- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
185 - Facebook Account Takeovers and a vBulletin RCE [Bug Bounty Podcast]
Is it possible to escalate a self-XSS into an account takeover? Perhaps, we take a look at some potential options by abusing single-sign on. Then we take a look at a few Facebook/Meta authentication issues, and a deserialization trick to increase the usable classes in PHP.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/185.html
[00:00:00] Introduction
[00:00:21] Single-Sign On Gadgets: Escalate (Self-)XSS to Account Takeover
[00:11:11] Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing
[00:14:00] DOM-XSS in Instant Games due to improper verification of supplied URLs
[00:18:55] Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
[00:29:33] Unserializable, but unreachable: Remote code execution on vBulletin
[00:34:54] Lexmark MC3224adwe RCE exploit
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
#BugBounty #BugHunting #InfoSec #Cyb43rSec #Podcast
Видео 185 - Facebook Account Takeovers and a vBulletin RCE [Bug Bounty Podcast] канала DAY[0]
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/185.html
[00:00:00] Introduction
[00:00:21] Single-Sign On Gadgets: Escalate (Self-)XSS to Account Takeover
[00:11:11] Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing
[00:14:00] DOM-XSS in Instant Games due to improper verification of supplied URLs
[00:18:55] Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
[00:29:33] Unserializable, but unreachable: Remote code execution on vBulletin
[00:34:54] Lexmark MC3224adwe RCE exploit
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
#BugBounty #BugHunting #InfoSec #Cyb43rSec #Podcast
Видео 185 - Facebook Account Takeovers and a vBulletin RCE [Bug Bounty Podcast] канала DAY[0]
Комментарии отсутствуют
Информация о видео
8 февраля 2023 г. 2:00:30
00:41:00
Другие видео канала

![095 - Discourse SNS RCE, a Stored XSS in GitLab, and a Reddit Race Condition [Bug Hunting Podcast]](https://i.ytimg.com/vi/2lBHvh0X42E/default.jpg)
![186 - An XNU Exploit and a Chrome Heap Overflow [Binary Exploitation Podcast]](https://i.ytimg.com/vi/gNahVSDSH1M/default.jpg)
![223 - Usurping Mastodon and Broken Signature Schemes [Bug Bounty Podcast]](https://i.ytimg.com/vi/VhCxOTJkBFs/default.jpg)


![233 - Spoofing Emails, PandoraFMS, and Keycloak [Bug Bounty Podcast]](https://i.ytimg.com/vi/KuIdZ70xEhU/default.jpg)
![195 - Stealing Secrets with Security Advisories and CorePlague [Bug Bounty Podcast]](https://i.ytimg.com/vi/clm2nYgk3oI/default.jpg)
![119 - Baby Monitor Bugs, Grafana, and Twitter De-anonymization [Bug Bounty Podcast]](https://i.ytimg.com/vi/-eRzqTguyoc/default.jpg)

![210 - TPMs and Baseband Bugs [Binary Exploitation Podcast]](https://i.ytimg.com/vi/OMqAb59cnCY/default.jpg)
![212 - Attacking VirtualBox and Malicious Chess [Binary Exploitation Podcast]](https://i.ytimg.com/vi/Qytii_mpqR4/default.jpg)
![181 - Cloud Bugs and More Vulns in Galaxy App Store [Bug Bounty Podcast]](https://i.ytimg.com/vi/gvbjSpWCp1A/default.jpg)
![106 - MediaTek, Yet Another Chrome Bug, and BigSig [Binary Exploitation Podcast]](https://i.ytimg.com/vi/bjzS-eBZIFY/default.jpg)


![220 - Windows Kernel Bugs, Safari Integer Underflow, and CONSTIFY [Binary Exploitation Podcast]](https://i.ytimg.com/vi/72E2ZePCrnQ/default.jpg)
![130 - Chrome Heap OOB Access and TLStorm [Binary Exploitation Podcast]](https://i.ytimg.com/vi/fQGz7cWLAqI/default.jpg)
![082 - NETGEAR smart switches, SpookJS, & Parallels Desktop [Binary Exploitation Podcast]](https://i.ytimg.com/vi/FIYxRfk8zzU/default.jpg)

![118 - Fastly Infoleak, Samba OOB Access, and Pwning MacOS [Binary Exploitation Podcast]](https://i.ytimg.com/vi/YKU3eDChD6c/default.jpg)