Light

Episode #810 Quiz

ProxyLogon
Date: 2021-03-16 | Length: 2 hrs | Episode page at twit.tv

About this episode

Chrome 89 patched five flaws, including a Blink use-after-free zero-day, while improving memory use via PartitionAlloc and tab discarding. Google also published Spectre JavaScript PoCs, urging COOP, COEP, CORP, and Fetch Metadata headers plus X-Frame-Options and X-Content-Type-Options to isolate processes, block cross-origin access, and resist CSRF and fingerprinting attacks.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific combination was required to guarantee process-level isolation for highly sensitive applications in Chrome or Firefox?
Question 2: What did the episode say the new Chrome zero-day was found in?
Question 3: How did the Ben-Gurion/University of Michigan/University of Adelaide researchers eliminate JavaScript from their browser-based side-channel attack?
Question 4: Which feature of DNS server did Microsoft patch in March that the episode said was used for these remote code execution flaws?
Question 5: What did the episode say was still necessary after patching Exchange servers compromised by ProxyLogon?
Cancel