Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE.
Links and summaries are available at https://dayzerosec.com/podcast/153.html
[00:00:00] Introduction
[00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
[00:10:31] Breaking Bitbucket: Pre Auth Remote Command Execution [CVE-2022-36804]
[00:16:25] [Chrome] Sanitizer API bypass via prototype pollution
[00:23:02] How we Abused Repository Webhooks to Access Internal CI Systems at Scale
[00:35:03] WAF bypasses via 0days
[00:42:40] Cloning internal Google repos for fun and… info?
[00:43:19] How to turn security research into profit: a CL.0 case study
[binary] Hacking the DSi and some Fuzzing Tips
[bounty] ImageMagick, Cracking SmartLocks, and Broken OAuth
[binary] A GPU Bug and the World's Worst Fuzzer Findings
[bounty] Param Pollution in Golang, OpenEMR, and CRLF Injection
[binary] Fuzzing cURL, Netatalk, and an Emulator Escape
[bounty] Compromising Azure, Password Verification Fails, and Readline Crime
[binary] Rusty Kernel Bugs, mast1c0re, and OpenSSH
[bounty] Top 2022 Web Hacking Techniques and a Binance Bug
[binary] An XNU Exploit and a Chrome Heap Overflow
[bounty] Facebook Account Takeovers and a vBulletin RCE
[binary] KASAN comes to Windows and Shuffling ROP Gadgets
[bounty] CSS Injection and a Google Cloud Project Takeover Bug
[binary] Exploiting Null Derefs and Windows Type COM-fusion
[bounty] Cloud Bugs and More Vulns in Galaxy App Store
[binary] An iPod Nano Bug, XNU Vuln, and a WebKit UAF
[bounty] Client-Side Path Traversal and Hiding Your Entitlement(s)
[binary] Attacking Bhyves and a Kernel UAF
[bounty] Web Hackers vs. Cars and a Facebook Account Takeover
[binary] JS Type Confusions and Bringing Back Stack Attacks
[bounty] Pwn2Own Bugs and WAF Bypasses
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
A Prairie Home Companion: News from Lake Wobegon