Critical Thinking - Bug Bounty Podcast cover image

Episode 72: Research TLDRs & Smuggling Payloads in Well Known Data Types

Critical Thinking - Bug Bounty Podcast

CHAPTER

Bug Bounty Research Conference and PDF .js XSS Vulnerability

The chapter covers the experience at a bug bounty research conference in Johannesburg, South Africa, and highlights the release of Nuclei 3.2 and a new POC related to PDF .js XSS. It discusses a zero-day vulnerability in the font processing JavaScript code of PDF.js, affecting Firefox users, with implications for CD, and the discovery of a critical vulnerability in applications using PDF.js for malicious code execution. The conversation also speculates on potential vulnerabilities in PDF .yum in Chromium, the challenges in securing JS libraries rendering complex file types, and the intricacies of exploit code understanding with comparisons of white box and black box approaches.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner