In this bounty episode, some straightforward bugs were disclosed in GhostCMS and ClamAV, and Portswigger publishes their top 10 list of web hacking techniques from 2023.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/243.html
[00:00:00] Introduction
[00:02:15] Ghost CMS Stored XSS Leading to Owner Takeover [CVE-2024-23724]
[00:16:07] ClamAV Not So Calm [CVE-2024-20328]
[00:21:00] Top 10 web hacking techniques of 2023
[00:44:46] Hacking a Smart Home Device
[00:48:15] Cloud cryptography demystified: Amazon Web Services
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
[binary] A Huawei Hypervisor Vuln and More Memory Safety
[bounty] Remotely Controlling Hyundai and a League of Legends XSS
[binary] Patch Gaps and Apple Neural Engine Vulns
[bounty] Tailscale RCE, an SQLi in PAM360, and Exploiting Backstage
[binary] Hacking Pixel Bootloaders and Injecting Bugs
[bounty] Racing Grafana, Stealing Mastadon Passwords, and Cross-Site Tracing
[binary] Exploiting Undefined Behavior and a Chrome UAF
[bounty] Bypassing Pixel Lock Screens and Checkmk RCE
[binary] OpenSSL Off-by-One, Java XML Bugs, and an In-the-Wild Samsung Chain
[bounty] Apache Batik, Static Site Generators, and an Android App Vuln
[binary] XNU's kalloc_type, Stranger Strings, and a NetBSD Bug
[bounty] A Galaxy Store Bug, Facebook CSRF, and Google IDOR
[binary] Edge Vulns, a SHA-3 Overflow, and an io_uring Exploit
[bounty] XMPP Stanza Smuggling in Jabber and a Cobalt Strike RCE
[binary] Some Browser Exploitation and a Format String Bug?
[bounty] GitHub to GitLab RCE and a new PHP Supply Chain Attack
[binary] i.MX Secure Boot Bypass and a Hancom Office Underflow
[bounty] Got UNIX Sockets and Some Filter Bypasses?
[binary] Pwning Scoreboards, uClibC, and PS5 Exploitation
[bounty] Akamai Cache Poisoning and a Chrome Universal XSS
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
Lex Fridman Podcast