Light

Episode #865 Quiz

Port Knocking
Date: 2022-04-05 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

The episode surveys Spring4Shell, a Java Spring Core bypass on JDK 9+ enabling unauthenticated remote code execution through crafted HTTP requests, plus related exploitation uncertainty. It also covers QNAP and Sophos firewall vulnerabilities, browser-in-the-browser phishing, NPM dependency-confusion package flooding, and Wyze camera flaws, stressing patching and concealment.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to Steve Gibson, what made the original old-school port knocking approach vulnerable to replay attacks?
Question 2: What specific mechanism did Steve say FWKNOP uses to prevent reuse of a previously valid authorization packet?
Question 3: In the Wyze camera flaw Steve described, what exact mistake in the handshake allowed unauthenticated access?
Question 4: What did Bitdefender say could be done after exploiting the Wyze authentication bypass, before chaining to code execution?
Question 5: What did Steve identify as the immediate public-risk condition for the OpenSSL denial-of-service issue affecting some QNAP NAS devices?
Cancel