Segfault.fm ist ein wissenschaftsorientierter Podcast über IT-Sicherheit. Wir versuchen in diesem Podcast eine Brücke zwischen Praxis und Akademia zu schlagen.

Segfault.fm
Claim This Podcastby Florian und Daniel
Podcast Overview
Segfault.fm ist ein wissenschaftsorientierter Podcast über IT-Sicherheit. Wir versuchen in diesem Podcast eine Brücke zwischen Praxis und Akademia zu schlagen.
Language
🇩🇪
Publishing Since
8/25/2018
1 verified contact email on file for Segfault.fm
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

April 6, 2024
0x28 xz - You owe Freund a beer!
<strong>Beschreibung:</strong> <p> Summary durch AI generiert: In dieser Episode von Sackford FM wird die Entdeckung einer potenziell schwerwiegenden Backdoor in der XZ-Kompressionssoftware diskutiert. Der Microsoft-Ingenieur Andres Freund identifizierte die Backdoor durch ungewöhnliche CPU-Auslastung von OpenSSH. Es wird betont, dass solche Sicherheitsprobleme in der Open-Source-Welt schnell angegangen werden müssen, um Katastrophen zu verhindern. Technische Details der Backdoor, wie ihre Aktivierung und Tarnung als Unit-Tests, werden ausführlich behandelt. Die Diskussion endet mit Überlegungen zu potenziellen Lösungsansätzen in der Open-Source-Community, um von einzelnen Maintainern abhängige Sicherheitsrisiken zu minimieren. </p> <strong>Shownotes:</strong> <ul> <li><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank">Andres Freund initial e-mail</a> </li> <li><a href="https://research.swtch.com/xz-timeline" target="_blank">Timeline of the xz open source attack</a> </li> <li><a href="https://research.swtch.com/xz-script" target="_blank">The xz attack shell script </a> </li> <li><a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/" target="_blank">ArchLinux: The xz package has been backdoored</a> </li> <li><a href="https://infosec.exchange/@briankrebs/112197305365490518" target="_blank">Some thoughs from Brian Krebs on xz</a> </li> <li><a href="https://gynvael.coldwind.pl/?lang=en&id=782" target="_blank">xz/liblzma: Bash-stage Obfuscation Explained</a> </li> <li><a href="https://pbs.twimg.com/media/GJ-6mD9aIAARaiY?format=jpg&name=4096x4096" target="_blank">xz outbreak (jpg)</a> </li> <li><a href="https://tukaani.org/xz-backdoor/" target="_blank">xz utils backdoor</a> </li> <li><a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" target="_blank">FAQ on the xz-utils backdoor (CVE-2024-3094)</a> </li> <li><a href="https://risky.biz/RB743/" target="_blank">Small Interview of Andres Freund</a> </li> <li><a href="https://github.com/amlweems/xzbot" target="_blank">xzbot</a> </li> <li><a href="https://joeyh.name/blog/entry/reflections_on_distrusting_xz/" target="_blank">Reflections on distrusting xz</a> </li> <li><a href="https://pentest-tools.com/blog/xz-utils-backdoor-cve-2024-3094" target="_blank">XZ Utils Backdoor - critical SSH vulnerability (CVE-2024-3094)</a> </li> <li><a href="https://www.wired.com/story/jia-tan-xz-backdoor/" target="_blank">The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind</a> </li> </ul>

