Light

Episode #909 Quiz

How ESXi Fell
Date: 2023-02-07 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

The EU plans mandatory, universal CSAM surveillance, forcing providers to detect, report, block, and remove images and grooming text via an EU Centre database, despite privacy-rights rulings. VMware ESXiArgs exploited a two-year-old OpenSLP heap overflow on port 427, encrypting VM files; patching, disabling OpenSLP, and reducing attack surface are key mitigations.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what made the EU’s proposed CSAM surveillance regime especially significant compared with the earlier arrangement?
Question 2: What did the HSTS preload discussion say about the .dev top-level domain?
Question 3: What did the episode identify as the immediate technical weakness behind the ESXi ransomware wave?
Question 4: Which deployment choice did VMware later announce for newer ESXi releases to reduce exposure to the OpenSLP issue?
Question 5: What was the main criticism Steve raised about accountability in the ESXi attack?
Cancel