BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.hackfest.ca//hf2023
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hf2023-Q9MVYT@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T090000
DTEND;TZID=EST:20231013T095000
DESCRIPTION:Applications use secret servers to store the credentials requir
 ed for their day-to-day operations. Their usage increases as businesses im
 prove application security and follow best practices. When permissions giv
 en to an application are too broad\, the secret server becomes a central p
 oint of failure that can represent a new kind of weak link for an organiza
 tion. It may be used as a stepping stone to further compromise the network
 .\n\nAs an attacker\, when you compromise an application that can access a
  secret server and leak its credentials\, the next logical step is to remo
 tely access the secrets contained in the secret server. However\, it can b
 e tedious to thoroughly abuse secret servers within the duration of a secu
 rity assessment. Even more so when credentials obtained in the secret serv
 er can connect to the secret server themselves\, and recursivity comes int
 o play. Recursive extraction of credentials is useful to get the full pote
 ntial out of your obtained accesses. A tool to tackle the issue will be re
 leased and detailed.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Weaponizing and auditing secret servers for further compromise - Si
 mon Lacasse
URL:https://cfp.hackfest.ca/hf2023/talk/Q9MVYT/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-F783UL@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T090000
DTEND;TZID=EST:20231013T095000
DESCRIPTION:Le protocole RDP (Remote Desktop Protocol) est un vecteur d'att
 aque critique utilisé par des acteurs malveillants\, notamment par les gr
 oupes de rançongiciel.  Pour étudier les attaques RDP\, nous avons cré
 é PyRDP\, un outil d'interception RDP open source doté de capacités in
 égalées qui nous a permis de collecter plus de 100 heures de séquences 
 vidéo d'attaquants en action.\n\nPour décrire les comportements des atta
 quants\, nous avons caractérisé les différents archétypes d'attaquants
  en fonction de leurs caractéristiques à travers une analogie de Donjon 
 et Dragon : 1) les bardes effectuant des recherches obtuses\; 2) les rodeu
 rs explorent furtivement les ordinateurs et effectuent de la reconnaissanc
 es \; 3) les voleurs tentent de monétiser l'accès RDP \; 4) les barbares
  utilisent une large gamme d'outils pour attaquer davantage d'ordinateurs 
 \; et 5) les magiciens utilisent leur accès RDP comme portail magique pou
 r dissimuler leurs origines.\n\nCette présentation démontre l’impressi
 onnante capacité d'interception RDP pour les bénéfices de la recherche 
 et les équipes de défense.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Une surveillance RDP sans précédent révèle le savoir-faire des 
 attaquants - Andreanne Bergeron
URL:https://cfp.hackfest.ca/hf2023/talk/F783UL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-ADCHRP@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T090000
DTEND;TZID=EST:20231013T095000
DESCRIPTION:I'll show you an analysis of 3 cloud hacking tools that were ta
 ken from the underground. These tools are being used these days by hackers
  and being sold/downloadable on the Darknet and other hackers forums. You 
 will be amazed how simple to use these tools are and how easy it is to ope
 rate them. These tools are the first phase of hacking cloud accounts and e
 mails. We will focus on brute force and password spraying tools\, show you
  the tools\, what they are doing and a deep analysis of the tools includin
 g decryption of their encrypted communication. To wrap it up we will talk 
 about the current landscape changes of cloud attacks.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:The Dark side of Cloud attack tools (underground style) - Yaniv Mir
 on
URL:https://cfp.hackfest.ca/hf2023/talk/ADCHRP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-DTF3C8@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T100000
DTEND;TZID=EST:20231013T105000
DESCRIPTION:La cybersécurité\, ce n'est pas important \; jusqu'à ce que 
 ça le devienne. Nous allons voir le cas d'une PME qui a décider d'agir A
 VANT que quelque chose arrive en implantant les contrôles CyberSécuritai
 re Canada !
