POPULARITY
A mix of issues this week, not traditionally bounty topics, but there are some lessons that can be applied. First is a feature, turned vulnerability in VS Code which takes a look at just abusing intentional functionality. Several XOS bugs with a web-console. A Sonos Era 100 jailbreak which involves causing a particular call to fail, a common bug path we've seen before, and some discussion about doing fast DNS rebinding attacks against Chrome and Safari. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/231.html [00:00:00] Introduction [00:01:00] It's not a Feature, It's a Vulnerability [00:13:40] Multiple Vulnerabilities In Extreme Networks ExtremeXOS [00:24:06] Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100 [00:30:08] Tricks for Reliable Split-Second DNS Rebinding in Chrome and Safari [00:46:02] Apache Struts2 文件上传漏洞分析(CVE-2023-50164) - 先知社区 [00:48:49] Blind CSS Exfiltration: exfiltrate unknown web pages [00:51:11] Finding that one weird endpoint, with Bambdas The DAY[0] Podcast episodes are streamed live on Twitch twice a week: -- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities -- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits. We are also available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec You can also join our discord: https://discord.gg/daTxTK9
Jake and Ron are honored to have the legendary Lucy A. Snyder as a guest for the podcast! We chat with her about her latest novel. Sister, Maiden, Monster published by Tor Nightfire. Lucy A. SnyderLucy A. Snyder is the Shirley Jackson Award-nominated and five-time Bram Stoker Award-winning author of 15 books and over 100 published short stories. Her most recent books are the collection Halloween Season, the Tor Nightfire novel Sister, Maiden, Monster, and the forthcoming novel The Star-Stained Soul. She also wrote the novels Spellbent, Shotgun Sorceress, and Switchblade Goddess, the nonfiction book Shooting Yourself in the Head for Fun and Profit: A Writer's Survival Guide, and the collections Garden of Eldritch Delights, While the Black Stars Burn, Soft Apocalypses, Orchid Carousals, Sparks and Shadows, Chimeric Machines, and Installing Linux on a Dead Badger. Her writing has been translated into French, Russian, Italian, Spanish, Czech, and Japanese editions and has appeared in publications such as Asimov's Science Fiction, Apex Magazine, Nightmare Magazine, Pseudopod, Strange Horizons, and Best Horror of the Year. She lives near Columbus, Ohio. You can learn more about her at www.lucysnyder.com and you can follow her on Twitter at @LucyASnyderThe Wrath of the iOtiansEmail: thewrathoftheiotians@gmail.comInstagram: thewrathoftheiotiansTwitter: @OfiOtiansWebsite: https://thewrathoftheiotians.buzzsprout.com/MusicLand Of The Me-me by Aleksandar Dimitrijevic (TONO)Licensed under the NEO Sounds Music License Agreement
Futurists tell us that over 50 percent of jobs today will soon be replaced by automation and AI. The shelf lives of certain skills are diminishing rapidly. Longstanding industries and industry leaders are being massively disrupted. These staggering changes are challenging our concepts of what a career really looks like today and how we should build organizations going forward. We are facing what today's guest has called, “a Workquake.” The Pandemic has had a profound impact on every area of our lives. The shockwaves have impacted everything from physical and mental health, to supply chain and political power. However, this is also a perfect opportunity to tackle the challenges we have been ignoring or denying. How? Let's find out. Our guest for the next two episodes is Steve Cadigan. Steve sees his mission in life to help individuals and organizations unlock their greatness and discover their magic. He is an expert in the future of work and is considered a corporate culture guru, bringing winning insights from over thirty years of HR experience to industry titans like Google, Salesforce, The Royal Bank of Scotland, McKinsey, the BBC, as well as venture capital firms like Andreessen Horowitz. Steve Cadigan's speaks around the world at global conferences and major universities. Steve is famous for architecting LinkedIn's amazing culture during their years of hyper-growth, seen by many as the gold standard. His latest book is, Workquake: Embracing the Aftershocks of COVID-19 to Create a Better Model of Working. Website: https://stevecadigan.com Social Media https://www.linkedin.com/in/cadigan https://www.instagram.com/stevecadigan https://www.tiktok.com/@stevecadigan Part 1) Alumni, Your Greatest Untapped Resource The Burden of Building for an Exit Lessons in Cultural Destruction from Byte Dance, Uber and WeWork Why Lack of “Tenure" is NOT the Problem! What are Employees Really Loyal to? When Production Cycles are Faster Than Learning Cycles Why Investors Put Money into Tesla over Ford. Why See Your Alumni as Having Abandoned You is Shooting Yourself in The Foot!
