dayzerosec
Day[0]
A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
[binary] i.MX Secure Boot Bypass and a Hancom Office Underflow 13.10.2022 36:09
Just a couple issues this week and a discussion about why you should look at old vulnerabilities and the pace exploit development advanced at. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/158.html [00:00:00] Introduction [00:00:26] Spot the Vuln - Authentic Token ... Fixed [00:05:42] Hancom Office 2020 Hword Docx XML parsing heap underflow vul...
[bounty] Got UNIX Sockets and Some Filter Bypasses? 11.10.2022 44:30
No actual bounties this week, but we start off with a discussion on semgrep vs codeql, then get into some cool issues that you can start testing for. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/157.html [00:00:00] Introduction [00:00:39] Comparing Semgrep and CodeQL [00:14:27] A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX soc...
[binary] Pwning Scoreboards, uClibC, and PS5 Exploitation 06.10.2022 42:33
Starting off with some discussion about XOM and CFI on the PS5 and how it impacts exploitation. Then into a uClibC issue, and hacking wireless scoreboards. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/156.html [00:00:00] Introduction [00:00:27] Spot the Vuln - Authentic Token [00:05:04] PS5-4.03-Kernel-Exploit: An experimental webkit-based ker...
[bounty] Akamai Cache Poisoning and a Chrome Universal XSS 04.10.2022 33:05
Had some varied issues this week, a file format allowing JScript for a $20,000 bounty, Akamai Cache Poisoning, Universal XSS in Chrome. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/155.html [00:00:00] Introduction [00:00:26] Two Lines of JScript for $20,000 [00:05:31] Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty...
[binary] SoCs with Holes, Crow HTTP Bugs, and Bypassing Intel CET 29.09.2022 53:49
Starting off with meme vulnerabilities in UNISOC BootROMs, and ending with a discussion about bypassing CFI/Intel CET and some fun issues in-between. Links and summaries are available at https://dayzerosec.com/podcast/154.html [00:00:00] Introduction [00:00:24] Spot the Vuln - You Put Where Where?! [00:04:05] There’s Another Hole In Your SoC: Unisoc ROM Vulnerabilities [00...
[bounty] Web3 Universal XSS, Breaking BitBucket, and WAF Bypasses 27.09.2022 45:17
Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE. Links and summaries are available at https://dayzerosec.com/podcast/153.html [00:00:00] Introduction [00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library [00:10:31] Breaking Bitbucket: Pre Auth Remote Comma...
[binary] An iOS Bug, Attacking Titan-M, and MTE Arrives 22.09.2022 1:15:31
This week we've got some summer highlights: the impact of MTE on Android, an iOS vuln and some primitive chaining in a Titan M exploit. Links and summaries of today's topics are available on our website: https://dayzerosec.com/podcast/an-ios-bug-attacking-titan-m-and-mte-arrives.html [00:01:17] Spot the Vuln - Easy Regex [00:03:53] Binary Ninja - 3.1 The Performance Release [00:...
[bounty] Reading GitLab Hidden HackerOne Reports and Golang Parameter Smuggling 20.09.2022 1:15:20
We are back at it, covering some write-ups and exploits we found interesting this summer. From browse-powered desyncs, to account take overs. Links are available on our website at: https://dayzerosec.com/podcast/reading-gitlab-hidden-hackerone-reports-and-golang-parameter-smuggling.html [00:02:17] Ridiculous vulnerability disclosure process with CrowdStrike Falc...
[binary] Fuchsia OS, Printer Bugs, and Hacking Radare2 02.06.2022 54:43
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/fuchsia-os-printer-bugs-and-hacking-radare2.html Some silly issues in radare2, some printer hacking, some kernel vulnerabilities, and a look at exploiting Fuchsia OS on this weeks episode. Just as a reminder this will be our last episode until September. [00:00:40] Spot the Vuln - Size Matters [00:0...
[bounty] A Zoom RCE, VMware Auth Bypass, and GitLab Stored XSS 31.05.2022 51:35
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-zoom-rce-vmware-auth-bypass-and-gitlab-stored-xss.html Last bounty episode before our summer vacation, and we are ending off with some cool issues. XML Stanza smuggling in Zoom for a MitM attack, an odd auth bypass, a Gitlab Stored XSS and gadget based CSP bypass, and an interesting technique to l...
[binary] Pwn2Own, Parallels Desktop, and an AppleAVD Bug 26.05.2022 34:29
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwn2own-parallels-desktop-and-an-appleavd-bug.html Just a couple vulnerabilities to talk about this week, but some interesting things to talk about in them. We also have some discussion about this year's pwn2own results and a couple things that caught out attention. [00:01:02] Spot the Vuln - NoSQL,...
[bounty] Stealing DropBox Google Drive Tokens, a GitLab Bug, and macOS "Powerdir" Vulnerability 24.05.2022 32:32
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/stealing-dropbox-google-drive-tokens-a-gitlab-bug-and-macos-powerdir-vulnerability.html Kicking off the week with some discussion about DOJ's policy change before getting into some vulnerabilities: "powerdir" a macOS TCC bypass, an integer overflow on the web, and another attack against HelloSign an...
[binary] Python 3 UAF and PS4/PS5 PPPoE Kernel Bug 19.05.2022 38:15
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/python-3-uaf-and-ps4-ps5-pppoe-kernel-bug.html We have a couple normally low-impact bugs in Solana rBPF this week netting a $200k bounty, a Python 2.7+ Use-After-Free and a PS4 and PS5 remote kernel heap overflow along with some discussion about exploitability and usability for a jailbreak. [00:00:4...