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Agir AVANT - Jacques Sauve
URL:https://cfp.hackfest.ca/hf2023/talk/DTF3C8/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-HAK8SR@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T100000
DTEND;TZID=EST:20231013T105000
DESCRIPTION:Jedi contre les hackers est un conférence sur le Darkweb et le
 s groupes de hackers. Elle permet d'apprendre à rechercher des informatio
 ns exfiltré facilement sur les sites de 50 groupes de hackers actif. Elle
  démontre la facilité et comment agir avec un client ou une personne qui
  se retrouve avec des informations exfiltrés. Elle a été donné à trav
 ers le monde : Las Vegas\, République dominicaine\, Calgary\, Toronto\, N
 ew York bientôt Paris et Dubai. Elle est en français ou anglais.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Jedi Contre les hackers - Simon David Williams\, Audrey Shink
URL:https://cfp.hackfest.ca/hf2023/talk/HAK8SR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-AEQMVB@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T110000
DTEND;TZID=EST:20231013T115000
DESCRIPTION:Passkeys are the future of authentication. Moving beyond passwo
 rds to Passkeys and WebAuthN provides a significant security upgrade for e
 nd users. But what are penetration testers that have relied on weak passwo
 rds to do? In this talk I will explore the attack surface of Passkeys and 
 identify the viable paths to help pentesters identify vulnerabilities and 
 achieve account takeovers. A new BurpSuite plugin will also be dropped to 
 automate the tricky parsing of Passkey objects and identify vulnerabilitie
 s in Passkey implementations.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:You Won’t Own Passwords\, and You’ll Like It - Alex Cowperthwaite
URL:https://cfp.hackfest.ca/hf2023/talk/AEQMVB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-RUNDRV@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T110000
DTEND;TZID=EST:20231013T115000
DESCRIPTION:# Résumé:\nNous avons tous des parcours différents\, cela fa
 it que nous n'avons pas le même niveau de connaissances de Git. Certains 
 ont fait un parcours réseau\, administratif\, sécurité offensive/défen
 sive ou encore en programmation. Cela explique la différence de niveau et
  c'est normal. La chose que j'ai découverte avec le temps c'est qu'il y a
  peu de gens qui sont confortables à utiliser Git\, malgré que plusieurs
  de ces personnes l'utilisent pour fréquemment.\n\nLe but de cette prése
 ntation est de vous familiariser avec certains aspects de Git\, du dévelo
 ppement de type DevOps avec les pipelines (CI/CD) en plus de vous donnez d
 es avenues de solution pour vous permettre de vous améliorer.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Dans le monde de Git - De Zéro à Héros - Félix Lehoux
URL:https://cfp.hackfest.ca/hf2023/talk/RUNDRV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-KQGZLF@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T110000
DTEND;TZID=EST:20231013T115000
DESCRIPTION:Threat hunting is both an art and a science. In this session\, 
 we’ll cover the basics of threat hunting\, what a well-architected progr
 am looks like\, lessons learned\, share ideas and concepts\, and conduct a
  live hunt. \n \nA proactive security team is an effective security team.\
 nLearn how we can reduce adversary dwell time and increase operational tem
 po with threat hunting over endpoint telemetry.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:The Art & Science of Threat Hunting Endpoint Signal - Andrew Munchb
 ach
URL:https://cfp.hackfest.ca/hf2023/talk/KQGZLF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-9BXV9C@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T120000
DTEND;TZID=EST:20231013T133000
DESCRIPTION:///EN\nThis is your chance to get behind the driver’s seat of
  the industry’s leading network security solutions. This workshop is cus
 tomized to enhance your understanding of how our products work and how the
 y can improve your organization’s security posture. We’ll take you ste
 p-by-step through each of our solutions\, with an expert instructor to gui
 de you.\n\n///FR\nVoici l'opportunité de prendre le volant du pare-feu ch
 ef de file de l'industrie de la sécurité des réseaux. Cette session vou
 s permettra d'augmenter votre compréhension de nos pare-feux\, comment le
 s opérer\, en tirer la valeur pour ultimement\, augmenter la posture de s
 écurité de votre organisation. Nous vous guiderons étape par étape à 
 travers la solution avec un instructeur expert pour vous soutenir.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Ultimate Test Drive - Next-Generation Firewalls - Guillaume Roy
URL:https://cfp.hackfest.ca/hf2023/talk/9BXV9C/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-WN3KKJ@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T133000
DTEND;TZID=EST:20231013T142000
DESCRIPTION:Les entreprises par leur transformation numérique se doivent d
 e prendre conscience tout comme tout le monde\, que nous sommes très dép
 endants des TI maintenant et nous nous devons au quotidien toujours avoir 
 un plan "B". \n\nRemplissage 150 mots // Remplissage 150 mots // Remplissa
 ge 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage
  150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 1
 50 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150
  mots // Remplissage 150 mots // Remplissage 150 mots // \nRemplissage 150
  mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 m
