Light

Episode #848 Quiz

XSinator
Date: 2021-12-07 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Tavis Ormandy found a memory-corruption bug in Mozilla NSS signature verification, affecting most NSS uses before 3.73/3.68.1 ESR; DER-encoded DSA and RSA-PSS signatures in PDF and email clients could trigger heap overflow, crashing or enabling code execution. Researchers also showed XS-Leaks let hostile pages infer cross-origin user state through browser side channels.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, which kind of NSS usage was identified as the locus of the heap-based buffer overflow in the Mozilla NSS signature verification bug?
Question 2: What did Dr.Web find was the default password on the kids' smartwatches they analyzed?
Question 3: Which six VPN services were added to Russia's banned list in the episode?
Question 4: In the GitLab example of an XS-Leak, what value of window.length indicated that the user was not logged in?
Question 5: How did the Glupteba botnet recover command-and-control information when its C&C server was interrupted, according to the episode?
Cancel