cover of episode Rust in the Web? A Special Guest and some Bad Crypto [Bounty Hunting]

Rust in the Web? A Special Guest and some Bad Crypto [Bounty Hunting]

2021/11/16
logo of podcast Day[0]

Day[0]

Frequently requested episodes will be transcribed first

Shownotes Transcript

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/rust-in-the-web-a-special-guest-and-some-bad-crypto.html

We are joined by Bastian Gruber to start the episode with a discussion about Rust. Then we'll dive into a few interesting vulnerabilities this week including yet another ECDSA implementation issue and some header smuggling research.

[00:00:40] Rust Discussion with Bastian Gruber (Use the code poddayzero21 for 35% off Manning books)

[00:46:29] Arbitrary Signature Forgery in Stark Bank ECDSA Libraries [CVE-2021-43572, CVE-2021-43570, CVE-2021-43569, CVE-2021-43568, CVE-2021-43571]

[01:02:37] Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over

[01:06:52] Private Blog Content Disclosed in Atom Feed

[01:08:29] Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

[01:17:01] IDOR through MongoDB Object IDs Prediction

[01:18:45] History of Cross-Site History Leaking

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities

- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

You can also join our discord: https://discord.gg/daTxTK9

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.