 ots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mot
 s // \nRemplissage 150 mots // Remplissage 150 mots // Remplissage 150 mot
 s // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots 
 // Remplissage 150 mots // \nRemplissage 150 mots // Remplissage 150 mots 
 // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots //
  Remplissage 150 mots // Remplissage 150 mots //
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Avons-nous amélioré notre résilience à l’évolution technolog
 ique en 25 ans ? - Steve Waterhouse
URL:https://cfp.hackfest.ca/hf2023/talk/WN3KKJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-Q9WGGG@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T133000
DTEND;TZID=EST:20231013T142000
DESCRIPTION:As mobile devices have become increasingly prevalent\, the secu
 rity of Android applications has become a critical concern. \nPentesting i
 s an essential process for identifying and mitigating potential vulnerabil
 ities in these applications\, but Android app hacking is a specialized are
 a that is less well-documented than other pentesting techniques. \nIn this
  session\, the focus will be on how to pentest Android apps and their APIs
 . \n\nThe presentation will address key questions such as what Android pen
 testing is\, how to set up an Android App pentest lab\, and how to pentest
  an Android App and its APIs from start to finish. \n\nParticipants will l
 eave the session with tips and resources for learning\, practicing\, and s
 etting up a complete set of tools for Android application pentesting\, inc
 luding detailed examples on a purposefully vulnerable application. \nThe g
 oal is to equip attendees with the knowledge and skills necessary to condu
 ct thorough and effective pentests of Android applications.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Android Application and APIs hacking - Gabrielle Botbol
URL:https://cfp.hackfest.ca/hf2023/talk/Q9WGGG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-7NFLVW@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T133000
DTEND;TZID=EST:20231013T143000
DESCRIPTION:Step into the exciting world of the Cortex Xpanse Capture the F
 lag challenge! This game invites participants to journey through the Expan
 der UI\, tackling a series of intricate challenges. For each challenge con
 quered\, players will be rewarded with a "flag" and earn valuable points. 
 The ultimate glory goes to the team or individual who unravels the most my
 steries and accumulates the highest score. By participating\, you not only
  get a hands-on experience with Cortex Xpanse but also indulge in a fun\, 
 immersive competition. This event is tailored to both seasoned pros and en
 thusiastic newcomers. Are you up for the challenge? Dive in\, learn\, comp
 ete\, and emerge victorious!\n\nThis game\, with a duration of one hour\, 
 calls on participants to explore the Expander interface. Make sure to brin
 g your laptop to take part in this challenge.\n\n=========\n\nEntrez dans 
 l'univers palpitant du défi Capture the Flag de Cortex Xpanse! Ce jeu inv
 ite les participants à s'aventurer dans l'interface Expander\, en affront
 ant une série de défis élaborés. Chaque défi surmonté récompensera 
 les joueurs avec un "drapeau" et leur permettra de gagner des points préc
 ieux. La gloire suprême est décernée à l'équipe ou à l'individu qui 
 dévoile le plus de mystères et obtient le score le plus élevé. En part
 icipant\, vous bénéficiez non seulement d'une expérience pratique avec 
 Cortex Xpanse\, mais vous vous immergez aussi dans une compétition amusan
 te et immersive. Cet événement est adapté aussi bien aux professionnels
  chevronnés qu'aux novices enthousiastes. Êtes-vous prêt à relever le 
 défi? Plongez\, apprenez\, concourez et triomphez!"\n\n\nCe jeu\, d'une d
 urée d'une heure\, sollicite les participants à explorer l'interface d'E
 xpander. Assurez-vous d'apporter votre ordinateur portable pour participer
  à ce défi.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:CORTEX XPANSE CAPTURE THE FLAG: Where in the World are Your Exposur
 es? - Patrick Hamel
URL:https://cfp.hackfest.ca/hf2023/talk/7NFLVW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-ZTQ7DM@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T143000
DTEND;TZID=EST:20231013T145000
DESCRIPTION:Static Application Security Testing (SAST) enables organization
 s to detect vulnerabilities in code early\; however\, interviews with appl
 ication security analysts indicate that SAST reports are often dense and i
 nclude little to no visual aids. \n\nOver the Winter and Spring of 2023\, 
 my research partner and I invented the Abstract Syntax Tree Reader and Ana
 lyzer (ASTRA) which responds to this need of a value-adding and intuitive 
 visual aid for more rapid and thorough consumption of SAST insights. ASTRA
  is a collection of Python scripts that transforms certain parts of SAST d
 ocumentation a Universal Graph Format which can be imported into many grap
 hical visualization tools.\n\nThe key insight from our research is that vu
 lnerability stack traces\, which are spread sparsely in the report and oft
 en overlooked by security analysts\, can be collected and graphed to provi
 de new vulnerability information. Once graphed\, principles of graph theor
 y can be applied to make calculations. These include calculating the subst
 ructure entropy to discover surprising occurrences and calculating the mod
 ularity for the number of vulnerability communities in code repositories. 
 Further\, calculating the eigenvector centrality allows us to see the exte
 nt to which each individual vulnerability contributes to the overall vulne
 rability graph of the application. \n\nAs a result\, the files contributin
 g most to the vulnerability profile of the application will be identified.
  Sections of the applications that are most vulnerable will also be able t
 o be identified. Our transformed ASTRA data has been successfully uploaded
  into standard 2D and 3D graphing engines\, as well as Virtual Reality (VR
 ) simulations so analysts are able to explore SAST results more intuitivel
 y\, bringing more humanity and rigorous calculation into cyber analysis.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:How a Global Retail Hack Breathed Life Into Static Security Analysi
 s - Naeem Budhwani
URL:https://cfp.hackfest.ca/hf2023/talk/ZTQ7DM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-Q99AGU@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T143000
DTEND;TZID=EST:20231013T152000
DESCRIPTION:Many information security professionals recommend VPN services 
 to end-users\, especially to protect against the dreaded man-in-the-middle
  attack on your local coffee shop's open Wi-Fi network.  The commercial VP
 N vendors advertise heavily\, making bold statements such as  "we encrypt 
 your network data so no one can see what you’re doing"\,  "surf the web 
 without a trace!"\, "avoid government eavesdropping"\, and assure you that
   "your web traffic can't be tracked anymore".   These claims are all "sna
 ke oil"\, and attendees will watch them be debunked. The actual benefits a
 nd limitations of VPNs will be reviewed\, and a discussion of the myriad w
 ays that are  used to surveil your online activities that go far beyond br
 owser cookies . Some tactics to minimize and mitigate this online tracking
  will be discussed\, as well as what it takes to be truly untraceable onli
 ne.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:VPNs are Internet snake oil - James Troutman
URL:https://cfp.hackfest.ca/hf2023/talk/Q99AGU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-BWKUFD@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T143000
DTEND;TZID=EST:20231013T152000
DESCRIPTION:In the field of digital forensics\, the analysis of volatile me
 mory\, commonly known as RAM\, has emerged as a powerful technique for unc
 overing critical digital evidence. As cybercriminals become increasingly s
 ophisticated in their methods\, traditional disk-based forensic approaches
  may miss crucial information stored solely in the volatile memory. This t
 alk aims to shed light on the significance of RAM forensic analysis and it
 s role in modern investigations.\nDuring the presentation\, we will explor
 e the intricacies of RAM forensic analysis\, from its foundations to advan
 ced techniques used to extract valuable artifacts. Attendees will gain ins
 ights into the wealth of information stored in RAM\, such as running proce
 sses\, network connections\, open files\, and cryptographic keys\, and how
  it can be leveraged to reconstruct events and attribute actions to specif
 ic actors.\nThe talk will cover a range of topics\, including the acquisit
 ion and preservation of RAM\, memory imaging\, analysis methodologies\, an
 d the utilization of specialized tools for efficient examination. Real-wor
 ld case studies will be presented to showcase the practical application of
  RAM forensic analysis in various scenarios\, such as malware investigatio
 ns\, data breaches\, and incident response.\nFurthermore\, the presentatio
 n will delve into the challenges and limitations associated with RAM foren
 sic analysis\,\n\nBy attending this talk\, forensic professionals\, incide
 nt responders\, and cybersecurity experts will gain a deeper understanding
  of the immense value of RAM forensic analysis in modern investigations. T
 hey will acquire practical knowledge\, techniques\, and tools that can enh
 ance their capabilities in uncovering digital footprints\, attributing act
 ions\, and ultimately\, advancing the field of digital forensics.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Exploring RAM Forensic Analysis for Effective Digital Investigation
 s - Sneha Banerjee
URL:https://cfp.hackfest.ca/hf2023/talk/BWKUFD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-ASRMBB@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T150000
DTEND;TZID=EST:20231013T152000
DESCRIPTION:As Cloud computing evolves\, adversaries can take advantage of 
 new attack surfaces and services. The threat actors are deploying sophisti
 cated campaign strategies to abuse millions of dollars in cloud computing 
 in compromised tenants and subscriptions while avoiding detection. Microso
 ft's research reveals that targeted organizations faced more than $300\,00
 0 in compute fees from cryptojacking attacks.\n\n\nIn this talk\, we will 
 explore the attackers’ behaviours that we observed in numerous incidents
  across many organizations. We will dissect the inner workings of cloud at
 tacks such as cryptojacking and resource abuse. As we move from the Initia
 l Access stage to the Impact stage\, we will explore key TTPs (Tactics\, T
 echniques\, and Procedures). Additionally\, we will explore several ways t
 hat threat actors can abuse and hijacking subscriptions that are forensica
 lly disruptive. By analyzing footprints and logs\, we will provide insight
 s that blue teamers can use to detect and counterattack these at early sta
 ge of attacks
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Cryptojacking: Defending against cloud compute resource abuse - Ami
 r Gharib
URL:https://cfp.hackfest.ca/hf2023/talk/ASRMBB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-U8AXSF@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T153000
DTEND;TZID=EST:20231013T162000
DESCRIPTION:Épiées\, suivies\, tourmentées : 70% des victimes de violenc
 e conjugales rapportent de la violence technologique. Alors que l'environn
 ement techno autour des victimes se complexifient\, comment peut-on travai
 ller à augmenter la littératie numérique auprès des populations vulné
 rables et mettre en place des outils de soutien.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Combattre la violence technologique - Catherine Dupont-Gagnon
URL:https://cfp.hackfest.ca/hf2023/talk/U8AXSF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-F7FZUR@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T153000
DTEND;TZID=EST:20231013T162000
DESCRIPTION:Dans un contexte de pénurie de talents en cybersécurité et d
 e menaces de plus en plus complexes\, l'automatisation est un concept trè
 s important dans n'importe quel centre d'opérations de cyberdéfense (SOC
 ). Un SOAR est un outil d'automatisation pour les SOCs. Dans ce talk\, nou
 s allons démystifier ce qu'est un SOAR\, ce que ça permet de faire et de
  ne pas faire\, proposer une feuille de route pour maximiser la valeur qu'
 un SOC peut tirer de cet outil et partager des astuces pour bien choisir e
 t utiliser un SOAR. Le contenu est tiré de notre expérience des trois de
 rnières années à développer des automatisations pour notre grand SOC.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Automatiser la Cyberdéfense: feuille de route et trucs pour bien s
 'en SOARtir - Émilio Gonzalez
URL:https://cfp.hackfest.ca/hf2023/talk/F7FZUR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-GVFX3J@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T153000
DTEND;TZID=EST:20231013T155000
DESCRIPTION:Concours de tatouage\, vol de bus\, détournement de panneau pu
 blicitaire\, "black friday" et soldes\, Etc. Le blackmarket a évolué\, e
 n 30 ans\, pour proposer un marketing de la malveillance agressif.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Les nouveaux "Business" du blackmarket - Damien Bancal
URL:https://cfp.hackfest.ca/hf2023/talk/GVFX3J/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-GHPW9Y@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T160000
DTEND;TZID=EST:20231013T173000
DESCRIPTION:///EN\nThis is your chance to get behind the driver’s seat of
  the industry’s leading network security solutions. This workshop is cus
