Light

Episode #859 Quiz

A BGP Routing Attack
Date: 2022-02-22 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

WordPress force-updated UpdraftPlus after a missing permissions check let any authenticated user download backups, risking PII and site takeover. Xenomorph Android banking malware used accessibility overlays, SMS and notification interception, and extensive logging to steal credentials. Hive ransomware’s flawed custom XOR keystream was reverse-engineered, enabling decryption without the attacker’s private key.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the UpdraftPlus vulnerability discussed in the episode, what prerequisite did an attacker need in order to abuse the backup-download flaw?
Question 2: What did ThreatFabric identify as the main attack vector used by the Xenomorph Android banking trojan?
Question 3: How did the South Korean researchers say Hive ransomware generated the keystream used for file encryption?
Question 4: Why was the BGP attack against KLAYswap able to divert traffic to the attackers' server even though the site used HTTPS?
Question 5: What did the attackers do after setting up the fraudulent routing entry and serving malicious JavaScript in the KLAYswap incident?
Cancel