Jan. 10, 2023, 9 p.m. | DAY[0]

DAY[0] www.youtube.com

First episode of the new year, and we've got some cool stuff. Several authentication issues and "class pollution" in Python.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/177.html

[00:00:00] Introduction
[00:00:31] ReDoS "vulnerabilities" and misaligned incentives
[00:17:14] Web Hackers vs. The Auto Industry
[00:37:19] Prototype Pollution in Python
- Correction: We discuss a bit of a disagreement regarding calling the issue "Prototype Pollution" in Python, turns out we missed the fact the author calls it "Class Pollution" …

account account takeover authentication author auto auto industry bounty bug bug bounty cars class discuss facebook fact hackers incentives industry introduction issue new year podcast prototype python redos takeover vulnerabilities web

Intern, Cyber Security Vulnerability Management

@ Grab | Petaling Jaya, Malaysia

Compliance - Global Privacy Office - Associate - Bengaluru

@ Goldman Sachs | Bengaluru, Karnataka, India

Cyber Security Engineer (m/w/d) Operational Technology

@ MAN Energy Solutions | Oberhausen, DE, 46145

Armed Security Officer - Hospital

@ Allied Universal | Sun Valley, CA, United States

Governance, Risk and Compliance Officer (Africa)

@ dLocal | Lagos (Remote)

Junior Cloud DevSecOps Network Engineer

@ Accenture Federal Services | Arlington, VA