Light

Episode #855 Quiz

Inside the NetUSB Hack
Date: 2022-01-25 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Log4j scanning persisted, while cyber-insurers tightened coverage, forcing multifactor authentication and sharply higher premiums. WordPress plugins remained a major risk: WP HTML Mail exposed unauthenticated REST endpoints enabling code injection and takeover, and AccessPress themes/plugins were backdoored in a supply-chain breach. Kaspersky also found MoonBounce, a persistent UEFI SPI-memory bootkit.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the NetUSB flaw discussed in the episode, what specific arithmetic mistake turns the router's intended allocation into a 16-byte buffer?
Question 2: What was the key network exposure detail that made the NetUSB service especially dangerous beyond a normal LAN-only flaw?
Question 3: Which command path did the Sentinel Labs researchers identify as the one that led into the vulnerable allocation logic?
Question 4: What mitigation did the episode say the school-district cyber-insurance pool required before full coverage limits would apply?
Question 5: How did MoonBounce differ from most other UEFI bootkits according to the episode?
Cancel