Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE.
Links and summaries are available at https://dayzerosec.com/podcast/153.html
[00:00:00] Introduction
[00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
[00:10:31] Breaking Bitbucket: Pre Auth Remote Command Execution [CVE-2022-36804]
[00:16:25] [Chrome] Sanitizer API bypass via prototype pollution
[00:23:02] How we Abused Repository Webhooks to Access Internal CI Systems at Scale
[00:35:03] WAF bypasses via 0days
[00:42:40] Cloning internal Google repos for fun and… info?
[00:43:19] How to turn security research into profit: a CL.0 case study
[bounty] Spring4Shell, PEAR Bugs, and GitLab Hardcoded Passwords
[binary] Pwning WD NAS, NetGear Routers, and Overflowing Kernel Pages
[bounty] GitLab Arbitrary File Read and Bypassing PHP's filter_var
[binary] Chrome Heap OOB Access and TLStorm
[bounty] DOMPDF XSS to RCE, Chrome Leaking Envrionment Vars, and cr8escape
[binary] A Windows UAF, Branch Prediction Bugs, and an io_uring Exploit
[bounty] Pascom RCE, AutoWarp, and a GKE Container Escape
[binary] Dirty Pipe and Analyzing Memory Tagging
[bounty] Facebook Exploits, pfSense RCE, and MySQLjs SQLi
[binary] ImageGear JPEG Vulns, NetFilter, and a LibCurl Memory Disclosure
[bounty] DynamicWeb RCE, VMWare Bugs, and Exploiting GitHub Actions
[binary] Zynq-7000 Secure Boot Bypass and Compiler-Created Bugs
[bounty] CoinDesk, Zabbix, and Leaking Secrets Through Mirrored Repos
[binary] Another Kernel TIPC Bug, MySQL, and Buggy Go
[bounty] Baby Monitor Bugs, Grafana, and Twitter De-anonymization
[binary] Fastly Infoleak, Samba OOB Access, and Pwning MacOS
[bounty] Hacking Google Drive Integrations and XSS Puzzles
[binary] PwnKit, a Win32k Type Confusion, and Binary Ninja 3.0
[bounty] Zoho Auth Bypass, a Bogus Bug, and Leaking Microsoft Bug Reports
[binary] NetUSB RCE, a Linux Kernel Heap Overflow, and an XNU Use-After-Free
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
A Prairie Home Companion: News from Lake Wobegon