Light

Episode #896 Quiz

Something for Everyone
Date: 2022-11-08 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Dropbox mitigated a CircleCI phishing compromise that stole GitHub credentials via hardware-key OTP replay and copied 130 repositories. OpenSSL 3.0.7 fixes stack overflows in X.509 name-constraint checking, potentially causing DoS or RCE. Chegg’s failures included plaintext S3 data, no MFA, weak hashes, poor training, and repeated phishing breaches.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the specific phishing-chain technique Dropbox described as succeeding against its GitHub organization access?
Question 2: According to the episode, what was the key technical precondition for the more serious OpenSSL CVE-2022-3602 to become exploitable in a way that could lead to remote code execution?
Question 3: What combination of weaknesses did the FTC cite in Chegg’s S3 environment as part of its data-security complaints?
Question 4: How did the OPERA1ER bank-heist group reportedly turn access into cash once they reached the money-transfer systems?
Question 5: What opt-out mechanism did the NCSC provide for systems administrators who did not want their servers scanned?
Cancel