Light

Episode #812 Quiz

GIT Me Some PHP
Date: 2021-03-30 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

ProxyLogon remediation still left tens of thousands of Exchange servers exposed. Linux patches closed two Spectre bypasses in kernel/bpf/verifier.c, enabling speculative out-of-bounds reads via eBPF and browser JavaScript. OpenSSL 1.1.1k fixed a renegotiation NULL dereference DoS and a strict-verification CA chain bypass. PHP moved Git to GitHub with mandatory two-factor authentication.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the current estimate of Exchange Server instances still vulnerable to ProxyLogon after the early March patching push?
Question 2: What capability did the Linux Spectre bypasses described in the episode allow malicious code to obtain from affected systems?
Question 3: Under what condition could the OpenSSL issue CVE-2021-3449 crash a server, according to the advisory quoted in the episode?
Question 4: What did the malicious PHP Git commit actually do when the HTTP user-agent string began with the trigger value?
Question 5: What operational change did the PHP project announce after the Git server compromise?
Cancel