Share Security Explained
Share to email
Share to Facebook
Share to X
By Chris Grayson, Drew Porter, Logan Lamb
4.9
1818 ratings
The podcast currently has 49 episodes available.
In recent days we've heard whistleblower testimony from Peiter Zatko (aka Mudge) alleging some pretty serious security problems at Twitter. This comes at a fairly opportune time given Elon Musk's interest in buying the company and subsequent cold feet due to Twitter's "bot problem."
For the uninitiated, Mudge is a long-time hacker (an "OG" you could say) that has a reputation of being someone that can "speak truth to power." While we're skeptical of the timing too, the material content of Mudge's report should raise some serious eyebrows. Join us as we dig into the ins and outs of the report and talk a bit more about Mudge and why this report should be taken seriously.
- https://s3.documentcloud.org/documents/22186683/twitter-whistleblower-disclosure.pdf
- https://www.npr.org/2022/09/13/1122671582/twitter-whistleblower-mudge-senate-hearing
Welcome back for our FIFTH season :)
So it turns out that Uber got hacked... and it looks to be bad. Hats off to their PR team for the job they've done keeping things quiet since. We go over the ins and outs of what we know so far and touch on the status of our DEF CON recordings too!
Here's to our best season yet!
- https://twitter.com/BillDemirkapi/status/1570602097640607744
- https://twitter.com/MalwareTechBlog/status/1570600059909345280
- https://techcrunch.com/2022/09/26/london-police-arrest-uber-rockstar/
- https://blog.avast.com/uber-hack#
It's the last episode of our fourth season! The security gods were kind to us and gave us a softball with some exploits that are in the news recently; code execution in Confluence and a new ms-msdt code execution exploit in Windows. Lastly, we talk about preparations for DEF CON (we hope to see you there)!
We've loved his journey so far and are so thankful to have you all as listeners. Come say hi at DEF CON and grab a beer with us.
- Windows ms-msdt PoC - https://gist.github.com/tothi/66290a42896a97920055e50128c9f040
- Confluence OGNL Injection PoC - https://github.com/Nwqda/CVE-2022-26134
We directly address the question of how hacking actually works by going through some of the underlying issues that contribute to a hack, tell hacking stories, then wrap up with a very brief explanation of the differences with state sponsored hacking!
https://xkcd.com/327/ - Little Bobby Tables
https://www.saleae.com/ - Example Logic Analyzer
The podcast currently has 49 episodes available.
600 Listeners
8 Listeners