Light

Episode #804 Quiz

NAT Slipstreaming 2.0
Date: 2021-02-02 | Length: 2 hrs | Episode page at twit.tv

About this episode

Google revoked trust in Camerfirma certificates after years of CA mis-issuance, disclosure failures, unconstrained sub-CAs, and invalid entropy or validity periods. The episode also covered a libgcrypt heap overflow in GPG 1.9.0, a ten-year SUDO heap overflow enabling local root, supply-chain malware in NoxPlayer updates, and iOS 14 iMessage sandboxing, rerandomized ASLR, and crash throttling.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the specific condition that let the original NAT Slipstreaming attack reach a NAT router’s Application Layer Gateway in the first place, before the 2.0 variant was developed?
Question 2: Which Apple iOS 14 change was described as moving most parsing of untrusted iMessage data into a new tightly sandboxed service?
Question 3: What was the key change in iOS 14 that neutralized the shared-cache ASLR-bypass technique used in zero-click iMessage attacks?
Question 4: According to the episode, which vulnerability detail made the SUDO flaw especially dangerous even in default configurations?
Question 5: What specific browser-side mitigation was deployed after the NAT Slipstreaming 2.0 disclosure to block the new attack path?
Cancel