Day[0]

A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the

Episodes

Total: 268

Few discussions this week, from using ASAN for effectively, to vulnerabilities in Rust code, and som

Bit slow this week, so we talk about the Top Web-hacking techniques of 2022, and some TruffleSec/XSS

First, we take a look at some positive changes to OSS Fuzz, then we dive into some vulnerabilities.

Is it possible to escalate a self-XSS into an account takeover? Perhaps, we take a look at some pote

Discussion heavy episode this week, talking about KASAN landing on Windows, shuffling gadgets to mak

Starting off the week strong we have a CSS injection turned full-read SSRF, and a MyBB exploit chain

Null-dereferences might not be too exploitable on a lot of systems, what about the handling of a nul

We've got a cloud focused episode this week, starting with a logging bypass in AWS CloudTrail, a SSH

An Apple-focused episode this week, with a trivial iPod Nano BootRom exploit, and a WebKit Use-after

This week kicks off with another look at client-side path traversal attacks, this time with some mor

Just a few issues this week, but some solid exploitation. A Kernel UAF, IoT, and a bhyve escape. Li

First episode of the new year, and we've got some cool stuff. Several authentication issues and "cla

In this episode, we discuss the discovery of a type confusion in Internet Explorer's JScript. We als

Is Pwn2Own worth it for bug bounty hunters? A handful of trivial command injections, and some awesom

Will AI be your next vuln research assistant? ... Maybe? We also talk about a stack-based overflow i

A variety of issues this week, DOM Clobbering, argument injection, a filesystem race condition, cros

The end of kASLR bypasses? Probably just click-bait, but the patch gap is real and we discuss that a

Some RCE chains starting with DNS rebinding, always fun to see, a fairly basic SQL injection, and a

A hardware heavy episode as we talk about two read protection bypasses, Pixel 6 bootloader exploitat

This week has the return of cross-site tracing, HTML injection, a golang specific vulnerable code pa