January 31, 2024
0x27 Dickpics in der Ubahn
<strong>Beschreibung:</strong> <p> Summary durch AI generiert: In der 40. Folge von Segfault FM diskutieren wir Sicherheitsprobleme von Druckern, potenzielle Sicherheitslücken und den Angriff auf Microsoft. Wir sprechen auch über Ransomware, die Verwendung von Google, Slack und Zoom in deutschen Unternehmen sowie Erfahrungen auf dem 37c3. Abschließend verabschieden wir uns und freuen uns auf ein Wiedersehen im Februar. Viel Spaß beim Hören! </p> <strong>Shownotes:</strong> <ul> <li><a href="https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/" target="_blank">Daniel Stenberg’s Blog - The I in LLM Stands for Intelligence</a> </li> <li><a href="https://hackerone.com/reports/2298307" target="_blank">HackerOne Report 2298307</a> </li> <li><a href="https://www.usenix.org/conference/usenixsecurity21/presentation/heinrich" target="_blank">Usenix Security Symposium - PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop</a> </li> <li><a href="https://www.heise.de/news/Warum-ein-Sicherheitsforscher-im-Fall-Modern-Solution-verurteilt-wurde-9601392.html" target="_blank">Heise Online - Warum ein Sicherheitsforscher im Fall Modern Solution verurteilt wurde</a> </li> <li><a href="https://www.action-intell.com/2022/10/05/hp-bug-bounty-program-finds-reprogrammable-chips-open-printers-to-malware/" target="_blank">Action Intelligence - HP Bug Bounty Program Finds Reprogrammable Chips Open Printers to Malware</a> </li> <li><a href="https://www.bleepingcomputer.com/news/security/kasseika-ransomware-uses-antivirus-driver-to-kill-other-antiviruses/" target="_blank">BleepingComputer - Kasseika Ransomware Uses Antivirus Driver to Kill Other Antiviruses</a> </li> <li><a href="https://cybernews.com/security/bring-your-own-vulnerable-driver-attack/" target="_blank">CyberNews - Bring Your Own Vulnerable Driver Attack</a> </li> <li><a href="https://arstechnica.com/gadgets/2024/01/hp-ceo-blocking-third-party-ink-from-printers-fights-viruses/" target="_blank">Ars Technica - HP CEO: Blocking Third-Party Ink from Printers Fights Viruses</a> </li> <li><a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html" target="_blank">Heise Online - Verwirrend: Internet-Domain fritz.box zeigt NFT-Galerie statt Router-Verwaltung</a> </li> <li><a href="https://www.linkedin.com/pulse/microsofts-dangerous-addiction-security-revenue-alex-stamos-1ukzc" target="_blank">LinkedIn - Microsoft’s Dangerous Addiction To Security Revenue</a> </li> <li><a href="https://www.heise.de/news/HP-Verchipte-Druckerpatronen-sind-Sicherheitsrisiko-9605290.html" target="_blank">Heise Online - HP: Verchipte Druckerpatronen sind Sicherheitsrisiko</a> </li> <li><a href="https://tim.siosm.fr/blog/2023/12/19/ssh-over-unix-socket/" target="_blank">Tim’s Blog - SSH Over Unix Socket</a> </li> <li><a href="https://huggingface.co/WhiteRabbitNeo/WhiteRabbitNeo-33B-v1" target="_blank">WhiteRabbitNeo/WhiteRabbitNeo-33B-v1</a> </li> <li><a href="https://events.ccc.de/congress/2023/infos/startpage.html" target="_blank">37c3 Unlocked</a> </li> </ul>

December 13, 2023
0x26 Responsible Release
<strong>Beschreibung:</strong> <p> Diesen Monat aus Gründen der Qualitätssicherung ohne AI Summary. Es gibt Updates zu VPN-Sperren, dem Okta Incident, Signal, Tetra und dem Hackerparagraphen. Weiterhin diskutieren wir Schwachstellen bei Fingerabdruckscannern und Windows Hello, Intel Prozessoren, das polnische Dieselgate on Trains und LogoFail. Viel Spaß beim Hören! </p> <strong>Shownotes:</strong> <ul> <li><a href="https://www.golem.de/news/alles-fuer-die-sicherheit-russland-sperrt-167-vpn-und-ueber-200-e-mail-dienste-2310-178970.html" target="_blank">Russland sperrt 167 VPN- und über 200 E-Mail-Dienste</a> </li> <li><a href="https://arstechnica.com/information-technology/2023/11/no-okta-senior-management-not-an-errant-employee-caused-you-to-get-hacked/" target="_blank">No, Okta, senior management, not an errant employee, caused you to get hacked</a> </li> <li><a href="https://lock.cmpxchg8b.com/reptar.html" target="_blank">Reptar</a> </li> <li><a href="https://www.stayforever.de/2023/09/der-pentium-prozessor-sft-12/" target="_blank">Podcast Stay Forever: Der Pentium Prozessor</a> </li> <li><a href="https://www.golem.de/news/behoerden-funk-etsi-will-tetra-verschluesselung-offenlegen-2311-179493.html" target="_blank">Etsi will Tetra-Verschlüsselung offenlegen</a> </li> <li><a href="https://www.theverge.com/2023/11/22/23972220/microsoft-windows-hello-fingerprint-authentication-bypass-security-vulnerability" target="_blank">Microsoft’s Windows Hello fingerprint authentication has been bypassed</a> </li> <li><a href="https://projectblack.io/blog/trusted-by-millions-yet-so-wrong/" target="_blank">Trusted by Millions, Yet So Wrong - Password Strength Tools</a> </li> <li><a href="https://community.signalusers.org/t/public-username-testing-staging-environment/56866" target="_blank">https://community.signalusers.org/t/public-username-testing-staging-environment/56866</a> </li> <li><a href="https://www.heise.de/news/Sicherheitsforschung-Justizminister-will-Hackerparagrafen-novellieren-9539708.html" target="_blank">Sicherheitsforschung: Justizminister will Hackerparagrafen novellieren</a> </li> <li><a href="https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/" target="_blank">Dieselgate, but for trains – some heavyweight hardware hacking</a> </li> <li><a href="https://arstechnica.com/security/2023/12/just-about-every-windows-and-linux-device-vulnerable-to-new-logofail-firmware-attack/" target="_blank">LogoFail</a> </li> <li><a href="https://events.ccc.de/congress/2023/infos/startpage.html" target="_blank">37c3 Unlocked</a> </li> </ul>
41 total episodes available
Deep-dive analytics for Segfault.fm
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Segfault.fm?
- How often does this podcast release new episodes?
This podcast updates inactive.
- Where can I listen to this podcast?
This podcast is available on 9 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.
