[bounty] Akamai Cache Poisoning and a Chrome Universal XSS

Published: Oct. 4, 2022, 8 p.m.

Had some varied issues this week, a file format allowing JScript for a $20,000 bounty, Akamai Cache Poisoning, Universal XSS in Chrome.

\n


\n

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/155.html

\n


\n

[00:00:00] Introduction

\n

[00:00:26] Two Lines of JScript for $20,000

\n

[00:05:31] Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)

\n

[00:14:10] [Chrome] Universal XSS in Autofill Assistant

\n

[00:22:51] Aurora Improper Input Sanitization Bugfix Review

\n

[00:31:21] What I learnt from reading 126* Information Disclosure Writeups.