Nov. 21, 2023, 1 p.m. | DAY[0]

DAY[0] www.youtube.com

This week has an interesting mix of issues, starting with a pretty standard template inject. Then we get into a Windows desktop issue, a TOCTOU in how the Mark-of-the-Web would be applied to file extracted from an archive, a privilege escalation from a Chrome extension, and a bit of a different spin on what you could do with a prompt injection.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/225.html

[00:00:00] Introduction
[00:00:26] Magento Template Engine, a story …

archive bounty bug bug bounty chrome chrome extension desktop escalation extension extensions file inject issue malicious malicious extensions mark podcast privilege privilege escalation secrets standard template toctou web week windows

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Security Engineer II- Full stack Java with React

@ JPMorgan Chase & Co. | Hyderabad, Telangana, India

Cybersecurity SecOps

@ GFT Technologies | Mexico City, MX, 11850

Senior Information Security Advisor

@ Sun Life | Sun Life Toronto One York

Contract Special Security Officer (CSSO) - Top Secret Clearance

@ SpaceX | Hawthorne, CA

Early Career Cyber Security Operations Center (SOC) Analyst

@ State Street | Quincy, Massachusetts