BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.hackfest.ca//hf-2021-cfp
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-CSJJUF@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T090000
DTEND;TZID=EST:20211119T110000
DESCRIPTION:Docker is one of the trending technologies that rules the IT ec
 osystem. \nMany companies have started to adapt the usage of docker in the
 ir companies. While  Docker offers a high level of scalability and portabi
 lity\, security can fall into the sidelines.Like many other technologies\,
  it is not safe by default. We have to take certain steps to make sure tha
 t the docker deployment is safe and secure. \n\nThis workshop introduces t
 he attendees to docker basics\, discuss various security problems in the d
 efault configuration and also discuss the various defense mechanisms.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:Defenders Guide to the Container Ecosystem - Joshua
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/CSJJUF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-X7KNDZ@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T090000
DTEND;TZID=EST:20211119T095000
DESCRIPTION:It is undeniable that sensors are the backbone for any IoT\, sm
 art devices or Industrial Control Systems and have been playing an importa
 nt role in the technology world. They play a major role in taking inputs f
 rom the surrounding and giving output to the respective systems.\nBut what
  if these sensor based systems operate in an unintended manner? What if th
 eir inputs inadvertently lead to compromising the system? Also\, how often
  do organizations talk about security in Sensors? In this talk we will dis
 cuss various attacks which can be used to hack sensor based systems using 
 Physics. This talk will also discuss some mitigations for such attacks.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Hacking with Physics - Hrishikesh Somchatwar
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/X7KNDZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-LNSNTP@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T100000
DTEND;TZID=EST:20211119T102000
DESCRIPTION:Ever wondered your presence exposed to an unknown entity even w
 hen you are promised for full security and discretion in a hotel? Well\, i
 t would be scary to know that the hospitality industry is a prime board no
 wadays for cyber threats as hotels offer many opportunities for hackers an
 d other cybercriminals to target them and therefore resulting in data brea
 ches. Not just important credit card details are a prime reason\, but also
  an overload of guest data\, including emails\, passport details\, home ad
 dresses and more. Marriot International where 500 million guests' private 
 information was compromised sets for one of the best examples. Besides dat
 a compromise\, surgical strikes have been conducted by threat actors again
 st targeted guests at luxury hotels in Asia and the United States. The adv
 anced persistent threat campaign called Darkhotel infected wifi-networks a
 t luxury hotels\, prompted the victim to download the malware and thus\, s
 ucceeded in specifically targeting traveling business executives in a vari
 ety of industries and all its prevalence seems to have no end yet. \n\nFor
  a broader look\, this time a popular internet gateway device for visitor 
 based networks commonly installed in hotels\, malls and other places that 
 provides guests temporary access to Wi-Fi was examined. To see\, how the g
 uests and the hotels both have a serious stake in this\, we will discourse
  about the working of guest Wi-Fi systems\, different use cases and their 
 attack surfaces: device exploitation\, network traffic hi-jacking\, access
 ing guest's details and more. Common attacks and their corresponding defen
 ses will be discussed. This talk will contain demos of attacks to reveal h
 ow the remote exploitation of such a device puts millions of guests at ris
 k.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:The Great Hotel Hack: Adventures in attacking hospitality industry 
 - Etizaz Mohsin
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/LNSNTP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-9VY9BV@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T103000
DTEND;TZID=EST:20211119T112000
DESCRIPTION:Retours d'expériences réelles d'une équipe de réponse à in
 cident confrontée\, au quotidien\, à des incidents de sécurités et cel
 a dans plusieurs compagnies. Nous évoquerons principalement les cas des a
 ttaques par rançongiciel\, leur méthode\, les impacts\, etc.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:De la fiction à la réalité\, retours d’expériences d’une é
 quipe de réponses aux incidents - Bruno PHILIPPE\, Jordan MICHALLET
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/9VY9BV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-D37PHX@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T110500
DTEND;TZID=EST:20211119T112500
DESCRIPTION:This presentation will dive into multiple SQL injections faced 
 in the field and showcase spicy SQL injections that go from exploiting int
 eractive display terminals of a mall center to AWS WAF bypass using a scie
 ntific notation parser bug in MySQL. In addition\, we will be sharing tech
 niques to help you find SQL Injections.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:SQL Injection Is Still Alive: From a Mall's Interactive Terminal to
  AWS WAF Bypass - Marc Olivier Bergeron
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/D37PHX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-RP3EYJ@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T113000
DTEND;TZID=EST:20211119T122000
DESCRIPTION:An introduction to 100 (more or less ^_- ) useful security rela
 ted tools in 50 minutes.  It will be quick\, but just enough for you to sa
 y: "Oh\, that's cool!"
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Security Tools 101: Tools of the Trade - Josh Galvez
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/RP3EYJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-W3YTQS@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T113000
DTEND;TZID=EST:20211119T153000
DESCRIPTION:This is an introduction to crypto: building blocks\, protocols 
 and attacks on them. We cover: encoding vs encryption\, hashes\, ‘classi
 c’ crypto\, stream ciphers\, block ciphers\, symmetric crypto\, asymmetr
 ic crypto\, has attacks\, classic crypto attacks\, stream cipher attack\, 
 block cipher attack models\, ECB attacks\, crypto protocols\, digital sign
 atures\, message authentication code\, nonces\, simple authentication\, ch
 allenge response\, simple authentication attacks (key collisions\, key ext
 raction and extension\, replay\, valet\, bad counter resync)\, MAC attacks
 \, digital signature attacks\, pubkey substitution\, challenge response at
 tacks (middleperson attack\, UDS style seed-key predictions)\, WPA2 passwo
 rd cracking\, WPA2 key reinstallation\, WPA2 key nulling\, TLS/SSL middlep
 erson attacks\, SWEET32\, DROWN\, logjam\, POODLE\, UDS seed-key exchange 
 attacks (reverse key algorithm\, lift key algorithm\, solve for unknowns\,
  retry-retry-retry\, brute force\, glitch past).\n\nTools covered include:
  rumkin.com\, hashcat\, john the ripper\, binwalk\, radare2\, binvis.io\, 
 Veles\, airocrack-ng\, mitmproxy\, MITMf.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:Crypto 101: How Crypto Gets Broken (by you) - Ben Gardiner
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/W3YTQS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-VK78LZ@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T123000
DTEND;TZID=EST:20211119T132000
DESCRIPTION:Divers intervenants discuteront de ce que devrait avoir l'air l
 'éducation du numérique\, en termes de sécurité informatique\, vie pri
 vée et autres sujets reliés.  L'idée provient de récentes mention de c
 hangements à faire dans le cours d'ÉCR et un intérêt pour enseigner la
  culture du numérique.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Table ronde sur l'éducation en matière de sécurité de l'informa
 tion et vie privée - Steve Waterhouse\, Serge Tremblay\, Gabrielle Joni V
 erreault\, Julie April\, Luc Lefebvre
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/VK78LZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-TTWWUP@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T133000
DTEND;TZID=EST:20211119T142000
DESCRIPTION:Les cadres normatifs peuvent faire peur aux gestionnaires de PM
 E qui y voient surtout d'importantes dépenses pour la mise en place. De p
 lus\, en PME\, les techniciens sont souvent des généralistes sans format
 ion spécifique en cybersécurité.  L'utilisation d'un cadre de normatif 
 permet de se remettre en question\, d'évaluer ses pratiques et d'établir
  un plan d'action pour assurer une meilleure sécurité pour sa PME.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:L'importance d'un cadre de conformité en PME - Steve Lavoie
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/TTWWUP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-7Q3XL9@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T143000
DTEND;TZID=EST:20211119T152000
DESCRIPTION:As Marc Andreesen so aptly noted “Software is eating the worl
 d”. Our technology-driven world increasingly relies on third party code\
 , open source libraries and shared repositories. We don’t fully apprecia
 te just how interconnected we are\, and how that translates into software 
 code dependencies. It took an event like the SolarWinds Orion attack to ra
 ttle the bars on that cage\, and wake us up to what’s been going on for 
 some time. The reality is that software supply chain attacks aren’t new.
  They’ve been around for many years\, and we’ve been watching that che
 ck engine light but not really addressing the issues. Recent attacks show 
 how easy it is to create confusion and send malicious code undetected thro
 ugh automated channels to trusting recipients. SolarWinds delivered a hard
  truth to defenders: everyone is vulnerable when trust can be abused. Wher
 e is the weakest link in your software supply chains of trust?
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Signed\, Sealed\, Delivered: Abusing Trust in Software Supply Chain
  Attacks - Cheryl Biswas
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/7Q3XL9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-LE7398@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T153000
DTEND;TZID=EST:20211119T162000
DESCRIPTION:In a modern hospital\, protocols are required to allow differen
 t departments to communicate to each other.  HL7's FHIR is the next genera
 tion of the most widely used of these protocols.  This talk is about the f
 orm of the protocol\, vulnerabilities and CVEs discovered during research 
 into the protocol that could lead to everything from account compromise to
  completely disabling a hospital's electronic medical record system (EMRs)
 \, as well as design flaws that may lead to significant misconfigurations 
 in deployments.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:I'm Not A Doctor\, I Just Play One On HTTP: Vulnerabilities in HL7 
 FHIR - Zachary Minneker
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/LE7398/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-KVHR9T@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T153000
DTEND;TZID=EST:20211119T162000
DESCRIPTION:In this talk\, Tim Allsopp from TELUS will present his approach
  to the analytics and making the most of your organization's haystack of s
 ecurity control data via the TELUS Security Ecosystem Report. And with it\
 , his view of how analytics can help the front-line practitioner inform an
 d refine cybersecurity activities at their organization\, regardless of si
 ze or complexity.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:How to Eat an Elephant – Security analytics and navigating organi
 zational and technical complexity - Tim Allsopp
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/KVHR9T/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-BRH87A@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T163000
DTEND;TZID=EST:20211119T172000
DESCRIPTION:In this talk we will go through a common approach used in asses
 sing Windows based enterprise implementations. It will describe the common
  security misconfigurations that adversaries positioned on the internal ne
 twork can exploit to compromise authentication credentials and enumerate h
 osts within the network.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:The Legacy of Windows Enterprise Authentication: Are you safe from 
 the "Man In The Middle"? - Tarl Bitz
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/BRH87A/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-C8HVKC@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T163000
DTEND;TZID=EST:20211119T172000
DESCRIPTION:Est-il réaliste que les entreprise de toutes tailles sauront s
 'adapter et appliquer une gestion plus saine de l'informaiton avant la mis
 e en oeuvre de la loi 64 ?  Il reste moins de 2 ans....
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Développer une culture de la sécurité de l'information - Steve W
 aterhouse
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/C8HVKC/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-MTEGLA@cfp.hackfest.ca
DTSTART;TZID=EST:20211119T183000
DTEND;TZID=EST:20211119T223000
DESCRIPTION:Heap exploitation is an incredibly powerful tool for a hacker. 
 As exploit mitigations have made exploitation more difficult\, modern expl
 oit development has moved to the heap. However\, heap exploitation is a su
 bject that has evaded many people for years for one reason: they focus on 
 the techniques instead of the allocator. By learning with an allocator fir
 st style\, the techniques are easily understood and practical to use. \n\n
 This workshop is for learning heap exploit development in GLibC Malloc\, w
 hich is the deallocate allocator on most Linux distros. With this hands-on
  introduction into GLibC Malloc heap exploitation you will learn how the a
 llocator functions\, heap specific vulnerability classes and how to pwn wi
 th a variety of techniques. Whether you're an avid CTFer\, trying to beat 
 a pwnables challenge or exploiting 0-days\, this course is good for adding
  another tool to the tools arsenal. After taking this course you will unde
 rstand the GLibC Malloc allocator\, be able to discover heap specific vuln
 erability classes and pwn the heap with a variety of techniques\, with the
  capability to easily learn more.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:House of Heap Exploitation - Maxwell Dulin\, ging3r
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/MTEGLA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-LNLKZ7@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T090000
DTEND;TZID=EST:20211120T130000
DESCRIPTION:Want to learn the world’s most popular penetration testing fr
 amework but never had the time? This intensive workshop is your chance to 
 get up to speed with Metasploit and go from zero to hero in 4 hours!\n\nPl
 ease carefully check the prerequisites below!!!
