
Episode 72: Research TLDRs & Smuggling Payloads in Well Known Data Types
Critical Thinking - Bug Bounty Podcast
Bug Bounty Research Conference and PDF .js XSS Vulnerability
The chapter covers the experience at a bug bounty research conference in Johannesburg, South Africa, and highlights the release of Nuclei 3.2 and a new POC related to PDF .js XSS. It discusses a zero-day vulnerability in the font processing JavaScript code of PDF.js, affecting Firefox users, with implications for CD, and the discovery of a critical vulnerability in applications using PDF.js for malicious code execution. The conversation also speculates on potential vulnerabilities in PDF .yum in Chromium, the challenges in securing JS libraries rendering complex file types, and the intricacies of exploit code understanding with comparisons of white box and black box approaches.
00:00
Transcript
Play full episode
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.