- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY [Binary Exploitation Podcast]
Diving right into some binary exploitation issues this week. Starting wtih a look at a rare sort of curl vulnerability where a malicious server could compromise a curl user. Then we take a look at a pretty straight-forward type confusion in Windows kernel code, and an integer underflow in Safari with some questionable exploitation. Ending the episode with some thoughts on how impactful grsecurity's "constify" mitigation could be.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/220.html
[00:00:00] Introduction
[00:00:14] How I made a heap overflow in curl
[00:17:32] Critically close to zero (day): Exploiting Microsoft Kernel streaming service
[00:30:34] Story of an innocent Apple Safari copyWithin gone (way) outside [CVE-2023-38600]
[00:38:10] CONSTIFY: Fast Defenses for New Exploits
[00:46:53] An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
[00:47:40] Getting RCE in Chrome with incomplete object initialization in the Maglev compiler
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
#ExploitDevelopment #BinaryExploitation #InfoSec #CyberSec #Podcast
Видео 220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY [Binary Exploitation Podcast] канала DAY[0]
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/220.html
[00:00:00] Introduction
[00:00:14] How I made a heap overflow in curl
[00:17:32] Critically close to zero (day): Exploiting Microsoft Kernel streaming service
[00:30:34] Story of an innocent Apple Safari copyWithin gone (way) outside [CVE-2023-38600]
[00:38:10] CONSTIFY: Fast Defenses for New Exploits
[00:46:53] An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
[00:47:40] Getting RCE in Chrome with incomplete object initialization in the Maglev compiler
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
#ExploitDevelopment #BinaryExploitation #InfoSec #CyberSec #Podcast
Видео 220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY [Binary Exploitation Podcast] канала DAY[0]
Комментарии отсутствуют
Информация о видео
24 октября 2023 г. 17:00:10
00:48:50
Другие видео канала

![095 - Discourse SNS RCE, a Stored XSS in GitLab, and a Reddit Race Condition [Bug Hunting Podcast]](https://i.ytimg.com/vi/2lBHvh0X42E/default.jpg)
![185 - Facebook Account Takeovers and a vBulletin RCE [Bug Bounty Podcast]](https://i.ytimg.com/vi/ref7zbeNGFo/default.jpg)
![186 - An XNU Exploit and a Chrome Heap Overflow [Binary Exploitation Podcast]](https://i.ytimg.com/vi/gNahVSDSH1M/default.jpg)
![223 - Usurping Mastodon and Broken Signature Schemes [Bug Bounty Podcast]](https://i.ytimg.com/vi/VhCxOTJkBFs/default.jpg)


![233 - Spoofing Emails, PandoraFMS, and Keycloak [Bug Bounty Podcast]](https://i.ytimg.com/vi/KuIdZ70xEhU/default.jpg)
![195 - Stealing Secrets with Security Advisories and CorePlague [Bug Bounty Podcast]](https://i.ytimg.com/vi/clm2nYgk3oI/default.jpg)
![119 - Baby Monitor Bugs, Grafana, and Twitter De-anonymization [Bug Bounty Podcast]](https://i.ytimg.com/vi/-eRzqTguyoc/default.jpg)

![210 - TPMs and Baseband Bugs [Binary Exploitation Podcast]](https://i.ytimg.com/vi/OMqAb59cnCY/default.jpg)
![212 - Attacking VirtualBox and Malicious Chess [Binary Exploitation Podcast]](https://i.ytimg.com/vi/Qytii_mpqR4/default.jpg)
![181 - Cloud Bugs and More Vulns in Galaxy App Store [Bug Bounty Podcast]](https://i.ytimg.com/vi/gvbjSpWCp1A/default.jpg)
![106 - MediaTek, Yet Another Chrome Bug, and BigSig [Binary Exploitation Podcast]](https://i.ytimg.com/vi/bjzS-eBZIFY/default.jpg)


![130 - Chrome Heap OOB Access and TLStorm [Binary Exploitation Podcast]](https://i.ytimg.com/vi/fQGz7cWLAqI/default.jpg)
![082 - NETGEAR smart switches, SpookJS, & Parallels Desktop [Binary Exploitation Podcast]](https://i.ytimg.com/vi/FIYxRfk8zzU/default.jpg)

![118 - Fastly Infoleak, Samba OOB Access, and Pwning MacOS [Binary Exploitation Podcast]](https://i.ytimg.com/vi/YKU3eDChD6c/default.jpg)