Day[0]

[bounty] GitHub to GitLab RCE and a new PHP Supply Chain Attack


Listen Later

This week we look at a insecure deserialization (GitLab), argument injection (Packagist), and insecure string interpolation (Apache Commons Text)


Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/159.html


[00:00:00] Introduction

[00:01:01] New reward system to accelerate learning and growth on Detectify

[00:04:33] RCE via github import

[00:11:27] Securing Developer Tools: A New Supply Chain Attack on PHP

[00:17:32] FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive [CVE-2022-40684]

[00:23:08] Apache Commons Text Interpolation leading to potential RCE [CVE-2022-42889]


...more
View all episodesView all episodes
Download on the App Store

Day[0]By dayzerosec

  • 4
  • 4
  • 4
  • 4
  • 4

4

10 ratings


More shows like Day[0]

View all
Critical Thinking - Bug Bounty Podcast by Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Critical Thinking - Bug Bounty Podcast

56 Listeners