TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Day[0]

    A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the latest disclosed vulnerabilities and exploits.

    Advertise

    Copyright: © dayzerosec

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    FortiJump Higher, Pishi, and Breaking Control Flow Flattening Nov 18, 2024
    Show notes

    This week, we dive into some changes to V8CTF, the FortiJump Higher bug in Fortinet's FortiManager, as well as some coverage instrumentation on blackbox macOS binaries via Pishi.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/263.html


    [00:00:00] Introduction

    [00:00:25] V8 Sandbox Bypass Rewards

    [00:25:39] Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager [CVE-2024-47575]

    [00:38:07] Pishi: Coverage guided macOS KEXT fuzzing.

    [00:44:20] Breaking Control Flow Flattening: A Deep Technical Analysis

    [00:55:10] Firefox Animation CVE-2024-9680 - Dimitri Fourny

    [00:57:13] Internship Offers for the 2024-2025 Season


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Static Analysis, LLMs, and In-The-Wild Exploit Chains Nov 11, 2024
    Show notes

    Methodology is the theme of this week's episode. We cover posts about static analysis via CodeQL, as well as a novel blackbox binary querying language called QueryX. Project Zero also leverages Large Language Models to successfully find a SQLite vulnerability. Finally, we wrap up with some discussion on Hexacon and WOOT talks, with a focus on Clem1's In-The-Wild exploit chains insights via Google's Threat Analysis Group.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/262.html


    [00:00:00] Introduction

    [00:00:35] Discovering Hidden Vulnerabilities in Portainer with CodeQL

    [00:18:12] Finding Vulnerabilities in Firmware with Static Analysis Platform QueryX

    [00:28:25] From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code

    [00:50:00] Hexacon2024 - Caught in the Wild, Past, Present and Future by Clem1

    [01:06:34] Hexacon 2024 Videos

    [01:11:34] WOOT 2024 Videos

    [01:18:38] Securing the open source supply chain: The essential role of CVEs

    [01:20:19] A New Era of macOS Sandbox Escapes: Diving into an Overlooked Attack Surface and Uncovering 10+ New Vulnerabilities


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Attacking Browser Extensions and CyberPanel Nov 04, 2024
    Show notes

    In this week's episode, we talk a little bit about LLMs and how they can be used with static analysis. We also cover GitHub Security Blog's post on attacking browser extensions, as well as a somewhat controversial CyberPanel Pre-Auth RCE that was disclosed.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/261.html


    [00:00:00] Introduction

    [00:01:56] Autonomous Discovery of Critical Zero-Days

    [00:14:43] Attacking browser extensions

    [00:25:26] What Are My OPTIONS? CyberPanel v2.3.6 pre-auth RCE

    [00:52:15] Security research on Private Cloud Compute

    [01:01:02] Bluetooth Low Energy GATT Fuzzing


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9



    Hardwear.IO NL, DEF CON 32, and Filesystem Exploitation Oct 29, 2024
    Show notes

    In this week's episode, Specter recaps his experiences at Hardwear.IO and a PS5 hypervisor exploit chain presented there. We also cover some of the recently released DEF CON 32 talks. After the conference talk, we get into some filesystem exploit tricks and how arbitrary file write can be taken to code execution in read-only environments.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/260.html


    [00:00:00] Introduction

    [00:00:27] Hardwear.io NL 2024

    [00:14:27] Byepervisor - Breaking the PS5 Hypervisor Security

    [00:26:38] DEF CON 32 Main Stage Talks

    [00:51:16] The Missing Guide to Filesystem Security

    [01:00:51] Why Code Security Matters - Even in Hardened Environments

    [01:09:12] How I Defeated An MMO Game Hack Author


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Zendesk's Email Fiasco and Rooting Linux with a Lighter Oct 16, 2024
    Show notes

    In this week's episode, we cover the fiasco of a vulnerability in Zendesk that could allow intrusion into multiple fortune 500 companies. We also discuss a project zero blogpost that talks about fuzzing Dav1d and the challenges of fuzzing, as well as rooting Linux via EMFI with a lighter.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/259.html


    [00:00:00] Introduction

    [00:00:57] 1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies

    [00:27:10] Effective Fuzzing: A Dav1d Case Study

    [00:40:15] Can You Get Root With Only a Cigarette Lighter?


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Summer Recap: Phrack, Off-by-One, and RCEs Oct 08, 2024
    Show notes

    In our summer recap, we discuss Phrack's latest issue and talks from the new Off-by-One conference. We also cover some interesting bugs, such as a factorio lua RCE and another RCE via iconv.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/258.html


    [00:00:00] Introduction

    [00:01:06] Getting Started with Exploit Development

    [00:14:07] Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws

    [00:24:35] Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 1)

    [00:43:29] Off-by-One Conference 2024


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Attack of the CUPS and Exploiting Web Views via HSTS Sep 30, 2024
    Show notes

    In this week's episode, we cover an attack utilizing HSTS for exploiting Android WebViews and abusing YouTube embeds in Google Slides for clickjacking. We also talk about the infamous CUPS attack, and the nuances that seem to be left behind in much of the discussion around it.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/257.html


    [00:00:00] Introduction

    [00:01:30] Exploiting Android Client WebViews with Help from HSTS

    [00:09:08] Using YouTube to steal your files

    [00:18:43] Attacking UNIX Systems via CUPS, Part I


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Future of the Windows Kernel and Encryption Nonce Reuse Sep 23, 2024
    Show notes

    In this week's episode, we discuss Microsoft's summit with vendors on their intention to lock down the Windows kernel from endpoint security drivers and possibly anti-cheats. We also talk cryptography and about the problems of nonce reuse.


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/256.html


    [00:00:00] Introduction

    [00:01:12] Friends don’t let friends reuse nonces

    [00:13:22] Serious Cryptography, 2nd Edition

    [00:14:30] Taking steps that drive resiliency and security for Windows customers


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9



    Iterating Exploits & Extracting SGX Keys Sep 16, 2024
    Show notes

    We are back and testing out a new episode format focusing more on discussion than summaries. We start talking a bit about the value of learning hacking by iterating on the same exploit and challenging yourself as a means of practicing the creative parts of exploitation. Then we dive into the recent Intel SGX fuse key leak, talk a bit about what it means, how it happened.


    We are seeking feedback on this format. Particularly interested in those of you with more of a bug bounty or higher-level focus if an episode like this would still be appealing? If you want to share any feedback feel free to DM us (@__zi or @specterdev) or email us at media [at] dayzerosec.com


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/255.html


    [00:00:00] Introduction

    [00:04:55] Exploiting CVE-2024-20017 4 different ways

    [00:22:26] Intel SGX Fuse Keys Extracted

    [00:51:01] Introducing the URL validation bypass cheat sheet


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9


    Memory Corruption: Best Tackled with Mitigations or Safe-Languages May 17, 2024
    Show notes

    Memory corruption is a difficult problem to solve, but many such as CISA are pushing for moves to memory safe languages. How viable is rewriting compared to mitigating?


    Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/254.html


    [00:00:00] Introduction

    [00:01:12] Clarifying Scope & Short/Long Term

    [00:04:28] Mitigations

    [00:15:37] Safe Languages Are Falliable

    [00:21:20] Weaknesses & Evolution of Mitigations

    [00:29:19] Rewriting and the Iterative Process

    [00:34:55] The Rewriting Scalability Argument

    [00:41:43] System vs App Bugs

    [00:48:46] Mitigations & Rewriting Are Not Mutually Exclusive

    [00:50:25] Corporate vs Open Source

    [00:54:12] Generational Change

    [00:56:18] Conclusion


    Podcast episodes are available on the usual podcast platforms:

    -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063

    -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt

    -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz

    -- Other audio platforms can be found at https://anchor.fm/dayzerosec


    You can also join our discord: https://discord.gg/daTxTK9



    Previous 1 2 3 4 5 29 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights