This week we get to take a look into some basic heap grooming techniques as we examine multiple heap overflows. We also briefly discuss the hand-on (by the DoD and Synack) assessment of the "unhackable" morpheus chip, and briefly discuss the new-ish paper claiming to defeat RSA.
\n\n[00:00:53] "This destroys the RSA cryptosystem." - Fast Factoring Integers by SVP Algorithms
\n
\n[00:06:55] DARPA pitted 500+ hackers against this computer chip. The chip won.
\n
\n[00:18:10] SaltStack API vulnerabilities
\n
\n[00:22:57] An Interesting Feature in the Samsung DSP Driver
\n
\n[00:30:50] Pre-Auth Remote Code Execution in VMware ESXi [CVE-2020-3992 CVE-2021-21974]
\n
\n[00:39:05] Defeating the TP-Link AC1750
\n
\n[00:44:52] Anatomy of an Exploit: RCE with CVE-2020-1350 SIGRed
\n
\n[00:57:11] Yet another RenderFrameHostImpl UAF
\n
\n[01:03:16] Webkit AudioSourceProviderGStreamer use-after-free vulnerability
\n
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
\nOr the video archive on Youtube (@dayzerosec)