EPISODE · Oct 11, 2022 · 44 MIN
[bounty] Got UNIX Sockets and Some Filter Bypasses?
from Day[0] · host dayzerosec
No actual bounties this week, but we start off with a discussion on semgrep vs codeql, then get into some cool issues that you can start testing for. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/157.html [00:00:00] Introduction [00:00:39] Comparing Semgrep and CodeQL [00:14:27] A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX socket) [00:20:18] Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style [00:28:23] [OpenJDK] Weak Parsing Logic in java.net.InetAddress and Related Classes [00:34:22] RCE via Phar Deserialisation [CVE-2022-41343]
Embed this episode
NOW PLAYING
[bounty] Got UNIX Sockets and Some Filter Bypasses?
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.