dayzerosec
Day[0]
A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
[bounty] CSS Injection and a Google Cloud Project Takeover Bug 31.01.2023 28:04
Starting off the week strong we have a CSS injection turned full-read SSRF, and a MyBB exploit chain from XSS to server-side code injection. And we've got a couple auth token disclosures to end off the episode. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/183.html [00:00:00] Introduction [00:00:22] Unleashing the power of CSS injection: The ac...
[binary] Exploiting Null Derefs and Windows Type COM-fusion 26.01.2023 51:04
Null-dereferences might not be too exploitable on a lot of systems, what about the handling of a null-dereference. We cover a great Project Zero post on the topic, then look at a type confusion in Windows COM, a Nintendo buffer overflow, and several memory corruptions in git, highlighting their unique primitives and potential exploitability. Links and vulnerability summaries for this episode are a...
[bounty] Cloud Bugs and More Vulns in Galaxy App Store 24.01.2023 29:49
We've got a cloud focused episode this week, starting with a logging bypass in AWS CloudTrail, a SSH Key injection, and cross-tenant data access in Azure Cognitive Search. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/181.html [00:00:00] Introduction [00:00:25] Undocumented API allows CloudTrail bypass [00:06:00] Multiple Vulnerabilities in the...
[binary] An iPod Nano Bug, XNU Vuln, and a WebKit UAF 19.01.2023 45:10
An Apple-focused episode this week, with a trivial iPod Nano BootRom exploit, and a WebKit Use-after-free. We also have a really cool XNU Virutal Memory bug, strictly a race condition and a logic differential between two alternate paths resulting in bypassing copy-on-write protection. We also handle a few questions from chat, how much reverse engineering is necessary for vuln research, how much pr...
[bounty] Client-Side Path Traversal and Hiding Your Entitlement(s) 17.01.2023 48:47
This week kicks off with another look at client-side path traversal attacks, this time with some more case-studies. Then we get into some mobile issues, one a cool desync between DER processors resulting in an iOS privilege escalation. The other a Bundle processing issue in Android that provides an almost use-after-free like primitive but in Java. Links and vulnerability summaries for this episode...
[binary] Attacking Bhyves and a Kernel UAF 12.01.2023 46:55
Just a few issues this week, but some solid exploitation. A Kernel UAF, IoT, and a bhyve escape. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/178.html [00:00:00] Introduction [00:00:35] Spot the Vuln - Internal Externals [00:06:35] Escaping from bhyve [00:13:14] Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg [00:29:28] Meshy...
[bounty] Web Hackers vs. Cars and a Facebook Account Takeover 10.01.2023 1:02:33
First episode of the new year, and we've got some cool stuff. Several authentication issues and "class pollution" in Python. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/177.html [00:00:00] Introduction [00:00:31] ReDoS "vulnerabilities" and misaligned incentives [00:17:14] Web Hackers vs. The Auto Industry [00:37:19] Prototype Pollution in Py...
[binary] JS Type Confusions and Bringing Back Stack Attacks 15.12.2022 40:02
In this episode, we discuss the discovery of a type confusion in Internet Explorer's JScript. We also explore a fun exploit strategy for a low-level memory management bug in the Linux kernel and delve into several issues in Huawei's Secure Monitor that enable code execution in the secure world. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/176....
[bounty] Pwn2Own Bugs and WAF Bypasses 13.12.2022 1:00:30
Is Pwn2Own worth it for bug bounty hunters? A handful of trivial command injections, and some awesome WAF bypasses. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/175.html [00:00:00] Introduction [00:00:34] Pwn2Own Toronto 2022 - Results [00:10:31] Cool vulns don't live long - Netgear and Pwn2Own [00:15:03] The Last Breath of Our Netgear RAX30 B...
[binary] A Huawei Hypervisor Vuln and More Memory Safety 08.12.2022 47:30
Will AI be your next vuln research assistant? ... Maybe? We also talk about a stack-based overflow in `ping` and a Huawei hypervisor vuln. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/174.html [00:00:00] Introduction [00:00:41] Spot the Vuln - A Nice Choice [00:03:49] ChatGPT - AI for Vuln Research? [00:21:46] Memory Safe Languages in Android...
[bounty] Remotely Controlling Hyundai and a League of Legends XSS 06.12.2022 42:40
A variety of issues this week, DOM Clobbering, argument injection, a filesystem race condition, cross-site scripting, and a normalization-based auth bypass. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/173.html [00:00:00] Introduction [00:00:41] Humble Tech Book Bundle: The Art of Hacking by No Starch Press [00:03:23] Hijacking service workers...
[binary] Patch Gaps and Apple Neural Engine Vulns 01.12.2022 43:49
The end of kASLR bypasses? Probably just click-bait, but the patch gap is real and we discuss that a bit before getting into a couple AI-based corruptions. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/172.html [00:00:00] Introduction [00:01:15] Spot the Vuln - Escape [00:06:00] Humble Tech Book Bundle: The Art of Hacking by No Starch Press [00...
[bounty] Tailscale RCE, an SQLi in PAM360, and Exploiting Backstage 29.11.2022 44:32
Some RCE chains starting with DNS rebinding, always fun to see, a fairly basic SQL injection, and a JS sandbox escape for RCE in Spotify. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/171.html [00:00:00] Introduction [00:00:38] RCE in Tailscale, DNS Rebinding, and You [CVE-2022-41924] [00:17:55] SQL Injection in ManageEngine Privileged Access M...
