43 subscribers
Go offline with the Player FM app!
[binary] A Heap of Linux Bugs
Manage episode 385173537 series 2606557
Last week we brought you several Windows bugs, this week we are talking Linux kernel vulnerabilities and exploitation. We start off looking at a weird but cool CPU bug, Reptar, then we get into nftables, io_uring, and talk about a newer mitigations hitting Linux 6.6 that randomizes the caches allocations end up in.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/226.html
[00:00:00] Introduction
[00:00:21] Reptar
[00:11:56] One shot, Triple kill: Pwning all three Google kernelCTF instances with a single 1-day Linux vulnerability
[00:31:09] Conquering the memory through io_uring - Analysis of CVE-2023-2598
[00:38:00] Exploring Linux's New Random Kmalloc Caches
[00:48:09] ThinkstScapes Quarterly - 2023.Q3
[00:49:34] CacheWarp
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
282 episodes
Manage episode 385173537 series 2606557
Last week we brought you several Windows bugs, this week we are talking Linux kernel vulnerabilities and exploitation. We start off looking at a weird but cool CPU bug, Reptar, then we get into nftables, io_uring, and talk about a newer mitigations hitting Linux 6.6 that randomizes the caches allocations end up in.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/226.html
[00:00:00] Introduction
[00:00:21] Reptar
[00:11:56] One shot, Triple kill: Pwning all three Google kernelCTF instances with a single 1-day Linux vulnerability
[00:31:09] Conquering the memory through io_uring - Analysis of CVE-2023-2598
[00:38:00] Exploring Linux's New Random Kmalloc Caches
[00:48:09] ThinkstScapes Quarterly - 2023.Q3
[00:49:34] CacheWarp
The DAY[0] Podcast episodes are streamed live on Twitch twice a week:
-- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
-- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
We are also available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
282 episodes
All episodes
×
1 Mitigating Browser Hacking - Interview with John Carse (SquareX Field CISO) 1:46:57

1 Pulling Gemini Secrets and Windows HVPT 1:33:22

1 Session-ception and User Namespaces Strike Again 49:36

1 Extracting YouTube Creator Emails and Spilling Azure Secrets 44:04

1 ESP32 Backdoor Drama and SAML Auth Bypasses 1:14:08

1 Exploiting Xbox 360 Hypervisor and Microcode Hacking 1:19:05

1 Path Confusion and Mixing Public/Private Keys 59:34

1 ZDI's Triaging Troubles and LibreOffice Exploits 57:02

1 Recycling Exploits in MacOS and Pirating Audiobooks 1:17:06

1 Top 10 Web Hacking Techniques and Windows Shadow Stacks 1:12:42

1 Unicode Troubles, Bypassing CFG, and Racey Pointer Updates 41:29

1 Deanonymization with CloudFlare and Subaru's Security Woes 1:07:35
![Day[0] podcast artwork](/static/images/64pixel.png)
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Machine Learning Attacks and Tricky Null Bytes 45:07
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Linux Is Still a Mess and Vaultwarden Auth Issues 52:18
![Day[0] podcast artwork](/static/images/64pixel.png)
1 FortiJump Higher, Pishi, and Breaking Control Flow Flattening 1:00:38
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Static Analysis, LLMs, and In-The-Wild Exploit Chains 1:22:02
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Attacking Browser Extensions and CyberPanel 58:18
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Hardwear.IO NL, DEF CON 32, and Filesystem Exploitation 1:11:24
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Zendesk's Email Fiasco and Rooting Linux with a Lighter 50:26
![Day[0] podcast artwork](/static/images/64pixel.png)
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Attack of the CUPS and Exploiting Web Views via HSTS 1:08:09
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Future of the Windows Kernel and Encryption Nonce Reuse 33:52
![Day[0] podcast artwork](/static/images/64pixel.png)
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Memory Corruption: Best Tackled with Mitigations or Safe-Languages 58:23
![Day[0] podcast artwork](/static/images/64pixel.png)
1 [discussion] A Retrospective and Future Look Into DAY[0] 1:03:55
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.