Light

Episode #878 Quiz

The ZuoRAT
Date: 2022-07-05 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome 103.0.5060.114 fixed a high-severity WebRTC heap-buffer overflow zero-day, reported by Avast and assigned CVE-2022-2294. Firefox 102 added query-parameter stripping to remove tracking identifiers, but private browsing needs privacy.query_stripping.enabled.pbmode enabled. HackerOne found an ex-employee abusing internal disclosure logs, sockpuppet accounts, and payment trails to resubmit vulnerabilities for profit.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the specific reason Firefox v102’s new query-parameter stripping feature was still not enabled in private browsing mode for Steve until he made an additional tweak?
Question 2: In the HackerOne insider-threat case, what combination of evidence most directly let the team link the suspicious external disclosure to the then-employee?
Question 3: What did Black Lotus Labs say ZuoRAT’s first-stage router implant did if it could not obtain a public IP address during execution?
Question 4: Which set of services did ZuoRAT query to try to determine the router’s public IP address, as described in the episode?
Question 5: What was Steve’s recommended defensive use of TTL values for equipment that should never be reachable from outside a local network?
Cancel