Futurists tell us that over 50 percent of jobs today will soon be replaced by automation and AI. The shelf lives of certain skills are diminishing rapidly. Longstanding industries and industry leaders are being massively disrupted. These staggering changes are challenging our concepts of what a career really looks like today and how we should build organizations going forward. We are facing what today's guest has called, “a Workquake.” The Pandemic has had a profound impact on every area of our lives. The shockwaves have impacted everything from physical and mental health, to supply chain and political power. However, this is also a perfect opportunity to tackle the challenges we have been ignoring or denying. How? Let's find out. Our guest for the next two episodes is Steve Cadigan. Steve sees his mission in life to help individuals and organizations unlock their greatness and discover their magic. He is an expert in the future of work and is considered a corporate culture guru, bringing winning insights from over thirty years of HR experience to industry titans like Google, Salesforce, The Royal Bank of Scotland, McKinsey, the BBC, as well as venture capital firms like Andreessen Horowitz. Steve Cadigan's speaks around the world at global conferences and major universities. Steve is famous for architecting LinkedIn's amazing culture during their years of hyper-growth, seen by many as the gold standard. His latest book is, Workquake: Embracing the Aftershocks of COVID-19 to Create a Better Model of Working. Website: https://stevecadigan.com Social Media https://www.linkedin.com/in/cadigan https://www.instagram.com/stevecadigan https://www.tiktok.com/@stevecadigan Part 1) Alumni, Your Greatest Untapped Resource The Burden of Building for an Exit Lessons in Cultural Destruction from Byte Dance, Uber and WeWork Why Lack of “Tenure" is NOT the Problem! What are Employees Really Loyal to? When Production Cycles are Faster Than Learning Cycles Why Investors Put Money into Tesla over Ford. Why See Your Alumni as Having Abandoned You is Shooting Yourself in The Foot! Curious about how to tap into what drives meaning in your life and create meaningful transformation in the lives you touch? Take a look at DovBaron.com Learn more about your ad choices. Visit megaphone.fm/adchoices
Rejoice all younglings, foundlings, and gunganlings! For Life Day is early this year! Yes, as a little holiday special, this episode is released a week earlier, so you can listen to the calm voices of Master Jedi Jake, Sith Lord Tim, and their trusty companion Phil the one legged Ewok, while you travel across the galaxy to be with your loved ones. And as an added bonus, they talk about, not TWO movies, but THREE movies! All the new Star Wars Movies Force, Jedi and Skywalker! Which side do they fall on? DO THEY REJOICE AND CLAP?! OR DO THEY WORRY AS SOON AS THEY SEE THAT THE DEAD SPEAK?!?! FIND OUT, TONIGHT ON THE NEW EPISODE OF THREEFOLD PODCAST! Before we start:The Evacuation of the Movie Goers (03:24)We Saw The Movie After All (14:00) Movie 2&3: Star Wars: Episode VII - The Force Awakens & Star Wars: Episode VIII - The Last JediThe Force Awakens Begins (15:38)Logistics and Mechanics (24:12)The Last Jedi Continues (25:38)Shooting Yourself in the Foot (32:01) Intermission:Mike Verta - Tears of a Jedi (47:09) Movie 1: Star Wars: Episode IX - The Rise of Skywalker The Rise (49:14)What Was Happening (1:03:31)We Have to Keep Going (1:13:52)Principles of a Continuation (1:22:09)The Artificial Endgame (1:30:45)In Conclusion (1:40:09) Before we end:Congratulations to Twofold End of the Year Giveaway Winners Mark Jay & Frank Ireland! (1:44:44) Links:Star Wars: Episode VII - The Force Awakens Podcast Episode Star Wars: Episode VIII - The Last Jedi Podcast Episode Youtube Playlist of all the episodes where Jake and Phil watc the Star Wars Saga films as if seeing it for the first time. The Hobbit: The Desolation of Smaug Podcast EpisodeThe Hobbit: The Battle of the Five Armies Podcast Episode 1, Episode 2, Episode 3
Lucy A. Snyder is a five-time Bram Stoker Award-winning author. She wrote the novels Spellbent, Shotgun Sorceress, and Switchblade Goddess, the nonfiction book Shooting Yourself in the Head for Fun and Profit: A Writer’s Survival Guide, and the collections While the Black Stars Burn, Soft Apocalypses, Orchid Carousals, Sparks and Shadows, Chimeric Machines, and Installing Linux on a Dead Badger. Her writing has been translated into French, Russian, Italian, Czech, and Japanese editions and has appeared in publications such as Apex Magazine, Nightmare Magazine, Pseudopod, Strange Horizons, Weird Tales, Scary Out There, Seize the Night, and Best Horror of the Year. She lives in Columbus, Ohio and is faculty in Seton Hill University’s MFA program in Writing Popular Fiction. Snyder is featured in the newest anthology Tales From The Lake Volume 5 from Crystal Lake Publishing. Theme music for Madame Perry's Salon composed and performed by Denton Perry. Authors! Need to promote your book but can't afford a publicist? Get Sell Your Books Todayright now! As a seasoned entertainment publicist I know exactly what insider info you need to get your books to the world!
