Finding Zero-days With Github

Поділитися
Вставка
  • Опубліковано 10 січ 2021
  • In this video, we review the discovery and exploit development process for CVE-2020-7209 - a remote command injection vulnerability in HP's LinuxKi project.
  • Наука та технологія

КОМЕНТАРІ • 17

  • @TalsonHacks
    @TalsonHacks 3 роки тому +4

    A comment for YT algo :D

  • @InfiniteLogins
    @InfiniteLogins 2 роки тому +2

    Super awesome methodology. It's like automating CVE discovery! Genius!

  • @cocplayer9511
    @cocplayer9511 3 роки тому +1

    You deserve more subscribers, great job

  • @adalbertoguerra8402
    @adalbertoguerra8402 2 роки тому

    Great content.!!! Very educational.!!! I am wondering if you can make a video explaining what are the steps to learn zero-day vulnerabilities.

  • @crash4o4
    @crash4o4 Рік тому

    Good video doing oswe now and gives me a insight on how to document my steps.

  • @000t9
    @000t9 2 роки тому

    Oh thank you bro! Nice tools!

  • @mahdimix5468
    @mahdimix5468 2 роки тому

    You have amazing voice 😍, I have a feeling that telling me that you should be famous in this field, work hard as much as you can

  • @TechieGanesh
    @TechieGanesh Рік тому

    great info :D can you tell me how much time on avg does it take for you to discover a zero day like you've shown in the video???? also do you have any tips when starting to hunt 0day in the wild?

    • @cwinfosec
      @cwinfosec  6 місяців тому +1

      I'm sorry for taking so long to respond. It really depends on the app, sometimes I've found them within an hour, sometimes it took me a day or so after initially investigating. Especially when you consider the skill requirement for certain binary vulnerabilities, it can really take a lot of time to develop a working POC. The important part is hunting for bugs, whether you ultimately find one or not isn't important, just looking for them in the first place is IMO. Best of luck to you my friend!

  • @audiobook890
    @audiobook890 3 роки тому

    Hmm awesome.

  • @CustomDabber360
    @CustomDabber360 2 роки тому +3

    Do you talk to your mother with that voice?

  • @MygenteTV
    @MygenteTV 4 місяці тому

    So basically a zero day is any cve before you make it a cve?

    • @cwinfosec
      @cwinfosec  4 місяці тому +1

      Sorta but not exactly. Definitions vary, but generally the term "zero-day" comes from the fact that once a vulnerability has been discovered and an exploit developed for it, the vendor has had zero days to patch or fix it before attackers are able take advantage of it. If the developer knows about a vulnerability, but hasn't released a patch yet we typically refer to them as "N-day"

    • @MygenteTV
      @MygenteTV 4 місяці тому

      @@cwinfosec I see, Thank you. So to put it in a very simplistic way. Let's say I find a RCE/sqli in a software(SuperFive) many companies around the world use SuperFive. Now I can just hack any SuperFive user because they don't know about my discovery, unless I tell the world about and to make it more effective, I made a python script that will do my manual steps in auto

  • @taiquangong9912
    @taiquangong9912 10 місяців тому

    Long time

  • @samsepi0101
    @samsepi0101 3 роки тому

    Great Content, but why was your voice shaking?

  • @user-dw9tx5sp2z7
    @user-dw9tx5sp2z7 6 місяців тому

    Throwaway your backspace man. It is making your life so sad