlights, and trunk of vehicles made after 2012.

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

The end of kASLR bypasses? Probably just click-bait, but the patch gap is real and we discuss that a bit before getting into a couple AI-based corruptions.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/172.html

[00:00:00] Introduction

[00:01:15] Spot the Vuln - Escape

[00:06:00] Humble Tech Book Bundle: The Art of Hacking by No Starch Press

[00:11:00] An End to KASLR Bypasses?

[00:15:59] Mind the Gap

[00:24:36] ANE_ProgramCreate() multiple kernel memory corruption [CVE-2022-32898]

[00:34:29] Chat Question: Guides/Techniques to Help With C++ Reverse Engineering

[00:36:35] ZinComputeProgramUpdateMutables() OOB write due to double fetch issue [CVE-2022-32932]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Some RCE chains starting with DNS rebinding, always fun to see, a fairly basic SQL injection, and a JS sandbox escape for RCE in Spotify.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/171.html

[00:00:00] Introduction

[00:00:38] RCE in Tailscale, DNS Rebinding, and You [CVE-2022-41924]

[00:17:55] SQL Injection in ManageEngine Privileged Access Management [CVE-2022-40300]

[00:22:34] Unauthenticated Remote Code Execution in Spotify’s Backstage

[00:36:28] Till REcollapse

[00:41:19] Chat Question: Alternatives to IDA Freeware

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A hardware heavy episode as we talk about two read protection bypasses, Pixel 6 bootloader exploitation and benchmarking fuzzers.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/170.html

[00:00:00] Introduction

[00:00:26] Spot the Vuln - Do More

[00:05:04] Pixel6 Bootloader Exploitation

[00:16:41] NXP i.MX SDP_READ_DISABLE Fuse Bypass [CVE-2022-45163]

[00:22:05] Bypassing the Renesas RH850/P1M-E read protection using fault injection

[00:29:32] FIXREVERTER: A Realistic Bug Injection Methodology for Benchmarking Fuzz Testing

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities  and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

This week has the return of cross-site tracing, HTML injection, a golang specific vulnerable code pattern, and a fun case-sensitivity auth bypass.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/169.html

[00:00:00] Introduction

[00:01:02] A Confused Deputy Vulnerability in AWS AppSync

[00:07:05] Grafana Race Condition Leading to Potential Authentication Bypass [CVE-2022-39328]

[00:16:12] Stealing passwords from infosec Mastodon - without bypassing CSP

[00:24:01] Cross-Site Tracing was possible via non-standard override headers [CVE-2022-45411]

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Is the compiler make exploitation easier, these divergent representations seem to do so. We also look at a chrome UAF and a double stack overflow.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/168.html

[00:00:00] Introduction

[00:00:52] Spot the Vuln - The Right Start

[00:03:25] Look out! Divergent representations are everywhere!

[00:12:18] Chrome: heap-use-after-free in password_manager::WellKnownChangePasswordState::SetChangePasswordResponseCode

[00:17:34] Netgear Nighthawk r7000p aws_json Unauthenticated Double Stack Overflow Vulnerability

[00:23:52] A validation flaw in Netfilter leading to Local Privilege Escalation [CVE-2022-1015]

[00:25:03] Windows Kernel multiple memory corruption issues when operating on very long registry paths

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A Pixel Lockscreen bypass and some discussion about dupes in bug bounty, then a long RCE chain, and a look at client-side path traversals.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/167.html

[00:00:00] Introduction

[00:00:48] Accidental $70k Google Pixel Lock Screen Bypass

[00:23:28] Discovering vendor-specific vulnerabilities in Android

[00:34:30] Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)

[00:52:13] Practical Client Side Path Traversal Attacks

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities  and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A lot of discussion about the OpenSSL vulnerability, fuzzing and exploitation. Then into a RCE in XML Signature verification, and a Samsung exploit chain.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/166.html

[00:00:00] Introduction

[00:00:35] Spot the Vuln - Spaced Out

[00:03:29] OpenSSL punycode vulnerability [CVE-2022-3602]

[00:35:43] Gregor Samsa: Exploiting Java's XML Signature Verification

[00:46:37] A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain

[00:58:53] Symbolic Triage: Making the Best of a Good Situation

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Several slightly weird issues this week, a reentrancy attack abusing a read-only function, SSRF and XSS through a statically generated website and others.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/165.html

[00:00:00] Introduction

[00:01:10] Vulnerabilities in Apache Batik Default Security Controls - SSRF and RCE Through Remote Class Loading

[00:05:48] Exploiting Static Site Generators: When Static Is Not Actually Static

[00:12:51] Decoding $220K Read-only Reentrancy Exploit

[00:23:56] Weird Vulnerabilities Happening on Load Balancers, Shallow Copies and Caches

[00:28:42] Arbitrary File Read in Tasks.org Android app [CVE-2022-39349]

[00:33:13] [GitLab] RepositoryPipeline allows importing of local git repos

[00:36:15] [GitLab] RepositoryPipeline allows importing of local git repos

[00:46:05] Visual Studio Code Jupyter Notebook RCE

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Kicking off the week with a look at Apple's new security blog and the kalloc_type introduced into XNU, then a mix of issues including an overflow in SQLite.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/164.html

[00:00:00] Introduction

[00:00:24] Spot the Vuln - Right Code, Wrong Place

[00:03:05] Hexacon Talks are Available

[00:04:56] Towards the next generation of XNU memory safety: kalloc_type

[00:21:23] NetBSD Coredump Kernel Refcount LPE

[00:24:56] [Chrome] heap-use-after-free in AccountSelectionBubbleView::OnAccountImageFetched

[00:31:42] Stranger Strings: An exploitable flaw in SQLite

[00:44:35] Reaching Vulnerable Point starting from 0 Knowledge on RPC [CVE-2022-26809

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Several simple bugs with significant impacts, XSS to being able to install apps, CSRFing via a Captcha, and a Google IDOR.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/163.html

[00:00:00] Introduction

[00:00:29] Defcon Talks are Available

[00:03:10] Galaxy Store Applications Installation/Launching without User Interaction

[00:08:49] Facebook SMS Captcha Was Vulnerable to CSRF Attack

[00:15:32] Google Data Studio Insecure Direct Object Reference

[00:21:06] HTTP Request Smuggling Due to Incorrect Parsing of Multi-line Transfer-Encoding

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

A few issues this week, including an overflow in SHA-3, yet another io_uring bug, and multiple (questionably exploitable) corruptions in Edge.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/162.html

[00:00:00] Introduction

[00:00:23] Spot the Vuln - Tricky Notes

[00:04:04] Memory corruption vulnerabilities in Edge

[00:15:19] SHA-3 Buffer Overflow

[00:23:53] A Journey To The Dawn [CVE-2022-1786]

[00:36:57] Exploiting Xbox Game Frogger Beyond to Execute Arbitrary Unsigned Code

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities  and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

Several fun issues this week, from a Cobalt Strike RCE, a couple auth bypasses, and stanza smuggling in Jabber.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/161.html

[00:00:00] Introduction

[00:00:28] Sophos Firewall User Portal and Web Admin Code Injection [CVE-2022-3236]

[00:07:05] [Cisco Jabber] XMPP Stanza Smuggling with stream:stream tag

[00:14:52] Authentication Bypass & File Upload & Arbitrary File Overwrite

[00:25:31] Analysis of a Remote Code Execution (RCE) Vulnerability in Cobalt Strike 4.7.1

[00:33:38] HTTP/3 connection contamination: an upcoming threat?

The DAY[0] Podcast episodes are streamed live on Twitch twice a week:

-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

We are also available on the usual podcast platforms:

-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

-- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

View Details

We've got a few interesting vulns, a blind format string attack, Windows kernel int overflow, and a browser exploit (unchecked bounds after lowering).

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/160.html

[00:00:00] Introduction

[00:00:24] Spot the Vuln - Chat Configuration

[00:02:06] CCC Cancelled

[00:07:53] Hacking TMNF: Part 2 - Exploiting a blind format string

[00:19:17] Windows Kernel integer overflows in registry subkey lists leading to memory corruption

[00:28:13] Browser Exploitation: A Case Study Of CVE-2020-6507

[00:45:48] Chat Question: Getting Into Browser Exploitation

View Details

This week we look at a insecure deserialization (GitLab), argument injection (Packagist), and insecure string interpolation (Apache Commons Text)

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/159.html

[00:00:00] Introduction

[00:01:01] New reward system to accelerate learning and growth on Detectify

[00:04:33] RCE via github import

[00:11:27] Securing Developer Tools: A New Supply Chain Attack on PHP

[00:17:32] FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive [CVE-2022-40684]

[00:23:08] Apache Commons Text Interpolation leading to potential RCE [CVE-2022-42889]

View Details

Just a couple issues this week and a discussion about why you should look at old vulnerabilities and the pace exploit development advanced at.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/158.html

[00:00:00] Introduction

[00:00:26] Spot the Vuln - Authentic Token ... Fixed

[00:05:42] Hancom Office 2020 Hword Docx XML parsing heap underflow vulnerability

[00:11:07] Shining New Light on an Old ROM Vulnerability: Secure Boot Bypass via DCD and CSF Tampering on NXP i.MX Devices

[00:22:21] Discussion: Why Care About Old Vulnerabilities

View Details

No actual bounties this week, but we start off with a discussion on semgrep vs codeql, then get into some cool issues that you can start testing for.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/157.html

[00:00:00] Introduction

[00:00:39] Comparing Semgrep and CodeQL

[00:14:27] A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX socket)

[00:20:18] Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style

[00:28:23] [OpenJDK] Weak Parsing Logic in java.net.InetAddress and Related Classes

[00:34:22] RCE via Phar Deserialisation [CVE-2022-41343]

View Details

Starting off with some discussion about XOM and CFI on the PS5 and how it impacts exploitation. Then into a uClibC issue, and hacking wireless scoreboards.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/156.html

[00:00:00] Introduction

[00:00:27] Spot the Vuln - Authentic Token

[00:05:04] PS5-4.03-Kernel-Exploit: An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on 4.03FW

[00:17:54] uClibC and uClibC-ng libpthread linuxthreads memory corruption vulnerabilities

[00:26:35] Scoreboard Hacking  Part 2 - Getting the AES Key

[00:41:16] When Hypervisor Met Snapshot Fuzzing

View Details

Had some varied issues this week, a file format allowing JScript for a $20,000 bounty, Akamai Cache Poisoning, Universal XSS in Chrome.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/155.html

[00:00:00] Introduction

[00:00:26] Two Lines of JScript for $20,000

[00:05:31] Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)

[00:14:10] [Chrome] Universal XSS in Autofill Assistant

[00:22:51] Aurora Improper Input Sanitization Bugfix Review

[00:31:21] What I learnt from reading 126* Information Disclosure Writeups.

View Details

Starting off with meme vulnerabilities in UNISOC BootROMs, and ending  with a discussion about bypassing CFI/Intel CET and some fun issues in-between.  

Links and summaries are available at  https://dayzerosec.com/podcast/154.html 

[00:00:00] Introduction [00:00:24] Spot the Vuln - You Put Where Where?!

[00:04:05] There’s Another Hole In Your SoC: Unisoc ROM Vulnerabilities

[00:12:19] Crow HTTP framework use-after-free

[00:17:51] Crowbleed (Crow HTTP framework vulnerability)

[00:19:34] exploit for CVE-2022-2588

[00:23:24] Bypassing Intel CET with Counterfeit Objects

[00:48:05] Analyzing BSD Kernels for Uninitialized Memory Disclosures using Binary Ninja

[00:50:32] PS5 IPV6_2292PKTOPTIONS Use-After-Free

View Details

Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE.

Links and summaries are available at https://dayzerosec.com/podcast/153.html

[00:00:00] Introduction

[00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

[00:10:31] Breaking Bitbucket: Pre Auth Remote Command Execution [CVE-2022-36804]

[00:16:25] [Chrome] Sanitizer API bypass via prototype pollution

[00:23:02] How we Abused Repository Webhooks to Access Internal CI Systems at Scale

[00:35:03] WAF bypasses via 0days

[00:42:40] Cloning internal Google repos for fun and… info?

[00:43:19] How to turn security research into profit: a CL.0 case study

View Details

This week we've got some summer highlights: the impact of MTE on  Android, an iOS vuln and some primitive chaining in a Titan M exploit.

Links and summaries of today's topics are available on our website:  https://dayzerosec.com/podcast/an-ios-bug-attacking-titan-m-and-mte-arrives.html  

[00:01:17] Spot the Vuln - Easy Regex

[00:03:53] Binary Ninja - 3.1 The Performance Release

[00:11:52] Dogbolt - Decompiler Explorer

[00:15:28] Making Linux Kernel Exploit Cooking Harder

[00:23:31] MTE comes to Android

[00:37:19] ipc_kmsg_get_from_kernel, iOS 15.4 - root cause analysis

[00:44:48] Attacking Titan M with Only One Byte

[01:00:01] CVE-2022-29582 - An io_uring vulnerability

[01:07:47] mast1c0re: Hacking the PS4 / PS5 through the PS2 Emulator

[01:09:32] bd-jb: The first bd-j hack (PS4/PS5)

[01:11:01] [CVE-2022-34918] A crack in the Linux firewall

View Details

We are back at it, covering some write-ups and exploits we found  interesting this summer. From browse-powered desyncs, to account take  overs. 

Links are available on our website at:  https://dayzerosec.com/podcast/reading-gitlab-hidden-hackerone-reports-and-golang-parameter-smuggling.html 

[00:02:17] Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

[00:15:03] [GitLab] Able to view hackerone report attachments

[00:26:59] Forwarding addresses is hard [CVE-2022-31813]

[00:32:18] "ParseThru" – Exploiting HTTP Parameter Smuggling in Golang

[00:46:41] Browser-Powered Desync Attacks

[01:09:30] Scraping the bottom of the CORS barrel (part 1)

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/fuchsia-os-printer-bugs-and-hacking-radare2.html

Some silly issues in radare2, some printer hacking, some kernel vulnerabilities, and a look at exploiting Fuchsia OS on this weeks episode. Just as a reminder this will be our last episode until September.

[00:00:40] Spot the Vuln - Size Matters

[00:04:30] Multiple vulnerabilities in radare2

[00:10:08] The printer goes brrrrr!!!

[00:17:25] A Kernel Hacker Meets Fuchsia OS

[00:33:55] Finding Bugs in Windows Drivers, Part 1 - WDM

[00:41:23] Chat Question: Learning Kernel Exploitation

[00:50:25] Resources While We are Gone

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-zoom-rce-vmware-auth-bypass-and-gitlab-stored-xss.html

Last bounty episode before our summer vacation, and we are ending off with some cool issues. XML Stanza smuggling in Zoom for a MitM attack, an odd auth bypass, a Gitlab Stored XSS and gadget based CSP bypass, and an interesting technique to leverage a path traversal/desync against NGINX Plus

[00:01:00] How I hacked CTX and PHPass Modules

[00:10:55] [Zoom] Remote Code Execution with XMPP Stanza Smuggling

[00:19:38] VMware Authentication Bypass Vulnerability [CVE-2022-22972]

[00:23:05] Breaking Reverse Proxy Parser Logic

[00:26:44] [GitLab] Stored XSS in Notes (with CSP bypass)

[00:37:13] GhostTouch: Targeted Attacks on Touchscreens without Physical Touch

[00:48:00] Resources While We Are Gone

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwn2own-parallels-desktop-and-an-appleavd-bug.html

Just a couple vulnerabilities to talk about this week, but some interesting things to talk about in them. We also have some discussion about this year's pwn2own results and a couple things that caught out attention.

[00:01:02] Spot the Vuln - NoSQL, No Problem

[00:02:46] Pwn2Own Vancouver 2022 - The Results

[00:16:14] CVE-2022-22675: AppleAVD Overflow in AVC_RBSP::parseHRD

[00:23:16] Exploiting an Unbounded memcpy in Parallels Desktop

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/stealing-dropbox-google-drive-tokens-a-gitlab-bug-and-macos-powerdir-vulnerability.html

Kicking off the week with some discussion about DOJ's policy change before getting into some vulnerabilities: "powerdir" a macOS TCC bypass, an integer overflow on the web, and another attack against HelloSign and their Google Drive integration

[00:02:12] DOJ’s New CFAA Policy is a Good Start But Does Not Go Far Enough to Protect Security Researchers

[00:11:02] macOS Vulnerability "powerdir" could lead to unauthorized user data access

[00:17:17] Arbitrary POST request as victim user from HTML injection in Jupyter notebooks

[00:21:44] [Glovo] Integer overflow vulnerability

[00:25:11] Stealing Google Drive OAuth tokens from Dropbox

[00:29:46] Privileged pod escalations in Kubernetes and GKE

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/python-3-uaf-and-ps4-ps5-pppoe-kernel-bug.html

We have a couple normally low-impact bugs in Solana rBPF this week netting a $200k bounty, a Python 2.7+ Use-After-Free and a PS4 and PS5 remote kernel heap overflow along with some discussion about exploitability and usability for a jailbreak.

[00:00:48] Spot the Vuln - Clowning Around

[00:03:27] Earn $200K by fuzzing for a weekend

[00:17:37] Exploiting a Use-After-Free for code execution in every version of Python 3

[00:26:21] [PlayStation] Remote kernel heap overflow

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/yanking-rubygems-big-ip-auth-bypass-and-a-priceline-account-takeover.html

A lot of cool little bugs this week with some solid impact, Facebook and Priceline account takeovers, F5 iControl Authentication Bypass, and a couple other logic bugs.

[00:01:55] rubygems CVE-2022-29176 explained

[00:06:09] Multiple bugs chained to takeover Facebook Accounts which uses Gmail

[00:15:16] [curl] curl removes wrong file on error [CVE-2022-27778]

[00:18:33] [Priceline] Account takeover via Google OneTap

[00:22:14] F5 iControl REST Endpoint Authentication Bypass Technical Deep Dive

[00:29:02] The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…

[00:30:20] Hunting evasive vulnerabilities

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwn2owning-routers-and-anker-eufy-bugs.html

Just a few vulnerabilities this week, but we have some codeql discussion as its used to find several vulnerabilities in Accel-PPP VPN server, and a look at a bug submitted to Pwn2Own 2021.

[00:00:33] Spot the Vuln - Is It Clear

[00:05:13] Anker Eufy Homebase 2 libxm_av.so DemuxCmdInBuffer buffer overflow vulnerability

[00:08:18] Hunting bugs in Accel-PPP with CodeQL

[00:15:53] Competing in Pwn2Own 2021 Austin: Icarus at the Zenith

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/cloudflare-pages-hacking-a-bank-and-attacking-price-oracles.html

Some interesting vulnerabilities this week from a Cloudflare Pages container escape chain, to hacking a bank's web application with some neat tricks to get abuse a file-write in a hardened envrionment, and even another dumb smart-contract bug.

[00:00:23] Cloudflare Pages, part 1: The fellowship of the secret

[00:10:07] Ruby on Rails - Possible XSS Vulnerability in ActionView tag helpers [CVE-2022-27777]

[00:15:01] Hacking a Bank by Finding a 0day in DotCMS

[00:22:23] Aave V3’s Price Oracle Manipulation Vulnerability

[00:33:53] [Reddit] Able to bypass email verification and change email to any other user email

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/nimbuspwn-a-clfs-vulnerability-and-dataflow.html

A few vulnerabilities from a TOCTOU to an arbitrary free, and some research into using data-flow in your fuzzing.

[00:00:18] Spot the Vuln - Where's it At?

[00:03:44] Nimbuspwn - A Linux Elevation of Privilege

[00:08:38] Windows Common Log File System (CLFS) Logical-Error Vulnerability [CVE-2022-24521]

[00:15:32] Arbitrary Free in Accusoft ImageGear ioca_mys_rgb_allocate

[00:25:31] Commit Level Vulnerability Dataset

[00:28:44] DatAFLow - Towards a Data-Flow-Guided Fuzzer

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/xss-for-nfts-a-vmware-workspace-one-uem-ssrf-and-gitlab-ci-container-escape.html

Some straight forward bugs this week with some interesting discussion around cryptographic protocols (VMWare Workspace), XSS in the Web3 world, and whether container escapes into a low-privileged VM matter. Along with a couple just note-worthy test-cases to keep in mind while bug hunting.

[00:00:35] Wormable Cross-Site Scripting Vulnerability affecting Rarible’s NFT Marketplace

[00:09:14] Encrypting our way to SSRF in VMWare Workspace One UEM [CVE-2021-22054]

[00:14:29] How I Bypass 2FA while Resetting Password

[00:16:41] Container escape on public GitLab CI Runners

[00:30:39] [Nextcloud] Bypass the protection lock in andoid app

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/getting-into-vulnerability-research-and-a-fuse-use-after-free.html

We are joined by Cts for a discussion about getting into vulnerability research and some thoughts about the higher-level bug hunting process, then a look at some black-box fuzzing of MS Defender for IoT and a FUSE use-after-free.

[00:00:44] Spot the Vuln - What do I need?

[00:03:11] Discussion: Getting into Vulnerability Research

[00:39:43] Inside the Black Box - How We Fuzzed Microsoft Defender for IoT and Found Multiple Vulnerabilities

[00:43:25] FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes

[00:46:51] FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-struts-rce-broken-java-ecdsa-psychic-signatures-and-a-bad-log4shell-fix.html

An intresting mix of issues from crypto (Psychic Signatures), to a bad vulnerability patching service (patching log4shell), and bad logic leading to authentication bypassing and leaking sensitive keys.

[00:00:24] Psychic Signatures in Java [CVE-2022-21449]

[00:15:09] AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation

[00:18:33] Bypass Apple Corp SSO on Apple Admin Panel

[00:21:55] Exploiting Struts RCE on 2.5.26

[00:27:46] bluez: malicious USB devices can steal Bluetooth link keys over HCI using fake BD_ADDR

[00:31:20] New XSS vectors

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/another-ios-bug-and-edge-chakra-exploitation.html

A massive 11,000 byte overflow in WatchGuard, some discussion about lock-related vulnerabilities and analysis, and a look at a ChakraCore exploit dealing with all the mitigations (ASLR, DEP, CFG, ACG,CIG)

[00:00:32] Spot the Vuln - The Global Query

[00:05:04] Diving Deeper into WatchGuard Pre-Auth RCE [CVE-2022-26318]

[00:09:42] HTTP Protocol Stack Remote Code Execution Vulnerability [CVE-2022-21907]

[00:18:21] iOS in-the-wild vulnerability in vouchers [CVE-2021-1782]

[00:37:06] Microsoft Edge Type Confusion Vulnerability (Part 2) [CVE-2019-0567]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/taking-over-an-internal-aws-service-and-an-interesting-xss-vector.html

Short episode this week, looking at some relatively simple vulnerabilities ranging XSS, to leaking internal service credentials in AWS Relational Database Service by disabling validiation.

[00:00:40] Git security vulnerability announced

[00:06:37] AWS RDS Vulnerability Leads to AWS Internal Service Credentials

[00:14:04] Privilege Escalation to SYSTEM in AWS VPN Client [CVE-2022-25165]

[00:18:37] Copy-paste XSS in vditor text editor [CVE-2021-32855]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-subtle-ios-parsing-bug-and-a-php-use-after-free.html

We dive into an ASN.1 parsing bug impacting iOS, and a PHP use-after-free to bypass disabled functions, ending the week with a discussion about whether or not its too late to get into this area of security.

[00:00:29] Spot the Vuln - One HMAC at a Time

[00:03:19] CVE-2021-30737, @xerub's 2021 iOS ASN.1 Vulnerability

[00:19:03] In the land of PHP you will always be (use-after-)free

[00:30:13] security things in Linux v5.10

[00:36:16] Discussion: Is It too late to get into "cyber security"

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-double-edged-ssrf-pritunl-vpn-lpe-and-a-nodebb-vuln.html

Quick bounty episode this week with some request smuggling, abusing a SSRF for client-sided impact, a weird oauth flow, and a desktop VPN client LPE.

[00:00:28] HTTP Request Smuggling on business.apple.com and Others.

[00:06:25] Exploiting a double-edged SSRF for server and client-side impact

[00:14:47] Local Privilege Escalation in Pritunl VPN Client [CVE-2022-25372]

[00:20:27] A NodeBB 0-day

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/forcedentry-sandbox-escape-and-netfilter-bugs.html

More information about the FORCEDENTRY exploit chain, and some Linux exploitation with a couple netfilter bugs. Ending the episode with some discussion about exploiting blind kernel read primitives from Microsoft.

[00:00:28] Spot the Vuln - Adding Entropy

[00:02:56] FORCEDENTRY: Sandbox Escape

[00:15:21] How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables

[00:32:38] Exploring a New Class of Kernel Exploit Primitive

[00:40:18] BlueHat IL Videos are up

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/spring4shell-pear-bugs-and-gitlab-hardcoded-passwords.html

This week we have some fun with some bugs that really shouldn't have passed code-review, we of course talk about Spring4Shell/SpringShell and dive into the decade long history of that bug, and a bit of discussion about triaging more subtle bugs.

[00:00:29] [Stripe] CSRF token validation system is disabled

[00:09:42] GitLab Account Takeover with Hardcoded Password

[00:21:22] Spring4Shell: Security Analysis of the latest Java RCE '0-day' vulnerabilities in Spring

[00:37:49] PHP Supply Chain Attack on PEAR

[00:52:16] Finding bugs that doesn’t exists

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwning-wd-nas-netgear-routers-and-overflowing-kernel-pages.html

Plenty of exploit strategy talk this week with vulnerabilities and complete exploits targeting a NAS, a router, and a Linux Kernel module with a page-level overflow.

