April 4, 2023, 8 p.m. | DAY[0]

DAY[0] www.youtube.com

Some audio issues this week, sorry for the ShareX sound. But we have a few interesting issues. A curl quirk that it might be useful to be aware of, Azure Pipelines vulnerability abusing attacker controlled logging. A look at a pretty classic Android/mobile bug, and a crazy auth misconfiguration (BingBang).

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/201.html

[00:00:00] Introduction
[00:00:39] The curl quirk that exposed Burp Suite and Google Chrome
[00:03:33] Exploiting prototype pollution in Node …

abusing android attack audio auth aware azure azure pipelines bing bingbang bounty bug bug bounty burp burp suite chrome code code execution curl exploiting exposed filesystem google google chrome introduction logging misconfiguration mobile node pipelines podcast remote code remote code execution software software supply chain software supply chain attack sound supply supply chain supply chain attack vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Digital Trust Cyber Transformation Senior

@ KPMG India | Mumbai, Maharashtra, India

Security Consultant, Assessment Services - SOC 2 | Remote US

@ Coalfire | United States

Sr. Systems Security Engineer

@ Effectual | Washington, DC

Cyber Network Engineer

@ SonicWall | Woodbridge, Virginia, United States

Security Architect

@ Nokia | Belgium