Light

Episode #928 Quiz

The Massive MOVEit Maelstrom
Date: 2023-06-20 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Microsoft patched 73 flaws, including 26 remote code execution bugs and a 9.8 SharePoint authentication bypass using spoofed JSON Web Token access. Researchers then showed power LED video leaks: rolling-shutter cameras can sample LED brightness at 60K Hz, recovering cryptographic keys from smart cards and phones without prior device compromise.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific video-camera feature did Ben Nassi's group exploit to raise the effective sampling rate for power-LED analysis, and to what approximate rate did they claim it could reach on an iPhone 13 Pro Max?
Question 2: What was the exact attack setup used in the first demonstrated cryptanalytic case described in the paper, as summarized on the show?
Question 3: Which combination best matches the second demonstrated attack in the paper, including the target device, the observed LED source, and the camera used?
Question 4: What was the role of the file named human2.aspx in the MOVEit compromise, according to the episode?
Question 5: What did Progress announce on June 16th regarding MOVEit Cloud and MOVEit Transfer customers after the newly discovered SQL injection issue?
Cancel