[00:00:26] Spot the Vuln - Normalized Regex

[00:01:52] Remote Code Execution on Western Digital PR4100 NAS (CVE-2022-23121)

[00:07:10] Defeating the Netgear R6700v3

[00:18:36] Exploit esp6 modules in Linux kernel [CVE-2022-27666]

[00:27:17] Racing against the clock -- hitting a tiny kernel race window

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/gitlab-arbitrary-file-read-and-bypassing-php-s-filter-var.html

Some easy vulnerabilities this week, a directory traversal due to a bad regex, a simply yet somewhat mysterious authentication bypass, arbitrary file read in GitLab thanks to archives with symlinks, and a PHP filter_var bypass.

[00:00:25] elFinder: The story of a repwning

[00:11:56] Authentication bypass using root array

[00:17:04] [GitLab] Arbitrary file read via the bulk imports UploadsPipeline

[00:19:54] PHP filter_var shenanigans

[00:30:26] Quick Thoughts on Finding a Mentor

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/chrome-heap-oob-access-and-tlstorm.html

A few issues this week, a OOB access in chrome and in the Linux Kernel's Netfilter, and a few issues in Smart UPS devices.

[00:00:17] Spot the Vuln - Where's My Token

[00:03:21] Chrome: heap-buffer-overflow in chrome_pdf::PDFiumEngine::RequestThumbnail

[00:06:23] TLStorm - Three Critical Vulnerabilities in Smart-UPS devices

[00:15:59] The Discovery and Exploitation of CVE-2022-25636

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dompdf-xss-to-rce-chrome-leaking-envrionment-vars-and-cr8escape.html

Several easy issues this week from leaking envrionment variables, to gaining host code execution and an XSS to RCE.

[00:01:15] Chrome, Edge and Opera - System environment variables leak [CVE-2022-0337]

[00:10:05] [Yoti] Pin Bruteforce Rate-Limiting Bypass

[00:21:58] From XSS to RCE (dompdf 0day)

[00:31:49] cr8escape: New Vulnerability in CRI-O Container Engine [CVE-2022-0811]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-windows-uaf-branch-prediction-bugs-and-an-io-uring-exploit.html

This time as we get side tracked with a couple discussions, first about security through obscurity, secondly about the nvidia leaks. We also have our usual mix of vulnerabilities this week, a cool exploit in the Linux kernel, a use-after-free in Windows Common Logging File System, and some speculative execution issues.

[00:00:43] Spot the Vuln - Do You Even HMAC?

[00:05:49] Put an io_uring on it: Exploiting the Linux Kernel

[00:26:18] Discussion: Security through Obscurity in the Linux Kernel

[00:34:20] Exploiting a use-after-free in Windows Common Logging File System (CLFS)

[00:43:57] The AMD Branch (Mis)predictor Part 2: Where No CPU has Gone Before [CVE-2021-26341]

[00:56:20] Branch History Injection

[01:04:25] Chat Question: About the Nvidia Leak

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pascom-rce-autowarp-and-a-gke-container-escape.html

We've got some cloud issues this week, in Azure Automation and GKE Autopilot along with a couple other interesting chains.

[00:02:11] Pascom: The story of 3 bugs that lead to unauthed RCE

[00:12:37] How I Made +$16,500 Hacking CDN Caching Servers - Part 2

[00:17:16] AutoWarp Microsoft Azure Automation Vulnerability

[00:23:19] Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dirty-pipe-and-analyzing-memory-tagging.html

No spot the vuln this week, but we do have a cool kernel bug, "Dirty Pipe", a look at a stack based overflow: BrokenPrint, and finally some discussion about memory tagging.

[00:00:31] The Dirty Pipe Vulnerability

[00:18:26] BrokenPrint: A Netgear stack overflow

[00:30:21] Security Analysis of MTE Through Examples [BHIL2022]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/facebook-exploits-pfsense-rce-and-mysqljs-sqli.html

A few interesting issues you this week, a JS race condition in some auth related code for Facebook, some fake prepared queries, and a RCE through sed commands (in pfSense)

[00:00:56] Remote Code Execution in pfSense (2.5.2 and earlier)

[00:06:13] Finding an Authorization Bypass on my Own Website

[00:17:43] More secure Facebook Canvas Part 2: More Account Takeovers

[00:32:43] The perils of the “real” client IP

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/imagegear-jpeg-vulns-netfilter-and-libcurl.html

Quick episode with four somewhat simple bugs in JPEG parsing, a remote memory disclosure in libcurl due to the difference sizeof(long) on Linux vs Windows, and a heap out of bounds write in the Linux Kernel.

[00:00:16] Spot the Vuln - One of a Kind

[00:03:14] Accusoft ImageGear JPEG-JFIF Scan header parser out-of-bounds write vulnerability

[00:07:15] Accusoft ImageGear Palette box parser heap-based buffer overflow vulnerability

[00:11:55] Remote memory disclosure vulnerability in libcurl on 64 Bit Windows

[00:19:15] Linux kernel: heap out of bounds write in nf_dup_netdev.c since 5.4

[00:23:03] Overview of GLIBC heap exploitation techniques

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dynamicweb-rce-vmware-bugs-and-exploiting-github-actions.html

Re-accessing the stup page, an unlikely scenario leaking Github Secrets, and a proxying issue in Carbon Black.

[00:00:34] Logic Flaw Leading to RCE in Dynamicweb 9.5.0 - 9.12.7

[00:06:15] Stealing a few more GitHub Actions secrets

[00:19:31] Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/zynq-7000-secure-boot-bypass-and-compiler-created-bugs.html

Just one vulnerability this week, a secure boot bypass, and some research into detecting compiler introduced bugs. Ending the week with a discussion about how to learn fuzzing.

[00:00:58] Spot the Vuln - All Inclusive HMAC

[00:03:47] Zynq-7000 Secure Boot Bypass [CVE-2021-44850]

[00:19:32] Cross-Architecture Testing for Compiler-Introduced Security Bugs

[00:35:02] Question: Learning to Fuzz

[01:03:00] tmp.0ut v2

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/coindesk-zabbix-and-leaking-secrets-through-mirrored-repos.html

Lets talk about "sidedoors" this week, with two vulnerabilities abusing alternative access points, along with an overly verbose error message that actually had some immediate impact, and a look at the challenges of client-sided session.

[00:00:26] CoinDesk API Error Exposes Privileged Token

[00:05:28] A tale of 0-Click Account Takeover and 2FA Bypass.

[00:10:26] Zabbix - A Case Study of Unsafe Session Storage

[00:17:54] Multiple vulnerabilities in Concrete CMS - part2 (PrivEsc/SSRF/etc)

[00:25:15] Finding secrets in mirrored Git repositories

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/another-kernel-tipc-bug-mysql-and-buggy-go.html

This week we discuss taint analysis and where to use it compared with fuzzing, a couple buggy code patterns in Go to be on the lookout for, and another remote stack-overflow in the Kernel TIPC module.

[00:00:14] Spot the Vuln - How Much

[00:03:11] Linux Kernel kCTF VRP Extended

[00:05:39] MindShaRE: When MySQL Cluster Encounters Taint Analysis

[00:24:46] A deeper dive into CVE-2021-39137 - a Golang security bug that Rust would have prevented

[00:38:47] Remote Stack Overflow in Linux Kernel TIPC Module since 4.8 (net/tipc) [CVE-2022-0435]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/baby-monitor-bugs-grafana-and-twitter-de-anonymization.html

CSRF lives again in the form of CORF, Cross-Origin Request Forgery with an attack against Grafana. We also take a look at some baby monitor issues and a de-anonymization attack against Twitter.

[00:00:28] Cross-origin request forgery against Grafana [CVE-2022-21703]

[00:17:50] Vulnerabilities Identified in Nooie Baby Monitor

[00:26:47] [Twitter] Discoverability by phone number/email restriction bypass

[00:32:40] EarnHub Exploit - Post mortem

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/fastly-infoleak-samba-oob-access-and-pwning-macos.html

A discussion heavy episode this week as we speculate about how some XNU code passed muster, and how to exploit a small overflow and weaponizing a large info-leak.

[00:00:17] Spot the Vuln - From Bits to Bytes

[00:05:09] MacOS 12 Use After Free

[00:13:08] A story of leaking uninitialized memory from Fastly

[00:34:08] Details on a Samba Code Execution Bug [CVE-2021-44142]

[00:46:05] Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google's KCTF Containers [CVE-2022-0185]

[00:49:38] Sha256 Algorithm Explained

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/hacking-google-drive-integrations-and-xss-puzzles.html

A "maybe" issue this week in Ruby's net/http library, some long chains leading to XSS, and a look at abusing parameter injection for SSRF in applications integrating with the Google Drive API.

[00:00:26] [Ruby - net/http] HTTP Header Injection in the set_content_type method

[00:10:22] Don't trust comments

[00:16:54] HigherLogic Community RCE Vulnerability

[00:24:29] Solving DOM XSS Puzzles

[00:37:32] Hacking Google Drive Integrations

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwnkit-a-win32k-type-confusion-and-binary-ninja-3-0.html

Binary ninja 3.0 just dropped, lets talk about that, then into pwnkit and a couple kernel bugs, and ending this week off with a discussion about dealing with imposter syndrome.

[00:00:18] Spot the Vuln - Maintain Order

[00:03:52] Binary Ninja 3.0

[00:13:09] PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec [CVE-2021-4034]

[00:27:20] Win32k Window Object Type Confusion [CVE-2022-21882]

[00:34:20] Linux kernel: erroneous error handling after fd_install()

[00:38:26] Question: Dealing with Imposter Syndrome

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/zoho-auth-bypass-a-bogus-bug-and-leaking-microsoft-bug-reports.html

A few unique issues this week, routing issues in ManageEngine, a Little Snitch bypass, an undecodable characters leading to a denial of service.

[00:00:37] CVE-2022-0329 and the problems with automated vulnerability management

[00:19:45] [Omise] XSS via X-Forwarded-Host header

[00:25:44] [FetLife] Specific Payload makes a Users Posts unavailable

[00:31:03] How I could have read your confidential bug reports by simple mail?

[00:36:38] Bypassing Little Snitch Firewall with Empty TCP Packets

[00:45:06] ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/netusb-rce-a-kernel-heap-overflow-an-xnu-uaf.html

Integer overflows and underflow this week, covering vulns from desktop Zoom clients, to kernel and some routers.

[00:00:19] Spot the Vuln - One Verified JWT, Please

[00:03:27] Zooming in on Zero-click Exploits

[00:12:18] Zooming in on Zero-click Exploits

[00:26:39] XNU kernel use-after-free in mach_msg

[00:34:06] Linux kernel v5.1+ Heap buffer overflow in fs_context.c

[00:36:03] Linux kernel v5.1+ Heap buffer overflow in fs_context.c

[00:42:21] NetUSB RCE Flaw in Millions of End User Routers [CVE-2021-45608]

[00:47:54] Humble Book Bundle: Cybersecurity by Wiley

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/bypassing-box-mfa-bad-aes-key-generation.html

A new security-related humble bundle, MFA bypass in Box, and a a few older style vulnerabilities: lfi2rce, allow-list bypass with an @ sign, and insecure random number seeds.

[00:00:37] Humble Book Bundle: Cybersecurity by Wiley

[00:08:18] CWP CentOS Web Panel - preauth RCE [CVE-2021-45467]

[00:13:37] Stealing administrative JWT's through post auth SSRF [CVE-2021-22056]

[00:17:27] Telenot Complex: Insecure AES Key Generation

[00:25:12] Mixed Messages: Busting Box’s MFA Methods

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwning-camera-and-overflowing-your-integers.html

Short episode this week, stack smashing, integer overflowing and a more logical issue. Ending off with a discussion about what to do when you're stuck on CTFs.

[00:00:42] Spot the Vuln - One at a Time

[00:04:15] Uniview PreAuth RCE

[00:06:59] Adobe Acrobat Reader DC annotation gestures integer overflow vulnerability

[00:12:31] Chrome: Interface ID reuse leading to memory corruption in IPC::ChannelAssociatedGroupController

[00:18:31] Question: Unsuccessful getting into CTFs

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/bad-code-and-bad-urls.html

This week is a shorter episode looking at some bad code in mermaid.js and Moodle's Shibboleth plugin, and a bit of research regarding URL parsing issues.

[00:00:44] Orca Security Discovered Two AWS Vulnerabilities

[00:06:44] Cross-Site Scripting (XSS) in mermaid.js

[00:12:41] Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth

[00:20:24] Exploiting URL Parsing Confusion Vulnerabilities

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rooting-ubuntu-by-accident-and-samsung-kernel-bugs.html

We are back for the first 2022 binary episode, and its all kernel. Obtaining root through an hours long exploit process on Ubuntu thanks to an invalid free, use-after-free in XNU due to bad locking, and some terrible code in Samsung S20 DSP kernel driver with multiple integer overflows.

[00:00:42] Getting root on Ubuntu through wishful thinking

[00:19:21] XNU: heap-use-after-free in inm_merge

[00:29:42] Kernel LPE in the Vision DSP Kernel Driver [CVE-2021-25467]

[00:34:34] Kernel LPE in the Vision DSP Kernel Driver's ELF Linker [CVE-2021-25475]

[00:37:16] Linux Heap Exploitation - Part 3

[00:38:37] PS4 CCP Crypto Bug

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rocketchat-rce-flickr-and-a-critical-smart-contract-bug.html

More cases of developers make insecure assumptions and getting owned because of it. This week we've got a Flickr account takeover, escalating restricted SSRF into something more useful, and XSS to RCE in Rocket.Chat.

[00:00:34] Rocket.Chat Client-side Remote Code Execution

[00:10:14] Flickr Account Takeover

[00:24:33] Turning bad SSRF to good SSRF: Websphere Portal

[00:34:47] Polygon Lack Of Balance Check Bugfix Postmortem

[00:45:22] Fuzzing for XSS via nested parsers condition

[00:52:35] Cache Poisoning at Scale

[00:54:48] Fixing the Unfixable: Story of a Google Cloud SSRF

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/an-android-kernel-bug-a-chrome-edge-exploit.html

Hex-rays/Adobe cross-over as they move to a subscription model and we are not too happy about it, we also discuss a few interesting bugs this week from an odd optimization and a signedness bug in Chrome, to some mishandled null-bytes in runc, and a subtle object-state confusion in the Linux kernel

[00:00:21] Spot the Vuln - Revenge of the Average

[00:04:38] Hex-rays is moving to a Subscription model

[00:32:49] Understanding the Root Cause of a Chrome Bug from Pwn2Own 2021 [CVE-2021-21220]

[00:44:30] runc/libcontainer: insecure handling of null-bytes in bind mount sources

[00:49:50] refcount increment on mid-destruction file [CVE-2021-1048]

[00:56:30] Overview of V8 Exploitation

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/log4j-rce-coming-to-a-service-near-you-and-ublock-css-injection.html

Log4Shell RCE spawns a lot of discussion this episode, but we also look at a W10 RCE, Google SSRF and some CSS injection in uBlock.

[00:00:29] Apache Log4j2 jndi RCE

[00:29:50] Windows 10 RCE: The exploit is in the link

[00:46:00] SSRF vulnerability in AppSheet - Google VRP

[00:52:43] uBlock, I exfiltrate: exploiting ad blockers with CSS

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/mediatek-yet-another-chrome-bug-and-bigsig.html

A few easy issues this week, but some discussion about fuzzing campaigns and measurements and bypassing modern mitigations.

[00:00:20] Spot the Vuln - Just a Normal Walk

[00:06:10] This shouldn't have happened: A vulnerability postmortem

[00:22:52] Looking for vulnerabilities in MediaTek audio DSP

[00:35:23] Exploiting CVE-2021-43267

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Some readily understood vulnerabilities, but with some interesting impacts, from escalating self-XSS to cross-account CSRF, data exfiltration with CSS, web-cache poisoning and MFA bypassing.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/bypassing-mfa-webcache-poisoning-and-aws-sagemaker.html

[00:00:00] Introduction [00:00:34] Humble Book Bundle: Hacking by No Starch Press [00:05:50] AWS SageMaker Jupyter Notebook Instance Takeover [00:16:39] [Glassdoor] CSS injection via link tag whitelisted-domain bypass [00:21:15] [Symfony] Webcache Poisoning via X-Forwarded-Prefix and sub-request [00:25:47] Bypassing Box’s Time-based One-Time Password MFA [00:31:26] Exploring Container Security: A Storage Vulnerability Deep Dive [00:36:28] Hakluke: Creating the Perfect Bug Bounty Automation [00:37:10] Data Exfiltration via CSS + SVG Font

The DAY[0] Podcast episodes are streamed live on Twitch twice a week: - Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities - Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The audio-only version of the podcast is available on: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

BugBounty #EthicalHacking #InfoSec #Podcast

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/kvm-bugs-and-an-ios-iomfb-kernel-exploit.html

Starting off this week with the new humble bundle and some discussion about hacking books. Then onto the vulns, some OOB access, uninitalized memory, and iOS exploit strategy.

[00:00:17] Spot the Vuln - Counting Widgets

[00:02:36] Humble Book Bundle: Hacking by No Starch Press

[00:17:14] KVM: SVM: out-of-bounds read/write in sev_es_string_io

[00:23:42] Anker Eufy Homebase 2 home_security CMD_DEVICE_GET_SERVER_LIST_REQUEST out-of-bounds write vulnerability

[00:34:14] Apple ColorSync: use of uninitialized memory in CMMNDimLinear::Interpolate

[00:40:16] Popping iOS <=14.7 with IOMFB

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/gitlab-prototype-pollution-and-some-authentication-bypasses.html

Short but sweet episode this week, prototype pollution, crypto issues, SSRF and some weird authentication.

[00:00:46] Arbitrary command execution in Gerapy [CVE-2021-32849]

[00:06:03] [jitsi-meet] Authentication Bypass when using JWT w/ public keys

[00:07:41] [jitsi-meet] Authentication Bypass when using JWT w/ public keys

[00:10:24] [shopify] A non-privileged user may create an admin account in Stocky

[00:13:21] [#0008] URL whitelist bypass in https://cxl-services.appspot.com

[00:19:20] [GitLab] Stored XSS via Mermaid Prototype Pollution vulnerability

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/hacking-neural-nets-a-chrome-webrtc-uaf-and-pwning-windows.html

Some mroe kernel bugs this week as we look at bugs in Samsung's NPU driver (Android), Linux, and the WIndows Kernel.

[00:00:17] Spot the Vuln - Once Again - Solution

[00:03:12] Google Chrome WebRTC addIceCandidate use after free vulnerability

[00:08:53] Linux: UAF read: SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect())

[00:15:08] Fall of the machines: Exploiting the Qualcomm NPU (neural processing unit) kernel driver

[00:31:13] POC2021 – Pwning the Windows 10 Kernel with NTFS and WNF Slides

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/big-bounties-by-exploiting-webkit-s-csp-concrete-cms-bugs.html

What happens when a vendor refused to fix your bug? Well you can go claim a bunch of bounties with it. We also talk about some novel request smuggling research on this episode.

[00:00:58] Multiple Concrete CMS vulnerabilities ( part1 - RCE )

[00:12:02] Exploiting CSP in Webkit to Break Authentication & Authorization

[00:24:57] T-Reqs: HTTP Request Smuggling with Differential Fuzzing

[00:35:30] An Illustrated Guide to Elliptic Curve Cryptography Validation

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/ddr4-rowhammer-azure-bugs-essential-0days-and-backdoored-ida.html

North Korea is at it again targeting researchers, 0day hoarding, breaching secure hardware, and fuzzing on this weeks episode.

[00:01:15] Spot the Vuln - Beyond the Grave

[00:03:50] ESET Research discovered a trojanized IDA Pro installer, distributed by the #Lazarus APT group

[00:12:39] Why Zero-Days Are Essential to Security - Randori

[00:29:32] Blacksmith - Rowhammer Returns

[00:43:04] Fuzzing Microsoft's RDP Client using Virtual Channels: Overview & Methodology

[00:57:45] Microsoft Azure Sphere Security Monitor SMSyscallCommitImageStaging stage-without-manifest denial of service vulnerability

[01:04:53] Microsoft Azure Sphere Kernel GPIO_SET_PIN_CONFIG_IOCTL information disclosure vulnerability

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rust-in-the-web-a-special-guest-and-some-bad-crypto.html

We are joined by Bastian Gruber to start the episode with a discussion about Rust. Then we'll dive into a few interesting vulnerabilities this week including yet another ECDSA implementation issue and some header smuggling research.

[00:00:40] Rust Discussion with Bastian Gruber (Use the code poddayzero21 for 35% off Manning books)

[00:46:29] Arbitrary Signature Forgery in Stark Bank ECDSA Libraries [CVE-2021-43572, CVE-2021-43570, CVE-2021-43569, CVE-2021-43568, CVE-2021-43571]

[01:02:37] Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over

[01:06:52] Private Blog Content Disclosed in Atom Feed

[01:08:29] Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

[01:17:01] IDOR through MongoDB Object IDs Prediction

[01:18:45] History of Cross-Site History Leaking

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-too-trusty-trustzone-and-a-few-linux-kernel-bugs.html

Some interesting vulnerability envrionments this week, some Trusted App issues, a couple Linux Kernel vulns, and a look at memory safety issues in unsafe Rust.

[00:00:19] Spot The Vuln - Extract All The Things - Solution

[00:03:43] Gerbv drill format T-code tool number out-of-bounds write vulnerability

[00:13:27] Vulnerable tzdemuxerservice TA on Samsung TVs (J-series)

[00:27:06] Remote Linux Kernel Heap Overflow | TIPC Module Allows Arbitrary Code Execution [CVE-2021-43267]

[00:33:49] SLUB overflow [CVE-2021-42327]

[00:43:50] Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem Scale

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-macos-sip-bypass-an-xss-fiesta.html

A discussion heavy episode this week, starting off with the "new" Trojan Source attackers, and then talking about a handful of interesting vulnerabilities.

[00:00:18] Trojan Source Attacks

[00:24:07] [SmartStoreNET] Malicious Message leading to E-Commerce Takeover

[00:34:24] [Chrome] Cross-Site Scripting in New-Tab Page [CVE-2021-37999]

[00:39:48] [StreamLabs] Steal access_token via open redirect

[00:43:18] Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection

[00:50:04] Android security checklist: WebView

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/type-confusion-in-android-nfc-php-fpm-local-privilege-escalation-and-callbackhell.html

This week we dive into PHP-FPM internals to look at escelating from a worker process to the root process, anotehr GDI bug, and a type confusion.

[00:00:18] Spot the Vuln - Over the Edge - Solution

[00:03:40] Trick & Treat! Paying Leets and Sweets for Linux Kernel privescs and k8s escapes

[00:10:33] Android NFC: Type confusion due to race condition during tag type change

[00:14:50] PHP-FPM local root vulnerability

[00:28:26] GitHub - ly4k/CallbackHell: Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

[00:29:54] GitHub - ly4k/CallbackHell: Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

[00:36:39] This bug doesn’t exist on x86: Exploiting an ARM-only race condition

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/discourse-sns-rce-a-stored-xss-in-gitlab-and-a-reddit-race-condition.html

A couple unique vulns this week involving getting extra coins on Reddit, and bypassing certificate checking for a Discourse RCE.

[00:00:40] Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD

[00:09:50] Race condition leads to Inflation of coins when bought via Google Play Store

[00:15:11] [GitLab] Stored XSS in Mermaid when viewing Markdown files

[00:33:28] Discourse SNS webhook RCE

[00:47:28] [GitLab] Stored XSS in Mermaid when viewing Markdown files

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-kernel-race-sudump-and-a-chrome-garbage-collector-bug.html

We start off this week with a look at in-the-wild 0days from the past seven years, before diving into some pretty awesome bugs this week including a OOB access in Squirrel (programming language), a couple Linux kernel issues and a Chrome garbage collector bug.

[00:00:22] Spot The Vuln - Just Be Positive - Solution

[00:06:42] Overview of 0days seen in the wild the last 7 years

[00:18:33] Squirrel Sandbox Escape allows Code Execution in Games and Cloud Services

[00:29:15] SuDump: Exploiting suid binaries through the kernel

[00:38:09] How a simple Linux kernel memory corruption bug can lead to complete system compromise

[00:55:46] Chrome in-the-wild bug analysis [CVE-2021-37975]

[01:12:40] FuzzCon Europe 2021

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-slack-attack-and-a-mysql-scientific-notation-bug.html

Just four bugs this week, but that all are somewhat interesting, from an Instagram 2FA removal, deanonymizing Slack users, a MySQL bug, and how to get cheap reddit coins.

[00:00:31] How I was able to revoke your Instagram 2FA

[00:10:02] Abusing Slack's file-sharing functionality to de-anonymise fellow workspace members

[00:29:41] A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection

[00:35:38] Reddit disclosed on HackerOne: IDOR to pay less for coin purchases...

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/webkit-bugs-a-windows-race-and-house-of-io-improved.html

Tianfu Cup happened this week, we also got some cool windows and webkit issues, along side an improvment to the House of IO attack

[00:00:17] Spot The Vuln - Prepare To Inject - Solution

[00:03:14] Tianfu Cup 2021

[00:09:10] Six Privilege Escalations and an Info Leak in Windows [Blackswan vulnerabilities]

[00:25:16] nt!ObpCreateSymbolicLinkName Race Condition Write-Beyond-Boundary

[00:31:37] CVE-2021-30858: Use-after-free in WebKit

[00:44:53] WebKit: heap-use-after-free in DOMWindow::open

[00:50:23] House of IO - Heap Reuse

[01:02:06] Getting started in macOS security

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/websocket-hijacking-github-review-bypass-and-sqli-to-rce.html

Just a handful of traditional vulns this week: IDOR, CSRF, SQLi, a logic vuln and zi's boomer side starts to show.

[00:00:18] Remote Chaos Experience

[00:03:30] [Concrete CMS] Stored unauth XSS in calendar event via CSRF

[00:08:47] ‘Websocket Hijacking’ to steal Session_ID of victim users

[00:14:17] IDOR + Account Takeover leads to PII leakage

[00:27:27] Bypassing required reviews using GitHub Actions

[00:33:20] How I Escalated a Time-Based SQL Injection to RCE

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/hyperkit-bugs-an-open5gs-stack-overflow.html

Uninitialized variables everywhere in Hyperkit, and a Open5GS stack-based buffer overflow.

[00:00:19] Spot The Vuln - Mind the Sign - Solution

[00:00:51] Spot The Vuln - Mind the Sign - Solution

[00:03:53] In EU no contract can prevent you from decompiling software you bought, if your goal is fixing a bug.

[00:11:05] Open5GS Stack Buffer Overflow During PFCP Session Establishment on UPF [CVE-2021-41794]

[00:14:00] Open5GS Stack Buffer Overflow During PFCP Session Establishment on UPF [CVE-2021-41794]

[00:15:27] Code execution outside the virtualized guest in hyperkit

[00:19:45] Disclosure of the host memory into the virtualized guest in hyperkit [CVE-2021-32847]

[00:30:14] The Challenges of Fuzzing 5G Protocols

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/sharepoint-rce-an-apache-path-traversal.html

A simple to exploit path traversal in Apache...in 2021, a one-time-password defeat by having it be send to the attacker and victim, and more JWT issues.

[00:00:24] critical: Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

[00:07:47] [Zomato] Improper Validation at Partners Login

[00:12:25] How did I earned 6000$ from tokens and scopes in one day

[00:22:13] Remote Code Execution in SharePoint via Workflow Compilation [CVE-2021-26420]

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/chrome-exploits-and-a-firefox-update-bug.html

This week we start off with a nice introduction to signedness issues before diving into a couple Chrome bugs (type confusion and use-after-free)

[00:00:17] Spot the Vuln - I Can't Even (Solution)

[00:03:46] Fixing a Security Bug by Changing a Function Signature

[00:11:58] Chrome in-the-wild bug analysis: CVE-2021-30632

[00:21:25] GHSL-2021-124: Use After Free (UAF) in Chrome - CVE-2021-30528

[00:26:56] Phrack - Issue 70

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/gatekeeper-bypass-opera-rce-and-prototype-pollution.html

A few interesting issues this week, ranging from a macOS Gatekeeper bypass, some oauth flow issues in Facebook, and even an RCE through the password field.

[00:00:37] The discovery of Gatekeeper bypass CVE-2021-1810

[00:08:50] Multiple bugs allowed malicious Android Applications to takeover Facebook/Workplace accounts

[00:22:50] Cisco Hyperflex: How We Got RCE Through Login Form and Other Findings

[00:30:50] XSS to RCE in the Opera Browser

[00:35:28] Prototype Pollution

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/kernel-uafs-and-a-parallels-vm-escape.html

This week we we've got a couple Linux kernel Use-After-Frees and a Parallels guest to host escape.

[00:00:18] Spot The Vuln - Solution

[00:02:53] ChaffCTF

[00:17:10] Kernel Vmalloc Use-After-Free in the ION Allocator

[00:25:31] Linux Kernel: Exploitable vulnerability in io_uring

[00:35:09] Parallels Desktop Guest to Host Escape

[00:46:35] Igor: Crash Deduplication Through Root-Cause Clustering

[00:51:10] Igor: Crash Deduplication Through Root-Cause Clustering

[00:57:57] Deus x64: A Pwning Campaign | RET2 Systems

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/ios-0days-apache-dubbo-rces-and-npm-bugs.html

Some of Apple's XPC services are leaking information, Finder has an RCE, and some CodeQL use to find many RCEs in Apache Dubbo.

[00:00:38] macOS Finder RCE

[00:06:11] AWS WorkSpaces Remote Code Execution [CVE-2021-38112]

[00:10:09] Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program

[00:26:51] 5 RCEs in npm for $15,000

[00:42:32] Apache Dubbo: All roads lead to RCE

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-curl-uaf-iphone-forcedentry-and-a-crazy-hp-omen-driver.html

We start off the week with a crazy driver that exposes some powerful primitives, a use-after-free in curl, we speculate a bit about exploiting a 2-byte information disclosure, and talk about FORCEDENTRY.

[00:00:20] Spot The Vuln - Minimax (Solution)

[00:04:30] HP OMEN Gaming Hub Privilege Escalation Bug Hits Millions of Gaming Devices [CVE-2021-3437]

[00:12:32] Nitro Pro PDF JavaScript document.flattenPages JSStackFrame stack-based use-after-free vulnerability

[00:19:31] Microsoft Azure Sphere Security Monitor SMSyscallPeripheralAcquire information disclosure vulnerability

[00:27:24] [curl] UAF and double-free in MQTT sending [CVE-2021-22945]

[00:34:41] Analyzing Pegasus Spyware's Zero-Click iPhone Exploit ForcedEntry

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-flickr-csrf-gitlab-omigod-azure-again.html

Some high impact vulnerabilities this week, CSRF in account deletion, remote code execution as root, and an apache "0day" that discloses PHP source.

[00:00:23] [Flickr] CSRF in Account Deletion feature

[00:03:38] OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers

[00:23:38] How I found my first Adobe Experience Manager related bug.

[00:27:41] [GitLab] Stored XSS in main page of a project

[00:31:01] [Mattermost] Privilege Escalation leading to post in channel without having privilege

[00:34:15] Hacking CloudKit - How I accidentally deleted your Apple Shortcuts

[00:48:52] Apache 0day bug, which still nobody knows of, and which was fixed accidentally

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/netgear-smart-switches-spookjs-parallels-desktop.html

This week we've got an awesome chain of attacks in NETGEAR smart switches, a speculative type confusion (Spook.js) and an integer overflow leading to HTTP Request Smuggling

[00:03:40] Security researchers fed up with Apple’s bug bounty program

[00:18:26] Demon's Cries vulnerability (some NETGEAR smart switches)

[00:22:21] Draconian Fear vulnerability (some NETGEAR smart switches)

[00:25:31] Seventh Inferno vulnerability (some NETGEAR smart switches)

[00:34:33] Spook.js - Speculative Type Confusion

[00:50:36] Critical vulnerability in HAProxy

[00:55:45] Ribbonsoft dxflib DL_Dxf::handleLWPolylineData Heap-Based Buffer Overflow Vulnerability

[01:03:43] Analysis of a Parallels Desktop Stack Clash Vulnerability and Variant Hunting using Binary Ninja

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/reused-vmware-exploits-escaping-azure-container-instances.html

Some drama with the VMWare bounty program, and then a few straight forward vulnerabilities and a really cool Azure Container Instances escape and takeover.

[00:01:51] Exploit Fired At VMWare leaked to Nuclei Project.

[00:14:02] Bypassed! and uploaded a sweet reverse shell

[00:18:51] Local File Read via Stored XSS in The Opera Browser

[00:27:14] NETGEAR D7000 Authentication Bypass

[00:33:34] GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink

[00:42:25] Create free Shopify application credits

[00:47:24] Cross-Account Container Takeover in Azure Container Instances

[00:58:59] IAM Vulnerable - An AWS IAM Privilege Escalation Playground

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week: * Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities * Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

A tricky to exploit WhatsApp vulnerability, but still an interesting bug, several Bhyve vulnerabilities, and a named bluetooth vuln (Braktooth)

Links and summaries are available on our website: https://dayzerosec.com/podcast/escaping-the-bhyve-whatsapp-braktooth.html

[00:00:00] Introduction + The Future

[00:02:08] Spot The Vuln Solution

[00:07:25] Replay-based attack on Honda and Acura vehicles

[00:15:54] A Heap-based Buffer Overflow Bug in the MySQL InnoDB memcached Plugin [CVE-2021-2429]

[00:25:44] Vulnerability in WhatsApp could have led to data exposure of users

[00:32:26] Code execution outside the virtualized guest in bhyve [CVE-2021-29631]

[00:40:59] Your vulnerability is in another OEM!

[01:01:36] BrakTooth

[01:09:00] HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUs

The DAY[0] Podcast has two weekly episodes that are streamed live on Twitch (https://www.twitch.tv/dayzerosec)

Mondays at 3pm Eastern we focus on vulnerabilities that would be of interest to bounty hunters, and on Tuesdays at 7:00pm Eastern we focus on low-level vulnerabilities.

You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Multiple account takeover vulnerabilities in this episode with three  cross-origin communication vulnerabilities in Facebook, an odd OTP  endpoint in SnapChat and an open redirect in JetBrains leaking your JWT.    

Links and summaries are available on our website: https://dayzerosec.com/podcast/takeover-a-facebook-snapchat-or-jetbrains-account.html 

[00:00:00] Introduction + The Future

[00:08:37] How MarkMonitor left 60,000 domains for the taking

[00:17:21] Eye for an eye: Unusual single click JWT token takeover

[00:25:20] How I found a primitive but critical broken access control vulnerability in YouTrack…

[00:29:02] Ghost CMS 4.3.2 - Cross-Origin Admin Takeover

[00:33:47] Tale of $126k worth of bugs that lead to Facebook Account Takeovers

[00:47:15] Improper Authentication - any user can login as other user

[00:53:35] Illogical Apps - Exploring and Exploiting Azure Logic Apps  

The DAY[0] Podcast has two weekly episodes that are streamed live on Twitch (https://www.twitch.tv/dayzerosec)

Mondays at 3pm Eastern we focus on vulnerabilities that would be of interest to bounty hunters, and on Tuesdays at 7:00pm Eastern we focus on low-level vulnerabilities.

You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

View Details

Another short episode this week covering graphql attacks, a couple NoSQL injections, a few misconfigurations and a cool attack to reset monotonic counters on a Mifare card.

[00:01:25] From CTFs to the Real World

  • https://dayzerosec.com/tags/ctf-to-real-world/

[00:02:50] [GitHub] Exploits and Malware Policy Updates

  • https://github.com/github/site-policy/pull/397

  • https://github.com/github/site-policy/pull/397/files

[00:07:37] Mobile app developers’ misconfiguration of third party services leave personal data of over 100 million exposed

  • https://research.checkpoint.com/2021/mobile-app-developers-misconfiguration-of-third-party-services-leave-personal-data-of-over-100-million-exposed/

[00:13:49] QNAP MusicStation/MalwareRemover Pre-Auth RCE

  • https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/

[00:17:45] 2FA Bypass via Forced Browsing

  • https://infosecwriteups.com/2fa-bypass-via-forced-browsing-9e511dfdb8df

[00:24:22] That single GraphQL issue that you keep missing

  • https://blog.doyensec.com/2021/05/20/graphql-csrf.html

[00:32:22] Remote code execution in squirrelly [CVE-2021-32819]

  • https://securitylab.github.com/advisories/GHSL-2021-023-squirrelly/

[00:44:30] NoSQL Injections in Rocket.Chat

  • https://blog.sonarsource.com/nosql-injections-in-rocket-chat/

  • https://hackerone.com/reports/1130721

[00:49:15] RFID: Monotonic Counter Anti-Tearing Defeated

  • https://blog.quarkslab.com/rfid-monotonic-counter-anti-tearing-defeated.html

[00:56:24] A Wormable Code Execution Bug in HTTP.sys [CVE-2021-31166]

  • https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys

  • https://github.com/0vercl0k/CVE-2021-31166

[01:04:15] Fuzzing iOS code on macOS at native speed

  • https://googleprojectzero.blogspot.com/2021/05/fuzzing-ios-code-on-macos-at-native.html

[01:05:07] RuhrSec 2018: "Keynote: Weird machines, exploitability and unexploitability", Thomas Dullien

  • https://www.youtube.com/watch?v=1ynkWcfiwOk

[01:07:58] Browser fuzzing at Mozilla

  • https://blog.mozilla.org/attack-and-defense/2021/05/20/browser-fuzzing-at-mozilla/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

A shorter episode, but some really cool vulns none-the-less, from mitigation bypassing on D-Link routers, to a new set of WiFi protocol design flaws.

[00:01:14] Security Vulnerability Detection Using Deep Learning Natural Language Processing

  • https://arxiv.org/abs/2105.02388v1

  • https://samate.nist.gov/SARD/

[00:08:12] Stealing secrets with Rust Macros proof-of-concept via VSCode

  • https://github.com/lucky/bad_actor_poc

[00:13:21] [GitLab] RCE when removing metadata with ExifTool

  • https://hackerone.com/reports/1154542

  • https://github.com/exiftool/exiftool/blob/11.70/lib/Image/ExifTool/DjVu.pm#L233

[00:19:47] Terminal escape injection in AWS CloudShell

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2154

  • https://github.com/c9/core/blob/master/plugins/c9.ide.terminal/aceterm/libterm.js#L1276

[00:23:54] Cross-browser tracking vulnerability in Tor, Safari, Chrome and Firefox

  • https://fingerprintjs.com/blog/external-protocol-flooding/

[00:34:27] Fei Protocol Flashloan Vulnerability Postmortem

  • https://medium.com/immunefi/fei-protocol-flashloan-vulnerability-postmortem-7c5dc001affb

  • https://uniswap.org/docs/v2/smart-contract-integration/providing-liquidity/

[00:44:46] One-click reflected XSS on Instagram

  • https://ysamm.com/?p=695

[00:47:24] D-Link Vulnerability [CVE-2021-27342]

  • https://blog.whtaguy.com/2021/05/d-link-router-cve-2021-27342.html

[00:51:52] Experimental Security Assessment of Mercedes-Benz Cars

  • https://keenlab.tencent.com/en/2021/05/12/Tencent-Security-Keen-Lab-Experimental-Security-Assessment-on-Mercedes-Benz-Cars/

  • https://keenlab.tencent.com/en/whitepapers/Mercedes_Benz_Security_Research_Report_Final.pdf

[01:01:08] FragAttacks: Fragmentation & Aggregation Attacks

  • https://github.com/vanhoefm/fragattacks

  • https://www.youtube.com/watch?v=OJ9nFeuitIU

[01:10:57] Dell ‘dbutil_2_3.sys’ Kernel Exploit [CVE-2021-21551]

  • https://connormcgarr.github.io/cve-2020-21551-sploit/

[01:11:45] googleprojectzero/Hyntrospect

  • https://github.com/googleprojectzero/Hyntrospect

[01:13:01] IDA Free w/ Cloud Decompiler Dropped

  • https://www.hex-rays.com/ida-free/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Kicking off the week with some awesome vulns, an "almost" padding oracle in Azure Functions, a race-condition in AWS Cognito, some sound engine bugs, and a Foxit Reader Use-after-free.

[00:00:52] Arbitrary Code Execution in the Universal Turing Machine [CVE-2021-32471]

  • Our discussion of this topic was probably a bit premature and there does seem to be a bit more to it than the title implied. Still no real-world impact, but a bit more interesting of situation none-the-less.
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32471
  • https://arxiv.org/abs/2105.02124

[00:03:18] Detecting and annoying Burp users

  • https://dustri.org/b/detecting-and-annoying-burp-users.html
  • https://www.youtube.com/watch?v=I3pNLB3Cq24

[00:08:08] Enabling Hardware-enforced Stack Protection (cetcompat) in Chrome

  • https://security.googleblog.com/2021/05/enabling-hardware-enforced-stack.html

[00:13:00] Password reset code brute-force vulnerability in AWS Cognito

  • https://www.pentagrid.ch/en/blog/password-reset-code-brute-force-vulnerability-in-AWS-Cognito/

[00:16:52] ASUS GT-AC2900 Authentication Bypass [CVE-2021-32030]

  • https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass

[00:20:10] The False Oracle - Azure Functions Padding Oracle Issue

  • https://polarply.medium.com/the-false-oracle-azure-functions-padding-oracle-issue-2025e0e6b8a

[00:25:30] How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit

  • https://blog.polybdenum.com/2021/05/05/how-i-hacked-google-app-engine-anatomy-of-a-java-bytecode-exploit.html

[00:38:01] Workplace by Facebook | Unauthorized access to companies environment

  • https://mvinni.medium.com/workplace-by-facebook-unauthorized-access-to-companies-environment-27-5k-a593a57092f1

[00:42:39] Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida

  • https://ctf.re//source-engine/exploitation/2021/05/01/source-engine-2/
  • https://phoenhex.re/2018-08-26/csgo-fuzzing-bsp

[00:53:11] [Valve] OOB reads in network message handlers leads to RCE

  • https://hackerone.com/reports/807772

[01:01:07] Security probe of Qualcomm MSM data services

  • https://research.checkpoint.com/2021/security-probe-of-qualcomm-msm/

[01:05:17] Foxit Reader FileAttachment annotation use-after-free vulnerability

  • https://talosintelligence.com/vulnerability_reports/TALOS-2021-1287

[01:09:45] Attack llvmpipe Graphics Driver from Chromium

  • https://insinuator.net/2021/05/attack-llvmpipe-graphics-driver-from-chromium/

[01:16:00] Privilege Escalation Via a Use After Free Vulnerability In win32k [CVE-2021-26900]

  • https://www.zerodayinitiative.com/blog/2021/5/3/cve-2021-26900-privilege-escalation-via-a-use-after-free-vulnerability-in-win32k

[01:26:25] 21Nails: Multiple vulnerabilities in Exim

  • https://www.qualys.com/2021/05/04/21nails/21nails.txt

[01:27:22] nRF52 Debug Resurrection (APPROTECT Bypass)

  • https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/

[01:28:56] Capture The Flag - Discussion Video

  • https://www.youtube.com/watch?v=4u5MDsIfQM8

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Big episode this week, with a lot of discussion about CTFs, kernel drama, and Github's exploit policy. Then some really interesting exploit strategies on Tesla and Netgear, along with some simple, yet deadly issues in Wordpress and Composer.

[00:00:32] An Update on the UMN Affair

  • https://lwn.net/SubscriberLink/854645/334317047842b6c3/

  • https://www-users.cs.umn.edu/%7Ekjlu/papers/full-disclosure.pdf

[00:11:29] [GitHub] Exploits and Malware Policy Updates

  • https://github.com/github/site-policy/pull/397

  • https://github.com/github/site-policy/pull/397/commits/f220679709b60dd4d6b34465a56b89bb79efcfe6#diff-24d72c4cb9785e60d5cbf50905291a5e079f4efd8c03f67904077cc2af4b8412L34

[00:18:22] OOO - DEF CON CTF

  • https://oooverflow.io/

  • https://twitter.com/oooverflow/status/1388920554111987715

[00:34:23] BadAlloc - Memory Allocation Vulnerabilities

  • https://msrc-blog.microsoft.com/2021/04/29/badalloc-memory-allocation-vulnerabilities-could-affect-wide-range-of-iot-and-ot-devices-in-industrial-medical-and-enterprise-networks/

  • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-04

[00:40:15] I See Dead μops: Leaking Secrets via Intel/AMDMicro-Op Caches

  • http://www.cs.virginia.edu/venkat/papers/isca2021a.pdf

  • https://comparch.org/2021/05/01/i-see-dead-uops-thoughts-on-the-latest-spectre-paper-targeting-uop-caches/

[00:54:43] Brave - Stealing your cookies remotely

  • https://infosecwriteups.com/brave-stealing-your-cookies-remotely-1e09d1184675

[00:57:37] Facebook account takeover due to unsafe redirects after the OAuth flow

  • https://ysamm.com/?p=667

[01:03:11] WordPress 5.7 XXE Vulnerability

  • https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/

[01:05:43] PHP Supply Chain Attack on Composer

  • https://blog.sonarsource.com/php-supply-chain-attack-on-composer

[01:10:25] Multiple Issues in Libre Wireless LS9 Modules

  • https://www.iot-inspector.com/blog/advisory-multiple-issues-libre-wireless-ls9/

[01:14:50] macOS Gatekeeper Bypass

  • https://objective-see.com/blog/blog_0x64.html

  • https://cedowens.medium.com/macos-gatekeeper-bypass-2021-edition-5256a2955508

[01:19:28] Linux Kernel /proc/pid/syscall information disclosure vulnerability

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211

[01:24:08] Remote Zero-Click Exploit in Tesla Automobiles

  • https://kunnamon.io/tbone/

[01:31:00] NETGEAR Nighthawk R7000 httpd PreAuth RCE

  • https://ssd-disclosure.com/ssd-advisory-netgear-nighthawk-r7000-httpd-preauth-rce/

[01:34:43] Parallels Desktop RDPMC Hypercall Interface and Vulnerabilities

  • https://www.zerodayinitiative.com/blog/2021/4/26/parallels-desktop-rdpmc-hypercall-interface-and-vulnerabilities

[01:39:24] Exploiting Undocumented Hardware Blocks in the LPC55S69

  • https://oxide.computer/blog/lpc55/

[01:40:05] python stdlib "ipaddress" - Improper Input Validation [CVE-2021-29921]

  • https://sick.codes/sick-2021-014/

[01:40:35] Ham Hacks: Breaking Into Software-defined Radio

  • https://labs.bishopfox.com/industry-blog/ham-hacks-breaking-into-software-defined-radio

[01:41:59] gand3lf/heappy: A happy heap editor to support your exploitation process

  • https://github.com/Gand3lf/heappy

[01:43:38] LiveQL Episode II: The Rhino in the room

  • https://securitylab.github.co

View Details

Some drama in the Linux Kernel and so many vulns resulting in code execution in Homebrew, GitLab, an air fryer, Source engine, Super Mario Maker, Adobe Reader and the Linux Kernel.

[00:00:32] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits

  • https://github.com/QiushiWu/QiushiWu.github.io/blob/main/papers/OpenSourceInsecurity.pdf
  • https://lore.kernel.org/linux-nfs/YH+zwQgBBGUJdiVK@unreal/
  • https://lore.kernel.org/linux-nfs/YH%2FfM%2FTsbmcZzwnX@kroah.com/
  • During this episode we speculated that the recent patches might be unrelated to the research. This seems to have been confirmed by U. Mn in an email we did not see before recording
  • https://lore.kernel.org/lkml/CAK8KejpUVLxmqp026JY7x5GzHU2YJLPU8SzTZUNXU2OXC70ZQQ@mail.gmail.com/

[00:15:18] Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective

  • https://signal.org/blog/cellebrite-vulnerabilities/

[00:22:30] [Ubuntu] OverlayFS LPE

  • https://ssd-disclosure.com/ssd-advisory-overlayfs-pe/

[00:25:48] Synology DSM AppArmor synosearchagent misconfiguration

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1158

[00:28:22] [GitLab] RCE via unsafe inline Kramdown options

  • https://hackerone.com/reports/1125425

[00:35:25] [Homebrew] Broken parsing of Git diff allows an attacker to inject arbitrary Ruby scripts to Casks on official taps

  • https://hackerone.com/reports/1167608
  • https://blog.ryotak.me/post/homebrew-security-incident-en/

[00:41:52] Remote code execution vulnerabilities in Cosori smart air fryer

  • https://blog.talosintelligence.com/2021/04/vuln-spotlight-co.html
  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1217
  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1216

[00:48:54] Source engine remote code execution via game invites [CVE-2021-30481]

  • https://secret.club/2021/04/20/source-engine-rce-invite.html

[01:00:40] Discussion: Should programs be banned from Hackerone

  • https://dayzerosec.com

[01:08:54] [Nintendo|3DS] Buffer Overflow in Super Mario Maker level decompression

  • https://hackerone.com/reports/687887

[01:15:12] PrusaSlicer Obj.cpp load_obj() out-of-bounds write vulnerability

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1219

[01:20:12] Analysis of a use-after-free Vulnerability in Adobe Acrobat Reader DC

  • https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/
  • https://www.zerodayinitiative.com/blog/2021/4/22/cve-2021-20226-a-reference-counting-bug-in-the-linux-kernel-iouring-subsystem

[01:31:21] Designing sockfuzzer, a network syscall fuzzer for XNU

  • https://googleprojectzero.blogspot.com/2021/04/designing-sockfuzzer-network-syscall.html

[01:37:26] gaasedelen/tenet: A Trace Explorer for Reverse Engineers

  • https://github.com/gaasedelen/tenet

[01:40:41] tmp.0ut

  • https://tmpout.sh/1/

[01:44:35] Phœnix exploit / iOS 9.3.5

  • https://gist.github.com/Siguza/96ae6d6806e974199b1d44ffffca5331

[01:46:02] Experiences with Apple Security Bounty

  • https://theevilbit.github.io/posts/experiences_with_asb/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the vide

View Details

Authentication bypasses, a Duo 2FA bypass, RCEs, a VM escape, and some reverse engineering writeups.