[bounty] Deleting Rubygems, BIG-IP Auth Bypass, and a Priceline Account Takeover 17.05.2022 34:23
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/yanking-rubygems-big-ip-auth-bypass-and-a-priceline-account-takeover.html A lot of cool little bugs this week with some solid impact, Facebook and Priceline account takeovers, F5 iControl Authentication Bypass, and a couple other logic bugs. [00:01:55] rubygems CVE-2022-29176 explained [00:06:09] Mu...
[binary] Pwn2Owning Routers and Anker Eufy Bugs 12.05.2022 30:40
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwn2owning-routers-and-anker-eufy-bugs.html Just a few vulnerabilities this week, but we have some codeql discussion as its used to find several vulnerabilities in Accel-PPP VPN server, and a look at a bug submitted to Pwn2Own 2021. [00:00:33] Spot the Vuln - Is It Clear [00:05:13] Anker Eufy Homeba...
[bounty] Cloudflare Pages, Hacking a Bank, and Attacking Price Oracles 10.05.2022 38:36
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/cloudflare-pages-hacking-a-bank-and-attacking-price-oracles.html Some interesting vulnerabilities this week from a Cloudflare Pages container escape chain, to hacking a bank's web application with some neat tricks to get abuse a file-write in a hardened envrionment, and even another dumb smart-contr...
[binary] NimbusPwn, a CLFS Vulnerability, and DatAFLow (Fuzzing) 05.05.2022 41:59
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/nimbuspwn-a-clfs-vulnerability-and-dataflow.html A few vulnerabilities from a TOCTOU to an arbitrary free, and some research into using data-flow in your fuzzing. [00:00:18] Spot the Vuln - Where's it At? [00:03:44] Nimbuspwn - A Linux Elevation of Privilege [00:08:38] Windows Common Log File System...
[bounty] XSS for NFTs, a VMWare Workspace ONE UEM SSRF, and GitLab CI Container Escape 03.05.2022 37:06
<p>Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/xss-for-nfts-a-vmware-workspace-one-uem-ssrf-and-gitlab-ci-container-escape.html</p> <p>Some straight forward bugs this week with some interesting discussion around cryptographic protocols (VMWare Workspace), XSS in the Web3 world, and whether container escapes into a low-privil...
[binary] Getting into Vulnerability Research and a FUSE use-after-free 28.04.2022 49:54
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/getting-into-vulnerability-research-and-a-fuse-use-after-free.html We are joined by Cts for a discussion about getting into vulnerability research and some thoughts about the higher-level bug hunting process, then a look at some black-box fuzzing of MS Defender for IoT and a FUSE use-after-free. [00...
[bounty] A Struts RCE, Broken Java ECDSA (Psychic Signatures) and a Bad Log4Shell Fix 26.04.2022 32:44
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-struts-rce-broken-java-ecdsa-psychic-signatures-and-a-bad-log4shell-fix.html An intresting mix of issues from crypto (Psychic Signatures), to a bad vulnerability patching service (patching log4shell), and bad logic leading to authentication bypassing and leaking sensitive keys. [00:00:24] Psychic...
[binary] Another iOS Bug and Edge Chakra Exploitation 21.04.2022 55:33
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/another-ios-bug-and-edge-chakra-exploitation.html A massive 11,000 byte overflow in WatchGuard, some discussion about lock-related vulnerabilities and analysis, and a look at a ChakraCore exploit dealing with all the mitigations (ASLR, DEP, CFG, ACG,CIG) [00:00:32] Spot the Vuln - The Global Query [...
[bounty] Taking Over an Internal AWS Service and an Interesting XSS Vector 19.04.2022 22:28
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/taking-over-an-internal-aws-service-and-an-interesting-xss-vector.html Short episode this week, looking at some relatively simple vulnerabilities ranging XSS, to leaking internal service credentials in AWS Relational Database Service by disabling validiation. [00:00:40] Git security vulnerability an...
[binary] A subtle iOS parsing bug and a PHP use-after-free 14.04.2022 54:55
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-subtle-ios-parsing-bug-and-a-php-use-after-free.html We dive into an ASN.1 parsing bug impacting iOS, and a PHP use-after-free to bypass disabled functions, ending the week with a discussion about whether or not its too late to get into this area of security. [00:00:29] Spot the Vuln - One HMAC at...
[bounty] A Double-Edged SSRF, Pritunl VPN LPE, and a NodeBB Vuln 12.04.2022 26:11
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-double-edged-ssrf-pritunl-vpn-lpe-and-a-nodebb-vuln.html Quick bounty episode this week with some request smuggling, abusing a SSRF for client-sided impact, a weird oauth flow, and a desktop VPN client LPE. [00:00:28] HTTP Request Smuggling on business.apple.com and Others. [00:06:25] Exploiting a...
[binary] FORCEDENTRY Sandbox Escape and NetFilter Bugs 07.04.2022 42:33
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/forcedentry-sandbox-escape-and-netfilter-bugs.html More information about the FORCEDENTRY exploit chain, and some Linux exploitation with a couple netfilter bugs. Ending the episode with some discussion about exploiting blind kernel read primitives from Microsoft. [00:00:28] Spot the Vuln - Adding E...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.