Day[0]

[bounty] Got UNIX Sockets and Some Filter Bypasses?


Listen Later

No actual bounties this week, but we start off with a discussion on semgrep vs codeql, then get into some cool issues that you can start testing for.


Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/157.html


[00:00:00] Introduction

[00:00:39] Comparing Semgrep and CodeQL

[00:14:27] A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX socket)

[00:20:18] Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style

[00:28:23] [OpenJDK] Weak Parsing Logic in java.net.InetAddress and Related Classes

[00:34:22] RCE via Phar Deserialisation [CVE-2022-41343]


...more
View all episodesView all episodes
Download on the App Store

Day[0]By dayzerosec

  • 4
  • 4
  • 4
  • 4
  • 4

4

10 ratings


More shows like Day[0]

View all
Critical Thinking - Bug Bounty Podcast by Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Critical Thinking - Bug Bounty Podcast

56 Listeners