- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
119 - Baby Monitor Bugs, Grafana, and Twitter De-anonymization [Bug Bounty Podcast]
CSRF lives again in the form of CORF, Cross-Origin Request Forgery with an attack against Grafana. We also take a look at some baby monitor issues and a de-anonymization attack against Twitter.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/baby-monitor-bugs-grafana-and-twitter-de-anonymization.html
[00:00:00] Introduction
[00:00:28] Cross-origin request forgery against Grafana [CVE-2022-21703]
[00:17:50] Vulnerabilities Identified in Nooie Baby Monitor
[00:26:47] [Twitter] Discoverability by phone number/email restriction bypass
[00:32:40] EarnHub Exploit - Post mortem
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
The audio-only version of the podcast is available on:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
#BugBounty #EthicalHacking #InfoSec #Podcast
Видео 119 - Baby Monitor Bugs, Grafana, and Twitter De-anonymization [Bug Bounty Podcast] канала DAY[0]
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/baby-monitor-bugs-grafana-and-twitter-de-anonymization.html
[00:00:00] Introduction
[00:00:28] Cross-origin request forgery against Grafana [CVE-2022-21703]
[00:17:50] Vulnerabilities Identified in Nooie Baby Monitor
[00:26:47] [Twitter] Discoverability by phone number/email restriction bypass
[00:32:40] EarnHub Exploit - Post mortem
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
The audio-only version of the podcast is available on:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
#BugBounty #EthicalHacking #InfoSec #Podcast
Видео 119 - Baby Monitor Bugs, Grafana, and Twitter De-anonymization [Bug Bounty Podcast] канала DAY[0]
Комментарии отсутствуют
Информация о видео
16 февраля 2022 г. 2:00:01
00:42:38
Другие видео канала

![095 - Discourse SNS RCE, a Stored XSS in GitLab, and a Reddit Race Condition [Bug Hunting Podcast]](https://i.ytimg.com/vi/2lBHvh0X42E/default.jpg)
![185 - Facebook Account Takeovers and a vBulletin RCE [Bug Bounty Podcast]](https://i.ytimg.com/vi/ref7zbeNGFo/default.jpg)
![186 - An XNU Exploit and a Chrome Heap Overflow [Binary Exploitation Podcast]](https://i.ytimg.com/vi/gNahVSDSH1M/default.jpg)
![223 - Usurping Mastodon and Broken Signature Schemes [Bug Bounty Podcast]](https://i.ytimg.com/vi/VhCxOTJkBFs/default.jpg)


![233 - Spoofing Emails, PandoraFMS, and Keycloak [Bug Bounty Podcast]](https://i.ytimg.com/vi/KuIdZ70xEhU/default.jpg)
![195 - Stealing Secrets with Security Advisories and CorePlague [Bug Bounty Podcast]](https://i.ytimg.com/vi/clm2nYgk3oI/default.jpg)

![210 - TPMs and Baseband Bugs [Binary Exploitation Podcast]](https://i.ytimg.com/vi/OMqAb59cnCY/default.jpg)
![212 - Attacking VirtualBox and Malicious Chess [Binary Exploitation Podcast]](https://i.ytimg.com/vi/Qytii_mpqR4/default.jpg)
![181 - Cloud Bugs and More Vulns in Galaxy App Store [Bug Bounty Podcast]](https://i.ytimg.com/vi/gvbjSpWCp1A/default.jpg)
![106 - MediaTek, Yet Another Chrome Bug, and BigSig [Binary Exploitation Podcast]](https://i.ytimg.com/vi/bjzS-eBZIFY/default.jpg)


![220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY [Binary Exploitation Podcast]](https://i.ytimg.com/vi/72E2ZePCrnQ/default.jpg)
![130 - Chrome Heap OOB Access and TLStorm [Binary Exploitation Podcast]](https://i.ytimg.com/vi/fQGz7cWLAqI/default.jpg)
![082 - NETGEAR smart switches, SpookJS, & Parallels Desktop [Binary Exploitation Podcast]](https://i.ytimg.com/vi/FIYxRfk8zzU/default.jpg)

![118 - Fastly Infoleak, Samba OOB Access, and Pwning MacOS [Binary Exploitation Podcast]](https://i.ytimg.com/vi/YKU3eDChD6c/default.jpg)