dayzerosec
Day[0]
A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
[bounty] Spring4Shell, PEAR Bugs, and GitLab Hardcoded Passwords 05.04.2022 1:02:10
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/spring4shell-pear-bugs-and-gitlab-hardcoded-passwords.html This week we have some fun with some bugs that really shouldn't have passed code-review, we of course talk about Spring4Shell/SpringShell and dive into the decade long history of that bug, and a bit of discussion about triaging more subtle b...
[binary] Pwning WD NAS, NetGear Routers, and Overflowing Kernel Pages 31.03.2022 32:23
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwning-wd-nas-netgear-routers-and-overflowing-kernel-pages.html Plenty of exploit strategy talk this week with vulnerabilities and complete exploits targeting a NAS, a router, and a Linux Kernel module with a page-level overflow. [00:00:26] Spot the Vuln - Normalized Regex [00:01:52] Remote Code Exe...
[bounty] GitLab Arbitrary File Read and Bypassing PHP's filter_var 29.03.2022 34:56
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/gitlab-arbitrary-file-read-and-bypassing-php-s-filter-var.html Some easy vulnerabilities this week, a directory traversal due to a bad regex, a simply yet somewhat mysterious authentication bypass, arbitrary file read in GitLab thanks to archives with symlinks, and a PHP filter_var bypass. [00:00:25...
[binary] Chrome Heap OOB Access and TLStorm 24.03.2022 33:14
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/chrome-heap-oob-access-and-tlstorm.html A few issues this week, a OOB access in chrome and in the Linux Kernel's Netfilter, and a few issues in Smart UPS devices. [00:00:17] Spot the Vuln - Where's My Token [00:03:21] Chrome: heap-buffer-overflow in chrome_pdf::PDFiumEngine::RequestThumbnail [00:06:...
[bounty] DOMPDF XSS to RCE, Chrome Leaking Envrionment Vars, and cr8escape 22.03.2022 39:41
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dompdf-xss-to-rce-chrome-leaking-envrionment-vars-and-cr8escape.html Several easy issues this week from leaking envrionment variables, to gaining host code execution and an XSS to RCE. [00:01:15] Chrome, Edge and Opera - System environment variables leak [CVE-2022-0337] [00:10:05] [Yoti] Pin Brutefo...
[binary] A Windows UAF, Branch Prediction Bugs, and an io_uring Exploit 17.03.2022 1:16:52
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-windows-uaf-branch-prediction-bugs-and-an-io-uring-exploit.html This time as we get side tracked with a couple discussions, first about security through obscurity, secondly about the nvidia leaks. We also have our usual mix of vulnerabilities this week, a cool exploit in the Linux kernel, a use-af...
[bounty] Pascom RCE, AutoWarp, and a GKE Container Escape 15.03.2022 33:16
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pascom-rce-autowarp-and-a-gke-container-escape.html We've got some cloud issues this week, in Azure Automation and GKE Autopilot along with a couple other interesting chains. [00:02:11] Pascom: The story of 3 bugs that lead to unauthed RCE [00:12:37] How I Made +$16,500 Hacking CDN Caching Servers -...
[binary] Dirty Pipe and Analyzing Memory Tagging 10.03.2022 46:51
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dirty-pipe-and-analyzing-memory-tagging.html No spot the vuln this week, but we do have a cool kernel bug, "Dirty Pipe", a look at a stack based overflow: BrokenPrint, and finally some discussion about memory tagging. [00:00:31] The Dirty Pipe Vulnerability [00:18:26] BrokenPrint: A Netgear stack ov...
[bounty] Facebook Exploits, pfSense RCE, and MySQLjs SQLi 08.03.2022 50:29
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/facebook-exploits-pfsense-rce-and-mysqljs-sqli.html A few interesting issues you this week, a JS race condition in some auth related code for Facebook, some fake prepared queries, and a RCE through sed commands (in pfSense) [00:00:56] Remote Code Execution in pfSense (2.5.2 and earlier) [00:06:13] F...
[binary] ImageGear JPEG Vulns, NetFilter, and a LibCurl Memory Disclosure 03.03.2022 26:05
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/imagegear-jpeg-vulns-netfilter-and-libcurl.html Quick episode with four somewhat simple bugs in JPEG parsing, a remote memory disclosure in libcurl due to the difference `sizeof(long)` on Linux vs Windows, and a heap out of bounds write in the Linux Kernel. [00:00:16] Spot the Vuln - One of a Kind [...
[bounty] DynamicWeb RCE, VMWare Bugs, and Exploiting GitHub Actions 01.03.2022 34:13
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/dynamicweb-rce-vmware-bugs-and-exploiting-github-actions.html Re-accessing the stup page, an unlikely scenario leaking Github Secrets, and a proxying issue in Carbon Black. [00:00:34] Logic Flaw Leading to RCE in Dynamicweb 9.5.0 - 9.12.7 [00:06:15] Stealing a few more GitHub Actions secrets [00:19:...
[binary] Zynq-7000 Secure Boot Bypass and Compiler-Created Bugs 24.02.2022 1:05:06
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/zynq-7000-secure-boot-bypass-and-compiler-created-bugs.html Just one vulnerability this week, a secure boot bypass, and some research into detecting compiler introduced bugs. Ending the week with a discussion about how to learn fuzzing. [00:00:58] Spot the Vuln - All Inclusive HMAC [00:03:47] Zynq-7...