[00:00:26] Project Zero: Policy and Disclosure: 2021 Edition

  • https://googleprojectzero.blogspot.com/2021/04/policy-and-disclosure-2021-edition.html

[00:06:27] Remote exploitation of a man-in-the-disk vulnerability in WhatsApp [CVE-2021-24027]

  • https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/

[00:14:06] Allow arbitrary URLs, expect arbitrary code execution

  • https://positive.security/blog/url-open-rce

[00:18:29] GHSL-2020-340: log injection in SAP/Infrabox

  • https://securitylab.github.com/advisories/GHSL-2020-340/

[00:22:21] Duo Two-factor Authentication Bypass

  • https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/

[00:31:22] [Grammarly] Ability to DOS any organization's SSO and open up the door to account takeovers

  • https://hackerone.com/reports/976603

[00:35:50] From 0 to RCE: Cockpit CMS

  • https://swarm.ptsecurity.com/rce-cockpit-cms/?d

[00:41:41] Big Bugs: Bitbucket Pipelines Kata Containers Build Container Escape

  • https://www.bugcrowd.com/blog/big-bugs-cve-2020-28914/

[00:48:52] xscreensaver: raw socket leaked

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2174

[00:51:31] Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)

  • https://doar-e.github.io/blog/2021/04/15/reverse-engineering-tcpipsys-mechanics-of-a-packet-of-the-death-cve-2021-24086/

  • https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html

[00:59:49] Exploiting System Mechanic Driver

  • https://voidsec.com/exploiting-system-mechanic-driver/

[01:03:27] Zero-day vulnerability in Desktop Window Manager used in the wild [CVE-2021-28310]

  • https://securelist.com/zero-day-vulnerability-in-desktop-window-manager-cve-2021-28310-used-in-the-wild/101898/

[01:08:33] Windows Defender mpengine remote code execution [CVE-2021-1647]

  • https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2021/CVE-2021-1647.html

[01:13:55] ELECTRIC CHROME - CVE-2020-6418 on Tesla Model 3

  • https://leethax0.rs/2021/04/ElectricChrome/

  • http://www.phrack.org/papers/attacking_javascript_engines.html

[01:20:36] QEMU and U: Whole-system tracing with QEMU customization

  • https://www.atredis.com/blog/qemu-and-u-whole-system-tracing-with-qemu-customization

[01:21:31] Learning Resource - Hexterisk Blog

  • https://hexterisk.github.io/blog/posts/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

MD5 is trending in 2021...a few kernel vulnerabilities, and some drama around pwn2own.

[00:00:26] Update on git.php.net incident

  • https://externals.io/message/113981

[00:06:38] Pwn2Own 2021 - Results

  • https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-2021-schedule-and-live-results

[00:18:53] CSGO exploit allows hackers to steal passwords, and Valve hasn't fixed it

  • https://www.dexerto.com/csgo/csgo-exploit-allows-hackers-steal-passwords-valve-no-fix-1551056/?amp

[00:26:20] I Built a TV That Plays All of Your Private YouTube Videos

  • https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/

[00:33:27] Leak of all accounts mail login md5 pass

  • https://hackerone.com/reports/514488

[00:37:11] What if you could deposit money into your Betting account for free?

  • https://mikey96.medium.com/what-if-you-could-deposit-money-into-your-betting-account-for-free-24f6690aff46

[00:41:41] Zero click vulnerability in Apple’s macOS Mail

  • https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c

[00:44:54] Stored XSS on the DuckDuckGo search results page

  • https://monke.ie/duckduckgoxss/

[00:49:13] Breaking GitHub Private Pages for $35k

  • https://robertchen.cc/blog/2021/04/03/github-pages-xss

[00:57:03] Royal Flush: Privilege Escalation Vulnerability in Azure Functions

  • https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/

[01:01:38] QNAP Pre-Auth CGI_Find_Parameter RCE

  • https://ssd-disclosure.com/ssd-advisory-qnap-pre-auth-cgi_find_parameter-rce/

[01:04:14] Domain Time II Upgrade Attack

  • https://blog.grimm-co.com/2021/04/time-for-upgrade.html

[01:07:12] Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel

  • https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html

[01:15:57] BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution

  • https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html

  • https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html

[01:28:05] BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution

  • https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html

[01:29:07] Exploiting Windows RPC to bypass CFG mitigation

  • https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html

  • https://medium.com/@mxatone/mitigation-bounty-from-read-write-anywhere-to-controllable-calls-ca1b9c7c0130#.9l7ejbkij

[01:34:00] security things in Linux v5.9

  • https://outflux.net/blog/archives/2021/04/05/security-things-in-linux-v5-9/

  • https://github.com/gcc-mirror/gcc/commit/d10f3e900b0377b4760a090b0f90371bcef01686

  • https://twitter.com/kees_cook/status/1380271827281276928

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

One episode and several failed attempts to fix vulnerabilities, an interesting Rocket.Chat XSS and an exploitable TXT file abusing some weird features.

[00:00:46] nOtWASP bottom 10: vulnerabilities that make you cry

  • https://portswigger.net/research/notwasp-bottom-10-vulnerabilities-that-make-you-cry

[00:07:28] Click here for free TV! - Chaining bugs to takeover Wind Vision accounts

  • https://labs.f-secure.com/blog/wind-vision-writeup/

[00:15:28] Elevate Yourself to Admin in Umbraco CMS 8.9.0 (CVE-2020-29454)

  • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/elevate-yourself-to-admin-in-umb-cms-890-cve-2020-29454/

[00:23:19] "netmask" npm package vulnerable to octal input data [CVE-2021-28918]

  • https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/

[00:28:38] [HackerOne] Jira integration plugin Leaked JWT

  • https://hackerone.com/reports/1103582

[00:33:20] [Kaspersky] A vulnerability in KAVKIS 2020 products family allows full disabling of protection

  • https://hackerone.com/reports/870615

[00:38:06] [Rocket.Chat] Account takeover via XSS

  • https://hackerone.com/reports/735638

[00:43:18] This man thought opening a TXT file is fine, he thought wrong. macOS [CVE-2019-8761]

  • https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html

[00:52:41] Who Contains the Containers?

  • https://googleprojectzero.blogspot.com/2021/04/who-contains-containers.html

[01:06:11] Getting Code Execution on Apache Druid [CVE-2021-25646]

  • https://www.thezdi.com/blog/2021/3/25/cve-2021-25646-getting-code-execution-on-apache-druid

[01:12:59] Security Analysis of AMD Predictive Store Forwarding

  • https://www.amd.com/system/files/documents/security-analysis-predictive-store-forwarding.pdf

[01:19:58] Pluralsight free for April

  • https://www.pluralsight.com/

[01:21:54] Pwn2Own 2021

  • https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-2021-schedule-and-live-results

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Long episode this week as we talk about Google's decision to thwart a western intelligence operation (by fixing vulns), multiple authorization and authentication issues, and of course some memory corruption.

[00:00:46] Google's unusual move to shut down an active counterterrorism operation being conducted by a Western democracy

  • https://www.technologyreview.com/2021/03/26/1021318/google-security-shut-down-counter-terrorist-us-ally/

[00:21:48] PHP Git Compromised

  • https://news-web.php.net/php.internals/113838

  • https://github.com/php/php-src/commit/2b0f239b211c7544ebc7a4cd2c977a5b7a11ed8a

[00:32:24] [Google Chrome] File System Access API vulnerabilities

  • https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome

[00:37:58] Indexing of urls on the "External link warning" pages discloses many vulnerable endpoints from the past and unlisted videos/photos

  • https://hackerone.com/reports/1034257

[00:42:05] GHSL-2020-323: Template injection in a GitHub workflow of geek-cookbook

  • https://securitylab.github.com/advisories/GHSL-2020-323-geek-cookbook-workflow/

[00:47:58] H2C Smuggling in the Wild

  • https://blog.assetnote.io/2021/03/18/h2c-smuggling/

  • https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c

[00:53:27] H2C Smuggling in the Wild

  • https://blog.assetnote.io/2021/03/18/h2c-smuggling/

[00:57:18] Multiple Authorization bypass issues in Google's Richmedia Studio

  • https://www.ehpus.com/post/multiple-authorization-bypass-issues-in-google-s-richmedia-studio

[01:06:15] DD-WRT UPNP Buffer Overflow

  • https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/

  • https://github.com/mirror/dd-wrt/commit/da1d65a2ec471f652c77ae0067544994cdaf5e27

[01:10:36] GHSL-2021-045: Integer Overflow in GLib - [CVE-2021-27219]

  • https://securitylab.github.com/advisories/GHSL-2021-045-g_bytes_new/

[01:14:12] Qualcomm IPQ40xx: Analysis of Critical QSEE Vulnerabilities

  • https://raelize.com/blog/qualcomm-ipq40xx-analysis-of-critical-qsee-vulnerabilities/

[01:22:50] One day short of a full chain: Part 3 - Chrome renderer RCE

  • https://securitylab.github.com/research/one_day_short_of_a_fullchain_renderer/

[01:35:37] Chat Question: Where to learn about Windows Heap exploitation

  • https://dayzerosec.com

[01:39:44] Adobe Reader CoolType arbitrary stack manipulation in Type 1/Multiple Master othersubrs 14-18

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2131

[01:46:26] Eliminating XSS from WebUI with Trusted Types

  • https://microsoftedge.github.io/edgevr/posts/eliminating-xss-with-trusted-types/

[01:54:19] Hidden OAuth attack vectors

  • https://portswigger.net/research/hidden-oauth-attack-vectors

[02:03:05] The Future of C Code Review

  • https://research.nccgroup.com/2021/03/23/the-future-of-c-code-review/

[02:15:03] Microsoft Exchange Server-Side Request Forgery [CVE-2021-26855]

  • https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2021/CVE-2021-26855.html

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Time to rewrite Linux in Rust? Probably not, but it has landed in linux-next which we talked about. We also look at a couple interesting GitHub vulns, and talk about fuzzing.

[00:00:28] Rust in the Linux Kernel

  • https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/rust?id=c77c8025525c36c9d2b9d82e4539403701276a1d

  • https://www.youtube.com/watch?v=FFjV9f_Ub9o&t=2066s

  • https://lkml.org/lkml/2020/7/9/952

  • https://lkml.org/lkml/2020/7/10/1261

[00:13:40] Two Undocumented Instructions to Update Microcode Discovered

  • https://twitter.com/_markel___/status/1373059797155778562

[00:19:06] DuckDuckGo Privacy Essentials vulnerabilities: Insecure communication and Universal XSS

  • https://palant.info/2021/03/15/duckduckgo-privacy-essentials-vulnerabilities-insecure-communication-and-universal-xss/

[00:26:46] Abusing VoIPmonitor for Remote Code Execution

  • https://www.rtcsec.com/post/2021/03/bug-discovery-diaries-abusing-voipmonitor-for-remote-code-execution/

[00:32:18] Stealing arbitrary GitHub Actions secrets

  • https://blog.teddykatz.com/2021/03/17/github-actions-write-access.html

[00:40:29] How we found and fixed a rare race condition in our session handling

  • https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare-race-condition-in-our-session-handling/

[00:49:05] GitLab - Ability To Delete User(s) Account Without User Interaction

  • https://hackerone.com/reports/928255

[00:52:49] New Old Bugs in the Linux Kernel

  • https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html

  • https://github.com/grimm-co/NotQuite0DayFriday/tree/trunk/2021.03.12-linux-iscsi

[01:00:33] Fuzzing: FastStone Image Viewer [CVE-2021-26236]

  • https://voidsec.com/fuzzing-faststone-image-viewer-cve-2021-26236/

[01:06:53] A Replay-Style Deserialization Attack Against SharePoint [CVE-2021-27076]

  • https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint

[01:12:38] One day short of a full chain: Part 2 - Chrome sandbox escape

  • https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx

[01:18:58] Code execution in Wireshark via non-http(s) schemes in URL fields

  • https://gitlab.com/wireshark/wireshark/-/issues/17232

[01:21:59] Attacking and Defending OAuth 2.0 (Part 2 of 2: Attacking OAuth 2.0 Authorization Servers)

  • https://www.praetorian.com/blog/attacking-and-defending-oauth-2/

[01:30:37] Fast Coverage-guided Fuzzing with Honeybee and Intel Processor Trace

  • https://blog.trailofbits.com/2021/03/19/un-bee-lievable-performance-fast-coverage-guided-fuzzing-with-honeybee-and-intel-processor-trace/

[01:42:00] Pulling Bits From ROM Silicon Die Images: Unknown Architecture

  • https://ryancor.medium.com/pulling-bits-from-rom-silicon-die-images-unknown-architecture-b73b6b0d4e5d

[01:42:28] 0dayfans.com

  • https://0dayfans.com/

  • https://github.com/dayzerosec/feedgen

  • https://shop.spreadshirt.com/dayzerosec/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

RCE while cloning a Git repo, injecting video into network cameras, and stealing logins with HTML injection when XSS isn't possible.

[00:00:32] Critics fume after Github removes exploit code for Exchange vulnerabilities

  • https://arstechnica.com/gadgets/2021/03/critics-fume-after-github-removes-exploit-code-for-exchange-vulnerabilities/

  • https://borncity.com/win/2021/03/14/gab-es-beim-exchange-massenhack-ein-leck-bei-microsoft/

[00:09:21] CCTV: Now You See Me, Now You Don't

  • https://research.aurainfosec.io/v380-ip-camera/

[00:13:47] CSRF to RCE Chain in Zabbix [CVE-2021-27927]

  • https://www.horizon3.ai/disclosures/zabbix-csrf-to-rce

[00:19:44] Stealing Froxlor login credentials using dangling markup [CVE-2020-29653]

  • https://labs.detectify.com/2021/03/10/cve-2020-29653-stealing-froxlor-login-credentials-dangling-markup/

[00:25:29] git: malicious repositories can execute remote code while cloning

  • https://www.openwall.com/lists/oss-security/2021/03/09/3

  • https://github.com/gitster/git/commit/684dd4c2b414bcf648505e74498a608f28de4592

[00:30:49] git: malicious repositories can execute remote code while cloning

  • https://www.openwall.com/lists/oss-security/2021/03/09/3

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2021

[00:33:37] Dell OpenManage Server Administrator File Read [CVE-2020-5377]

  • https://rhinosecuritylabs.com/research/cve-2020-5377-dell-openmanage-server-administrator-file-read/

[00:38:55] Windows Containers: ContainerUser has Elevated Privileges

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2127

[00:40:18] Windows Containers: Host Registry Virtual Registry Provider Bypass EoP

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2129

[00:42:34] F5 Big IP - ASM stack-based buffer overflow in is_hdr_criteria_matches

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2132

[00:48:59] F5 Big IP - TMM uri_normalize_host infoleak and out-of-bounds write

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2126

[00:59:37] One day short of a full chain: Part 1 - Android Kernel arbitrary code execution

  • https://securitylab.github.com/research/one_day_short_of_a_fullchain_android

[01:08:07] Exploiting a “Simple” Vulnerability, Part 2 – What If We Made Exploitation Harder?

  • https://windows-internals.com/exploiting-a-simple-vulnerability-part-2-what-if-we-made-exploitation-harder/?utm_source=rss&utm_medium=rss&utm_campaign=exploiting-a-simple-vulnerability-part-2-what-if-we-made-exploitation-harder

[01:09:11] Playing in the (Windows) Sandbox

  • https://research.checkpoint.com/2021/playing-in-the-windows-sandbox/

[01:09:39] Regexploit: DoS-able Regular Expressions

  • https://blog.doyensec.com/2021/03/11/regexploit.html

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

This week we get to take a look into some basic heap grooming techniques as we examine multiple heap overflows. We also briefly discuss the hand-on (by the DoD and Synack) assessment of the "unhackable" morpheus chip, and briefly discuss the new-ish paper claiming to defeat RSA.

[00:00:53] "This destroys the RSA cryptosystem." - Fast Factoring Integers by SVP Algorithms

  • https://eprint.iacr.org/2021/232

  • https://github.com/lducas/SchnorrGate

[00:06:55] DARPA pitted 500+ hackers against this computer chip. The chip won.

  • https://cse.engin.umich.edu/stories/morpheus-vs-everybody

  • https://www.reddit.com/r/HowToHack/comments/bl9qo3/morpheus_chip/empsclt/?context=10

[00:18:10] SaltStack API vulnerabilities

  • https://dozer.nz/posts/saltapi-vulns

  • https://github.com/saltstack/salt/blob/08fe46365f92583ea875f9e4a8b2cb5305b34e4b/salt/client/ssh/client.py#L72

[00:22:57] An Interesting Feature in the Samsung DSP Driver

  • https://www.synacktiv.com/en/publications/an-interesting-feature-in-the-samsung-dsp-driver.html

[00:30:50] Pre-Auth Remote Code Execution in VMware ESXi [CVE-2020-3992 CVE-2021-21974]

  • https://www.thezdi.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi

[00:39:05] Defeating the TP-Link AC1750

  • https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html

[00:44:52] Anatomy of an Exploit: RCE with CVE-2020-1350 SIGRed

  • https://www.graplsecurity.com/post/anatomy-of-an-exploit-rce-with-cve-2020-1350-sigred

[00:57:11] Yet another RenderFrameHostImpl UAF

  • https://microsoftedge.github.io/edgevr/posts/yet-another-uaf/

[01:03:16] Webkit AudioSourceProviderGStreamer use-after-free vulnerability

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1172

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

This week we talk a bit about newly released Black Hat 2020 and NDSS 2021 presentation videos, before jumping into several pre-auth RCEs, and some interesting exploitation research to bring a PAC enforced Shadow Stack to ARM and an examination of JSON parser interoperability issues.

[00:00:41] Microsoft open sources CodeQL queries used to hunt for Solorigate activity

  • https://www.microsoft.com/security/blog/2021/02/25/microsoft-open-sources-codeql-queries-used-to-hunt-for-solorigate-activity/

  • https://github.com/github/codeql/pull/5083/commits/5e1e27c2b6b3429623b66531d4fe0b090e70638a

[00:04:16] Black Hat USA 2020

  • https://www.youtube.com/playlist?list=PLH15HpR5qRsXE_4kOSy_SXwFkFQre4AV_

  • https://www.youtube.com/c/NDSSSymposium/search?query=NDSS+2021

[00:13:56] Cookie poisoning leads to DOS and Privacy Violation

  • https://hackerone.com/reports/1067809

[00:16:37] Unauthorized RCE in VMware vCenter

  • https://swarm.ptsecurity.com/unauth-rce-vmware/

[00:20:01] A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server [CVE-2020-8625]

  • https://www.thezdi.com/blog/2021/2/24/cve-2020-8625-a-fifteen-year-old-rce-bug-returns-in-isc-bind-server

[00:25:42] Arbitrary File Write on packagecontrol.io (Sublime Text)

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2163

[00:30:31] [Uber] PreAuth RCE on Palo Alto GlobalProtect

  • https://hackerone.com/reports/540242

  • http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html

[00:35:26] The little bug that couldn't: Securing OpenSSL

  • https://github.blog/2021-02-25-the-little-bug-that-couldnt-securing-openssl/

[00:41:49] PACStack: an Authenticated Call Stack

  • https://www.usenix.org/conference/usenixsecurity21/presentation/liljestrand

[00:56:29] An Exploration of JSON Interoperability Vulnerabilities

  • https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities

[01:03:59] Top 10 web hacking techniques of 2020

  • https://portswigger.net/research/top-10-web-hacking-techniques-of-2020

[01:05:50] OST 2.0 Beta Spots Open

  • https://twitter.com/XenoKovah/status/1366224804639031299

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

A couple privacy violations, PDF exploits, and a complicated API being misused by developers.

[00:00:48] Brave browser leaks onion addresses in DNS traffic

  • https://ramble.pw/f/privacy/2387

[00:07:05] Tales of Favicons and Caches: Persistent Tracking in Modern Browsers

  • https://www.ndss-symposium.org/ndss-paper/tales-of-favicons-and-caches-persistent-tracking-in-modern-browsers/

[00:18:12] Shadow Attacks: Hiding and Replacing Content in Signed PDFs

  • https://www.ndss-symposium.org/ndss-paper/shadow-attacks-hiding-and-replacing-content-in-signed-pdfs/

[00:28:20] Getting Information Disclosure in Adobe Reader Through the ID Tag

  • https://www.thezdi.com/blog/2021/2/17/zdi-21-171-getting-information-disclosure-in-adobe-reader-through-the-id-tag

[00:32:42] Middleware everywhere and lots of misconfigurations to fix

  • https://labs.detectify.com/2021/02/18/middleware-middleware-everywhere-and-lots-of-misconfigurations-to-fix/

[00:43:05] GPGme used confusion, it's super effective !

  • https://www.synacktiv.com/en/publications/gpgme-used-confusion-its-super-effective.html

[00:51:58] Bypassing the PIN in non-Visa Cards by Using Them for Visa Transactions

  • https://emvrace.github.io

[01:01:11] Hunting for bugs in Telegram's animated stickers remote attack surface

  • https://www.shielder.it/blog/2021/02/hunting-for-bugs-in-telegrams-animated-stickers-remote-attack-surface/

[01:08:03] Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits

  • https://arxiv.org/abs/2102.07869v1

[01:20:27] Model Skewing Attacks on Machine Learning Models

  • https://payatu.com/blog/nikhilj/sec4ml-machine-learning-model-skewing-data-poisoning

[01:21:37] Future of Exploit Development - 2021 and Beyond

  • https://www.youtube.com/watch?v=o_hk9nh8S1M

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

"Beg Bounty" hunters, dependency confusion, iOS kernel vuln, and how not to respond to security research.

[00:00:59] Florida Water Treatment Facility Hacked

  • https://twitter.com/Bing_Chris/status/1358873543623274499

[00:09:19] Have a domain name? "Beg bounty" hunters may be on their way

  • https://news.sophos.com/en-us/2021/02/08/have-a-domain-name-beg-bounty-hunters-may-be-on-their-way/amp/

[00:20:14] FootFallCam and MetaTechnology Drama

  • https://twitter.com/_MG_/status/1359582048260743169

[00:28:33] Telegram privacy fails [CVE-2021-27204] [CVE-2021-27205]

  • https://www.inputzero.io/2020/12/telegram-privacy-fails-again.html

[00:36:43] Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies

  • https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

[00:44:33] Exploiting a Second-Order SQL Injection in LibreNMS [CVE-2020-35700]

  • https://www.horizon3.ai/disclosures/librenms-second-order-sqli

[00:50:46] Swarm of Palo Alto PAN-OS vulnerabilities

  • https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/

[00:56:25] Advantech iView Missing Authentication RCE [CVE-2021-22652]

  • https://blog.rapid7.com/2021/02/11/cve-2021-22652-advantech-iview-missing-authentication-rce-fixed/

[01:02:30] Windows kernel zero-day exploit [CVE-2021-1732]

  • https://ti.dbappsecurity.com.cn/blog/index.php/2021/02/10/windows-kernel-zero-day-exploit-is-used-by-bitter-apt-in-targeted-attack/

[01:08:50] Analysis and exploitation of the iOS kernel vulnerability [CVE-2021-1782]

  • https://www.synacktiv.com/publications/analysis-and-exploitation-of-the-ios-kernel-vulnerability-cve-2021-1782

[01:20:10] Misusing Service Workers for Privacy Leakage

  • https://www.ndss-symposium.org/ndss-paper/awakening-the-webs-sleeper-agents-misusing-service-workers-for-privacy-leakage/

[01:27:53] security things in Linux v5.8

  • https://outflux.net/blog/archives/2021/02/08/security-things-in-linux-v5-8/

[01:40:42] Linux Heap Exploitation - Part 2

  • https://www.udemy.com/course/linux-heap-exploitation-part-2/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

A lot of discussion this week about OSS security and security processes, an iOS kernel type confusion and MediaTek Bootloader bypass impacting everything since atleast 2014.

[00:04:54] Know, Prevent, Fix: A framework for shifting the discussion around vulnerabilities in open source

  • https://security.googleblog.com/2021/02/know-prevent-fix-framework-for-shifting.html

[00:15:18] Launching OSV - Better vulnerability triage for open source

  • https://security.googleblog.com/2021/02/launching-osv-better-vulnerability.html

[00:22:38] Most Common Bugs of 2021 So Far

  • https://www.bugcrowd.com/blog/common-bugs-of-2021/

[00:31:59] Exploiting the Nespresso smart cards for fun and coffee

  • https://pollevanhoof.be/nuggets/smart_cards/nespresso

[00:39:10] Spoofing and Attacking With Skype

  • https://blog.thecybersecuritytutor.com/spoofing-and-attacking-with-skype/

[00:45:01] Getting root on webOS

  • https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html

[00:51:31] Applying Offensive Reverse Engineering to Facebook Gameroom

  • https://spaceraccoon.dev/applying-offensive-reverse-engineering-to-facebook-gameroom

[00:59:36] Major Vulnerabilities Discovered in Realtek RTL8195A Wi-Fi Module

  • https://www.vdoo.com/blog/realtek-rtl8195a-vulnerabilities-discovered

[01:06:32] MTK Bypass Universal

  • https://megafon929.github.io/mtk

[01:14:13] Project Zero: iOS Kernel privesc with turnstiles [CVE-2020-27932]

  • https://googleprojectzero.blogspot.com/p/rca-cve-2020-27932.html

  • https://googleprojectzero.blogspot.com/p/rca.html

[01:21:41] Why Security Defects Go Unnoticed during Code Reviews?

  • http://amiangshu.com/papers/paul-ICSE-2021.pdf

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Starting with a long discussion about the North Korean hackers targeting security reseachers, and some thoughts (rants) about the newly released Windows exploit dev course from Offensive Security before getting into some real exploits including NAT Slipstreaming 2.0 and a new Sudo vuln.

