Day[0]

Rust in the Web? A Special Guest and some Bad Crypto [Bounty Hunting]


Listen Later

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rust-in-the-web-a-special-guest-and-some-bad-crypto.html

We are joined by Bastian Gruber to start the episode with a discussion about Rust. Then we'll dive into a few interesting vulnerabilities this week including yet another ECDSA implementation issue and some header smuggling research.

[00:00:40] Rust Discussion with Bastian Gruber (Use the code poddayzero21 for 35% off Manning books)

[00:46:29] Arbitrary Signature Forgery in Stark Bank ECDSA Libraries [CVE-2021-43572, CVE-2021-43570, CVE-2021-43569, CVE-2021-43568, CVE-2021-43571]

[01:02:37] Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over

[01:06:52] Private Blog Content Disclosed in Atom Feed

[01:08:29] Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

[01:17:01] IDOR through MongoDB Object IDs Prediction

[01:18:45] History of Cross-Site History Leaking

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
  • The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

    You can also join our discord: https://discord.gg/daTxTK9

    Or follow us on Twitter (@dayzerosec) to know when new releases are coming.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Day[0]By dayzerosec

    • 4
    • 4
    • 4
    • 4
    • 4

    4

    10 ratings


    More shows like Day[0]

    View all
    Critical Thinking - Bug Bounty Podcast by Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

    Critical Thinking - Bug Bounty Podcast

    55 Listeners