Jan. 10, 2023, 9 p.m. | DAY[0]

DAY[0] www.youtube.com

First episode of the new year, and we've got some cool stuff. Several authentication issues and "class pollution" in Python.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/177.html

[00:00:00] Introduction
[00:00:31] ReDoS "vulnerabilities" and misaligned incentives
[00:17:14] Web Hackers vs. The Auto Industry
[00:37:19] Prototype Pollution in Python
- Correction: We discuss a bit of a disagreement regarding calling the issue "Prototype Pollution" in Python, turns out we missed the fact the author calls it "Class Pollution" …

account account takeover authentication author auto auto industry bounty bug bug bounty cars class discuss facebook fact hackers incentives industry introduction issue new year podcast prototype python redos takeover vulnerabilities web

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC