Artwork

Content provided by dayzerosec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by dayzerosec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

BlackHat USA, Pre-Auth RCEs, and JSON Smuggling

1:09:44
 
Share
 

Manage episode 286382054 series 2606557
Content provided by dayzerosec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by dayzerosec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

This week we talk a bit about newly released Black Hat 2020 and NDSS 2021 presentation videos, before jumping into several pre-auth RCEs, and some interesting exploitation research to bring a PAC enforced Shadow Stack to ARM and an examination of JSON parser interoperability issues.

[00:00:41] Microsoft open sources CodeQL queries used to hunt for Solorigate activity

  • https://www.microsoft.com/security/blog/2021/02/25/microsoft-open-sources-codeql-queries-used-to-hunt-for-solorigate-activity/

  • https://github.com/github/codeql/pull/5083/commits/5e1e27c2b6b3429623b66531d4fe0b090e70638a

[00:04:16] Black Hat USA 2020

  • https://www.youtube.com/playlist?list=PLH15HpR5qRsXE_4kOSy_SXwFkFQre4AV_

  • https://www.youtube.com/c/NDSSSymposium/search?query=NDSS+2021

[00:13:56] Cookie poisoning leads to DOS and Privacy Violation

  • https://hackerone.com/reports/1067809

[00:16:37] Unauthorized RCE in VMware vCenter

  • https://swarm.ptsecurity.com/unauth-rce-vmware/

[00:20:01] A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server [CVE-2020-8625]

  • https://www.thezdi.com/blog/2021/2/24/cve-2020-8625-a-fifteen-year-old-rce-bug-returns-in-isc-bind-server

[00:25:42] Arbitrary File Write on packagecontrol.io (Sublime Text)

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2163

[00:30:31] [Uber] PreAuth RCE on Palo Alto GlobalProtect

  • https://hackerone.com/reports/540242

  • http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html

[00:35:26] The little bug that couldn't: Securing OpenSSL

  • https://github.blog/2021-02-25-the-little-bug-that-couldnt-securing-openssl/

[00:41:49] PACStack: an Authenticated Call Stack

  • https://www.usenix.org/conference/usenixsecurity21/presentation/liljestrand

[00:56:29] An Exploration of JSON Interoperability Vulnerabilities

  • https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities

[01:03:59] Top 10 web hacking techniques of 2020

  • https://portswigger.net/research/top-10-web-hacking-techniques-of-2020

[01:05:50] OST 2.0 Beta Spots Open

  • https://twitter.com/XenoKovah/status/1366224804639031299

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

  continue reading

253 episodes

Artwork
iconShare
 
Manage episode 286382054 series 2606557
Content provided by dayzerosec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by dayzerosec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

This week we talk a bit about newly released Black Hat 2020 and NDSS 2021 presentation videos, before jumping into several pre-auth RCEs, and some interesting exploitation research to bring a PAC enforced Shadow Stack to ARM and an examination of JSON parser interoperability issues.

[00:00:41] Microsoft open sources CodeQL queries used to hunt for Solorigate activity

  • https://www.microsoft.com/security/blog/2021/02/25/microsoft-open-sources-codeql-queries-used-to-hunt-for-solorigate-activity/

  • https://github.com/github/codeql/pull/5083/commits/5e1e27c2b6b3429623b66531d4fe0b090e70638a

[00:04:16] Black Hat USA 2020

  • https://www.youtube.com/playlist?list=PLH15HpR5qRsXE_4kOSy_SXwFkFQre4AV_

  • https://www.youtube.com/c/NDSSSymposium/search?query=NDSS+2021

[00:13:56] Cookie poisoning leads to DOS and Privacy Violation

  • https://hackerone.com/reports/1067809

[00:16:37] Unauthorized RCE in VMware vCenter

  • https://swarm.ptsecurity.com/unauth-rce-vmware/

[00:20:01] A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server [CVE-2020-8625]

  • https://www.thezdi.com/blog/2021/2/24/cve-2020-8625-a-fifteen-year-old-rce-bug-returns-in-isc-bind-server

[00:25:42] Arbitrary File Write on packagecontrol.io (Sublime Text)

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2163

[00:30:31] [Uber] PreAuth RCE on Palo Alto GlobalProtect

  • https://hackerone.com/reports/540242

  • http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html

[00:35:26] The little bug that couldn't: Securing OpenSSL

  • https://github.blog/2021-02-25-the-little-bug-that-couldnt-securing-openssl/

[00:41:49] PACStack: an Authenticated Call Stack

  • https://www.usenix.org/conference/usenixsecurity21/presentation/liljestrand

[00:56:29] An Exploration of JSON Interoperability Vulnerabilities

  • https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities

[01:03:59] Top 10 web hacking techniques of 2020

  • https://portswigger.net/research/top-10-web-hacking-techniques-of-2020

[01:05:50] OST 2.0 Beta Spots Open

  • https://twitter.com/XenoKovah/status/1366224804639031299

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

  continue reading

253 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide