<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
  <channel>
    <title>PwnFunction</title>
    <link>https://youtube.com/channel/UCW6MNdOsqv2E9AjQkv9we7A</link>
    <description>OK.</description>
    <category>TV &amp; Film</category>
    <generator>Podsync generator (support us at https://github.com/mxpv/podsync)</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 16 Sep 2026 09:31:38 +0000</lastBuildDate>
    <pubDate>Thu, 17 Jan 2019 18:15:55 +0000</pubDate>
    <image>
      <url>https://yt3.ggpht.com/_a2M_-kdsIp85BJ_KD7FK0k_aGaLiPgkDEtKYtDlhE4px2EnKHA-qXT9-TzuC7C4Yn3rNj9hFw=s800-c-k-c0x00ffffff-no-rj</url>
      <title>PwnFunction</title>
      <link>https://youtube.com/channel/UCW6MNdOsqv2E9AjQkv9we7A</link>
    </image>
    <itunes:author>PwnFunction</itunes:author>
    <itunes:subtitle>PwnFunction</itunes:subtitle>
    <itunes:summary><![CDATA[OK.]]></itunes:summary>
    <itunes:image href="https://yt3.ggpht.com/_a2M_-kdsIp85BJ_KD7FK0k_aGaLiPgkDEtKYtDlhE4px2EnKHA-qXT9-TzuC7C4Yn3rNj9hFw=s800-c-k-c0x00ffffff-no-rj"></itunes:image>
    <itunes:explicit>no</itunes:explicit>
    <itunes:category text="TV &amp; Film"></itunes:category>
    <item>
      <guid>RLyhPGsEMz4</guid>
      <title>XSS like you&#39;ve never seen.</title>
      <link>https://youtube.com/watch?v=RLyhPGsEMz4</link>
      <description>In this video, I break down an insane Chrome exploit discovered by 17-year-old researcher Matan that turns a simple drag-and-drop interaction into complete system compromise. The attack exploits Chrome&#39;s DevTools, bypassing JavaScript URI filters and CSP protections to gain access to your local file system. I&#39;ll walk you through the entire vulnerability chain — from the initial social engineering to reading /etc/passwd and achieving universal XSS across any website.&#xA;&#xA;References:&#xA;https://issues.chromium.org/issues/40942152&#xA;https://x.com/MtnBer&#xA;https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/5028164/5/front_end/ui/legacy/components/utils/Linkifier.ts#b526&#xA;&#xA;🐶 Snyk is free forever. Check it out here - https://snyk.co/pwnfunction</description>
      <pubDate>Tue, 03 Jun 2025 18:43:43 +0000</pubDate>
      <enclosure url="https://podsync.watzinger.biz/pwnfnk/RLyhPGsEMz4.mp4" length="81630224" type="video/mp4"></enclosure>
      <itunes:author>PwnFunction</itunes:author>
      <itunes:subtitle>XSS like you&#39;ve never seen.</itunes:subtitle>
      <itunes:summary><![CDATA[In this video, I break down an insane Chrome exploit discovered by 17-year-old researcher Matan that turns a simple drag-and-drop interaction into complete system compromise. The attack exploits Chrome's DevTools, bypassing JavaScript URI filters and CSP protections to gain access to your local file system. I'll walk you through the entire vulnerability chain — from the initial social engineering to reading /etc/passwd and achieving universal XSS across any website.

References:
https://issues.chromium.org/issues/40942152
https://x.com/MtnBer
https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/5028164/5/front_end/ui/legacy/components/utils/Linkifier.ts#b526

🐶 Snyk is free forever. Check it out here - https://snyk.co/pwnfunction]]></itunes:summary>
      <itunes:image href="https://i.ytimg.com/vi/RLyhPGsEMz4/maxresdefault.jpg"></itunes:image>
      <itunes:duration>13:28</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <itunes:order>1</itunes:order>
    </item>
    <item>
      <guid>iTT2AYE2IMQ</guid>
      <title>Innocent Looking Backdoor Found in Universities and Government Systems</title>
      <link>https://youtube.com/watch?v=iTT2AYE2IMQ</link>
      <description>In this video, I break down the newly discovered Auto-Color malware — a sneaky Linux backdoor that’s been targeting universities and government systems. It hides in plain sight, messes with system files like /etc/ld.preload, and even uses encryption to keep its traffic under the radar. I’ll walk you through how it works and how it stays hidden.&#xA;&#xA;References:&#xA;https://unit42.paloaltonetworks.com/new-linux-backdoor-auto-color&#xA;https://gist.github.com/MalGamy12/fe4ab3d60fcb923fb96a7c968adf0e04&#xA;https://zw01f.github.io/malware%20analysis/auto-color/&#xA;&#xA;🐶 Snyk is free forever. Check it out here - https://snyk.co/pwnfunction</description>
      <pubDate>Sun, 13 Apr 2025 20:54:12 +0000</pubDate>
      <enclosure url="https://podsync.watzinger.biz/pwnfnk/iTT2AYE2IMQ.mp4" length="32078965" type="video/mp4"></enclosure>
      <itunes:author>PwnFunction</itunes:author>
      <itunes:subtitle>Innocent Looking Backdoor Found in Universities and Government Systems</itunes:subtitle>
      <itunes:summary><![CDATA[In this video, I break down the newly discovered Auto-Color malware — a sneaky Linux backdoor that’s been targeting universities and government systems. It hides in plain sight, messes with system files like /etc/ld.preload, and even uses encryption to keep its traffic under the radar. I’ll walk you through how it works and how it stays hidden.

References:
https://unit42.paloaltonetworks.com/new-linux-backdoor-auto-color
https://gist.github.com/MalGamy12/fe4ab3d60fcb923fb96a7c968adf0e04
https://zw01f.github.io/malware%20analysis/auto-color/

🐶 Snyk is free forever. Check it out here - https://snyk.co/pwnfunction]]></itunes:summary>
      <itunes:image href="https://i.ytimg.com/vi/iTT2AYE2IMQ/maxresdefault.jpg"></itunes:image>
      <itunes:duration>9:16</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <itunes:order>2</itunes:order>
    </item>
    <item>
      <guid>rgsIkZkflMw</guid>
      <title>2 Bytes Was Enough To Breach The US Treasury</title>
      <link>https://youtube.com/watch?v=rgsIkZkflMw</link>
      <description>In this episode we&#39;ll explore a bug in postgres.&#xA;&#xA;🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction&#xA;&#xA;🐤 X: https://twitter.com/PwnFunction</description>
      <pubDate>Fri, 07 Mar 2025 15:52:27 +0000</pubDate>
      <enclosure url="https://podsync.watzinger.biz/pwnfnk/rgsIkZkflMw.mp4" length="25876474" type="video/mp4"></enclosure>
      <itunes:author>PwnFunction</itunes:author>
      <itunes:subtitle>2 Bytes Was Enough To Breach The US Treasury</itunes:subtitle>
      <itunes:summary><![CDATA[In this episode we'll explore a bug in postgres.

🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction

🐤 X: https://twitter.com/PwnFunction]]></itunes:summary>
      <itunes:image href="https://i.ytimg.com/vi/rgsIkZkflMw/maxresdefault.jpg"></itunes:image>
      <itunes:duration>8:31</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <itunes:order>3</itunes:order>
    </item>
    <item>
      <guid>-h_rj2-HP2E</guid>
      <title>How To Predict Random Numbers Generated By Computers</title>
      <link>https://youtube.com/watch?v=-h_rj2-HP2E</link>
      <description>In this episode we&#39;ll break the Math.random method in JavaScript with z3.&#xA;&#xA;🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction&#xA;&#xA;⭐ Randomness Predictor: https://github.com/PwnFunction/v8-randomness-predictor&#xA;⭐ Z3 Challenges: https://github.com/PwnFunction/learn-z3&#xA;&#xA;✨ Info&#xA;➜ Tools used are: https://tools.pwnfunction.com/&#xA;➜ Video Production time(Research to Output): 100-ish hours.&#xA;➜ About 2L of Almond milk &amp; 3.5L of Gatorade were consumed during the video creation.&#xA;&#xA;💬 Discord: https://discord.gg/6KKQHvgJwv&#xA;🐤 Twitter: https://twitter.com/PwnFunction&#xA;&#xA;🎵 Track: Lost Sky - Dreams&#xA;NCS link: https://www.youtube.com/watch?v=SHFTHDncw0g</description>
      <pubDate>Thu, 14 Jul 2022 11:30:04 +0000</pubDate>
      <enclosure url="https://podsync.watzinger.biz/pwnfnk/-h_rj2-HP2E.mp4" length="59498880" type="video/mp4"></enclosure>
      <itunes:author>PwnFunction</itunes:author>
      <itunes:subtitle>How To Predict Random Numbers Generated By Computers</itunes:subtitle>
      <itunes:summary><![CDATA[In this episode we'll break the Math.random method in JavaScript with z3.

🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction

⭐ Randomness Predictor: https://github.com/PwnFunction/v8-randomness-predictor
⭐ Z3 Challenges: https://github.com/PwnFunction/learn-z3

✨ Info
➜ Tools used are: https://tools.pwnfunction.com/
➜ Video Production time(Research to Output): 100-ish hours.
➜ About 2L of Almond milk & 3.5L of Gatorade were consumed during the video creation.

💬 Discord: https://discord.gg/6KKQHvgJwv
🐤 Twitter: https://twitter.com/PwnFunction

🎵 Track: Lost Sky - Dreams
NCS link: https://www.youtube.com/watch?v=SHFTHDncw0g]]></itunes:summary>
      <itunes:image href="https://i.ytimg.com/vi/-h_rj2-HP2E/maxresdefault.jpg"></itunes:image>
      <itunes:duration>13:54</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <itunes:order>4</itunes:order>
    </item>
    <item>
      <guid>eTcVLqKpZJc</guid>
      <title>Dangerous Code Hidden in Plain Sight for 12 years!</title>
      <link>https://youtube.com/watch?v=eTcVLqKpZJc</link>
      <description>In this episode we&#39;ll explore a local privilege escalation vulnerability in polkit&#39;s pkexec.&#xA;&#xA;🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction&#xA;&#xA;⭐ Code + All Resources: https://github.com/PwnFunction/CVE-2021-4034&#xA;&#xA;✨ Info&#xA;➜ Tools used are: Adobe Animate, Adobe Premiere Pro, Adobe Illustrator &amp; Adobe Auditions.&#xA;➜ VSCode: Monokai Pro Theme, Jetbrains Mono Font, SF Mono Font.&#xA;➜ Video Production time: 80-ish hours.&#xA;➜ About 2.5L of Almond milk were consumed during the video creation.&#xA;&#xA;💬 Discord: https://discord.gg/6KKQHvgJwv&#xA;🐤 Twitter: https://twitter.com/PwnFunction&#xA;&#xA;🎵 Track: Lost Sky - Dreams&#xA;NCS link: https://www.youtube.com/watch?v=SHFTHDncw0g</description>
      <pubDate>Fri, 08 Apr 2022 16:47:39 +0000</pubDate>
      <enclosure url="https://podsync.watzinger.biz/pwnfnk/eTcVLqKpZJc.mp4" length="62075748" type="video/mp4"></enclosure>
      <itunes:author>PwnFunction</itunes:author>
      <itunes:subtitle>Dangerous Code Hidden in Plain Sight for 12 years!</itunes:subtitle>
      <itunes:summary><![CDATA[In this episode we'll explore a local privilege escalation vulnerability in polkit's pkexec.

🐶 Snyk is free forever. Sign up with my link https://snyk.co/pwnfunction

⭐ Code + All Resources: https://github.com/PwnFunction/CVE-2021-4034

✨ Info
➜ Tools used are: Adobe Animate, Adobe Premiere Pro, Adobe Illustrator & Adobe Auditions.
➜ VSCode: Monokai Pro Theme, Jetbrains Mono Font, SF Mono Font.
➜ Video Production time: 80-ish hours.
➜ About 2.5L of Almond milk were consumed during the video creation.

💬 Discord: https://discord.gg/6KKQHvgJwv
🐤 Twitter: https://twitter.com/PwnFunction

🎵 Track: Lost Sky - Dreams
NCS link: https://www.youtube.com/watch?v=SHFTHDncw0g]]></itunes:summary>
      <itunes:image href="https://i.ytimg.com/vi/eTcVLqKpZJc/maxresdefault.jpg"></itunes:image>
      <itunes:duration>18:00</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <itunes:order>5</itunes:order>
    </item>
  </channel>
</rss>