VirtualBox has a very buggy driver, PostgreSQL has an Out of Bounds Access, and lifetime issues are demonstrated in Rust in "safe" code.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/246.html
[00:00:00] Introduction
[00:00:22] cve-rs
[00:18:28] Oracle VM VirtualBox: Intra-Object Out-Of-Bounds Write in virtioNetR3CtrlVlan
[00:32:30] PostgreSQL: Array Set Element Memory Corruption
[00:35:06] Analyzing the Google Chrome V8 CVE-2024-0517 Out-of-Bounds Code Execution Vulnerability
[00:37:15] Continuously fuzzing Python C extensions
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
[binary] Hacking the DSi and some Fuzzing Tips
[bounty] ImageMagick, Cracking SmartLocks, and Broken OAuth
[binary] A GPU Bug and the World's Worst Fuzzer Findings
[bounty] Param Pollution in Golang, OpenEMR, and CRLF Injection
[binary] Fuzzing cURL, Netatalk, and an Emulator Escape
[bounty] Compromising Azure, Password Verification Fails, and Readline Crime
[binary] Rusty Kernel Bugs, mast1c0re, and OpenSSH
[bounty] Top 2022 Web Hacking Techniques and a Binance Bug
[binary] An XNU Exploit and a Chrome Heap Overflow
[bounty] Facebook Account Takeovers and a vBulletin RCE
[binary] KASAN comes to Windows and Shuffling ROP Gadgets
[bounty] CSS Injection and a Google Cloud Project Takeover Bug
[binary] Exploiting Null Derefs and Windows Type COM-fusion
[bounty] Cloud Bugs and More Vulns in Galaxy App Store
[binary] An iPod Nano Bug, XNU Vuln, and a WebKit UAF
[bounty] Client-Side Path Traversal and Hiding Your Entitlement(s)
[binary] Attacking Bhyves and a Kernel UAF
[bounty] Web Hackers vs. Cars and a Facebook Account Takeover
[binary] JS Type Confusions and Bringing Back Stack Attacks
[bounty] Pwn2Own Bugs and WAF Bypasses
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
Lex Fridman Podcast