[00:00:52] About the security content of iOS 14.4 and iPadOS 14.4

  • https://support.apple.com/en-us/HT212146

[00:02:42] New campaign targeting security researchers

  • https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/

  • https://www.microsoft.com/security/blog/2021/01/28/zinc-attacks-against-security-researchers/

  • https://twitter.com/pwn_expoit/status/1354024291398950913

  • https://twitter.com/chris_salls/status/1353989045617975297

[00:44:45] New Exploit Dev Course: EXP-301

  • https://www.offensive-security.com/offsec/new-course-exp301/

  • https://wargames.ret2.systems/

[01:04:53] Linksys WRT160NL – Authenticated Command Injection [CVE-2021-25310]

  • https://research.nccgroup.com/2021/01/28/technical-advisory-linksys-wrt160nl-authenticated-command-injection-cve-2021-25310/

[01:07:13] Vulnerabilities within TikTok Friend-Finder

  • https://research.checkpoint.com/2021/tiktok-fixes-privacy-issue-discovered-by-check-point-research/

[01:14:07] BitLocker touch-device lockscreen bypass

  • https://secret.club/2021/01/29/touch-lockscreen-bypass.html

[01:20:53] NAT Slipstreaming v2.0

  • https://www.armis.com/resources/iot-security-blog/nat-slipstreaming-v2-0-new-attack-variant-can-expose-all-internal-network-devices-to-the-internet/

  • https://samy.pl/slipstream/

[01:26:35] [Security fix] Libgcrypt 1.9.1 released

  • https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html

  • https://dev.gnupg.org/rC512c0c75276949f13b6373b5c04f7065af750b08

[01:30:44] Baron Samedit: Heap-based buffer overflow in Sudo [CVE-2021-3156]

  • https://www.openwall.com/lists/oss-security/2021/01/26/3

  • https://github.com/sudo-project/sudo/commit/1f8638577d0c80a4ff864a2aad80a0d95488e9a8

  • https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2021-3156

[01:44:49] Exploiting a “Simple” Vulnerability – Part 1.5 – The Info Leak

  • https://windows-internals.com/exploiting-a-simple-vulnerability-part-1-5-the-info-leak/

[01:50:53] Windows Kernel DoS/Privilege Escalation via a NULL Pointer Deref

  • https://www.thezdi.com/blog/2021/1/27/zdi-can-12671-windows-kernel-dosprivilege-escalation-via-a-null-pointer-deref

[01:56:31] XS-Leaks in redirect flows

  • https://docs.google.com/presentation/d/1rlnxXUYHY9CHgCMckZsCGH4VopLo4DYMvAcOltma0og/edit#slide=id.g63e29d5a06_0_0

[02:02:13] Keeping your GitHub Actions and workflows secure: Untrusted input

  • https://securitylab.github.com/research/github-actions-untrusted-input

[02:08:04] iOS Security Tutorial - Patching ASLR in the Kernel

  • https://www.youtube.com/watch?v=Gszvbi8AU68

[02:08:58] Project Zero: A Look at iMessage in iOS 14

  • https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html

[02:09:37] Effectively Fuzzing the IPC Layer in Firefox

  • https://blog.mozilla.org/attack-and-defense/2021/01/27/effectively-fuzzing-the-ipc-layer-in-firefox/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on

View Details

This week is a shorter episode, but still some solid bugs to look at. From a full chain Chrome exploit, to a Kindle chain from remote to root and a eBPF incorrect calculation leading to OOB read/write.

[00:00:41] Albicla launch clusterfuck

  • https://www.reddit.com/r/programminghorror/comments/l25ppk/albicla_launch_clusterfuck/

[00:04:41] [NordVPN] RCE through Windows Custom Protocol on Windows client

  • https://hackerone.com/reports/1001255

[00:09:00] Chaining Multiple bugs for Unauthenticated RCE in the SolarWinds Orion Platform

  • https://www.thezdi.com/blog/2021/1/20/three-bugs-in-orions-belt-chaining-multiple-bugs-for-unauthenticated-rce-in-the-solarwinds-orion-platform

[00:18:50] The Embedded YouTube Player Told Me What You Were Watching (and more)

  • https://bugs.xdavidhu.me/google/2021/01/18/the-embedded-youtube-player-told-me-what-you-were-watching-and-more/

[00:24:27] The State of State Machines

  • https://googleprojectzero.blogspot.com/2021/01/the-state-of-state-machines.html

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2085

[00:34:21] KindleDrip - From Your Kindle’s Email Address to Using Your Credit Card

  • https://medium.com/realmodelabs/kindledrip-from-your-kindles-email-address-to-using-your-credit-card-bb93dbfb2a08

[00:44:00] New campaign targeting security researchers

  • https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/

[00:44:42] An Incorrect Calculation Bug in the Linux Kernel eBPF Verifier

  • https://www.thezdi.com/blog/2021/1/18/zdi-20-1440-an-incorrect-calculation-bug-in-the-linux-kernel-ebpf-verifier

[00:49:18] Chat Question: What do we think of HackTheBox

  • https://hackthebox.eu

[00:53:51] Bad Pods: Kubernetes Pod Privilege Escalation

  • https://labs.bishopfox.com/tech-blog/bad-pods-kubernetes-pod-privilege-escalation

[00:53:24] [Linux Kernel Exploitation 0x2] Controlling RIP and Escalating privileges via Stack Overflow

  • https://blog.k3170makan.com/2021/01/linux-kernel-exploitation-0x2.html

  • https://pwn.college/modules/kernel

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Several lockscreen-related vulnerabilities this week, a cross-site leak, and the hijacking of all .cd domains.

One important thing to mention about this weeks episode that was neglected during the discussion is that the BitLocker Lockscreen Bypass is a lockscreen bypass. It does not necessarily provide access to data Bitlocker protects. If Bitlocker is being run in "transparent operation mode" where the ability to login is all that is necessary to decrypt data, then this vulnerability can grant access to encrypted data.

[00:00:00] Introduction

  • https://dayzerosec.com/

[00:00:59] Slayer Labs

  • https://slayerlabs.com/

[00:12:03] BugTraq Shutdown

  • https://seclists.org/bugtraq/2021/Jan/0

[00:17:22] Data Security on Mobile Devices

  • https://securephones.io/

[00:27:08] Running a fake power plant on the internet for a month

  • https://grimminck.medium.com/running-a-fake-power-plant-on-the-internet-for-a-month-4a624f685aaa

[00:33:43] BitLocker Lockscreen bypass

  • https://secret.club/2021/01/15/bitlocker-bypass.html

[00:39:30] [Linux Mint] Screensaver lock by-pass via the virtual keyboard

  • https://github.com/linuxmint/cinnamon-screensaver/issues/354

[00:43:02] [NextCloud] Bypassing Passcode/Device credentials

  • https://hackerone.com/reports/747726

[00:51:02] How I hijacked the top-level domain of a sovereign state

  • https://labs.detectify.com/2021/01/15/how-i-hijacked-the-top-level-domain-of-a-sovereign-state/

[01:00:28] Laravel <= v8.4.2 debug mode: Remote code execution

  • https://www.ambionics.io/blog/laravel-debug-rce

[01:05:47] Leaking silhouettes of cross-origin images

  • https://blog.mozilla.org/attack-and-defense/2021/01/11/leaking-silhouettes-of-cross-origin-images/

[01:10:36] Escaping VirtualBox 6.1: Part 1

  • https://secret.club/2021/01/14/vbox-escape.html

[01:17:15] Hunting for Bugs in Windows Mini-Filter Drivers

  • https://googleprojectzero.blogspot.com/2021/01/hunting-for-bugs-in-windows-mini-filter.html

[01:18:33] Project Zero: Introducing the In-the-Wild Series

  • https://googleprojectzero.blogspot.com/2021/01/introducing-in-wild-series.html

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

A new universal deserialization gadget for Ruby, a Rocket.Chat SAML auth bypass, and some heap exploitation research.

[00:00:36] Cybersecurity Knowledge and Skills Taught in Capture the Flag Challenges

  • https://arxiv.org/pdf/2101.01421v1.pdf

[00:10:36] Universal Deserialisation Gadget for Ruby 2.x-3.x

  • https://devcraft.io/2021/01/07/universal-deserialisation-gadget-for-ruby-2-x-3-x.html

[00:13:54] Stealing Your Private YouTube Videos, One Frame at a Time

  • https://bugs.xdavidhu.me/google/2021/01/11/stealing-your-private-videos-one-frame-at-a-time/

[00:21:43] Rocket.chat - SAML authentication bypass

  • https://hackerone.com/reports/1049375

[00:25:49] curl is vulnerable to SSRF due to improperly parsing the host component of the URL

  • https://hackerone.com/reports/704621

[00:31:02] Issue 2095: Node.js: use-after-free in TLSWrap

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2095

[00:35:28] Preventing Use-After-Free Attacks with Fast Forward Allocation

  • https://gts3.org/assets/papers/2021/wickman:ffmalloc.pdf

[00:49:38] Automatic Techniques to Systematically Discover New Heap Exploitation Primitives

  • https://www.usenix.org/system/files/sec20fall_yun_prepub.pdf

[00:59:50] A Samsung RKP Compendium

  • https://blog.longterm.io/samsung_rkp.html

[01:11:32] Analyzing CVE-2020-16040

  • https://faraz.faith/2021-01-07-cve-2020-16040-analysis/

[01:13:51] HexLasso Online

  • https://suszter.com/hexlasso-online/

[01:15:30] A Side Journey to Titan

  • https://ninjalab.io/a-side-journey-to-titan/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

An update on Apple v. Corellium, some 3DS vulnerabilities, and some drama on this weeks episode.

[00:00:34] Remote Chaos Experience

  • https://media.ccc.de/c/rc3

[00:20:06] Apple Inc. v. Corellium, LLC

  • https://www.courtlistener.com/docket/16064642/784/apple-inc-v-corellium-llc/

[00:28:17] The Great Suspender - New maintainer is probably malicious

  • https://github.com/greatsuspender/thegreatsuspender/issues/1263

[00:36:59] An HTML Injection Worth 600$ Dollars

  • https://medium.com/bugbountywriteup/a-html-injection-worth-600-dollars-5f065be0ab49

[00:44:06] Zoom Meeting Connector Post-Auth Remote Root

  • https://packetstormsecurity.com/files/160736/zoomer.py.txt

[00:46:21] Hijacking Google Docs Screenshots

  • https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/

[00:49:49] Nintendo 3DS - Improper certificate validation allows an attacker to perform MitM attacks

  • https://hackerone.com/reports/894922

[00:52:02] Nintendo 3DS - Unchecked number of audio channels in Mobiclip SDK leads to RCE in eShop movie player

  • https://hackerone.com/reports/897606

  • https://twitter.com/forestillusion/status/1341230631913541633

  • https://news.ycombinator.com/item?id=25508782

[00:55:45] Apple macOS 6LowPAN Vulnerability [CVE-2020-9967]

  • https://alexplaskett.github.io/CVE-2020-9967/

[01:01:24] An iOS hacker tries Android

  • https://googleprojectzero.blogspot.com/2020/12/an-ios-hacker-tries-android.html

[01:14:29] Turning Imprisonment to Advantage in the FreeBSD ftpd chroot Jail [CVE-2020-7468]

  • https://www.thezdi.com/blog/2020/12/21/cve-2020-7468-turning-imprisonment-to-advantage-in-the-freebsd-ftpd-chroot-jail

[01:18:36] Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)

  • https://arxiv.org/abs/2012.07432

[01:27:17] Helping secure DOMPurify (part 1)

  • https://research.securitum.com/helping-secure-dompurify-part-1/

[01:28:23] A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation

  • https://github.com/ant4g0nist/Vulnerable-Kext

[01:30:01] PS4 7.02 WebKit + Kernel Chain Implementation

  • https://github.com/ChendoChap/ps4-ipv6-uaf/tree/7.00-7.02

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Big news this week as several government agencies and contractors may have been compromised. We also have a number of great writeups this week covering everything from a PS4 webkit exploit, MacOS, and Windows.

[00:00:25] CISA issues emergency directive for SolarWinds Orion products compromise

  • https://twitter.com/CISAgov/status/1338348931571445762

  • https://www.sec.gov/ix?doc=/Archives/edgar/data/1739942/000162828020017451/swi-20201214.htm

  • https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html

  • https://twitter.com/KimZetter/status/1338305089597964290

  • https://twitter.com/mamah1987/status/1338369455177523201

  • https://www.cisa.gov/news/2020/12/13/cisa-issues-emergency-directive-mitigate-compromise-solarwinds-orion-network

[00:26:53] Finding Critical Open Source Projects

  • https://opensource.googleblog.com/2020/12/finding-critical-open-source-projects.html

  • https://github.com/ossf/criticality_score

[00:33:46] Vulnerabilities in McAfee ePolicy Orchestrator

  • https://swarm.ptsecurity.com/vulnerabilities-in-mcafee-epolicy-orchestrator/

[00:39:20] Chat Question: How to get good at exploit dev

[00:44:34] Novel Abuses On Wi-Fi Direct Mobile File Transfers

  • https://blog.doyensec.com//2020/12/10/novel-abuses-wifi-direct-mobile-file-transfers.html

[00:47:55] PsExec Local Privilege Escalation

  • https://medium.com/tenable-techblog/psexec-local-privilege-escalation-2e8069adc9c8

[00:52:31] Windows: WOF FSCTL_SET_REPARSE_POINT_EX Cached Signing Level SFB

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2088

[01:01:07] This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4

  • https://www.synacktiv.com/en/publications/this-is-for-the-pwners-exploiting-a-webkit-0-day-in-playstation-4.html

[01:08:51] Game On - Finding vulnerabilities in Valve’s "Steam Sockets"

  • https://research.checkpoint.com/2020/game-on-finding-vulnerabilities-in-valves-steam-sockets/

[01:14:57] Apple macOS Kernel OOB Write Privilege Escalation Vulnerability [CVE-2020-27897]

  • https://www.thezdi.com/blog/2020/12/9/cve-2020-27897-apple-macos-kernel-oob-write-privilege-escalation-vulnerability

[01:17:22] ABSTRACT SHIMMER: Host Networking is root-Equivalent, Again [CVE-2020-15257]

  • https://research.nccgroup.com/2020/12/10/abstract-shimmer-cve-2020-15257-host-networking-is-root-equivalent-again/

[01:24:41] Now you C me, now you don't, part two: exploiting the in-between

  • https://securitylab.github.com/research/now-you-c-me-part-two

[01:36:04] Portable Data exFiltration: XSS for PDFs

  • https://portswigger.net/research/portable-data-exfiltration

[01:45:27] HackerOne's 12 Days of Hacky Holidays

  • https://hackerone.com/h1-ctf?type=team

[01:47:55] The 2020 SANS Holiday Hack Challenge

  • https://holidayhackchallenge.com/2020/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

Some solid exploit development talk in this episode as we look at an iOS vuln, discuss the exploitability of a cURL buffer overflow and examine a new kernel UAF mitigation.

[00:00:43] Improving open source security during the Google summer internship program

  • https://security.googleblog.com/2020/12/improving-open-source-security-during.html

[00:03:35] Justices seem wary of breadth of federal computer fraud statute

  • https://www.scotusblog.com/2020/12/argument-analysis-justices-seem-wary-of-breadth-of-federal-computer-fraud-statute/

[00:11:37] Update regarding Snapchat SSRF

  • https://hackerone.com/reports/530974

[00:12:53] A 3D Printed Shell

  • https://www.securifera.com/blog/2020/12/02/a-3d-printed-shell/

[00:20:19] Site Wide CSRF on Glassdoor

  • https://blog.witcoat.com/2020/12/03/site-wide-csrf-on-glassdoor/

[00:24:24] [GitLab] Stored-XSS in error message of build-dependencies

  • https://hackerone.com/reports/950190

[00:27:44] Playstation Now RCE

  • https://hackerone.com/reports/873614

[00:32:29] MS Teams RCE (Important, Spoofing)

  • https://github.com/oskarsve/ms-teams-rce/

[00:38:34] An iOS zero-click radio proximity exploit odyssey

  • https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1982

[00:54:58] [curl] heap-based buffer overrun in /lib/urlapi.c

  • https://hackerone.com/reports/547630

[01:02:51] Google Duo: Race condition can cause callee to leak video packets from unanswered call

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2085

[01:05:35] Linux kernel heap quarantine versus use-after-free exploits

  • https://a13xp0p0v.github.io/2020/11/30/slab-quarantine.html

  • https://lore.kernel.org/kernel-hardening/CAG48ez1tNU_7n8qtnxTYZ5qt-upJ81Fcb0P2rZe38ARK=iyBkA@mail.gmail.com/T/#u

[01:13:23] Hey Alexa what did I just type? Decoding smartphone sounds with a voice assistant

  • https://arxiv.org/abs/2012.00687

[01:22:57] XS-Leaks Wiki

  • https://xsleaks.dev/

  • https://security.googleblog.com/2020/12/fostering-research-on-new-web-security.html

[01:27:14] Hacking 101 by No Starch Press

  • https://www.humblebundle.com/books/hacking-101-no-starch-press-books

[01:33:40] Gamozo Labs FuzzOS

  • https://gamozolabs.github.io/fuzzing/2020/12/06/fuzzos.html

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

More SD-PWN, more Tesla hacks, potential RCE in Drupal, and a couple windows vulns.

[00:00:27] Congress unanimously passes federal IoT security law

  • https://blog.rapid7.com/2020/11/18/congress-unanimously-passes-federal-iot-security-law/

[00:06:52] The Supreme Court will hear its first big CFAA case

  • https://www.scotusblog.com/2020/11/case-preview-justices-to-consider-breadth-of-federal-computer-fraud-statute/

[00:13:35] How much is unauthorized access sold for?

  • https://xorl.wordpress.com/2020/08/26/how-much-is-unauthorized-access-sold-for/

[00:20:10] Getting Banned for Security Research

  • https://nedwill.github.io/blog/jekyll/update/2020/11/25/banned-for-research.html

[00:33:11] SD-PWN Part 3 - Cisco vManage

  • https://medium.com/realmodelabs/sd-pwn-part-3-cisco-vmanage-another-day-another-network-takeover-15731a4d75b7

[00:36:10] SD-PWN Part 4 - VMware VeloCloud

  • https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175

[00:40:39] CVE-2020-7378: OpenCRX Unverified Password Change (FIXED)

  • https://blog.rapid7.com/2020/11/24/cve-2020-7378-opencrx-unverified-password-change/
  • https://github.com/opencrx/opencrx/commit/389ff0e22851407560091dfd25b25fee0b384eed?branch=389ff0e22851407560091dfd25b25fee0b384eed&diff=split#diff-2bb58016ce7d5cdb2f11bdb60d4aa7dd5c2e2cb816c9120a7f36ac93d0b64f33L702

[00:43:54] Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949)

  • https://github.com/pear/Archive_Tar/issues/33
  • https://www.drupal.org/sa-core-2020-013

[00:47:14] SSRFs caused by bad RegEx in "private-ip"

  • https://johnjhacking.com/blog/cve-2020-28360/

[00:53:13] [SnapChat] Server-Side Request Forgery using Javascript allows to exfill data from Google Metadata

  • https://hackerone.com/reports/530974

[00:57:50] Serious flaws in Tesla Model X keyless entry system

  • https://www.imec-int.com/en/press/belgian-security-researchers-ku-leuven-and-imec-demonstrate-serious-flaws-tesla-model-x

[01:03:48] Windows Print Spooler Vulnerability

  • https://www.accenture.com/us-en/blogs/cyber-defense/discovering-exploiting-shutting-down-dangerous-windows-print-spooler-vulnerability

[01:08:30] Exploiting a “Simple” Vulnerability - In 35 Easy Steps or Less!

  • https://windows-internals.com/exploiting-a-simple-vulnerability-in-35-easy-steps-or-less/
  • https://twitter.com/gabe_k/status/1330966182543777792
  • There was previously a link to br0vvnn here, this blog has been shown to be part of an attempt to compromise security researchers.
    • https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers

[01:17:55] Hitcon2020 Challenge Files + Solutions

  • https://github.com/david942j/ctf-writeups/tree/master/hitcon-2020

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

View Details

This week we talk a bit about some Black Friday deals before jumping into another SD-WAN pwn, some jailbreaks, and research into automatic exploit generation.

  • [00:00:40] Black Friday is coming...

    • VMWare - Usually ~35% off
    • Shodan - $5 lifetime, last year they ran the deal before and after Black Friday so pay attention.
    • Pluralsight - 40% off
    • INE - 40% off (access to all eLearnSecurity courses)
    • Cybrary.it - $600 off
    • PentesterLab - Last year was 13.37% off
    • NoStarchPress - Last year was 42% off
    • O'Reilly Online Learning - $199/year (normally $500/yr)
    • Pentester Academy - 70% off (covid "perma-deal")
    • [00:10:03] Oracle Security Alert - CVE-2020-14750

    • https://twitter.com/chybeta/status/1323220987442208769

    • [00:13:34] FileZilla "Scale Factor" field is vulnerable of Buffer Overflow
    • [00:21:33] Playstation Access Token Stealing

    • https://hackerone.com/reports/826394

    • [00:27:54] SD-PWN Part 2 - Citrix SD-WAN Center - Another Network Takeover
    • [00:37:19] Exploiting dynamic rendering engines to take control of web apps
    • [00:42:34] Privileged Container Escape - Control Groups release_agent
    • [00:47:23] Modern attacks on the Chrome browser
    • [00:58:57] Jailbreaks Never Die - Exploiting iOS 13.7
    • [01:08:27] Kernel Exploitation with a File System Fuzzer
    • [01:13:57] Greybox Automatic Exploit Generation for Heap Overflows in Language Interpreters

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Some interesting tips and tricks as we look at multiple privileges escalations from XNU to Ubuntu, Bitdefender, and Dropbox (HelloSign).

  • [00:01:31] Apple allegedly not crediting researchers
  • [00:10:26] Response to Voatz's Supreme Court Amicus Brief
  • [00:23:45] Standing up for developers: youtube-dl is back
  • [00:30:05] HelloSign SSRF leads to AWS private key disclosure
  • [00:38:02] Silver Peak Unity Orchestrator RCE
  • [00:42:51] Get root by pretending nobody's /home
  • [00:48:20] Project Zero: Oops, I missed it again!
  • [00:55:12] Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions
  • [01:01:07] Sleep Attack: Intel Bootguard vulnerability waking from S3
  • [01:05:56] SAD DNS Explained
  • [01:12:02] Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution Envrionments
  • [01:23:33] A Systematic Study of Elastic Objects in Kernel Exploitation

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

A Facebook DOM-based XSS, Rocket.chat and Github Actions RCEs, and a Brave Browser information disclosure in this week's episode.

  • [00:00:50] Pwn2Own Tokyo (Live from Toronto) - Schedule and Results

    • https://www.zerodayinitiative.com/blog/2020/7/28/announcing-pwn2own-tokyo-2020-live-from-toronto
    • [00:12:00] Tianfu Cup - Results
    • [00:16:28] Unlimited Chase Ultimate Rewards Points
    • [00:26:09] Github: Widespread injection vulnerabilities in Actions
    • [00:36:37] About the security content of iOS 14.2 and iPadOS 14.2

    • https://twitter.com/ShaneHuntley/status/1324431104187670529

    • [00:42:04] Rocket.Chat Desktop RCE
    • [00:44:44] git-lfs RCE
    • [00:46:46] Attack of the clones: Git clients remote code execution
    • [00:48:17] YOURLS 1.5 - 1.7.10, Multiple Stored XSS Vulnerabilities in Admin Panel
    • [00:53:23] Company forced to change name that could be used to hack websites
    • [00:57:12] Facebook DOM Based XSS using postMessage
    • [01:03:00] SQL Injection and Reflected XSS in Oracle Communications Diameter Signaling Router
    • [01:06:00] Re-discovering a JWT Authentication Bypass in ServiceStack

    • https://docs.servicestack.net/releases/v5.9#v592-patch-release-notes

    • [01:10:45] How I found a Tor vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276) and a small bounty, all in one working day
    • [01:18:12] Exploiting Microsoft Store Games [CVE-2020-16877]
    • [01:26:21] Fuzzing for eBPF JIT bugs in the Linux kernel
    • [01:41:18] Capture the Bot: Using Adversarial Examples to Improve CAPTCHA Robustness to Bot Attacks

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

This week we are joined by CTS to discuss fuzzing. We also take at PEN-300/OSEP. Before jumping into this weeks exploits, from NAT Slipstreaming to a Metasploit command injection and plenty in between.

  • [00:01:06] Cybersecurity as we know it will be 'a thing of the past in the next decade,' says Cloudflare's COO
  • [00:05:51] A Researcher’s Guide to Some Legal Risks of Security Research
  • [00:10:57] Exploit Developer Spotlight: The Story of PlayBit
  • [00:17:25] New Pentesting Course: PEN-300 (OSEP)

    • https://www.offensive-security.com/awe-osee/
    • [00:28:20] Vulnonym: Stop the Naming Madness!

    • https://twitter.com/vulnonym

    • [00:30:55] DeFuzz: Deep Learning Guided Directed Fuzzing
    • [00:59:32] NAT Slipstreaming
    • [01:08:10] GitLab CVE-2020-13294
    • [01:13:17] Attacking Roku sticks for fun and profit
    • [01:16:48] Tiki Wiki - Authentication Bypass [CVE-2020-15906]
    • [01:20:12] Metasploit framework template command injection - CVE-2020-7384
    • [01:23:43] Wormable remote code execution in Alien Swarm
    • [01:29:50] Pulse Connect Secure - RCE via Uncontrolled Gzip Extraction [CVE-2020-8260]
    • [01:32:55] The story of three CVE's in Ubuntu Desktop
    • [01:41:31] CVE-2020-16939: Windows Group Policy DACL Overwrite Privilege Escalation
    • [01:46:36] Windows Kernel cng.sys pool-based buffer overflow
    • [01:54:21] Vector35 releases all Binary Ninja core architecture plugins
    • [01:55:33] How Debuggers Work: Getting and Setting x86 Registers, Part 1
    • [01:56:12] CodeQL U-Boot Challenge (C/C++)
    • [01:59:14] Fundamentals of Software Exploitation

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

A lot to cover in this episode, from high performance fuzzing on GPUs, to low-cost pentesters, and APT groups. And, of course many vulns from GitHub RCEs to VMWare Workstation race conditions.

  • [00:01:21] Youtube-dl Cease and Desist
  • [00:14:33] Let’s build a high-performance fuzzer with GPUs!

    • https://gamozolabs.github.io/2020/10/23/some_thoughts_on_gpu_fuzzing.html
    • [00:29:07] Samsung S20 - RCE via Samsung Galaxy Store App
    • [00:33:24] Jitsi Meet Electron - Arbitrary Client Remote Code Execution [CVE-2020-27162]

    • https://github.com/jitsi/jitsi-meet-electron/blob/40866232594442ea77d5144deebcd38ed3d362be/main.js#L126

    • [00:39:14] 2FA Disable With Wrong Password - Response Tampering.
    • [00:41:22] HTTP Request Smuggling due to CR-to-Hyphen conversion

    • https://hackerone.com/nodejs?type=team

    • [00:46:56] GitHub Gist - Account takeover via open redirect
    • [00:53:19] GitHub - RCE via git option injection (almost)
    • [00:56:36] GitHub Pages - Multiple RCEs via insecure Kramdown configuration
    • [01:01:38] Gateway2Hell - Multiple Privilege Escalation Vulnerabilities in Citrix Gateway Plug-In
    • [01:09:02] Remote code execution on Symfony based websites
    • [01:18:40] Detailing Two VMware Workstation TOCTOU Vulnerabilities
    • [01:25:15] Linksys WRT160NL – Authenticated Remote Buffer Overflow [CVE-2020-26561]
    • [01:32:03] The FreeType Project - Heap buffer overflow due to integer truncation
    • [01:38:54] Uncovering the Hidden Dangers: Finding Unsafe Go Code in the Wild
    • [01:45:15] NSA Warns Chinese State-Sponsored Malicious Cyber Actors Exploiting 25 CVEs
    • [01:57:15] Penetration Testing and Low-Cost Freelancing
    • [02:23:24] WPScan.io "XSS"
    • [02:28:24] MITRE - Adversarial Threat Matrix
    • [02:29:16] Shoutout to Alh4zr3d

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

It has been a while since we had an exploit extravaganza but here we are. Several binary-level issues from Bad Neighbor on Windows to BleedingTooth on Linux, and several vulns in Qualcomm SoCs, even a Discord RCE.

  • [00:00:57] Introducing Edge Vulnerability Research
  • [00:06:57] Cache Partitioning in Chrome
  • [00:10:29] Magma: A Ground-Truth Fuzzing Benchmark
  • [00:25:27] "Bits Please!" - CVE-2020-16938
  • [00:29:50] ContainerDrip [CVE-2020-15157]
  • [00:40:01] Discord Desktop app RCE
  • [00:52:34] Time Based SQLi via referrer header

    • https://www.fedscoop.com/hack-the-army-2-results/
    • [00:57:35] PyYAML 0day
    • [01:09:24] Phantom of the ADAS
    • [01:15:03] Rollback Attack in Mozilla Maintenance Service
    • [01:19:33] Glitching The MediaTek BootROM
    • [01:25:05] AssaultCube RCE: Technical Analysis
    • [01:32:27] CVE-2020-12928 - Privilege Escalation in AMD Ryzen Master
    • [01:35:38] Major Vulnerabilities in Qualcomm QCMAP
    • [01:42:58] Bad Neighbor - RCE in Windows ICMPv6 Router Advertisement
    • [01:51:16] DOS2RCE: A New Technique to Exploit V8 NULL Pointer Dereference Bug (see: https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers)
    • [01:56:34] BleedingTooth - Linux Bluetooth Zero-Click RCE

    • https://github.com/google/security-research/security/advisories/GHSA-h637-c88j-47wq

    • https://github.com/google/security-research/security/advisories/GHSA-7mh3-gq28-gfrq

    • https://github.com/google/security-research/security/advisories/GHSA-ccx2-w2r4-x649

    • [02:07:25] shmdt doesn't check the tag of pointers
    • [02:12:29] Security Analysis of the CHERI ISA
    • [02:13:18] Evading defences using VueJS script gadgets
    • [02:14:32] Sega Master System Architecture - A Practical Analysis
    • [02:14:52] IPC scripts for access to Intel CRBUS

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on

View Details

Its a web-exploit heavy episode impacing Apple, Hasicorp, Azure, Google, and even a DOMPurify Bypass. Then we end-off with a look into benchmarking fuzzers, and a look at the House of Muney heap exploitation technique.

  • [00:00:49] Fuzzing internships for Open Source Software
  • [00:03:15] CET Updates – CET on Xanax
  • [00:09:07] Binary Ninja - Open Source Architectures
  • [00:14:03] Memory Safe 'curl' for a More Secure Internet

    • https://daniel.haxx.se/blog/2020/10/09/rust-in-curl-with-hyper/
    • [00:17:25] We Hacked Apple for 3 Months: Here’s What We Found
    • [00:25:46] Race condition while removing the love react in community files
    • [00:30:11] Enter the Vault: Authentication Issues in HashiCorp Vault
    • [00:46:39] Kud I Enter Your Server? New Vulnerabilities in Microsoft Azure
    • [00:51:11] Password Reset Link Leaked In Refer Header
    • [00:57:37] The mass CSRFing of .google.com/ products.
    • [01:06:02] A brief encounter with Leostream Connect Broker
    • [01:15:47] Bypassing DOMPurify again with mutation XSS

    • https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/

    • https://github.com/marcinguy/jquery-xss-in-html

    • [01:22:10] Apache Struts OGNL Remote Code Execution [CVE-2019-0230]
    • [01:28:11] UNIFUZZ: A Holistic, Pragmatic Metrics-Driven Platform for Evaluating Fuzzers

    • https://github.com/unifuzz/unibench

    • https://github.com/unifuzz

    • [01:47:15] House of Muney - Leakless Heap Exploitation Technique

    • https://github.com/mdulin2/house-of-muney

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Every wondering how you might fingerprint and trace exploit devs in the wild? Wondered what a backdoor in a D-Link router looks like? Want to hack Facebook (for Android)? We have all of that and more!

  • [00:00:43] Google: Android Partner Vulnerability Initiative

    • https://bugs.chromium.org/p/apvi/issues/list?q=&can=1
    • [00:02:55] Project Zero: Announcing the Fuzzilli Research Grant Program
    • [00:08:40] GitHub: Code scanning is now available
    • [00:16:39] Hunting for exploits by looking for the author's fingerprints
    • [00:22:26] Forcing Firefox to Execute XSS Payloads during 302 Redirects
    • [00:27:10] Exploiting fine-grained AWS IAM permissions for total cloud compromise

    • https://medium.com/bugbountywriteup/aws-iam-explained-for-red-and-blue-teams-2dda8b20fbf7

    • [00:38:04] BLURtooth (the BLUR attacks)
    • [00:44:25] Arbitrary code execution on Facebook for Android
    • [00:51:44] [stripo] Public and secret api key leaked in JavaScript source
    • [01:00:14] [GitLab] Unvalidated Oauth email results in accounts takeovers on 3rd parties
    • [01:06:03] Hacking Grindr Accounts with Copy and Paste
    • [01:16:37] Exploiting Other Remote Protocols in IBM WebSphere

    • https://portswigger.net/web-security/deserialization/exploiting

    • [01:25:57] The Anatomy of a Bug Door: Dissecting Two D-Link Router Authentication Bypasses
    • [01:38:36] Hacking Punkbuster.
    • [01:43:26] Race Condition in handling of PID by apport [CVE-2020-15702]
    • [01:57:24] Hardware Hacking Experiments
    • [01:59:11] How I automated McDonalds mobile game to win free iPhones
    • [01:59:42] Voyager - A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)
    • [02:00:28] zznop/sploit: Go package that aids in binary analysis and exploitation

Watch

View Details

Lets go back in time to look at the leaked WinXP source, and a Half-Life 1 exploit. And, while we are at it a couple Instagram vulns and a cheap hardware attack against Android.

  • [00:00:50] Windows XP Source Leak

    • https://twitter.com/vxunderground/status/1309231131313737735

    • https://twitter.com/dangeredwolf/status/1310067935902343170

    • [00:12:49] "I'm not a fan of critical bugs"
    • [00:28:01] API Keys leaked via Solana BBP github repo
    • [00:36:34] Exploiting Tiny Tiny RSS
    • [00:45:28] HackerOne Reflected XSS
    • [00:50:37] Steam Arbitrary File Overwrite
    • [00:55:23] Half-Life 1 Code Execution with malformed map name
    • [00:59:09] uTorrent Vulnerability [CVE-2020-8437]

    • https://raw.githubusercontent.com/guywhataguy/uTorrent-CVE-2020-8437/master/malicious.torrent

    • [01:09:26] $25K Instagram Almost XSS Filter Link
    • [01:14:57] #Instagram_RCE
    • [01:26:44] Kernel exploitation: weaponizing [CVE-2020-17382]
    • [01:34:07] Bypass Android MDM
    • [01:41:17] XSS without arbitrary JavaScript
    • [01:48:40] security things in Linux v5.7
    • [01:56:48] Code Review 101

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

A "trivial" Bhyve VM escape, a BitWarden "RCE", a ModSecurity "Denial of Service" and more scare quotes for your enjoyment in this week's episode.

  • [00:00:33] Patient Dies After Ransomware Attack
  • [00:08:05] Zerologon [CVE-2020-1472]
  • [00:14:29] BitWarden Blind HTTP GET SSRF

    • https://github.com/bitwarden/server/pull/812/commits/f094b76b6638932b13bb5ed2d9295185c54ce332

    • https://github.com/bitwarden/desktop/issues/552

    • [00:23:40] Apache + PHP under v7.4.10 open_basedir bypass
    • [00:29:59] ModSecurity v3 Affected By DoS (Severity HIGH) [CVE-2020-15598]
    • [00:38:09] Bhyve VM Escape

    • https://bsdsec.net/articles/freebsd-announce-freebsd-security-advisory-freebsd-sa-20-29-bhyve_svm

    • [00:42:59] Webkit aboutBlankURL() code execution vulnerability
    • [00:48:28] CVE-2020-9964 - An iOS infoleak
    • [00:51:44] Online Casino Roulette - A guideline for pen testers
    • [00:56:40] Light Can Hack Your Face! Black-box Backdoor Attack on Face Recognition
    • [01:03:06] UniFuzz: Optimizing Distributed Fuzzing via Dynamic Centralized Task Scheduling
    • [01:12:07] FANS: Fuzzing Android Native System Services via Automated Interface Analysis

    • https://github.com/iromise/fans

    • [01:19:52] OneFuzz framework, an open source developer tool to find and fix bugs at scale

    • https://github.com/microsoft/onefuzz

    • [01:28:35] Finding Australian Prime Minister Tony Abbott's passport number
    • [01:34:08] ARM64 Reversing and Exploitation
    • [01:37:25] Hypervisor Exploitation Compiled Research List

    • https://github.com/bitwarden/server/pull/812/commits/f094b76b6638932b13bb5ed2d9295185c54ce332

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Leading off this week's discussion is the news about the now remote CCC and Offensive Security's plans to retire OSCE. On the exploit side of things, this week we have a few recent bug bounties including a Google Maps XSS, a FreeBSD TOCTOU, and a couple of Linux kernel vulnerabilities.

  • [00:02:30] CCC going remote this year due to pandemic
  • [00:09:44] NVIDIA to Acquire Arm for $40 Billion
  • [00:20:36] OSCE being retired

    • https://ringzer0.training/
    • [00:34:21] Giggle; laughable security
    • [00:44:51] Raccoon Attack

    • https://portswigger.net/daily-swig/researchers-exploit-http-2-wpa3-protocols-to-stage-highly-efficient-timeless-timing-attacks

    • [00:53:34] Executing arbitrary code on NVIDIA GeForce NOW VMs
    • [01:02:07] Cache poisoning via X-Forwarded-Host
    • [01:08:56] Team object in GraphQL disclosed private_comment
    • [01:14:08] XSS->Fix->Bypass: 10000$ bounty in Google Maps
    • [01:28:33] Microsoft Sharepoint and Exchange Server Vulnerabilities
    • [01:45:35] Short story of 1 Linux Kernel Use-After-Free and 2 CVEs
    • [01:53:25] FreeBSD Kernel Privilege Escalation [CVE-2020-7460]
    • [02:02:47] WSL 2.0 dxgkrnl Driver Memory Corruption
    • [02:10:46] Project Zero: Attacking the Qualcomm Adreno GPU
    • [02:16:03] GoogleCTF 2020 Challenge Source + Exploits Release
    • [02:20:08] IDA Pro Tips to Add to Your Bag of Tricks
    • [02:20:48] Reverse Engineering: Marvel's Avengers - Developing a Server Emulator

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

The DAY[0] podcast will be on break until September 14, 2020

A quick chat about E2E Crypto and Zoom, followed by a few noteworth exploits including Bluetooth impersonation, a 15-year old qmail CVE, NordVPN, and an RCE in Google

  • [00:00:50] Adventures of porting MUSL to PS4
  • [00:01:55] End-to-End Encryption for Zoom Meetings
  • [00:13:16] Memory safety - The Chromium Projects
  • [00:21:17] First 0d iOS jailbreak in 6 years
  • [00:24:11] BIAS: Bluetooth Impersonation AttackS

    • https://little-canada.org/pdf/web/viewer.html?file=antonioli-20-bias.pdf

    • https://francozappa.github.io/about-bias/talk/bias-snp/

    • [00:33:13] 15 years later: Remote Code Execution in qmail (CVE-2005-1513)

    • http://tukan.farm/2016/07/27/munmap-madness/

    • https://cr.yp.to/qmail/guarantee.html

    • http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html

    • [00:48:01] Privilege Escalation in Parallels Desktop via VGA Device [CVE-2020-8871]

    • https://twitter.com/matalaz/status/580600098092105728

    • [00:55:50] Multiple vulnerabilities in Dovecot IMAP server
    • [00:59:05] Yet another arbitrary delete EoP [CVE-2020–1088]
    • [01:06:29] Vulnerabilities chain leading to privilege escalation [NordVPN]
    • [01:09:27] Race condition in activating email resulting in infinite amount of diamonds received
    • [01:12:23] RCE in Google Cloud Deployment Manager
    • [01:28:17] QNAP Pre-Auth Root RCE
    • [01:37:07] Safe-Linking - Eliminating a 20 year-old malloc() exploit primitive
    • [01:47:37] Not So Fast: Understanding and Mitigating Negative Impacts of Compiler Optimizations on Code Reuse Gadget Sets
    • [02:05:43] Precise XSS detection and mitigation with Client-side Templates
    • [02:17:53] Documenting the impossible: Unexploitable XSS labs

DAY[0] will be on break until September but you can find the video archive on on Youtube (@DAY[0])

View Details

Are iOS 0days now worthless? Can you hack a satellite...or hackerone? Are WAFs worthwhile? And more on a fairly discussion heavy episode of DAY[0].

  • [00:00:52] [UPDATE] Huawei HKSP Introduces Trivially Exploitable Vulnerability

    • https://github.com/cloudsec/aksp/blob/master/hksp.patch
    • [00:11:59] iOS one-click chains prices likely to drop

    • https://www.hackasat.com/

    • [00:33:30] Defcon Quals 2020

    • https://hxp.io/blog/72/DEFCON-CTF-Quals-2020-notbefoooled/

    • [00:46:33] vBulletin 5.6.1 SQL Injection
    • [00:52:52] Subdomain takeover of resources.hackerone.com
    • [01:01:11] MyLittleAdmin PreAuth RCE
    • [01:06:13] DOM-Based XSS at accounts.google.com by Google Voice Extension.
    • [01:16:47] Playing with GZIP: RCE in GLPI [CVE-2020-11060]
    • [01:36:24] Reverse RDP - The Path Not Taken
    • [01:44:19] PrintDemon: Print Spooler Privilege Escalation, Persistence & Stealth [CVE-2020-1048]

    • https://twitter.com/VbScrub/status/1260598344650539009

    • [01:53:34] Security Flaws in Adobe Acrobat Reader Allow Malicious Program to Gain Root on macOS Silently
    • [02:00:29] Cloud WAF Comparison Using Real-World Attacks

    • https://medium.com/fraktal/cloud-waf-comparison-part-2-e6e2d25f558c

    • https://en.wikipedia.org/wiki/Server_Side_Includes

    • [02:18:20] Fuzzing TLS certificates from their ASN.1 grammar
    • [02:22:25] DHS CISA and FBI share list of top 10 most exploited vulnerabilities

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Update: While we talk about Huawei Kernel Self Protection (HKSP) I make mention of the authors statement that he is unrelated to Huawei. Turns out this statement, despite a commit date of Friday wasn't pushed until Monday morning so it was not original. Further information has also come out showing that the author is a Huawei employee, so the relationship is much closer than I believe it to be. ~zi

It was a busy week, Microsofts Github account was hacked, Centurylink Routers have no security, and multiple interactionless RCEs in Samsung phones.

  • [00:01:45] OpenOrbis PS4 Toolchain
  • [00:05:06] DEF CON 28 in-person conference is CANCELLED
  • [00:13:23] The Nintendo leak saga continues...
  • [00:18:40] Keybase joins Zoom

    • https://www.bleepingcomputer.com/news/security/microsofts-github-account-hacked-private-repositories-stolen/
    • [00:33:41] Azure Security Lab - Research Challenge
    • [00:42:38] Hijacking Centurylink Routers [CVE 2019-19639]
    • [00:46:24] DoS on Twitter App
    • [00:51:39] A tale of verbose error message and a JWT token
    • [01:00:29] Pentesting Cisco SD-WAN Part 2: Breaking routers
    • [01:04:21] Memory leak and Use After Free in Squid
    • [01:17:48] How a Deceptive Assert Caused a Critical Windows Kernel Vulnerability
    • [01:28:30] Samsung Android multiple interactionless RCE

    • https://github.com/googleprojectzero/SkCodecFuzzer

    • [01:38:25] Linux futex+VFS Use-After-Free
    • [01:45:03] Huawei HKSP Introduces Trivially Exploitable Vulnerability
    • [01:50:32] Ragnarok Stopper: development of a vaccine
    • [01:55:51] Understanding Memory and Thread Safety Practices and Issues in Real-World Rust Programs
    • [02:09:34] Analyzing a Trio of Remote Code Execution Bugs in Intel Wireless Adapters
    • [02:10:19] GitHub - JHUAPL/Beat-the-Machine: Reverse engineering basics in puzzle form

View Details

Authentication bypasses, SQL injection, command injection, and more in this web-exploit heavy episode.

  • [00:09:11] Facebook v. NSO Group
  • [00:18:14] Netsweeper PreAuth RCE
  • [00:25:49] SaltStack authorization bypass

    • https://github.com/saltstack/salt/blob/0b2a5613b345f17339cb90e60b407199b3d26980/salt/master.py#L1139
    • [00:42:02] E-Learning Platforms Getting Schooled

    • https://github.com/LearnPress/learnpress/commit/d6f818b5f65b007acbdf62236d4aa549fb33d24a?diff=split

    • [01:03:54] Roblox - Subdomain Takeover
    • [01:08:09] Fix XSS issue in handling of CDATA in HTML messages · roundcube/roundcubemail@87e4cd0 · GitHub
    • [01:10:13] Stealing the Trello token by abusing a cross-iframe XSS on the Butler Plugin
    • [01:17:11] Gitlab - Arbitrary file read via the UploadsRewriter when moving and issue
    • [01:20:15] Researching Polymorphic Images for XSS on Google Scholar
    • [01:27:41] TP-LINK Cloud Cameras Multiple Vulnerabilities

    • https://seclists.org/fulldisclosure/2020/May/3

    • https://seclists.org/fulldisclosure/2020/May/4

    • [01:34:46] Remote Code Execution on Microsoft SharePoint Using TypeConverters [CVE-2020-0932]
    • [01:43:03] Firefox js::ReadableStreamCloseInternal Out-Of-Bounds Access
    • [01:51:56] Siguza - iOS <13.5 sandbox escape/entitlement 0day
    • [02:03:16] Honeysploit: Exploiting the Exploiters
    • [02:15:13] Guy's 30 Reverse Engineering Tips & Tricks
    • [02:16:45] Remote Code Execution on Nintendo 64 through Morita Shogi 64

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Since we forgot to cover it when it came out, we look at Relyze's new decompiler that is available on the free version. There is also some sandbox escaping, some crypto issues (AMD's SME/SEV) and even some IBM 0days.

  • [00:00:33] Relyze Decompiler
  • [00:22:06] Firefox's Bug Bounty in 2019 and into the Future
  • [00:30:29] Source code for both CS:GO and TF2 Leaked
  • [00:38:58] Fixing SQL injection vulnerability and malicious code execution in XG Firewall/SFOS
  • [00:44:34] MSI TrueColor Unquoted Service Path Vulnerability
  • [00:48:43] 1-click RCE on Keybase
  • [00:55:56] jQuery < 3.5 Cross-Site Scripting (XSS) in html()

    • https://xss.pwnfunction.com/challenges/ww3/
    • [01:01:37] Multiple 0 day vulnerabilities in IBM Data Risk Manager
    • [01:17:24] You Won't Believe what this One Line Change Did to the Chrome Sandbox

    • https://docs.microsoft.com/en-us/archive/blogs/david_leblanc/practical-windows-sandboxing-part-1

    • [01:23:58] You’ve Got (0-click) Mail!
    • [01:31:29] Sharing a Logon Session a Little Too Much
    • [01:37:00] SEVurity: No Security Without Integrity - Breaking Integrity-Free Memory Encryption with Minimal Assumptions

    • https://0x0539.net/play/fangorn/crypto_cookie

    • [01:47:10] MarkUs: Drop-in Use-After-Free Prevention for Low-Level Languages
    • [01:54:37] Android 8.0-9.0 Bluetooth Zero-Click RCE [CVE-2020-0022]
    • [01:57:26] Patchguard: Detection of Hypervisor Based Introspection

    • https://revers.engineering/patchguard-detection-of-hypervisor-based-instrospection-p2/

    • [01:59:37] HITB Lockdown Livestream Day 1

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Zoom vuln worth $500k? Probably not... What is worth $500k? Binary Ninja's new decompiler...okay probably not but it is exciting.We've also got some stupid issues and some interesting LPEs this episode.

  • [00:00:29] Cognizant suffers Maze Ransomware cyber attack
  • [00:14:08] Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000
  • [00:27:46] How I Reverse Engineered the LastPass CLI Tool
  • [00:35:59] State of the Ninja: Episode 13
  • [01:02:18] Riot offering up to $100k n Bug Bounty
  • [01:05:31] Research Grants to support Google VRP Bug Hunters during COVID-19
  • [01:09:08] Denial of service to WP-JSON API by cache poisoning
  • [01:11:43] CSRF to RCE bug chain in Prestashop
  • [01:21:16] Unintended disclosure of OTP
  • [01:24:20] JSON Web Token Validation Bypass in Auth0 Authentication API
  • [01:27:06] git: Newline injection in credential helper
  • [01:31:20] How Misleading Documentation Led to a Broken Patch for a Windows Arbitrary File Disclosure Vulnerability
  • [01:36:34] Pwning vCenter with CVE-2020-3952
  • [01:45:19] Oracle Solaris 11.x/10 whodo/w Buffer Overflow
  • [01:51:22] Linux Kernel EoP via Improper eBPF Program Verification [CVE-2020-8835]
  • [01:57:39] Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices

    • https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=c4f42c24e02ce82392d8f8fe215570568380c8ab
    • [02:07:20] Ricerca Security: "SMBGhost pre-auth RCE

    • https://blog.zecops.com/vulnerabilities/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-and-poc/

    • [02:14:01] IJON: Exploring Deep State Spaces via Fuzzing
    • [02:23:26] Pangolin: Incremental Hybrid Fuzzing with Polyhedral Path Abstraction
    • [02:27:45] GitHub - wcventure/FuzzingPaper

View Details

Starting off the week with a discussion about the disappointing IDA Home, before moving into a few easy command injections, code-reuse attacks applied to XSS, detecting trojaned hardware and ending with a subtle crypto-bug.

  • [00:00:45] DAY[0] Episode Transcripts now Available
  • [00:02:53] Microsoft Buys Corp.com to Keep It Safe from Hackers (Over $1.7 Million Deal)
  • [00:05:42] Hack for Good: Easily Donate Bounties to WHO’s COVID-19 Response Fund
  • [00:10:55] RetDec v4.0 is out
  • [00:17:33] IDA Home is coming

    • https://www.sophia.re/Binary-Rockstar/index.html

    • https://nostarch.com/GhidraBook

    • [00:33:44] Sandboxie Open Source Code is available

    • https://github.com/xanasoft/Sandboxie

    • [00:38:01] Exploiting the TP-Link Archer A7
    • [00:46:50] Exploiting the Starcraft 1 EUD Bug
    • [00:51:23] OhMyZsh dotenv Remote Code Execution
    • [00:56:19] Symantec Web Gateway 5.0.2.8 Remote Code Execution
    • [00:59:15] VMware vCenter Server Sensitive Information Disclosure [CVE-2020-3952]
    • [01:01:39] Bypassing modern XSS mitigations with code-reuse attacks
    • [01:07:49] Practical Data Poisoning Attack against Next-Item Recommendation
    • [01:11:40] Hardware Trojan Detection Using Controlled Circuit Aging
    • [01:16:18] A "Final" Security Bug
    • [01:27:05] RCEed version of computer malware / rootkit MyRTUs / Stuxnet.

    • https://github.com/christian-roggia/open-myrtus/blob/master/rootkit/FastIo.c

    • https://xkcd.com/350/

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

First, we talk about Facebook trying to buy some spyware, and then we feast upon a number of Zoom "vulns." Follow that up with some interesting vulnerabilities including a hyper-visor Guest-to-host escape, a complicated Safari permissions bypass, and a Gitlab Parser Differential.

