dayzerosec
Day[0]
A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
[binary] A Timing Side-Channel for Kernel Exploitation and VR in the wake of Rust 04.05.2023 42:01
Not a lot of interesting binary exploitation topics for this week, we've got a DHCPv6 service vuln, and a fun idea to use a timing side-channel to improve exploit stability. Then we end with a discussion about Rust coming the Windows operating system, what Rust means for the future of exploit development and vulnerability research and the value of memory corruption in Windows. Links and vulner...
[bounty] Git Config Injection and a Sophos Pre-Auth RCE 02.05.2023 39:20
On this weeks bug bounty podcast we take a look at a few interesting issues. While they are all patched, there is reason to believe they'd all creep up in other applications too. First up is an RCE due to nested use of an escaped string. Second a fgets loop that doesn't account for long lines. A XML signature verification tool with a deceptive interface, and last a look at how Bash's p...
[binary] A Ghostscript RCE and a Windows Registry Bug 27.04.2023 38:39
This week's binary exploitation episode has some pretty solid bugs. A string escaping routine that goes out of bounds, a web-based information disclosure. And a couple kernel issues, one in the Windows registry, a logical bug leading to memory corruption, and an AppleSPU out of bounds access. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/20...
[bounty] SecurePoint UTM, Chfn, and Docker Named Pipe Vulns 25.04.2023 37:44
For this week's bug bounty podcast We start off with a bit of a unique auth bypass in a firewall admin panel. We've also got a couple desktop-based software bugs, with a Docker Desktop privilege escalation on windows, and a chfn bug. We've also got a couple escalation techniques, one for Azure environments, and another trick for exploiting semi-controlled file-writes. Links and vulnera...
[binary] Glitching the Wii-U and Integer Overflows 13.04.2023 53:31
We start with a hardware/glitching attack against the Wii U, then lets talk about integer overflows. We've got three integer overflows this week that lead to buffer overflows in different ways. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/204.html [00:00:00] Introduction [00:00:19] Spot the Vuln - Easy as ABC [00:06:18] de_Fuse, the One Tr...
[bounty] Pentaho Pre-Auth RCE and Theft by CAN Injection 11.04.2023 31:50
Some fun issues this week as we explore code execution in Synthetics Recorder stemming from a comment in the code. An auth bypass in Pentaho leading to RCE via SSTI, car theft via CAN bus message injection, and how to become a cluster admin from a compromised pod in AWK Elastic Kubernetes Service. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/2...
[binary] A SNIProxy Bug and a Samsung NPU Double Free 06.04.2023 43:16
Just a few bugs this week, a classic buffer overflow because of an unbounded copy in SNIProxy. mast1c0re Part 2 with a few more easy vulnerability but some more complex and difficult exploitation. And a Samsung NPU in-the-wild double free. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/202.html [00:00:00] Introduction [00:00:24] Spot The Vuln -...
[bounty] Bamboozling Bing and a Curl Gotcha 04.04.2023 44:18
Some audio issues this week, sorry for the ShareX sound. But we have a few interesting issues. A curl quirk that it might be useful to be aware of, Azure Pipelines vulnerability abusing attacker controlled logging. A look at a pretty classic Android/mobile bug, and a crazy auth misconfiguration (BingBang). Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/...
[binary] 200th Episode! Integer Bugs & Synthetic Memory Protections 30.03.2023 1:08:19
Its our 200th episode, and we've got some stats from our first 200 episodes. Then we talk some Pwn2Own policy changes, a couple memeable overflows, and some new anti-ROP mitigations on OpenBSD. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/200.html [00:00:00] Introduction [00:00:52] Spot the Vuln - Just a Coupon [00:04:56] 200th Episode [00...
[bounty] Bypassing CloudTrail and Tricking GPTs 28.03.2023 51:07
We are back with more discussion about applying AI/ChatGPT to security research, but before that we have a few interesting vulnerabilities. An OTP implementation that is too complex for its own good, a directory traversal leading to a guest to host VM escape, and server-side mime-sniffing. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/199.html...
[binary] TOCTOUs in Intel SMM and Shannon Baseband Bugs 23.03.2023 44:49
We've got a pretty nice root/super-use check bypass in XNU this week, and a sort of double fetch issue in Intel's SMM leading to a potential privilege escalation into the Management system. We've also got a few meme-able Shannon Baseband issues and some tough to exploit out of bound reads in MIT Kerberos V5. Links and vulnerability summaries for this episode are available at: https://d...
[bounty] Popping Azure Web Services and Apollo Config Bugs 21.03.2023 41:38
Recovering data from a cropped image (thanks to an undocumented API change, bypassing an origin check with an emoji, and a trivial SSRF filter bypass all in this week's bug bounty podcast. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/197.html [00:00:00] Introduction [00:00:32] SSRF Cross Protocol Redirect Bypass [00:08:08] EmojiDeploy: Smi...
[binary] An OpenBSD overflow and TPM bugs 16.03.2023 41:14
Some simple, but interesting vulnerabilities. A use-after-free because of wrong operation ordering, an interesting type confusion, an integer underflow and some OOB access in TPM 2.0 reference code. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/196.html [00:00:00] Introduction [00:00:27] Spot the Vuln - Just be Positive [00:03:42] oss-sec: Linu...
