dayzerosec
Day[0]
A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
How to Hack a CTF and more (LVI, TRRespass and some web-exploits) 17.03.2020 1:57:15
Start off by looking at a few Google Cloud attacks, a couple named vulns (LVI: Load Value Injection, and TRRespass) and then into some web-focused exploits including how to hack a CTF. [00:00:15] P2O Vancouver now remote-only [00:04:10] Announcing our first GCP VRP Prize winner and updates to 2020 program https://offensi.com/2019/12/16/4-google-cloud-shell-bugs-explained-introduction/ [00:18:36] W...
FuzzBench, MediaTek-su, Request Smuggling, and Memory Tagging 10.03.2020 2:14:29
A New AMD sidechannel, and an old intel CSME attack, a couple deserialization attacks, and a few clever but not terribly useful attacks, and some discussion about memory tagging on this weeks episode of DAY[0]. [00:00:21] Election Security 2020: Don't Let Disinformation Undermine Your Right to Vote [00:06:52] Announcing Remote Participation in Pwn2Own Vancouver [00:11:22] Revoking certain certific...
kr00k, GhostCat, and more issues from NordVPN, Samsung, OpenSMTPd 03.03.2020 1:46:52
Join Specter and zi at they discuss several named vulns (kr00k, Forgot2kEyXCHANGE, GhostCat), the benefits of DNS-over-HTTPS, and a a few vulns in some of our regular targets: Samsung drivers, NordVPN, OpenSMTPd. [00:01:13] Facial-Recognition Company That Works With Law Enforcement Says Entire Client List Was Stolen [00:06:13] Firefox continues push to bring DNS over HTTPS by default for US users...
A Dark White-Hat hacker? and various vulns ft. Cisco, Periscope, NordVPN and Tesla/EyeQ 25.02.2020 2:00:52
Keeping up our streak, we talk about some vulnerabilities in Cisco, NordVPN and Tesla, and about SlickWraps being hacked by a very dark, white-hat. [00:02:32] Humble Book Bundle: Cybersecurity 2020 by Wiley [00:11:31] Google Summer of Code 2020 https://radare.org/gsoc/2020/ [00:23:01] Critical Issue In ThemeGrill Demo Importer [00:28:48] Cisco Security Advisory: Cisco Smart Software Manager On-Pre...
A New PWK/OSCP, Election Hacking, Kernel Exploits, and Fuzzing 18.02.2020 2:05:12
Is the new OSCP worth-it? Can election apps be made secure? We'll talk about those questions and several kernel exploits and a few cool fuzzing innovations. [00:00:23] PWK and the OSCP Certification | Offensive Security [00:16:24] Rescheduling Root KSK Ceremony 40 [00:20:15] The Ballot is Busted Before the Blockchain:A Security Analysis of Voatz https://blog.voatz.com/?p=1209 [00:49:26] Lat...
Hack Twitter, WhatsApp and all your Cisco phones (CDPwn) ft. GhostKnight 11.02.2020 1:38:41
Android, Bluetooth, Microsoft, NordVPN, Twitter, WhatsApp, Cisco, vulns for days impacting several big names and a couple new attack ideas, blind regex injection and GhostKnight a technique to breach data integrity using speculative execution. [00:01:07] Updated re. Sudo Exploit [00:03:32] Charges Filed against Four Chinese PLA Hackers for part in 2017 Equifax Breach [00:06:06] Announcing a...
OK Google, sudo ./hacktheplanet 04.02.2020 1:49:41
Ok Google! Bypass authentication..and while we're at it, lets explot sudo and OpenSMPTD for root access. This week we dive into various code bases to explore several recent exploits that take advantage of some common yet subtle issues. Correction: During the segment about the sudo (pwfeedback) exploit I incorrectly described the issue as a stack-based buffer overflow, however the buf variable is d...
Return of the Zombieload, Bezos Hacked, and other exploits 27.01.2020 1:55:31
This week we look at 15 CVEs this week including the new MDS Attacks/Zombieload and GhostImage a cool attack against vision-based classification systems. We also have discussion about mobile vs desktop security. Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) [00:01:33] Pwn2Own Miami 2020 [00:06:32] Allegations that Saudi Crown Prince involv...
Project Verona, CurveBall, CableHaunt, and RCEs-a-plenty 21.01.2020 1:47:05
Start off with some discussions about Google, privacy, Rust, and entitlement within open-source software. Then we look at some of the big vulns of the past week including CurveBall, CabelHaunt, and an RDP RCE. [00:00:27] Chromium Blog: Building a more private web: A path towards making third party cookies obsolete [00:07:05] WeLeakInfo.com Domain Name Seized [00:13:39] A sad day for Rust [0...
SHA-mbles, Shitrix, Responsible Disclosure, and wtf is TikTok doing? 14.01.2020 1:56:02
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:00:35] SHA-1 is a Shambles https://www.youtube.com/watch?v=Gh6p7Y74m9A [00:14:50] Government-funded phones come pre-installed with unremovable malware [00:22:09] Security Vulnerabilities fixed in Firefox 72.0.1 and Firefox ESR 68.4.1 — Mozill...
First Edge bounty, Hacking Tesla via Wi-Fi, Cisco advisories, and Shadow Clones 08.01.2020 2:20:30
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:00:40] CCC [00:14:58] Sunsetting Python 2 | Python.org https://www.python.org/blogs/ [00:19:11] Kali 2020.1 - Default Non-Root User https://www.kali.org/news/kali-default-non-root-user/ https://www.offensive-security.com/ [00:35:53] Caterpill...