 tomized to enhance your understanding of how our products work and how the
 y can improve your organization’s security posture. We’ll take you ste
 p-by-step through each of our solutions\, with an expert instructor to gui
 de you. Learn how to protect your network and detect known\, unknown and z
 ero-day threats 180X faster than any other platform or point solution – 
 all within a single\, integrated best-of-breed security platform.\n\n///FR
 \nVoici l'opportunité de prendre le volant du pare-feu chef de file de l'
 industrie de la sécurité des réseaux. Cette session vous permettra d'au
 gmenter votre compréhension de nos pare-feux\, comment les opérer\, en t
 irer la valeur pour ultimement\, augmenter la posture de sécurité de vot
 re organisation. Nous vous guiderons étape par étape à travers la solut
 ion avec un instructeur expert pour vous soutenir.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Ultimate Test Drive - Cloud Delivered Security Services - Guillaume
  Roy
URL:https://cfp.hackfest.ca/hf2023/talk/GHPW9Y/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-KUUB8L@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T163000
DTEND;TZID=EST:20231013T172000
DESCRIPTION:Découvrez l'impressionannte mobilisation technologique ukraini
 enne: combat dans le cyberespace et sur les réseaux sociaux\, drones modi
 fiés\, IT Army et OSINT.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:War from home: la technologie au service de la mobilisation ukraini
 enne - Gabrielle Joni Verreault\, Luc Lefebvre
URL:https://cfp.hackfest.ca/hf2023/talk/KUUB8L/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-ZGFADY@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T163000
DTEND;TZID=EST:20231013T172000
DESCRIPTION:Conditional Access in Microsoft Azure Active Directory\, when t
 ied with Mobile Application Management and Mobile Device Management in Mic
 rosoft Intune are the core pillars for building zero trust based access co
 ntrols in Microsoft 365 and Azure published services. We will cover MDM an
 d MAM policies\, how Intune device compliance is applied to Conditional Ac
 cess by Intune\, when deploying authentication and most importantly a test
 ed model for layered access\, specifically as it relates to M365 in a vari
 ety of trust states.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Unconditionally Conditional - Strong Authentication in Azure AD - D
 on Mallory
URL:https://cfp.hackfest.ca/hf2023/talk/ZGFADY/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-SWWCDY@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T173000
DTEND;TZID=EST:20231013T175000
DESCRIPTION:"Rubber DuckHunt"\, un outil innovant pour détecter et contrer
  les attaques de keystroke injection\, une menace souvent négligée depui
 s sa popularisation par le Rubber Ducky\; je souhaite présenter et partag
 er cet outil en exclusivité lors de la conférence.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Rubber DuckHunt - Détection d'un classique - Eric M. Gagnon
URL:https://cfp.hackfest.ca/hf2023/talk/SWWCDY/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-CGJ3ES@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T173000
DTEND;TZID=EST:20231013T175000
DESCRIPTION:In this talk the author proposes a novel method for interceptin
 g phone calls over PSTN\, including mobile networks.\nWe'll briefly each d
 iscuss the necessary components of the attack\, including Caller ID spoofi
 ng\, SS7\, call diverts\, and social engineering\, and then join the all t
 ogether to form the novel attack method.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:MITM on PSTN -- novel methods for intercepting phone calls - Kirils
  Solovjovs
URL:https://cfp.hackfest.ca/hf2023/talk/CGJ3ES/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-CXGCQZ@cfp.hackfest.ca
DTSTART;TZID=EST:20231013T205500
DTEND;TZID=EST:20231013T225500
DESCRIPTION:Joignez-vous à nous pour cette tradition annuel du Podcast en 
 direct lors de la 2e soirée du Hackfest!\nOpinions\, actualités\, poutin
 e et assurément quelques dérapages seront au rendez-vous pour discuter d
 e tout ce qui entour la sécurité de l'information!
