Jan. 30, 2024, 1 p.m. | DAY[0]

DAY[0] www.youtube.com

A packed episode this week as we cover recent vulnerabilities from the last two weeks, including some IDORs, auth bypasses, and a HackerOne bug. Some fun attacks such as a resurface of IDN Homograph Attacks and timing attacks also appear.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/237.html

[00:00:00] Introduction
[00:02:59]
37C3: Unlocked
- media.ccc.de

[00:09:00] Ivanti's Pulse Connect Secure Auth Bypass and RCE
[00:19:47] [HackerOne] View Titles of Private Reports with pending email invitation
[00:23:58] 1 …

attacks auth bounty bug bug bounty ccc fun hackerone idn introduction ivanti media passwords podcast unlocked vulnerabilities week

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior InfoSec Manager - Risk and Compliance

@ Federal Reserve System | Remote - Virginia

Security Analyst

@ Fortra | Mexico

Incident Responder

@ Babcock | Chester, GB, CH1 6ER

Vulnerability, Access & Inclusion Lead

@ Monzo | Cardiff, London or Remote (UK)

Information Security Analyst

@ Unissant | MD, USA