Have you been wondering how to market yourself? How about how to market a business? I discovered there’s a way to help market yourself that many people seem to overlook. Just the other week I wrote the article titled “Can Customer Feedback Increase Your Sales?“ The article discusses how to use customer testimonials to help with your sales. But what can giving a testimonial do for you? We all desire help with our marketing efforts and some portions of it requires an investment. Then there are ways that are cost effective. I learned that my giving genuine testimonials can help brand and market me with zero out of pocket expense. The goal with marketing is to reach your target audience and/or market over and over again while receiving a high ROI (return on investment). How can you achieve this goal without ever having to pay for it? Well earlier this year I decided to give a testimonial on a program that’s offered by someone I’ve been learning from since 2005. With my taking 10 to 15 minutes to share my true feelings about MRMI Basic Training, they placed my photo on the front page. This opportunity has allowed me to be contacted by someone whom I’ve admire because they saw me on this website. Now, Stephen Pierce is an authority in what he does, so being on a website of someone who is really respected makes it great. Just this past September I offered feedback to an article I read in the Entrepreneur Magazine on Russell Simmons. Again, taking about 15 minutes to express what inspired me the most about the article has allowed my letter to the editor to printed in the November issue of Entrepreneur Magazine. It’s really easy to get started with putting your name, brand, and face out there by providing testimonials. Here are few steps: 1. Recognize what products or services you’ve found of value. 2. Ask yourself: “Have I told everyone about it?” and “Have I shared by joy with the business?” 3. Sit down and write a brief email on what you like best about the product and/or service. 4. Most importantly be genuine. Remember this, your company and name is behind this testimonial, so be sure to stand firm on it. This is something you can implement right now. Don’t you agree? ================= About The Author ================= And to help you with writing a quality testimonial, C.F. Jackson invites you to check out Website Makeover Mentoring by the Minute (http://ww.MentoringByTheMinute.com), where your online questions are answered. The topics range from how to market a book online to I need web traffic. ~~~~~~~~~~~~~~~~~ You May Also Enjoy: ~~~~~~~~~~~~~~~~~ How To Create An Internet Presence In 10 Minutes 11 Ways You’re Shooting Yourself and Your Business in the Foot http://www.WebsiteMakeoverWorkshop.com
When I started out on the internet in the late 90’s it wasn’t as easy as it is today to get online and have a presence quickly. How To Create Internet Presence In 10 Minutes There were ways to create websites, but without knowledge of HTML or the desire to learn about web design it was a challenge.Most people invested large amounts of money to have their websites designed. Today any and everyone can create a web presence online overnight. Yes! You can have a web presence overnight. However the key is this, doing it right. I was online in the 2003, but it wasn’t right. The same struggles many are having today, I didn’t know the key and pivotal elements to getting started online right. How can one do it right? 1., Blog – Getting a blog is one of the fastest and cost effective ways to getting online today. Blogs are easy to update, which means there’s no need for a webmaster to make small and minute changes. The cost is either free, small base fee or you can host it yourself. It all depends your skill level. One thing, they are built to help you get started right. Search engines love blogs because they fuel their engine with content. 2., Keywords – These are the keys your audience use in order to find you online. I didn’t provide my target audience with a set of keys. Let’s say you have a blog or a website and you’re not getting the results you want. It’s possibility you haven’t defined your keywords. This is where a lot of people go wrong online. This is where I struggled. Without keywords and keyword phrases your website or your blog will forever be lost in the abyss. These are two strategies I use to capture my target audience, to drive traffic, and build my business. You can learn all seven key steps when you join me Thursday evening as I present an online workshop titled 7 Key Steps On How To Get Started RIGHT As An Author Online OVERNIGHT., In this workshop you’ll discover…, - Key Elements to a Domain Name, - Internet Presence In 10 Minutes, - How to Increase Book Sales, - How to Systematize Online Process, - Powerful Customer Getting Methods, - and a lot more, Date: Thursday, September 24, 2009, Time: 8:30 PM – 9:30 PM EST, Where: Online, Register Now http://budurl.com/7StepsWeb , ================= About The Author, ================= And to help you with getting started online right, C, F, Jackson invites you to check out Website Makeover Mentoring by the Minute, where your online questions are answered. The topics range from how to market a book online to I need web traffic. Go to... http://www.MentoringByTheMinute.com ~~~~~~~~~~~~~~~~~ You May Also Enjoy:, ~~~~~~~~~~~~~~~~~ 11 Ways You’re Shooting Yourself and Your Business in the Foot, 5 Ways To Improve Sales Through Your Website