

[bounty] Spoofing Emails, PandoraFMS, and Keycloak
Jan 9, 2024
The hosts delve into security vulnerabilities lurking in desktop applications, highlighting client-side path traversal risks. They reveal alarming issues in Pandora FMS, including unauthenticated access and remote code execution. A deep dive into SMTP vulnerabilities unravels the complex world of email spoofing and the failures of current security protocols. Through engaging anecdotes and technical analysis, they advocate for better security practices and responsible disclosure to combat these persistent threats.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8
Intro
00:00 • 3min
Holiday Reflections and Event Excitement
02:40 • 7min
Navigating Event Challenges and Security Vulnerabilities
09:45 • 26min
Understanding HTTP Redirect Codes: The Nuances of 307 and 308
36:10 • 2min
Vulnerabilities in Pandora FMS
38:24 • 6min
Unpacking SMTP Smuggling Vulnerabilities
44:35 • 17min
SMTP Secrets: Understanding Email Protocols and Vulnerabilities
01:01:39 • 18min
Automating Detection of Library Misuse through CodeQL
01:19:15 • 2min