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:Metasploit 101 - Amiran Alavidze\, Dan Reimer
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/LNLKZ7/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-VDJYV8@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T100000
DTEND;TZID=EST:20211120T105000
DESCRIPTION:Botnets and DDoS\, these words are never too far apart. However
 \, DDoS is just the tip of the iceberg for what botnets are actually used 
 for in the cybercrime community. Money talks - and botnets are the supply 
 side of cybercrime that drive multiple different campaigns like phishing\,
  exploit kit delivery\, adware and banking trojans.\n\nThis talk uncovers 
 the complex structure of cybercrime and how most criminal campaigns are li
 nked to botnets as their supply and delivery mechanism. We will explore th
 e economy of cybercrime and calculate in figures the amount of money renti
 ng a botnet or building a botnet can profit cybercriminals. You will learn
  exactly how and what botnets are used for outside DDOS and you will walk 
 away understanding how phishing/spam emails or banking trojans link back t
 o botnets. Afterall\, how can you protect against criminals without unders
 tanding them? \n\nFinally\, I will present my Crime Economy map which I’
 ve designed that maps out the hierarchy and the revenue streams derived fr
 om hiring botnets to run coordinated campaigns. This aims to assist blue t
 eams have a better understanding about the criminals they’re protecting 
 against.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:World War Three: Battle of the Bots - inversecos
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/VDJYV8/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-V9HB83@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T110000
DTEND;TZID=EST:20211120T115000
DESCRIPTION:Après avoir accompagnée plusieurs personnes dans la recherche
  de leur première expérience ou stage\, j'ai constaté que souvent\, les
  ''entry level'' ne savent pas forcément quelle est la marche à suivre e
 t surtout\, qui sont les donneurs de stages.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Décrocher son stage ou sa première expérience en TI - Karolynn
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/V9HB83/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-ESXTKU@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T120000
DTEND;TZID=EST:20211120T125000
DESCRIPTION:This talk will provide an inside peak from the U.S.' efforts to
  secure the research\, development\, and distribution of the COVID-19 vacc
 ines\, including the tools & methodologies used to rapidly secure the end-
 to-end vaccine creation\, as well as the current state of security of the 
 vaccine supply chain.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Ready...Set...Secure all the COVID vaccines! - Daniel Bardenstein
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/ESXTKU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-3ARGWF@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T130000
DTEND;TZID=EST:20211120T132000
DESCRIPTION:Aujourd'hui\, les réseaux sociaux font partie intégrante de n
 otre vie quotidienne. Nous y partageons des moments de notre vie\, des pho
 tos\, des opinions et des informations personnelles. Mais savons-nous vrai
 ment comment protéger notre vie privée sur ces plateformes ? Sommes-nous
  conscients des risques liés à la sécurité de nos comptes ?
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Réseaux sociaux et vie privée: Les dangers et les bonnes pratique
 s à adopter - Julien Teste-Harnois
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/3ARGWF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-STDRUF@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T133000
DTEND;TZID=EST:20211120T135000
DESCRIPTION:Comment faire le grand saut vers le domaine de la sécurité ? 
