Oct. 24, 2023, noon | DAY[0]

DAY[0] www.youtube.com

Diving right into some binary exploitation issues this week. Starting wtih a look at a rare sort of curl vulnerability where a malicious server could compromise a curl user. Then we take a look at a pretty straight-forward type confusion in Windows kernel code, and an integer underflow in Safari with some questionable exploitation. Ending the episode with some thoughts on how impactful grsecurity's "constify" mitigation could be.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/220.html

[00:00:00] …

binary binary exploitation bugs code compromise curl curl vulnerability exploitation forward integer kernel malicious podcast safari server sort type confusion vulnerability week windows windows kernel

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC