A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the
Few discussions this week, from using ASAN for effectively, to vulnerabilities in Rust code, and som
Bit slow this week, so we talk about the Top Web-hacking techniques of 2022, and some TruffleSec/XSS
First, we take a look at some positive changes to OSS Fuzz, then we dive into some vulnerabilities.
Is it possible to escalate a self-XSS into an account takeover? Perhaps, we take a look at some pote
Discussion heavy episode this week, talking about KASAN landing on Windows, shuffling gadgets to mak
Starting off the week strong we have a CSS injection turned full-read SSRF, and a MyBB exploit chain
Null-dereferences might not be too exploitable on a lot of systems, what about the handling of a nul
We've got a cloud focused episode this week, starting with a logging bypass in AWS CloudTrail, a SSH
An Apple-focused episode this week, with a trivial iPod Nano BootRom exploit, and a WebKit Use-after
This week kicks off with another look at client-side path traversal attacks, this time with some mor
Just a few issues this week, but some solid exploitation. A Kernel UAF, IoT, and a bhyve escape. Li
First episode of the new year, and we've got some cool stuff. Several authentication issues and "cla
In this episode, we discuss the discovery of a type confusion in Internet Explorer's JScript. We als
Is Pwn2Own worth it for bug bounty hunters? A handful of trivial command injections, and some awesom
Will AI be your next vuln research assistant? ... Maybe? We also talk about a stack-based overflow i
A variety of issues this week, DOM Clobbering, argument injection, a filesystem race condition, cros
The end of kASLR bypasses? Probably just click-bait, but the patch gap is real and we discuss that a
Some RCE chains starting with DNS rebinding, always fun to see, a fairly basic SQL injection, and a
A hardware heavy episode as we talk about two read protection bypasses, Pixel 6 bootloader exploitat
This week has the return of cross-site tracing, HTML injection, a golang specific vulnerable code pa