  • [00:09:31] Facebook tried to buy NSO Group's iOS spyware to monitor iPhone users
  • [00:14:49] Move Fast & Roll Your Own Crypto: A Quick Look at the Confidentiality of Zoom Meetings
  • [00:28:28] Security Vulnerabilities fixed in Firefox 74.0.1 and Firefox ESR 68.6.1
  • [00:33:20] Bug bounty platforms buy researcher silence, violate labor laws, critics say
  • [00:53:56] Zoom NTLM Hash Leak
  • [00:59:44] The 'S' in Zoom, Stands for Security
  • [01:05:52] Use-After-Free Vulnerability in the VMware Workstation DHCP Component [CVE-2020-3947]

    • https://www.vmware.com/security/advisories/VMSA-2020-0004.html

    • https://www.zerodayinitiative.com/advisories/ZDI-20-298/

    • [01:15:38] Exploiting SMBGhost for a Local Privilege Escalation [CVE-2020-0796]
    • [01:26:31] How to exploit parser differentials
    • [01:37:07] Unauthorized Camera access on iOS and macOS
    • [01:49:07] [Slack] Relative Path Vulnerability Results in Arbitrary Command Execution/Privilege Escalation
    • [01:54:21] Physically Realizable Adversarial Examples for LiDAR Object Detection
    • [02:01:39] Attack matrix for Kubernetes
    • [02:03:34] Project Zero: TFW you-get-really-excited-you-patch-diffed-a-0day-used-in-the-wild-but-then-find-out-it-is-the-wrong-vuln
    • [02:04:13] Tale of two hypervisor bugs - Escaping from FreeBSD bhyve
    • [02:08:21] So you want to be a web security researcher?

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Is there a shortcut to RCE? Well, on Windows .LNK files could be just that. We also talk about a few others vulnerabilities impacting Windows, Pi-Hole and Netflix. And end by looking at Window's new hardware enforced Shadow Stack and a proof-of-concept for fine-grained kASLR on Linux.

  • [00:01:18] The Netflix account compromise Bugcrowd doesn't want you to know about

    • https://bugcrowd.com/netflix
    • [00:16:21] Where is my Train : Tracking to Hacking
    • [00:22:59] Intel SGX removed from Rocket Skylake-S CPUs
    • [00:28:17] Type 1 Font Parsing Remote Code Execution Vulnerability
    • [00:33:41] Configuration Overwrite in IBM Cognos TM1 [CVE-2019-4716]
    • [00:42:19] Remote Code Execution Through .LNK Files [CVE-2020-0729]
    • [00:53:15] Pi-hole Remote Code Execution [CVE-2020-8816]
    • [01:03:14] NordVPN - Unauthorized User Can Delete Any User Account
    • [01:09:33] Smart Contracts Inside SGX Enclaves: Common Security Bug Patterns

    • https://blockchain-ctf.securityinnovation.com/#/

    • [01:20:01] Smart Contracts Inside SGX Enclaves: Common Security Bug Patterns
    • [01:20:28] Understanding Hardware-enforced Stack Protection

    • https://windows-internals.com/cet-on-windows/

    • [01:32:21] [RFC PATCH 00/11] Finer grained kernel address space randomization - Kristen Carlson Accardi

    • https://www.kryptoslogic.com/blog/2020/03/another-look-at-two-linux-kaslr-patches/

    • [01:42:14] Slayer Labs

    • https://www.reddit.com/r/netsec/comments/fr8w8u/free_vpn_access_to_slayer_labs_networks/?sort=top

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

More discussion about election hacking with Voatz undergoing a more complete security assessment, we also discuss a few interesting web attacks and end with a good discussion about a new code-reuse mitigation: Hurdle.

  • [00:00:20] Learn Exploit Development While Not Dying
  • [00:02:10] Exploit Education
  • [00:07:32] Pwn2Own Results

    • https://www.zerodayinitiative.com/blog/2020/3/19/pwn2own-2020-day-one-results
    • [00:16:19] DEF CON CTF 2020 QUALS COVID-19 DELAY
    • [00:22:30] Software Engineer - Jobs at Apple
    • [00:30:56] Tesla Model 3 Denial of Service Vulnerability [CVE-2020-10558]
    • [00:36:26] Trail of Bits - Voatz Security Review
    • [01:01:49] XXE-scape through the front door: circumventing the firewall with HTTP request smuggling
    • [01:08:12] Don't Clone That Repo: Visual Studio Code^2 Execution

    • https://github.com/doyensec/VSCode_PoC_Oct2019/

    • https://github.com/doyensec/VSCode_PoC_Oct2019/blob/master/.vscode/settings.json

    • https://github.com/doyensec/VSCode_PoC_Oct2019/commit/19b4687259bd5d1821525a3ebbe6aa76618359c3#diff-62b00de1d62bb867ef03dec7057712f1R50

    • [01:14:22] [Hacker101] Race Condition leads to undeletable group member
    • [01:19:58] JavaScript without parentheses using DOMMatrix

    • https://portswigger.net/web-security/cross-site-scripting/contexts/lab-javascript-url-some-characters-blocked

    • [01:24:21] Hurdle: Securing Jump Instructions Against Code Reuse Attacks

    • https://www.youtube.com/watch?v=qFWTZ2zZ1XQ

    • http://se.ri0.us/2020-03-23-110829182-9e1b1.png

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Start off by looking at a few Google Cloud attacks, a couple named vulns (LVI: Load Value Injection, and TRRespass) and then into some web-focused exploits including how to hack a CTF.

  • [00:00:15] P2O Vancouver now remote-only
  • [00:04:10] Announcing our first GCP VRP Prize winner and updates to 2020 program

    • https://offensi.com/2019/12/16/4-google-cloud-shell-bugs-explained-introduction/
    • [00:18:36] Whisper has exposed all user information
    • [00:28:10] LVI: Hijacking Transient Execution with Load Value Injection
    • [00:39:13] TRRespass: Exploiting the Many Sides ofTarget Row Refresh
    • [00:47:17] The unexpected Google wide domain check bypass
    • [00:56:34] Facebook OAuth Framework Vulnerability
    • [01:06:36] JSON CSRF with method override technique
    • [01:13:20] Breaking the Competition
    • [01:23:26] [Slack] TURN server allows TCP and UDP proxying to internal network
    • [01:26:08] [Slack] HTTP Request Smuggling to steal session cookies
    • [01:30:46] [Slack] DTLS uses a private key that is in the public domain
    • [01:32:55] [htmr] DOM-based XSS
    • [01:42:08] A Compiler Assisted Scheduler for Detecting and Mitigating Cache-Based Side Channel Attacks
    • [01:50:00] Bypassing memory safety mechanisms through speculative control flow hijacks

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

A New AMD sidechannel, and an old intel CSME attack, a couple deserialization attacks, and a few clever but not terribly useful attacks, and some discussion about memory tagging on this weeks episode of DAY[0].

  • [00:00:21] Election Security 2020: Don't Let Disinformation Undermine Your Right to Vote
  • [00:06:52] Announcing Remote Participation in Pwn2Own Vancouver
  • [00:11:22] Revoking certain certificates on March 4
  • [00:19:40] FuzzBench: Fuzzer Benchmarking as a Service
  • [00:28:53] Intel x86 Root of Trust: loss of trust
  • [00:39:07] Take A Way: Exploring the Security Implications of AMD's Cache Way Predictors
  • [00:49:11] VU#782301 - pppd vulnerable to buffer overflow due to a flaw in EAP packet processing

    • https://github.com/paulusmack/ppp/commit/8d45443bb5c9372b4c6a362ba2f443d41c5636af

    • https://github.com/paulusmack/ppp/commit/8d7970b8f3db727fe798b65f3377fe6787575426

    • [00:55:11] MediaTek rootkit affecting millions of Android devices
    • [01:01:56] Zoho ManageEngine RCE
    • [01:11:25] RCE Through a Deserialization Bug in Oracle's WebLogic Server (CVE-2020-2555)
    • [01:14:22] Regex Vulnerabilities - parse-community/parse-server
    • [01:18:57] HTTP request smuggling using malformed Transfer-Encoding header
    • [01:27:20] [Nextcloud] Delete All Data of Any User
    • [01:30:36] Dismantling DST80-based Immobiliser Systems
    • [01:37:53] Exploring Backdoor Poisoning Attacks Against Malware Classifiers
    • [01:45:59] Code Renewability for Native Software Protection
    • [01:55:42] Security Analysis of Memory Tagging
    • [02:04:15] DangKiller: Eliminating Dangling Pointers Efficiently via Implicit Identifier

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Join Specter and zi at they discuss several named vulns (kr00k, Forgot2kEyXCHANGE, GhostCat), the benefits of DNS-over-HTTPS, and a a few vulns in some of our regular targets: Samsung drivers, NordVPN, OpenSMTPd.

  • [00:01:13] Facial-Recognition Company That Works With Law Enforcement Says Entire Client List Was Stolen
  • [00:06:13] Firefox continues push to bring DNS over HTTPS by default for US users

    • https://github.com/curl/curl/wiki/DNS-over-HTTPS
    • [00:19:07] Securing Memory at EPYC Scale
    • [00:26:30] How a Hacker's Mom Broke Into a Prison—and the Warden's Computer
    • [00:29:12] kr00k | ESET
    • [00:33:14] CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
    • [00:37:41] CVE-2020-1938: Ghostcat vulnerability
    • [00:46:16] LPE and RCE in OpenSMTPD's default install (CVE-2020-8794)
    • [00:55:43] Blind SSRF on debug.nordvpn.com due to misconfigured sentry instance

    • https://hackerone.com/reports/374737

    • [01:00:30] x-request-id header reflected in server response without sanitization
    • [01:05:54] Malformed .BMP file in Counter-Strike 1.6 may cause shellcode injection

    • https://hackerone.com/valve/hacktivity

    • [01:12:56] Samsung Kernel /dev/hdcp2 hdcp_session_close() Race Condition
    • [01:14:59] Samsung Kernel Arbitrary /dev/vipx / /dev/vertex kfree
    • [01:18:34] Samsung Kernel /dev/vipx Pointer Leak
    • [01:22:21] HFL: Hybrid Fuzzing on the Linux Kernel – NDSS Symposium
    • [01:30:32] Et Tu Alexa? When Commodity WiFi Devices Turn into Adversarial Motion Sensors
    • [01:38:27] Evasion techniques
    • [01:39:31] Hacking Unicode Like a Boss
    • [01:43:05] Pwning VMware, Part 2: ZDI-19-421, a UHCI bug | nafod
    • [01:44:48] Intro to chrome's v8 from an exploit development angle

Watch Live on Twitch (@dayzerosec) at 3PM EST

View Details

Keeping up our streak, we talk about some vulnerabilities in Cisco, NordVPN and Tesla, and about SlickWraps being hacked by a very dark, white-hat.

  • [00:02:32] Humble Book Bundle: Cybersecurity 2020 by Wiley
  • [00:11:31] Google Summer of Code 2020

    • https://radare.org/gsoc/2020/
    • [00:23:01] Critical Issue In ThemeGrill Demo Importer
    • [00:28:48] Cisco Security Advisory: Cisco Smart Software Manager On-Prem Static Default Credential Vulnerability
    • [00:32:19] nordvpn Linux Desktop executable application does not use pie / no ASLR
    • [00:40:57] Race condition (TOCTOU) in NordVPN can result in local privilege escalation
    • [00:49:17] Periscope android app deeplink leads to CSRF in follow action
    • [00:54:01] I hacked SlickWraps. This is how. - Lynx0x00 - Medium

    • https://files.catbox.moe/fxn9r2.pdf

    • [01:10:23] Model Hacking ADAS to Pave Safer Roads for Autonomous Vehicles
    • [01:18:31] Edge CVE-2020-0767 RCE POC
    • [01:22:02] GadgetProbe: Exploiting Deserialization to Brute-Force the Remote Classpath
    • [01:28:37] CopyCat: Controlled Instruction-Level Attacks on Enclaves for Maximal Key Extraction
    • [01:37:31] MEUZZ: Smart Seed Scheduling for Hybrid Fuzzing
    • [01:49:36] pwn.college BETA
    • [01:53:17] Microcontroller Readback Protection: Bypasses and Defenses
    • [01:54:00] Libxml2 Tutorial | AFLplusplus
    • [01:56:06] Booting iOS on QEMU Research Slides

    • https://github.com/alephsecurity/confs/blob/master/OFFENSIVE20/offensive-20-ios-qemu.pdf

    • https://github.com/alephsecurity/xnu-qemu-arm64

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Is the new OSCP worth-it? Can election apps be made secure? We'll talk about those questions and several kernel exploits and a few cool fuzzing innovations.

  • [00:00:23] PWK and the OSCP Certification | Offensive Security

  • [00:16:24] Rescheduling Root KSK Ceremony 40

  • [00:20:15] The Ballot is Busted Before the Blockchain:A Security Analysis of Voatz

  • https://blog.voatz.com/?p=1209

  • [00:49:26] Lateral movement via MSSQL: a tale of CLR and socket reuse

  • [00:55:51] Fix for CVE-2018-12122 can be bypassed via keep-alive requests

  • [01:00:28] A Trivial Privilege Escalation Bug in Windows Service Tracing (CVE-2020-0668)

  • https://googleprojectzero.blogspot.com/2018/08/windows-exploitation-tricks-exploiting.html

  • [01:05:01] Intel CSME Escalation of Privilege

  • [01:07:41] Project Zero: A day^W^W Several months in the life of Project Zero

  • [01:18:54] Project Zero: Mitigations are attack surface, too

  • https://packetstormsecurity.com/files/156316/Samsung-Kernel-PROCA-Use-After-Free-Double-Free.html

  • [01:33:42] Samsung SEND_FILE_WITH_HEADER Use-After-Free

  • [01:35:52] Samsung /dev/tsmux Heap Out-Of-Bounds Write

  • [01:39:55] Exploiting a Linux kernel vulnerability in the V4L2 subsystem (CVE-2019-18683)

  • [01:45:10] KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write Vulnerabilities

  • [01:54:06] HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

  • [01:58:14] HYPER-CUBE: High-Dimensional Hypervisor Fuzzing

  • [02:02:21] FIDO2 Deep Dive: Attestations, Trust model and Security

  • [02:03:04] Hypervisor Necromancy; Reanimating Kernel Protectors

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Android, Bluetooth, Microsoft, NordVPN, Twitter, WhatsApp, Cisco, vulns for days impacting several big names and a couple new attack ideas, blind regex injection and GhostKnight a technique to breach data integrity using speculative execution.

  • [00:01:07] Updated re. Sudo Exploit

  • [00:03:32] Charges Filed against Four Chinese PLA Hackers for part in 2017 Equifax Breach

  • [00:06:06] Announcing a Targeted Incentive Program for Selected Trend Micro Products

  • [00:11:01] Android Security Bulletin - February 2020

  • https://android.googlesource.com/kernel/common/+/5eeb2ca0

  • https://android.googlesource.com/kernel/common/+/5eeb2ca0%5E%21/#F0

  • [00:17:06] Critical Bluetooth Vulnerability in Android (CVE-2020-0022)

  • [00:22:48] Dangerous Domain Corp.com Goes Up for Sale

  • [00:37:43] NordVPN - IDOR allow access to payments data of any user

  • https://hackerone.com/nordvpn

  • [00:43:35] Twitter - Bypass Password Authentication for updating email and phone number

  • [00:48:27] WhatsApp Desktop XSS to Local File read (CVE-2019-18426)

  • [01:03:03] CDPwn: 5 Zero-Days in Cisco Discovery Protocol

  • [01:15:07] A Rough Idea of Blind Regular Expression Injection Attack

  • https://speakerdeck.com/lmt_swallow/revisiting-redos-a-rough-idea-of-data-exfiltration-by-redos-and-side-channel-techniques

  • [01:20:45] GhostKnight: Breaching Data Integrity via Speculative Execution

  • [01:26:00] BRIGHTNESS: Leaking Sensitive Data from Air-Gapped Workstations via Screen Brightness

  • [01:30:27] Forging SWIFT MT Payment Messages for fun and pr... research!

  • [01:35:22] Grooming the iOS Kernel Heap

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Ok Google! Bypass authentication..and while we're at it, lets explot sudo and OpenSMPTD for root access. This week we dive into various code bases to explore several recent exploits that take advantage of some common yet subtle issues.

Correction: During the segment about the sudo (pwfeedback) exploit I incorrectly described the issue as a stack-based buffer overflow, however the buf variable is declared as static so it ends up in .bss and not on the stack. ~zi

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:00:22] Charges Dismissed Against Coalfire Employees
  • [00:06:50] Avast to Commence Wind Down of Subsidiary Jumpshot
  • [00:22:10] Say hello to OpenSK: a fully open-source security key implementation
  • [00:28:25] Kraken Identifies Critical Flaw in Trezor Hardware Wallets
  • [00:33:56] Zoom-Zoom: We Are Watching You
  • [00:39:08] TeamViewer using encrypted passwords
  • [00:47:43] Buffer overflow [in sudo] when pwfeedback is set in sudoers (CVE-2019-18634)
  • https://github.com/sudo-project/sudo/commit/fa8ffeb17523494f0e8bb49a25e53635f4509078
  • https://github.com/sudo-project/sudo/blob/0fcb6471609969b5911db0b2917ced16c913676f/src/tgetpass.c#L413
  • [01:01:23] Opkg susceptible to MITM (CVE-2020-7982)
  • https://git.openwrt.org/?p=project/opkg-lede.git;a=commitdiff;h=54cc7e3bd1f79569022aa9fc3d0e748c81e3bcd8
  • [01:07:18] LPE and RCE in OpenSMTPD (CVE-2020-7247)
  • [01:14:13] PHP 7.0-7.4 disable_functions bypass 0day PoC
  • https://github.com/mm0r1/exploits/blob/master/php7-backtrace-bypass/exploit.php
  • [01:28:53] Remote Cloud Execution – Critical Vulnerabilities in Azure Cloud Infrastructure (Part I)
  • https://research.checkpoint.com/2020/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-ii/
  • [01:40:22] OK Google: bypass the authentication!

View Details

This week we look at 15 CVEs this week including the new MDS Attacks/Zombieload and GhostImage a cool attack against vision-based classification systems. We also have discussion about mobile vs desktop security.

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

  • [00:01:33] Pwn2Own Miami 2020

  • [00:06:32] Allegations that Saudi Crown Prince involved in hacking of Jeff Bezos’ phone

  • https://twitter.com/dinodaizovi/status/1221324029841244161

  • [00:11:25] Chris Rohlf on Twitter: "...Mobile security was largely a success relative to the state of the desktop..."

  • [00:25:49] More MDS Attacks: Intel Patching its Patch of the Patch for MDS/ZombieLoad Attacks

  • https://blogs.intel.com/technology/2020/01/ipas-intel-sa-00329/#gs.upv68b

  • [00:31:34] MDHex Vulnerabilities

  • [00:42:55] JSSE Client Authentication Bypass (CVE-2020-2655)

  • [00:55:37] Local Privilege Escalation in many Ricoh Printer Drivers for Windows (CVE-2019-19363)

  • [00:58:34] ModSecurity Denial of Service (CVE-2019-19886)

  • [01:02:47] GGvulnz - How I hacked hundreds of companies through Google Groups

  • [01:09:14] Neowise CarbonFTP v1.4 / Insecure Proprietary Password Encryption (CVE-2020-6857)

  • [01:14:40] arm64: uaccess: Ensure PAN is re-enabled after unhandled uaccess fault - Patchwork

  • [01:18:54] Cisco Webex Meetings Suite and Cisco Webex Meetings Online Unauthenticated Meeting Join Vulnerability (CVE-2020-3142)

  • [01:21:35] iGPU Leak: An Information Leakage Vulnerability on Intel Integrated GPU (CVE-2019-14615)

  • [01:28:41] Information Leaks via Safari's Intelligent Tracking Prevention

  • [01:39:02] GhostImage: Perception Domain Attacks against Vision-based Object Classification Systems

  • [01:44:46] Nightmare - A collection of binary exploitation / reverse engineering challenges and writeups

  • [01:49:26] The Life of a Bad Security Fix

  • [01:51:22] macOS/iOS: ImageIO: heap corruption when processing malformed TIFF image

View Details

Start off with some discussions about Google, privacy, Rust, and entitlement within open-source software. Then we look at some of the big vulns of the past week including CurveBall, CabelHaunt, and an RDP RCE.

  • [00:00:27] Chromium Blog: Building a more private web: A path towards making third party cookies obsolete

  • [00:07:05] WeLeakInfo.com Domain Name Seized

  • [00:13:39] A sad day for Rust

  • [00:25:38] GitHub - microsoft/verona: Research programming language for concurrent ownership

  • https://github.com/microsoft/verona/blob/master/docs/explore.md

  • [00:37:30] Montage: A Neural Network Language Model-Guided JavaScript Engine Fuzzer

  • [00:47:16] Control Flow Integrity (CFI) in the Linux kernel

  • [00:53:54] ADV200001 | Microsoft Guidance on Scripting Engine Memory Corruption Vulnerability (CVE-2020-0674)

  • [00:57:19] Netgear TLS Private Key Disclosure through Device Firmware Images

  • https://news.ycombinator.com/item?id=22048619

  • https://github.com/ollypwn/CVE-2020-0601/blob/master/main.rb

  • [01:17:39] Cable Haunt

  • [01:27:19] RDP to RCE: When Fragmentation Goes Wrong

  • [01:31:46] Critical Auth Bypass Vulnerability In InfiniteWP Client And WP Time Capsule

  • [01:37:48] cuck00 | Twenty-twenty, bugs aplenty!

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:00:35] SHA-1 is a Shambles

  • https://www.youtube.com/watch?v=Gh6p7Y74m9A

  • [00:14:50] Government-funded phones come pre-installed with unremovable malware

  • [00:22:09] Security Vulnerabilities fixed in Firefox 72.0.1 and Firefox ESR 68.4.1 — Mozilla

  • [00:27:02] CVE-2019-19781 - Vulnerability in Citrix Application Delivery Controller and Citrix Gateway

  • https://github.com/projectzeroindia/CVE-2019-19781

  • https://www.mdsec.co.uk/2020/01/deep-dive-to-citrix-adc-remote-code-execution-cve-2019-19781/

  • https://twitter.com/GossiTheDog/status/1215785949709459456

  • [00:38:20] Project Zero: Policy and Disclosure: 2020 Edition

  • https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-faq.html

  • [00:52:07] Privileged Access Never (PAN) - Another day, another broken mitigation.

  • [00:57:43] Tik or Tok? Is TikTok secure enough?

  • [01:18:33] Fortinet FortiSIEM Hardcoded SSH Key

  • [01:22:58] Project Zero: Remote iPhone Exploitation Part 1: Poking Memory via iMessage and CVE-2019-8641

  • [01:32:00] WAF-A-MoLE: Evading Web Application Firewalls through Adversarial Machine Learning

  • [01:36:00] QSOR: Quantum-Safe Onion Routing

  • [01:45:09] Browser Games Aren't an Easy Target

  • [01:46:31] Reverse engineering RNG in a GBA game

  • https://en.wikipedia.org/wiki/Linear_congruential_generator#Parameters_in_common_use

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:00:40] CCC
  • [00:14:58] Sunsetting Python 2 | Python.org
  • https://www.python.org/blogs/
  • [00:19:11] Kali 2020.1 - Default Non-Root User
  • https://www.kali.org/news/kali-default-non-root-user/
  • https://www.offensive-security.com/
  • [00:35:53] Caterpillar padlocks all use the same key
  • [00:42:51] Shitcoin Wallet is a scam, says security researcher
  • [00:47:13] Microsoft Edge (Chromium) - Elevation of Privilege to Potential Remote Code Execution
  • [00:56:57] Exploiting Wi-Fi Stack on Tesla Model S | Keen Security Lab Blog
  • [01:08:52] Spiderman 2000 - Buffer overflow in file loading routine
  • [01:14:31] Alert Alarm SMS exploit
  • [01:27:33] D-Link DIR-859 - Unauthenticated RCE (CVE-2019-17621)
  • [01:33:20] Cisco Security Advisory: Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
  • https://tools.cisco.com/security/center/publicationListing.x
  • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-path-trav
  • [01:45:03] Starbuck's JumpCloud API Key leaked via Open Github Repository
  • https://www.androidpolice.com/2020/01/06/uh-oh-xiaomi-camera-feed-showing-random-homes-on-a-google-nest-hub-including-still-images-of-sleeping-people/
  • [01:56:39] JackHammer: Efficient Rowhammer on Heterogeneous FPGA-CPU Platforms
  • [02:02:28] Shadowclone: Thwarting and Detecting DOP Attacks with Stack Layout Randomization and Canary
  • [02:15:21] Breaking PHP's mt_rand() with 2 values and no bruteforce

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:01:18] Last Episode of the Year

  • [00:01:36] Real-World Bug Hunting: A Field Guide to Web Hacking

  • http://www.phrack.org/papers/attacking_javascript_engines.html

  • [00:11:29] President's Cup

  • [00:24:20] Better Password Protections [in Chrome]

  • [00:30:18] Apple DMCA's SEP Key

  • https://en.wikipedia.org/wiki/Illegal_number

  • [00:36:59] Rosita: Towards Automatic Elimination of Power-Analysis Leakage in Ciphers

  • [00:48:50] Camouflage: Hardware-assisted CFI for the ARM Linux kernel

  • [01:00:37] Binary Planting with the npm CLI

  • [01:04:55] Plundervolt

  • [01:17:35] Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726)

  • [01:24:09] AirDoS: Remotely render any nearby iPhone or iPad unusable

  • [01:26:24] Digital Lockpicking - Stealing Keys to the Kingdom (KeyWe Smart Lock)

  • https://labs.f-secure.com/advisories/keywe-smart-lock-unauthorized-access-traffic-interception

  • [01:31:44] SockPuppet: A Walkthrough of a Kernel Exploit for iOS 12.4

  • [01:39:05] Maddie Stone: Whatsup with WhatsApp: A Detailed Walk Through of Reverse Engineering CVE-2019-3568

  • [01:46:37] Client-side Vulnerabilities in Commercial VPNs

  • [01:54:50] A Technical Review of Connected Toy Security

  • https://www.which.co.uk/news/2019/12/kids-karaoke-machines-and-smart-toys-from-mattel-and-vtech-among-those-found-to-have-security-flaws-in-a-which-investigation/

  • [02:07:43] Interactive Buffer Overflow Exploitation

  • https://github.com/bordplate/js86

  • https://nagarrosecurity.com/blog/interactive-rop-tutorial

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:02:59] Android Permanent DoS (CVE-2019-2232)

  • [00:08:09] Inferring and hijacking VPN-tunneled TCP connections (CVE-2019-14899)

  • [00:16:00] An Update on Android TLS Adoption

  • [00:25:11] Mozilla and Opera remove Avast extensions from their add-on stores

  • https://palant.de/2019/10/28/avast-online-security-and-avast-secure-browser-are-spying-on-you/

  • [00:43:05] Tron: Evolution SecuROM DRM expiration makes game unplayable 9 years after release

  • [00:50:12] Millions of Americans at Risk After Huge Data and SMS Leak

  • [00:54:14] Nebraska Medicine Breached by Rogue Employee

  • [00:56:56] Practical Pentest Labs stores passwords in plaintext

  • [01:05:07] Incident Report | 2019-11-24 Account Takeover via Disclosed Session Cookie

  • [01:13:28] Authentication vulnerabilities in OpenBSD (CVE-2019-19521)

  • [01:24:36] Symantec Endpoint Protection Local Privilege Escalation (CVE-2019-12750)

  • [01:30:09] Omron PLC Denial-of-Service as a Feature

  • https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • https://github.com/Ox6e3062306479/omron/blob/master/cj2m.fins.dos.py

  • [01:38:35] FIRST CONTACT: New vulnerabilities in contactless payments

  • [01:46:39] Fuzzing Sega Genesis Emulators

  • [01:50:30] Verifiable Voting Primer

  • https://www.youtube.com/watch?v=LkH2r-sNjQs

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:02:08] Protecting users from government-backed hacking and disinformation

  • [00:10:23] ENISA threat landscape for 5G Networks

  • [00:16:13] EU raises eyebrows at possible US encryption ban

  • [00:24:16] You watch TV. Your TV watches back.

