EPISODE · Apr 6, 2023 · 43 MIN
[binary] A SNIProxy Bug and a Samsung NPU Double Free
from Day[0] · host dayzerosec
Just a few bugs this week, a classic buffer overflow because of an unbounded copy in SNIProxy. mast1c0re Part 2 with a few more easy vulnerability but some more complex and difficult exploitation. And a Samsung NPU in-the-wild double free. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/202.html [00:00:00] Introduction [00:00:24] Spot The Vuln - Operational Set [00:03:37] SNIProxy wildcard backend hosts buffer overflow vulnerability [00:08:17] mast1c0re Part 2 - Compiler Attack [00:21:46] Samsung NPU device driver double free in Android [CVE-2022-22265] [00:41:52] CodeQL zero to hero part 1: the fundamentals of static analysis for vulnerability research The DAY[0] Podcast episodes are streamed live on Twitch twice a week: -- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities -- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits. We are also available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec You can also join our discord: https://discord.gg/daTxTK9
What this episode covers
Just a few bugs this week, a classic buffer overflow because of an unbounded copy in SNIProxy. mast1c0re Part 2 with a few more easy vulnerability but some more complex and difficult exploitation. And a Samsung NPU in-the-wild double free. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/202.html [00:00:00] Introduction [00:00:24] Spot The Vuln - Operational Set [00:03:37] SNIProxy wildcard backend hosts buffer overflow vulnerability [00:08:17] mast1c0re Part 2 - Compiler Attack [00:21:46] Samsung NPU device driver double free in Android [CVE-2022-22265] [00:41:52] CodeQL zero to hero part 1: the fundamentals of static analysis for vulnerability research The DAY[0] Podcast episodes are streamed live on Twitch twice a week: -- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities -- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits. We are also available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec You can also join our discord: https://discord.gg/daTxTK9
NOW PLAYING
[binary] A SNIProxy Bug and a Samsung NPU Double Free
No transcript for this episode yet
Similar Episodes
Sep 22, 2023 ·20m
Sep 22, 2023 ·20m
Sep 22, 2023 ·27m
Sep 22, 2023 ·14m
Sep 22, 2023 ·24m
Sep 22, 2023 ·22m