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Podcast La French Connection - Épisode LIVE (salle 201A) - L'équi
 pe de La French Connection
URL:https://cfp.hackfest.ca/hf2023/talk/CXGCQZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-8B3QB8@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T090000
DTEND;TZID=EST:20231014T095000
DESCRIPTION:In the rapidly evolving landscape of gaming\, understanding the
  realm of game hacking is essential\, especially in multiplayer games. Whi
 le some people engage in game hacking for fun or as a hobby\, others use i
 t to cheat and gain an advantage in online multiplayer games\, which can r
 uin the experience for other players. As we delve together into this capti
 vating subject\, I will explore the fundamentals of game hacking\, includi
 ng its definition\, real-world examples\, common methods employed by hacke
 rs\, and the measures implemented to counter such exploits.\n\nDiscover th
 e intriguing world of cheats\, bots\, and exploits that have impacted the 
 gaming industry. I will showcase notable instances where game hacking has 
 disrupted fair play and affected player experiences. By examining these ex
 amples\, I aim to raise awareness about the potential consequences and imp
 lications of game hacking. Furthermore\, we will delve into the various te
 chniques employed by hackers\, such as memory editing\, code injection\, a
 nd packet manipulation. Understanding these methods is vital to recognize 
 vulnerabilities and formulating effective countermeasures.\n\nThe discussi
 on will also encompass the proactive steps taken by game developers to com
 bat cheating\, including encryption\, client-server validation\, behavior 
 monitoring\, and regular updates. By understanding these anti-cheat measur
 es\, we can gain insights into the ongoing battle between game developers 
 and hackers. Lastly\, we will explore the future of game hacking within th
 e broader information security landscape\, considering emerging technologi
 es\, evolving security measures\, and the potential impact on the gaming i
 ndustry.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:GamePwn 101 - Introduction to Game Hacking - James Li
URL:https://cfp.hackfest.ca/hf2023/talk/8B3QB8/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-SKGTQ9@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T090000
DTEND;TZID=EST:20231014T095000
DESCRIPTION:Outillez votre cyberdéfense en apprenant à naviguer dans la m
 atrice des tactiques et techniques utilisées par les cybercriminels et le
 urs écosystèmes !\n\nCette présentation est conçue tant pour les gesti
 onnaires que les professionnels de la cybersécurité et de la gouvernance
  de la sécurité de l'information souhaitant développer leurs connaissan
 ces du domaine des opérations de cybersécurité en commençant par les p
 lus jeunes à qui je parlerai du programme MITRE ATT&CK Defender™ (MAD) 
 ATT&CK®.\n\nAu fil des ans\, le MITRE ATT&CK® s'est immiscé dans les op
 érations de cybersécurité au point de devenir un standard de facto. Mai
 s de quoi s'agit-il ?\n\nApprenez comment opérationnaliser ce qui n’est
  ni un produit ni une technologie dans les pratiques de cyberenseignement 
 (CTI)\, chasse aux cybermenaces (TH) et simulations de cyberattaques (AE) 
 ou encore comment renforcer la valeur du centre de gestion des opérations
  de cybersécurité (SOC). \n\nEnfin\, que vous disposiez de l'expertise o
 u que vous fassiez appel à un fournisseur de services gérés\, découvre
 z comment intégrer l'approche MITRE ATT&CK® dans votre stratégie global
 e de sécurité de l'information en évaluant votre posture de cyberdéfen
 se afin d'aligner vos contrôles avec les mécanismes de détection et de 
 réponse requis.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:La meilleure cyberdéfense\, c'est l'ATT&CK® - Christophe Reverd
URL:https://cfp.hackfest.ca/hf2023/talk/SKGTQ9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-7FMB8N@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T100000
DTEND;TZID=EST:20231014T102000
DESCRIPTION:This talk offers a concise introduction to web scraping techniq
 ues using Python\, focusing on automated data extraction from websites. We
 b scraping enables the systematic collection of web data for various purpo
 ses\, including content aggregation\, research\, job hunting\, social medi
 a analysis\, and monitoring legal and compliance issues. It is also a valu
 able tool for preserving government data\, as evidenced during Donald Trum
 p's presidency when various government website data\, such as climate chan
 ge information and LGBTQ+ resources\, were altered or removed. This compre
 hensive overview equips attendees with a versatile toolkit for extracting 
 valuable web data.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Web Scraping Unleashed: Mastering Techniques for Data Harvesting - 
 Wendy Edwards
URL:https://cfp.hackfest.ca/hf2023/talk/7FMB8N/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-XRQDEH@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T100000
DTEND;TZID=EST:20231014T105000