[binary] Hacking Pixel Bootloaders and Injecting Bugs 24.11.2022 48:19
A hardware heavy episode as we talk about two read protection bypasses, Pixel 6 bootloader exploitation and benchmarking fuzzers. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/170.html [00:00:00] Introduction [00:00:26] Spot the Vuln - Do More [00:05:04] Pixel6 Bootloader Exploitation [00:16:41] NXP i. MX SDP_READ_DISABLE Fuse Bypass [CVE-2022-...
[bounty] Racing Grafana, Stealing Mastadon Passwords, and Cross-Site Tracing 22.11.2022 30:47
This week has the return of cross-site tracing, HTML injection, a golang specific vulnerable code pattern, and a fun case-sensitivity auth bypass. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/169.html [00:00:00] Introduction [00:01:02] A Confused Deputy Vulnerability in AWS AppSync [00:07:05] Grafana Race Condition Leading to Potential Authent...
[binary] Exploiting Undefined Behavior and a Chrome UAF 17.11.2022 27:16
Is the compiler make exploitation easier, these divergent representations seem to do so. We also look at a chrome UAF and a double stack overflow. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/168.html [00:00:00] Introduction [00:00:52] Spot the Vuln - The Right Start [00:03:25] Look out! Divergent representations are everywhere! [00:12:18] &nb...
[bounty] Bypassing Pixel Lock Screens and Checkmk RCE 15.11.2022 1:01:17
A Pixel Lockscreen bypass and some discussion about dupes in bug bounty, then a long RCE chain, and a look at client-side path traversals. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/167.html [00:00:00] Introduction [00:00:48] Accidental $70k Google Pixel Lock Screen Bypass [00:23:28] Discovering vendor-specific vulnerabilities in Android [00...
[binary] OpenSSL Off-by-One, Java XML Bugs, and an In-the-Wild Samsung Chain 10.11.2022 1:00:40
A lot of discussion about the OpenSSL vulnerability, fuzzing and exploitation. Then into a RCE in XML Signature verification, and a Samsung exploit chain. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/166.html [00:00:00] Introduction [00:00:35] Spot the Vuln - Spaced Out [00:03:29] OpenSSL punycode vulnerability [CVE-2022-3602] [00:35:43] Grego...
[bounty] Apache Batik, Static Site Generators, and an Android App Vuln 08.11.2022 48:29
Several slightly weird issues this week, a reentrancy attack abusing a read-only function, SSRF and XSS through a statically generated website and others. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/165.html [00:00:00] Introduction [00:01:10] Vulnerabilities in Apache Batik Default Security Controls - SSRF and RCE Through Remote Class Loading...
[binary] XNU's kalloc_type, Stranger Strings, and a NetBSD Bug 03.11.2022 46:58
Kicking off the week with a look at Apple's new security blog and the kalloc_type introduced into XNU, then a mix of issues including an overflow in SQLite. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/164.html [00:00:00] Introduction [00:00:24] Spot the Vuln - Right Code, Wrong Place [00:03:05] Hexacon Talks are Available [00:04:56] Towards t...
[bounty] A Galaxy Store Bug, Facebook CSRF, and Google IDOR 01.11.2022 28:40
Several simple bugs with significant impacts, XSS to being able to install apps, CSRFing via a Captcha, and a Google IDOR. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/163.html [00:00:00] Introduction [00:00:29] Defcon Talks are Available [00:03:10] Galaxy Store Applications Installation/Launching without User Interaction [00:08:49] Facebook S...
[binary] Edge Vulns, a SHA-3 Overflow, and an io_uring Exploit 27.10.2022 38:31
A few issues this week, including an overflow in SHA-3, yet another io_uring bug, and multiple (questionably exploitable) corruptions in Edge. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/162.html [00:00:00] Introduction [00:00:23] Spot the Vuln - Tricky Notes [00:04:04] Memory corruption vulnerabilities in Edge [00:15:19] SHA-3 Buffer Overflo...
[bounty] XMPP Stanza Smuggling in Jabber and a Cobalt Strike RCE 25.10.2022 40:46
Several fun issues this week, from a Cobalt Strike RCE, a couple auth bypasses, and stanza smuggling in Jabber. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/161.html [00:00:00] Introduction [00:00:28] Sophos Firewall User Portal and Web Admin Code Injection [CVE-2022-3236] [00:07:05] [Cisco Jabber] XMPP Stanza Smuggling with stream:stream tag...
[binary] Some Browser Exploitation and a Format String Bug? 20.10.2022 43:47
We've got a few interesting vulns, a blind format string attack, Windows kernel int overflow, and a browser exploit (unchecked bounds after lowering). Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/160.html [00:00:00] Introduction [00:00:24] Spot the Vuln - Chat Configuration [00:02:06] CCC Cancelled [00:07:53] Hacking TMNF: Part 2 - Exploiting...
[bounty] GitHub to GitLab RCE and a new PHP Supply Chain Attack 18.10.2022 25:37
This week we look at a insecure deserialization (GitLab), argument injection (Packagist), and insecure string interpolation (Apache Commons Text) Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/159.html [00:00:00] Introduction [00:01:01] New reward system to accelerate learning and growth on Detectify [00:04:33] RCE via github import [00:11:27] S...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.