[bounty] Stealing Secrets with Security Advisories and CorePlague 14.03.2023 30:51
A few varied issues this week, exploiting an apparently unexploitable CRLF injection, organization secrets exposure in GitHub, and a Jenkins XSS. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/195.html [00:00:00] Introduction [00:00:25] Abusing Hop-by-Hop Header to Chain A CRLF Injection Vulnerability [00:04:26] HubSpot Full Account Takeover in...
[binary] Hacking the DSi and some Fuzzing Tips 09.03.2023 33:36
Just one vulnerability this week about hacking the Nintendo DSi browser, but we have a good discussion about fuzzing and a new paper "autofz". Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/194.html [00:00:00] Introduction [00:00:27] Spot the Vuln - Checking your Numbers [00:03:23] autofz: Automated Fuzzer Composition at Runtime [00:14:52] Alex...
[bounty] ImageMagick, Cracking SmartLocks, and Broken OAuth 07.03.2023 41:02
This episode covers a lot of ground, from an insecure OAuth flow (Booking.com) to a crazy JSON injection and fail-open login system (DataHub) to hacking Bluetooth smart locks (Megafeis-palm). And even a new ImageMagick trick for a local file read. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/193.html [00:00:00] Introduction [00:00:26] Travelin...
[binary] A GPU Bug and the World's Worst Fuzzer Findings 02.03.2023 28:56
Just a couple issues this week, a cache coherency issue because the functions used to flush changes were not implemented on AARCH64. The second was using the "world's worst fuzzer" to find some bugs. Dumb fuzzer, but it worked. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/192.html [00:00:00] Introduction [00:00:24] Spot the Vuln - Targeting [0...
[bounty] Param Pollution in Golang, OpenEMR, and CRLF Injection 28.02.2023 38:06
Parameter pollution for an auth bypass, SQL injection in an ORM, CRLF injection for a WAF bypass...this episode has a great mix of issues. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/191.html [00:00:00] Introduction [00:00:26] OpenEMR - Remote Code Execution in your Healthcare System [00:10:13] Vulnerability write-up - "Dangerous assumptions"...
[binary] Fuzzing cURL, Netatalk, and an Emulator Escape 23.02.2023 40:11
This week we talk about more Rust pitfalls, and fuzzing cURL. Then we have a couple bugs, one involving messing with the TCP stack to reach the vulnerable condition. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/190.html [00:00:00] Introduction [00:00:27] Spot the Vuln - Insecure by Default [00:02:20] cURL audit: How a joke led to significant f...
[bounty] Compromising Azure, Password Verification Fails, and Readline Crime 21.02.2023 32:41
A variety episode this week with some bad cryptography in PHP and Azure, information disclosure in suid binaries, request smuggling in HAProxy, and some research on testing for server-side prototype pollution. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/189.html [00:00:00] Introduction [00:00:22] PHP :: Sec Bug #81744 :: Password_verify() alw...
[binary] Rusty Kernel Bugs, mast1c0re, and OpenSSH 16.02.2023 45:29
Few discussions this week, from using ASAN for effectively, to vulnerabilities in Rust code, and some discussion about exploiting the OpenSSH double free. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/188.html [00:00:00] Introduction [00:00:31] Spot the Vuln - Too Soft [00:04:19] One Weird Trick to Improve Bug Finding With ASAN [00:08:27] Rustp...
[bounty] Top 2022 Web Hacking Techniques and a Binance Bug 14.02.2023 31:21
Bit slow this week, so we talk about the Top Web-hacking techniques of 2022, and some TruffleSec/XSS Hunter drama before so we cover a blockchain verification bug, and a simple path traversal to SSTI and RCE chain. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/187.html [00:00:00] Introduction [00:00:32] Top 10 web hacking techniques of 2022 [00...
[binary] An XNU Exploit and a Chrome Heap Overflow 09.02.2023 33:02
First, we take a look at some positive changes to OSS Fuzz, then we dive into some vulnerabilities. This includes an XNU heap out-of-bounds write vulnerability, a Chrome heap-based overflow vulnerability, and an out-of-bounds read in cmark-gfm that, while probably not exploitable, is still intriguing. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podca...
[bounty] Facebook Account Takeovers and a vBulletin RCE 07.02.2023 40:59
Is it possible to escalate a self-XSS into an account takeover? Perhaps, we take a look at some potential options by abusing single-sign on. Then we take a look at a few Facebook/Meta authentication issues, and a deserialization trick to increase the usable classes in PHP. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/185.html [00:00:00] Introd...
[binary] KASAN comes to Windows and Shuffling ROP Gadgets 02.02.2023 41:17
Discussion heavy episode this week, talking about KASAN landing on Windows, shuffling gadgets to make ROP harder, and a paper about automatic exploit primitive discovery. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/184.html [00:00:00] Introduction [00:00:26] Spot the Vuln - Just the Data [00:04:20] Introducing kernel sanitizers on Microsoft p...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.