Day[0]

[bounty] Web3 Universal XSS, Breaking BitBucket, and WAF Bypasses


Listen Later

Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE.

Links and summaries are available at https://dayzerosec.com/podcast/153.html

[00:00:00] Introduction

[00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

[00:10:31] Breaking Bitbucket: Pre Auth Remote Command Execution [CVE-2022-36804]

[00:16:25] [Chrome] Sanitizer API bypass via prototype pollution

[00:23:02] How we Abused Repository Webhooks to Access Internal CI Systems at Scale

[00:35:03] WAF bypasses via 0days

[00:42:40] Cloning internal Google repos for fun and… info?

[00:43:19] How to turn security research into profit: a CL.0 case study

...more
View all episodesView all episodes
Download on the App Store

Day[0]By dayzerosec

  • 4
  • 4
  • 4
  • 4
  • 4

4

10 ratings


More shows like Day[0]

View all
Critical Thinking - Bug Bounty Podcast by Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Critical Thinking - Bug Bounty Podcast

56 Listeners