Sveriges mest populära poddar

Day[0]

Buggy Browsers, Heap Grooming, and Broken RSA?

68 min • 9 mars 2021

This week we get to take a look into some basic heap grooming techniques as we examine multiple heap overflows. We also briefly discuss the hand-on (by the DoD and Synack) assessment of the "unhackable" morpheus chip, and briefly discuss the new-ish paper claiming to defeat RSA.

[00:00:53] "This destroys the RSA cryptosystem." - Fast Factoring Integers by SVP Algorithms

  • https://eprint.iacr.org/2021/232

  • https://github.com/lducas/SchnorrGate

[00:06:55] DARPA pitted 500+ hackers against this computer chip. The chip won.

  • https://cse.engin.umich.edu/stories/morpheus-vs-everybody

  • https://www.reddit.com/r/HowToHack/comments/bl9qo3/morpheus_chip/empsclt/?context=10

[00:18:10] SaltStack API vulnerabilities

  • https://dozer.nz/posts/saltapi-vulns

  • https://github.com/saltstack/salt/blob/08fe46365f92583ea875f9e4a8b2cb5305b34e4b/salt/client/ssh/client.py#L72

[00:22:57] An Interesting Feature in the Samsung DSP Driver

  • https://www.synacktiv.com/en/publications/an-interesting-feature-in-the-samsung-dsp-driver.html

[00:30:50] Pre-Auth Remote Code Execution in VMware ESXi [CVE-2020-3992 CVE-2021-21974]

  • https://www.thezdi.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi

[00:39:05] Defeating the TP-Link AC1750

  • https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html

[00:44:52] Anatomy of an Exploit: RCE with CVE-2020-1350 SIGRed

  • https://www.graplsecurity.com/post/anatomy-of-an-exploit-rce-with-cve-2020-1350-sigred

[00:57:11] Yet another RenderFrameHostImpl UAF

  • https://microsoftedge.github.io/edgevr/posts/yet-another-uaf/

[01:03:16] Webkit AudioSourceProviderGStreamer use-after-free vulnerability

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1172

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)

Kategorier
Förekommer på
00:00 -00:00