[bounty] CoinDesk, Zabbix, and Leaking Secrets Through Mirrored Repos 22.02.2022 34:53
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/coindesk-zabbix-and-leaking-secrets-through-mirrored-repos.html Lets talk about "sidedoors" this week, with two vulnerabilities abusing alternative access points, along with an overly verbose error message that actually had some immediate impact, and a look at the challenges of client-sided session....
[binary] Another Kernel TIPC Bug, MySQL, and Buggy Go 17.02.2022 48:02
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/another-kernel-tipc-bug-mysql-and-buggy-go.html This week we discuss taint analysis and where to use it compared with fuzzing, a couple buggy code patterns in Go to be on the lookout for, and another remote stack-overflow in the Kernel TIPC module. [00:00:14] Spot the Vuln - How Much [00:03:11] Linu...
[bounty] Baby Monitor Bugs, Grafana, and Twitter De-anonymization 16.02.2022 42:37
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/baby-monitor-bugs-grafana-and-twitter-de-anonymization.html CSRF lives again in the form of CORF, Cross-Origin Request Forgery with an attack against Grafana. We also take a look at some baby monitor issues and a de-anonymization attack against Twitter. [00:00:28] Cross-origin request forgery agains...
[binary] Fastly Infoleak, Samba OOB Access, and Pwning MacOS 10.02.2022 52:42
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/fastly-infoleak-samba-oob-access-and-pwning-macos.html A discussion heavy episode this week as we speculate about how some XNU code passed muster, and how to exploit a small overflow and weaponizing a large info-leak. [00:00:17] Spot the Vuln - From Bits to Bytes [00:05:09] MacOS 12 Use After Free [...
[bounty] Hacking Google Drive Integrations and XSS Puzzles 08.02.2022 44:05
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/hacking-google-drive-integrations-and-xss-puzzles.html A "maybe" issue this week in Ruby's net/http library, some long chains leading to XSS, and a look at abusing parameter injection for SSRF in applications integrating with the Google Drive API. [00:00:26] [Ruby - net/http] HTTP Header Injection i...
[binary] PwnKit, a Win32k Type Confusion, and Binary Ninja 3.0 03.02.2022 48:05
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwnkit-a-win32k-type-confusion-and-binary-ninja-3-0.html Binary ninja 3.0 just dropped, lets talk about that, then into pwnkit and a couple kernel bugs, and ending this week off with a discussion about dealing with imposter syndrome. [00:00:18] Spot the Vuln - Maintain Order [00:03:52] Binary Ninja...
[bounty] Zoho Auth Bypass, a Bogus Bug, and Leaking Microsoft Bug Reports 01.02.2022 53:59
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/zoho-auth-bypass-a-bogus-bug-and-leaking-microsoft-bug-reports.html A few unique issues this week, routing issues in ManageEngine, a Little Snitch bypass, an undecodable characters leading to a denial of service. [00:00:37] CVE-2022-0329 and the problems with automated vulnerability management [00:1...
[binary] NetUSB RCE, a Linux Kernel Heap Overflow, and an XNU Use-After-Free 27.01.2022 50:52
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/netusb-rce-a-kernel-heap-overflow-an-xnu-uaf.html Integer overflows and underflow this week, covering vulns from desktop Zoom clients, to kernel and some routers. [00:00:19] Spot the Vuln - One Verified JWT, Please [00:03:27] Zooming in on Zero-click Exploits [00:12:18] Zooming in on Zero-click Expl...
[bounty] Bypassing Box MFA and Bad AES Key Generation 25.01.2022 33:25
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/bypassing-box-mfa-bad-aes-key-generation.html A new security-related humble bundle, MFA bypass in Box, and a a few older style vulnerabilities: lfi2rce, allow-list bypass with an @ sign, and insecure random number seeds. [00:00:37] Humble Book Bundle: Cybersecurity by Wiley [00:08:18] CWP CentOS Web...
[binary] Pwning Camera and Overflowing your Integers 20.01.2022 26:36
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/pwning-camera-and-overflowing-your-integers.html Short episode this week, stack smashing, integer overflowing and a more logical issue. Ending off with a discussion about what to do when you're stuck on CTFs. [00:00:42] Spot the Vuln - One at a Time [00:04:15] Uniview PreAuth RCE [00:06:59] Adobe Ac...
[bounty] Bad Code and Bad URLs 18.01.2022 36:49
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/bad-code-and-bad-urls.html This week is a shorter episode looking at some bad code in mermaid.js and Moodle's Shibboleth plugin, and a bit of research regarding URL parsing issues. [00:00:44] Orca Security Discovered Two AWS Vulnerabilities [00:06:44] Cross-Site Scripting (XSS) in mermaid.js [00:12:...
[Binary] Rooting Ubuntu By Accident and Samsung Kernel Bugs 13.01.2022 42:56
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rooting-ubuntu-by-accident-and-samsung-kernel-bugs.html We are back for the first 2022 binary episode, and its all kernel. Obtaining root through an hours long exploit process on Ubuntu thanks to an invalid free, use-after-free in XNU due to bad locking, and some terrible code in Samsung S20 DSP ker...
[Bounty] RocketChat RCE, Flickr, and a Critical Smart Contract Bug 11.01.2022 57:17
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rocketchat-rce-flickr-and-a-critical-smart-contract-bug.html More cases of developers make insecure assumptions and getting owned because of it. This week we've got a Flickr account takeover, escalating restricted SSRF into something more useful, and XSS to RCE in Rocket. Chat. [00:00:34] Rocket. Ch...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.