Rust in the Web? A Special Guest and some Bad Crypto [Bounty Hunting]
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rust-in-the-web-a-special-guest-and-some-bad-crypto.html
We are joined by Bastian Gruber to start the episode with a discussion about Rust. Then we'll dive into a few interesting vulnerabilities this week including yet another ECDSA implementation issue and some header smuggling research.
[00:00:40] Rust Discussion with Bastian Gruber (Use the code poddayzero21 for 35% off Manning books)
[00:46:29] Arbitrary Signature Forgery in Stark Bank ECDSA Libraries [CVE-2021-43572, CVE-2021-43570, CVE-2021-43569, CVE-2021-43568, CVE-2021-43571]
[01:02:37] Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over
[01:06:52] Private Blog Content Disclosed in Atom Feed
[01:08:29] Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
[01:17:01] IDOR through MongoDB Object IDs Prediction
[01:18:45] History of Cross-Site History Leaking
The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:
The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Create your
podcast in
minutes
It is Free