NoSQL Injection, Mobile Misconfigurations and a Wormable Windows Bug

Published: May 25, 2021, 10 p.m.

Another short episode this week covering graphql attacks, a couple NoSQL injections, a few misconfigurations and a cool attack to reset monotonic counters on a Mifare card.

\n

\n[00:01:25] From CTFs to the Real World
\n

    \n\t
  • https://dayzerosec.com/tags/ctf-to-real-world/

  • \n
\n

\n

\n[00:02:50] [GitHub] Exploits and Malware Policy Updates
\n

    \n\t
  • https://github.com/github/site-policy/pull/397

  • https://github.com/github/site-policy/pull/397/files

  • \n
\n

\n

\n[00:07:37] Mobile app developers\u2019 misconfiguration of third party services leave personal data of over 100 million exposed
\n

    \n\t
  • https://research.checkpoint.com/2021/mobile-app-developers-misconfiguration-of-third-party-services-leave-personal-data-of-over-100-million-exposed/

  • \n
\n

\n

\n[00:13:49] QNAP MusicStation/MalwareRemover Pre-Auth RCE
\n

    \n\t
  • https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/

  • \n
\n

\n

\n[00:17:45] 2FA Bypass via Forced Browsing
\n

    \n\t
  • https://infosecwriteups.com/2fa-bypass-via-forced-browsing-9e511dfdb8df

  • \n
\n

\n

\n[00:24:22] That single GraphQL issue that you keep missing
\n

    \n\t
  • https://blog.doyensec.com/2021/05/20/graphql-csrf.html

  • \n
\n

\n

\n[00:32:22] Remote code execution in squirrelly [CVE-2021-32819]
\n

    \n\t
  • https://securitylab.github.com/advisories/GHSL-2021-023-squirrelly/

  • \n
\n

\n

\n[00:44:30] NoSQL Injections in Rocket.Chat
\n

    \n\t
  • https://blog.sonarsource.com/nosql-injections-in-rocket-chat/

  • https://hackerone.com/reports/1130721

  • \n
\n

\n

\n[00:49:15] RFID: Monotonic Counter Anti-Tearing Defeated
\n

    \n\t
  • https://blog.quarkslab.com/rfid-monotonic-counter-anti-tearing-defeated.html

  • \n
\n

\n

\n[00:56:24] A Wormable Code Execution Bug in HTTP.sys [CVE-2021-31166]
\n

    \n\t
  • https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys

  • https://github.com/0vercl0k/CVE-2021-31166

  • \n
\n

\n

\n[01:04:15] Fuzzing iOS code on macOS at native speed
\n

    \n\t
  • https://googleprojectzero.blogspot.com/2021/05/fuzzing-ios-code-on-macos-at-native.html

  • \n
\n

\n

\n[01:05:07] RuhrSec 2018: "Keynote: Weird machines, exploitability and unexploitability", Thomas Dullien
\n

    \n\t
  • https://www.youtube.com/watch?v=1ynkWcfiwOk

  • \n
\n

\n

\n[01:07:58] Browser fuzzing at Mozilla
\n

    \n\t
  • https://blog.mozilla.org/attack-and-defense/2021/05/20/browser-fuzzing-at-mozilla/

  • \n
\n

\n

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

\n

Or the video archive on Youtube (@dayzerosec)