PlunderVolt, Real-World Bug Hunting, Presidents Cup CTF, SockPuppet and more 17.12.2019 2:13:06
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:01:18] Last Episode of the Year [00:01:36] Real-World Bug Hunting: A Field Guide to Web Hacking http://www.phrack.org/papers/attacking_javascript_engines.html [00:11:29] President's Cup [00:24:20] Better Password Protections [in Chrome] [00:3...
Permanent DoS, HackerOne Hacked, and Wide-OpenBSD 10.12.2019 2:14:23
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:02:59] Android Permanent DoS (CVE-2019-2232) [00:08:09] Inferring and hijacking VPN-tunneled TCP connections (CVE-2019-14899) [00:16:00] An Update on Android TLS Adoption [00:25:11] Mozilla and Opera remove Avast extensions from their add-on...
CWE Top 25, Hacking Anti-Viruses and Adversarial Machine Learning Attacks 03.12.2019 1:55:35
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:02:08] Protecting users from government-backed hacking and disinformation [00:10:23] ENISA threat landscape for 5G Networks [00:16:13] EU raises eyebrows at possible US encryption ban [00:24:16] You watch TV. Your TV watches back. [00:34:44]...
What does the NSA say? 26.11.2019 2:19:14
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:00:35] PagedOut #2 [00:07:38] Black Friday Deals to watch out for [00:17:59] Official Monero website is hacked to deliver currency-stealing malware [00:26:30] Managing Risk from Transport Lay Security Inspection [00:40:55] US student was alle...
Election hacking, Kernel Security, MDS Attacks and Github's Security Lab 19.11.2019 2:32:43
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:02:09] Thousands of hacked Disney+ accounts are already for sale [00:06:33] Faking an iVote decryption proof [00:16:20] "robot deployed at the famous Robot Hotels in Japan can be converted to offer anyone remote camera/mic access to all future guest...
Rogue Employees, Lasers, Fuzzing, and an iOS Exploit (checkra1n) 13.11.2019 1:34:28
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [1573502643] Blog launched, stream schedule, discord [1573503151] Pwn2Own Tokyo 2019 [1573503418] Blog launched, stream schedule, discord [00:01:56] Pwn2Own Tokyo 2019 https://www.zerodayinitiative.com/Pwn2OwnTokyo2019Rules.html [00:07:22] Pwn2Ow...
A Bit of everything: 0days, Breaches, Lawsuits, Attacking AI, and some insecure 05.11.2019 1:34:06
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:05:23] Apple v. Corellium [00:12:04] Firefox to Discontinue Sideloaded Extensions [00:16:52] Delegated Credentials for TLS [00:23:02] North Korean Malware Found on Indian Nuclear Plant's Network [00:28:20] The Pirate Bay Downtime Caused by Ma...
NordVPN Again, Snowden, CPDoS, a PHP-RCE, and some console hacking 28.10.2019 1:59:18
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:00:49] NordVPN's Response to Private Certificate Breach Discussed Last Week https://nordvpn.com/blog/security-plan/ [00:12:31] AWS Hit By major DDOS Attack https://status.digitalocean.com/incidents/1z3kmlvz69v6 [00:14:43] Seven Million Adobe...
Linux Exploits, Secure Credentials, Side-Channels and Election(SDK) hacking 21.10.2019 2:13:43
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube (@DAY[0]) [00:01:29] Sudo: CVE-2019-14287 [00:08:40] Buffer overflow in Realtek Wi-Fi chips [00:17:13] US Law Enforcement Traces Bitcoin Transfers to Nab ‘Largest’ Child Porn Site [00:39:45] Equifax Using admin:admin as Credentials for Sensitive Informatio...
When your errors have errors... 14.10.2019 1:48:40
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube [00:03:00] Critical Security Issue identified in iTerm2 as part of Mozilla Open Source Audit iTerm2 Patch [00:11:24] Windows Error Reporting Manager arbitrary file move Elevation of Privilege (CVE-2019-1315) James Forshaw A Link To The...
Exploits-galore iOS (checkm8), Android, Signal, Whatsapp, PHP and more 07.10.2019 1:50:55
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST) Or the video archive on Youtube [00:00:40] What happened while we were gone. ft. Defcon and Blackhat discussion [00:20:10] Checkm8 - iPhone bootROM exploit [00:28:52] iPhone A11 debug registers allow full-featured kernel debugging [00:32:52] Android: Use-After-Free in Binder driver https://grou...
Offensive Security's OSWE/AWAE, Massive Security failures, and a handful of cool attacks 27.05.2019 2:15:47
This will be our last episode until the fall, but once we are back you can catch the DAY[0] podcast on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec [00:00:50] This will be our last episode until the fall. [00:02:50] Thoughts on the Advanced Web Attacks and Exploitation (AWAE) Course, and the Offensive Security Web Expert (OSWE) certification [00:32:...
Intel has done it again, ft. Zombies, Cats, and Windows exploits 20.05.2019 1:44:51
Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec [00:01:55] Frida 12.5 Released [00:08:17] Damn Vulnerable Crypto Wallet [00:16:40] Thangry Cat: https://😾😾😾.fm/ [00:23:11] Micro-Architectural Data Sampling Attacks ZombieLoad RIDL paper Fallout paper Red Hat Overview Video [00:56:24] Update to Security Incident [May 17...
The Unhackable Morpheus chip and other exploit mitigations 13.05.2019 2:18:23
Watch the DAY[0] podcast live on Twitch every Monday afternoon at 12:00pm PST (3:00pm EST) -- https://www.twitch.tv/dayzerosec [00:00:30] Unhackable: New chip stops attacks before they start [00:15:00] DeepCheck: A Non-intrusive Control-flow Integrity Checking based... [00:25:54] Queue the Hardening Enhancements [00:50:18] For Cybersecurity, Computer Science Must Rely on Strong Types [00:57:43] A...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.