  • [00:34:44] CWE - Top 25

  • https://cwe.mitre.org/top25/archive/2011/2011_cwe_sans_top25.html

  • [00:46:58] LPE in K7 Security Anti-Virus (CVE-2019-16897)

  • [00:47:09] Weak Crypto in Forinet Products

  • [01:01:37] CVE-2019-11932 (double free in libpl_droidsonroids_gif) many apps vulnerable

  • https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263

  • [01:04:32] Max Secure Anti Virus Plus - 19.0.4.020 / CVE-2019-19382 Insecure Permissions

  • [01:10:41] Synology DSM Remote Command Injection

  • [01:16:45] SpoC: Spoofing Camera Fingerprints

  • [01:24:44] Defending Against Adversarial Machine Learning

  • [01:34:21] Can Attention Masks Improve Adversarial Robustness?

  • [01:38:58] Hidviz

  • [01:41:05] IDA 7 Demo Release

  • [01:47:54] Windows Terminal (Preview) 0.7 Release

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:00:35] PagedOut #2

  • [00:07:38] Black Friday Deals to watch out for

  • [00:17:59] Official Monero website is hacked to deliver currency-stealing malware

  • [00:26:30] Managing Risk from Transport Lay Security Inspection

  • [00:40:55] US student was allegedly building a custom Gentoo Linux distro for ISIS

  • [00:48:41] Google Outlines Plans for Mainline Linux Kernel Support in Android

  • [00:55:12] Introducing Flan Scan

  • [00:59:44] Expanding Android Security Rewards

  • [01:05:26] Updates to the Mozilla Web Security Bounty Program

  • [01:07:59] XSS in GMail’s AMP4Email via DOM Clobbering

  • [01:17:32] VNC Vulnerabilities (LibVNC, TightVNC, TurboVNC and UltraVNC)

  • [01:26:22] Arbitrary file capture in Kaspersky Total Security 2019

  • [01:30:43] Bad binder: Android In-The-Wild Exploit

  • [01:36:03] Building Fast Fuzzers

  • https://github.com/gamozolabs/fzero_fuzzer

  • [01:49:47] The Performance of Machine and Deep Learning Classifiers in Detecting Zero-Day Vulnerabilities

  • [02:02:08] PARAM: A Microprocessor Hardened for Power Side-Channel Attack Resistance

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:02:09] Thousands of hacked Disney+ accounts are already for sale
  • [00:06:33] Faking an iVote decryption proof
  • [00:16:20] "robot deployed at the famous Robot Hotels in Japan can be converted to offer anyone remote camera/mic access to all future guests."
  • [00:30:13] "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file"
  • [00:35:42] HHVM Security Update
  • [00:38:18] Symantec Endpoint Protection - Self-Defense Bypass - CVE-2019-12758
  • [00:38:27] McAfee - All Editions - Self-Defense Bypass - CVE-2019-3648
  • [00:43:26] Imperceptible Adversarial Attacks on Tabular Data
  • [00:48:48] 5GReasoner: A Property-Directed Security and Privacy AnalysisFramework for 5G Cellular Network Protocol
  • [00:55:26] Fuzzing Qualcomm Secure Execution Environment and CVE-2019-10574
  • [01:00:32] TPM-Fail
  • [01:08:54] Mitigations for Jump Conditional Code Erratum
  • [01:14:35] More MDS Attacks
  • [01:22:55] Tianfu Cup
  • [01:27:48] Protecting against code reuse in the Linux kernel with Shadow Call Stack
  • [01:34:04] Security things in Linux v5.3
  • [01:50:36] A Security Perspective on Unikernels
  • [01:54:26] Announcing GitHub Security Lab: securing the world's code, together
  • [02:09:32] Huawei introduces new invite-only bug bounty program
  • [02:12:37] Interpol plans to condemn encryption spread, citing predators, sources say
  • https://www.youtube.com/watch?v=VPBH1eW28mo
  • [02:17:33] How a turf war and a botched contract

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [1573502643] Blog launched, stream schedule, discord

  • [1573503151] Pwn2Own Tokyo 2019

  • [1573503418] Blog launched, stream schedule, discord

  • [00:01:56] Pwn2Own Tokyo 2019

  • https://www.zerodayinitiative.com/Pwn2OwnTokyo2019Rules.html

  • [00:07:22] Pwn2Own Tokyo 2019

  • [00:08:46] Google Begins Testing Extension manifest v3 in Chrome Canary

  • [00:12:03] Rogue Trend Micro Employee Sold Customer Data for 68K Accounts

  • [00:14:54] The DoJ charges former Twitter employees for allegedly accessing thousands of accounts on behalf of Saudi Arabia.

  • [00:23:02] OpenTitan – Open sourcing transparent, trustworthy, and secure silicon

  • https://arstechnica.com/information-technology/2019/11/newly-discovered-titanium-backdoor-employs-clever-ways-to-go-undetected/

  • [00:26:34] OpenTitan – Open sourcing transparent, trustworthy, and secure silicon

  • [00:29:33] Sandboxie transitioning to open source

  • https://arstechnica.com/information-technology/2019/11/newly-discovered-titanium-backdoor-employs-clever-ways-to-go-undetected/

  • https://securelist.com/titanium-the-platinum-group-strikes-again/94961/

  • https://arstechnica.com/information-technology/2019/11/newly-discovered-titanium-backdoor-employs-clever-ways-to-go-undetected/

  • [00:44:06] Facebook Groups API flaw exposed data to 100 developers

  • [00:47:47] Laser-Based Audio Injection on Voice-Controllable Systems

  • [00:54:07] Who is Real Bob? Adversarial Attacks on Speaker Recognition Systems

  • [00:54:20] Laser-Based Audio Injection on Voice-Controllable Systems

  • [00:57:11]

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:05:23] Apple v. Corellium
  • [00:12:04] Firefox to Discontinue Sideloaded Extensions
  • [00:16:52] Delegated Credentials for TLS
  • [00:23:02] North Korean Malware Found on Indian Nuclear Plant's Network
  • [00:28:20] The Pirate Bay Downtime Caused by Malicious Search Queries
  • [00:29:30] Web.com Breach (allegedly includes NetworkSolutions.com and Register.com)
  • [00:32:28] BlueKeep attacks are happening, but it's not a worm
  • https://www.kryptoslogic.com/blog/2019/11/bluekeep-cve-2019-0708-exploitation-spotted-in-the-wild/
  • [00:36:13] Untitled Goose Game - Insecure Deserialization
  • [00:39:58] Two Chrome 0Days get Patched
  • [00:42:45] NFC Beaming Bypasses Security Controls in Android [CVE-2019-2114]
  • [00:45:43] Abusing HTTP Hop-by-hop Request Headers
  • [00:50:54] Let's Make Windows Defender Angry: Antivirus Can be an Oracle! -icchy
  • https://en.wikipedia.org/wiki/EICAR_test_file
  • [00:56:54] rConfig v3.9.2 authenticated and unauthenticated RCE (CVE-2019-16663) and (CVE-2019-16662)
  • [01:02:26] Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors
  • [01:07:26] Silhouette: Efficient Intra-Address Space Isolation for Protected Shadow Stacks on Embedded Systems
  • [01:19:46] unfork(2)
  • [01:23:51] Destroying x86_64 instruction decoders with differential fuzzing
  • https://github.com/zyantific/zydis

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:00:49] NordVPN's Response to Private Certificate Breach Discussed Last Week

  • https://nordvpn.com/blog/security-plan/

  • [00:12:31] AWS Hit By major DDOS Attack

  • https://status.digitalocean.com/incidents/1z3kmlvz69v6

  • [00:14:43] Seven Million Adobe Creative Cloud Accounts Exposed to the Public

  • [00:25:24] Travel Reservations Platform Leaks US Government Personnel Data

  • [00:30:09] Joe Rogan Experience #1368 - Edward Snowden

  • [00:48:38] Technical Analysis of Checkm8

  • https://googleprojectzero.blogspot.com/2019/10/ktrw-journey-to-build-debuggable-iphone.html

  • [00:55:51] Cache Poisoned Denial of Service (CPDoS)

  • [01:08:27] CVE-2019-11043 - PHP-FPM (potential) RCE

  • https://github.com/neex/phuip-fpizdam/blob/master/attack.go

  • [01:20:44] Light Ears: Information Leakage via Smart Lights

  • [01:27:57] Don’t open that XML: XXE to RCE in XML plugins for VS Code, Eclipse, Theia, …

  • [01:33:28] Bringing ICS into the Pwn2Own World

  • [01:37:39] Analysis of Qualcomm Secure Boot Chains

  • [01:39:56] Microsoft Secured-Core PC

  • [01:47:46] Guarding Against Physical Attacks: The Xbox One Story

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@DAY[0])

  • [00:01:29] Sudo: CVE-2019-14287

  • [00:08:40] Buffer overflow in Realtek Wi-Fi chips

  • [00:17:13] US Law Enforcement Traces Bitcoin Transfers to Nab ‘Largest’ Child Porn Site

  • [00:39:45] Equifax Using admin:admin as Credentials for Sensitive Information

  • [00:48:40] CenturyLink Data Leak of 2.8 Million Records

  • [00:56:37] NordVPN Reportedly Compromised

  • https://crt.sh/?q=nordvpn.com

  • [00:59:07] NordVPN Reportedly Compromised

  • https://twitter.com/hexdefined/status/1185974575214940161

  • https://nordvpn.com/

  • https://thatoneprivacysite.net/

  • [01:07:45] Pop_OS 19.10

  • [01:13:26] JSFuzz

  • [01:19:08] Site Isolation improvement (and now on Android)

  • [01:22:54] A New Memory Type Against Speculative Side Channel Attacks

  • [01:30:06] oo7: Low-overhead Defense against Spectre Attacks via Program Analysis

  • [01:38:37] UK Government to fund development of attack resistant Arm chips

  • [01:46:59] Germany's Cyber Security Agency Recommends Firefox as Most Secure Browser

  • [02:01:36] Facebook Expanding Bug Bountry Program to Third-Party Apps

  • https://www.facebook.com/whitehat/info/

  • [02:04:14] ElectionGuard SDK Bug Bounty

  • https://www.youtube.com/watch?v=w3_0x6oaDmI

  • https://www.youtube.com/watch?v=BYRTvoZ3Rho

  • https://www.microsoft.com/en-us/msrc/bounty-electionguard

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube

  • [00:03:00] Critical Security Issue identified in iTerm2 as part of Mozilla Open Source Audit
  • iTerm2 Patch
  • [00:11:24] Windows Error Reporting Manager arbitrary file move Elevation of Privilege (CVE-2019-1315)
  • James Forshaw A Link To The Past.pdf
  • [00:16:12] CVE-2019-8697: MacOS System Escalation via Disk Management https://www.zerodayinitiative.com/blog/2019/10/3/cve-2019-8697-macos-system-escalation-via-disk-management
  • [00:20:20] Apple Zero Day Exploited in Bitpaymer Campaign
  • [00:25:50] BrokenStrokes: On the (in)Security of Wireless Keyboards
  • [00:31:53] PS2 Yabasic Exploit
  • Exploit Writeup
  • [00:40:12] Imperva Breach Report

[00:49:23] EU-coordinated risk assessment of 5G network security https://eeas.europa.eu/delegations/united-states-america/68637/eu-coordinated-risk-assessment-5g-network-security_me [00:55:11] Measuring Attack Surface Reduction in the Presence of Code (Re-)Randomization https://arxiv.org/abs/1910.03034 * [01:04:46] Finding Security Threats That Matter: An Industrial Case Study * [01:16:47] An Extended Survey on Vehicle Security

[01:21:56] Zydis 3.0 Released (x86-64 disassembler library) https://github.com/zyantific/zydis * [01:25:54] IDA 7.4 * [01:28:38] Government interference in Australia's premier cybersecurity conference is a worry * [01:33:16] uBlock dev build rejected * [01:39:19] Ken Thompson's Unix Password * [01:44:04] Humble Bundle

View Details

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube

  • [00:00:40] What happened while we were gone. ft. Defcon and Blackhat discussion
  • [00:20:10] Checkm8 - iPhone bootROM exploit
  • [00:28:52] iPhone A11 debug registers allow full-featured kernel debugging
  • [00:32:52] Android: Use-After-Free in Binder driver
  • https://groups.google.com/forum/#!msg/syzkaller-bugs/QyXdgUhAF50/g-FXVo1OAwAJ
  • [00:39:36] PHP 7.0-7.3 disable_functions bypass
  • https://bugs.php.net/bug.php?id=72530
  • [00:51:49] An Empirical Study of C++ Vulnerabilities in Crowd-Sourced Code Examples
  • https://cwe.mitre.org/data/definitions/20.html
  • [01:03:18] Signal RTP is processed before call is answered
  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1943
  • [01:08:47] Whatsapp RCE
  • [01:14:58] Attacking CNN-based anti-spoofing face authentication in the physical domain
  • [01:22:52] The Kernel Concurrency Sanitizer (KCSAN)
  • [01:30:36] Eradicating Attacks on the Internal Network with Internal Network Policy
  • [01:39:22] Analyzing Control Flow Integrity with LLVM-CFI

View Details

This will be our last episode until the fall, but once we are back you can catch the DAY[0] podcast on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:00:50] This will be our last episode until the fall.

[00:02:50] Thoughts on the Advanced Web Attacks and Exploitation (AWAE) Course, and the Offensive Security Web Expert (OSWE) certification

[00:32:05] r/AskNetsec - New windows LPE from non-admin :) - From SandboxEscaper

[00:45:20] First American Financial Corp. compromise

[00:53:48] Google admits storing G Suite user passwords in plain text for 14 years

[01:02:27] Safety vs. Security: Attacking Avionic Systems with Humans in the Loop

[01:17:30] Malware Guard Extension: Using SGX to Conceal Cache Attacks

[01:25:04] Biometric Backdoors: A Poisoning Attack Against Unsupervised Template Updates

[01:36:45] MemoryRanger Prevents Hijacking FILE_OBJECT Structures in Windows

[01:46:59] Hey Google, What Exactly Do Your Security Patches Tell Us?A Large-Scale Empirical Study on Android Patched Vulnerabilities

[02:03:35] MAC OSX Gatekeeper Bypass

[02:10:47] RCE Without Native Code: Exploitation of a Write-What-Where in Internet Explorer

View Details

Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:01:55] Frida 12.5 Released

[00:08:17] Damn Vulnerable Crypto Wallet

[00:16:40] Thangry Cat: https://😾😾😾.fm/

[00:23:11] Micro-Architectural Data Sampling Attacks

  • ZombieLoad
  • RIDL paper
  • Fallout paper
  • Red Hat Overview Video

[00:56:24] Update to Security Incident [May 17, 2019] - Stack Overflow Blog

[01:04:00] Global Takedown Shows the Anatomy of a Modern Cybercriminal Supply Chain

[01:15:12] How Hackers Broke WhatsApp With Just a Phone Call

  • CVE-2019-3568

[01:26:53] Over 25,000 Linksys Smart Wi-Fi Routers Vulnerable to Sensitive Information Disclosure

[01:34:01] Prevent a worm by updating Remote Desktop Services (CVE-2019-0708)

View Details

Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:00:30] Unhackable: New chip stops attacks before they start

[00:15:00] DeepCheck: A Non-intrusive Control-flow Integrity Checking based...

[00:25:54] Queue the Hardening Enhancements

[00:50:18] For Cybersecurity, Computer Science Must Rely on Strong Types

[00:57:43] A Novel Side-Channel in Real-Time Schedulers

[01:04:55] MAVSec: Securing the MAVLink Protocol

[01:10:39] Domain Specific Code Smells in Smart Contracts

[01:18:56] Over 275 Million Records Exposed by Unsecured MongoDB Database

[01:38:02] Applied Risk :: Advisories

[01:53:50] Alpine Linux Dockerimage contains a NULL root password

[01:59:01] Linux Kernel Race Condition and UAF

[02:05:44] Arbitrary file read vulnerability in HackerRank

View Details

Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:00:30]r/GlobalOffensive: PSA: Security issue regarding lobbies and games

[00:11:30]Vita Exploit

[00:20:05]Indie Game Removed From Switch eShop

[00:34:40]Eight Devices, One Exploit

[00:47:30]Remote Code Execution on most Dell computers

[00:56:35]All Firefox extensions disabled due to expiration of intermediate signing cert

[01:15:10]A hacker is wiping Git repositories and asking for a ransom | ZDNet

[01:38:25]Typer vs. CAPTCHA: Private information based CAPTCHA to defend against crowdsourcing human cheating

[01:50:50]36 Year old Kernel stack disclosure bug in UFS/FFS

[02:00:52]You Only Propagate Once: Painless Adversarial Training

[02:05:55]The Risks of WebGL: Analysis, Evaluation and Detection

[02:18:55]InternalBlue: Bluetooth Binary Patching and Experimentation Framework

[02:27:30]IRONHIDE: A Secure Multicore Architecture that Leverages Hardware Isolation Against Microarchitecture State Attacks

Extra Links:

  • h-encore exploit (old Vita exploit)

  • InternalBlue CCC talk

View Details

Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:00:30] - Physical Adversarial Textures that Fool Visual Object Tracking

[00:04:30] - DPatch: An Adversarial Patch Attack on Object Detectors

[00:11:45] - Side-Channel Attack to Extract ECDSA Private Keys from Qualcom Hardware-Based Keystore

[00:19:40] - For PayPal security team,“get user balances and transaction details" is not a vulnerability

[00:26:05] - "CI Knew There Would Be Bugs Here" - Exploring Continuous Integration

[00:40:10] - Hacker Finds They Can Kill Car Engines After Breaking Into GPS Tracking Device

[00:50:25] - Security baseline (DRAFT) for Windows 10 v1903

[00:58:25] - Security Analysis of Near-Field Communication (NFC) Payments

[01:12:10] - Docker Hub Hacked – 190k accounts, GitHub tokens revoked, Builds disabled

[01:18:50] - eGobbler - malvertising campaign exploits zero-day Chrome bug

[01:32:15] - New backdoor inspired by leaked NSA malware

[01:39:60] - Mueller report: Russia hacked state databases and voting machines

[01:54:10] - New Technique Uses Power Anomalies to ID Malware in Embedded Systems

View Details

[00:00:31] - https://blogs.grammatech.com/open-source-tools-for-binary-analysis-and-rewriting

[00:05:31] - https://arxiv.org/abs/1904.07280

[00:13:51] - https://www.zdnet.com/article/security-researcher-malwaretech-pleads-guilty/

[00:21:12] - https://www.zdnet.com/article/facebook-admits-to-storing-plaintext-passwords-for-millions-of-instagram-users/

[00:25:34] - https://security.googleblog.com/2019/04/better-protection-against-man-in-middle.html

[00:31:36] - https://pdfpiw.uspto.gov/.piw?docid=10262138&SectionNum=1&IDKey=0229F1C38B5D

[00:39:02] - https://arxiv.org/abs/1904.07370

[00:53:05] - https://github.com/vusec/kmvx

[01:04:45] - Discussion on valuation of an exploit

[01:08:05] - https://arxiv.org/abs/1904.07550

[01:16:02] - https://arxiv.org/abs/1904.08653

[01:24:36] - https://blog.underdogsecurity.com/rce_in_origin_client/

[01:35:14] - https://threatpost.com/windows-zero-day-active-exploits/143820/

[01:40:18] - https://www.ghacks.net/2019/04/16/adblock-plus-filter-exploit-to-run-arbitrary-code-discovered/

[01:47:26] - https://krbtgt.pw/dacl-permissions-overwrite-privilege-escalation-cve-2019-0841/

[01:50:47] - https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-asr9k-exr

View Details

Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec

[00:00:37] - Huawei Cyber Security Evaluation Report

[00:14:22] - Assange Arrest

[00:24:55] - Matrix Compromise

[00:32:20] - Outlook Compromise

[00:43:39] - Ghidra Source Release

[00:49:18] - Relyze 3 Beta (Another Free Decompiler)

[00:56:30] - Fracker (New PHP Tool)

[01:01:11] - Discussion about EncryptCTF and challenge design

[01:25:24] - Dragonblood/WPA3 Vulnerabilities

[01:32:21] - CVE-2019-0211 Apache Root Privilege Escalation

[01:41:27] - Detailing of CVE-2019-1636 and CVE-2019-6739 in QT

[01:49:47] - Splitting Atoms in XNU

[02:06:39] - PostgreSQL is it a CVE?

[02:11:41] - RELOAD+REFRESH: Abusing Cache Replacement Policies to Perform Stealthy Cache Attacks

[02:26:45] - The ROP Needle: Hiding Trigger-based Injection Vectors via Code Reuse

[02:29:30] - Assessing Unikernel Security

View Details

00:01:10 Sunshine CTF

00:10:27 Question Discussion: Opinions regarding CTF's vs. Real World Exploits

00:24:15 ENCRYPT CTF Discussion

00:31:25 Pwn2Own 2019 (P2O) and Tesla Hacking

00:41:25 Tricking Tesla Autopilot

00:56:45 Ghidra 9.0.1 Release

00:59:30 Commando VM

01:06:50 PoC||GTFO 0x19

01:13:20 ASUS Update Tool Backdoor

01:19:05 Windows Defender APC Code Injection Sensors

01:22:55 BSEA-1 - A Stream Cipher Backdooring Technique

01:32:40 LockerGoga Randomware Vaccination

01:37:40 Hearing your touch: A new acoustic side channel on smartphones

01:43:05 Keybase is not softer than TOFU

01:48:30 Exploitation Techniques and Defenses for Data-Oriented Attacks

01:56:00 Restricting Control Flow During Speculative Execution with Venkman

Additional Links:

  • Sunshine CTF Writeups
  • Attacking Javascript Engines Phrack Article

View Details

00:00:50 Ghidra from XXE to RCE

00:08:50 Cutter (Radare2) Release

00:15:00 Daenerys IDA Pro and Ghidra Interoperability Framework

00:22:00 IDA Educational Release

00:39:35 Windows Defender on MacOS

00:59:20 A new Windows 10 KASLR Bypass

01:11:07 EVMFuzz Fuzzing Ethereum Virtual Machines

01:30:10 Researchers find 36 new security flaws in LTE Protocol

01:45:50 Facebook logging plaintext passwords

Other Interesting Links: SecurityInnovation Blockchain CTF Analysis of a Chrome Zero-Day (CVE-2019-5786) Writeup

View Details

00:00:30 Steam Client (CSGO) RCE

00:04:44 CS 1.6 Trojan.Belonard Malware Campaign

00:11:55 WebKit Structure ID Randomness Mitigation

00:20:48 Reuse Gadget Counts Whitepaper (ROP)

00:31:50 DTrace on Windows

00:38:20 Backdoor Attack in CNN's

00:55:05 DARPA's $10m Open Source Voting System

01:13:30 Vulnerability in Swiss E-Voting System

View Details

00:00:00 Intro / General Discussion

00:00:55 Ghidra Overview (Pros, Cons)

00:30:20 Ghidra JDWP Debug Port 'Backdoor' Discussion

00:38:05 Ghidra and National Security

00:52:15 "Finding Unicorns: When The C++ Compiler Writes the Vuln" Discussion

01:06:15 "Windows 7 may insecurely load Dynamic Link Libraries" Discussion

01:21:40 "Exploiting Car Alarms" Discussion

01:45:05 XNU (Mac OS) Copy-on-Write Behavior Bypass Zero-Day Discussion

02:03:15 Chrome Zero-Day Discussion