 Les parcours possibles\, les formations\, les certifications\, comment s
 ’entrainer\, mais surtout comment y avoir le Mindset pour ensuite surviv
 re dans le domaine ? C’est ce que je vais traiter en parlant de mon parc
 ours personnel et faisant également part des témoignages d’autres pers
 onnes en sécurité.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Le grand saut en Cybersécurité - Danny Boivin - Narcomed
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/STDRUF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-JCGNLL@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T140000
DTEND;TZID=EST:20211120T145000
DESCRIPTION:Attackers have looked all around for means to compromise organi
 zations through developers: malicious 3rd party packages\, leaked credenti
 als\, unpatched vulnerabilities\, and more. But the place that has become 
 the new threat laid under their nose: the IDE.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:1-click to infiltrate your org via vulnerable VS Code extensions - 
 Raul Onitza-Klugman\, Kirill Efimov
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/JCGNLL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-NTSMAR@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T140000
DTEND;TZID=EST:20211120T145000
DESCRIPTION:How are CDW Canada\, Google and Intel accelerating growth\, dri
 ving innovation\, increasing coworker engagement\, and fostering coordinat
 ion? They are all using OKRs (Objective Key Results)\; a simple yet effect
 ive approach to achieve operating excellence.\n\n Join Darren as he shares
  how OKRs are driving growth\, innovation\, and engagement for the Risk Ad
 visory Services team at CDW Canada.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:The OKRs to driving growth\, innovation and engagement - Darren Chi
 n
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/NTSMAR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-BDET9E@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T150000
DTEND;TZID=EST:20211120T155000
DESCRIPTION:Ransomware attacks are sudden and one click away. For this reas
 on\, we should assume that ransomware attack will occur and be prepared fo
 r handling ransomware incident.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Ransomware Hunt and Incident Response - Mehtap Erdogan
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/BDET9E/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-83SD9W@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T150000
DTEND;TZID=EST:20211120T170000
DESCRIPTION:Load balancers and proxies\, such as HAProxy\, Varnish\, Squid 
 and Nginx\, play a crucial role in website performance\, and they all have
  different HTTP protocol parser implementation. HTTP Request Smuggling (HR
 S) is an attack abusing inconsistencies between the interpretation of requ
 ests’ ending by HTTP request parsers. What might be considered the end o
 f one request for your load balancer might not be considered as such by yo
 ur web server. \n\nWe will see how an attacker can abuse several vulnerabl
 e configurations. HTTP Request Smuggling (HRS) enables multiple attack vec
 tors\, including cache poisoning\, credential hijacking\, URL filtering by
 pass\, open-redirect and persistent XSS. For each of these vectors\, a pay
 load will be showcased and explained in-depth. Also\, a live demonstration
  will be made to see the vulnerability in action. Aside from exploitation\
 , we will show how developers and system administrators can detect such fa
 ulty configurations using automated tools. \n\nThroughout the session\, si
 mple exercises will be given to participants to reproduce the exploitation
  of these vulnerabilities. A case of HTTP1 header confusion as well as mor
 e recent variants with the HTTP2 protocol will be exploited. To participat
 e in the workshop section\, you will need to install Burp Suite\, Docker a
 nd Python. \n\nBy the end of this workshop\, security enthusiasts from any
  level will have solid foundations to detect request smuggling\, a vulnera
 bility that has greatly evolved in the past 15 years.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:Request Smuggling Workshop - Philippe Arteau
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/83SD9W/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-HAPYSK@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T160000
DTEND;TZID=EST:20211120T165000
DESCRIPTION:Whether you are a builder or a defender\, keeping your applicat
 ions secure grows increasingly hard as they increase in number and complex
 ity\, especially without a proper game plan. This talk aims to explore a s
 olution in Threat Modeling\,  a process that enables developers and securi
 ty professionals alike to pinpoint security requirements and identify weak
 nesses and vulnerabilities before they make it into a product as well as q
 uantify threat and prioritize remediation efforts for existing vulnerabili
 ties.
DTSTAMP:20260909T160938Z
LOCATION:Hackfest - Track 1
SUMMARY:Threat modeling: Field guide to staying ahead of the bad guys - sdu
 ssault
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/HAPYSK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-H899ER@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T170500
DTEND;TZID=EST:20211120T175500
DESCRIPTION:Discussion is in French\, but slides will be in English! Prizes
  and summary of the CTFs (Casual\, Beginner and Casual) will be discussed.
  The team will be presented along with the challenges.
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:CTF Ceremony 2021 - Hackfest CTF Team
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/H899ER/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf-2021-cfp-EHTEHV@cfp.hackfest.ca
DTSTART;TZID=EST:20211120T180000
DTEND;TZID=EST:20211120T210000
DESCRIPTION:Venez participer en direct avec l'équipe de La French Connecti
 on à une petite rétrospective de l'année. Le tout accompagné de nouvel
 les\, discussions et d'opinions... dans un format UNIQUE... en vidéo!
DTSTAMP:20260909T160938Z
LOCATION:Sponsors - Workshops
SUMMARY:Podcast - La French Connection LIVE (French) - Patrick\, Steve Wate
 rhouse\, L'équipe de La French Connection\, Vanessa Henri\, Guillaume Mor
 issette\, Richer Dinelle\, Jacques Sauvé\, Damien Bancal
URL:https://cfp.hackfest.ca/hf-2021-cfp/talk/EHTEHV/
END:VEVENT
END:VCALENDAR