DESCRIPTION:Security monitoring in any environment is made or broken by the
  signal quality in the event logs. With mass migration to the cloud\, defe
 nders are putting all of their logging capability "eggs" in one provider's
  "basket". This works when the logging facilities are well designed and wo
 rk robustly\, but what do you do when issues arise?\n\nIn this talk\, we w
 ill examine logging facilities in Azure (concentrating on events generated
  by Azure AD and Microsoft 365) and discuss multiple problems that we have
  observed in monitoring them. \n \nThese include:  \n- Blind spots hiding 
 critical security events\n- Poorly documented events\, attributes and magi
 c values \n- Missing important information about user actions\n- Bugs in l
 og records \n- Unannounced changes that break detection queries\n- Log pol
 lution opportunities\, potentially leading to RCE \n- and more \n\nWe will
  examine impact of these issues on defense and monitoring\, opportunities 
 for red-teamers\, and the ways the cloud provider can address the problems
  going forward.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Between a Log and a Hard Place: (mis)Adventures in Azure Logs - Dmi
 triy Beryoza
URL:https://cfp.hackfest.ca/hf2023/talk/XRQDEH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-WQMGUN@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T100000
DTEND;TZID=EST:20231014T105000
DESCRIPTION:LastPass is a popular password manager used from individuals th
 rough corporate levels. However\, in 2022 it suffered two breaches\, and o
 nly recently was the extent of the damage made known. An unknown attacker 
 was able to take the literal keys to the kingdom\, compromising everything
  stored in the LastPass vaults.  This talk will bring to light why the Las
 tPass events matter to everyone\, even those who think they are safe using
  other password managers or no password managers. There are lessons here a
 bout sophisticated staged attacks that bypass defenses in place\, and the 
 increasing onus on businesses to manage IAM and BYOD
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Lessons from LastPass: Beyond Secure Password Management - Cheryl B
 iswas
URL:https://cfp.hackfest.ca/hf2023/talk/WQMGUN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-UHGLNE@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T103000
DTEND;TZID=EST:20231014T123000
DESCRIPTION:Let's get hands on and dive into the marvelous world of "artifi
 cial intelligence" and "prompt engineering"!\n\nThis session will cover tw
 o CTF challenges based on Stable Diffusion which is a model capable of gen
 erating photo-realistic images given any text input. This will show in a p
 ractical fashion some real impact of something otherwise artificial.\n\nTh
 e challenges are going to be solved step by step alongside a dive into dif
 fusion models and technical details on machine learning.\n\nWe will provid
 e a dedicated online environment that requires low computing power on your
  end to do prompt hacking and try out Stable Diffusion.\n\nPrerequisites:\
 nThis workshop supports three levels of technical readiness:\n1) To partic
 ipate in prompt hacking\, bring any laptop or cellphone with a Web browser
 \n2) For a more low-level challenge\, bring a laptop with Python installed
 \n3) To optionally play with Stable Diffusion tools locally\, a laptop wit
 h dedicated 3D graphic card is required\n\nL'aide aux participants en Fran
 çais sera aussi disponible.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Stable Diffusion Workshop - Jonathan Marcil
URL:https://cfp.hackfest.ca/hf2023/talk/UHGLNE/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-XARKMK@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T110000
DTEND;TZID=EST:20231014T115000
DESCRIPTION:Ever wondered if Skynet could run a fake news empire and win a 
 Pulitzer? This is CounterCloud\, a two month online experiment that is par
 t 'Terminator\,' part 'Black Mirror\,' and takes us deep into the wild fro
 ntier of totally autonomous AI-generated disinformation.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Hacking Reality: CounterCloud's AI-Driven Disinformation Campaign -
  MJ Banias\, N
URL:https://cfp.hackfest.ca/hf2023/talk/XARKMK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-Y8VWXL@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T110000
DTEND;TZID=EST:20231014T115000
DESCRIPTION:During the pandemic I took up Bluetooth (BT) sniffing as a way 
 to get out of the house. \n\nBluedriving left me with questions that are d
 ifferent from those you'd ask based on traditional WiFi wardriving. Is the
 re a geographic correlation between poverty\, obesity\, and BT sleep apnea
  medical devices? What are the implications of BT on police body cameras? 
 Are fitness trackers still making it easy to track humans instead? Can som
 eone steal heavy-construction equipment thanks to BT keyless ignition? Can
  hackers be tracked by their "portable multi-tool[s]"? Do hotels using BT 
 door locks "open the door" to easier assassinations?\n\nIn this talk I wil
 l share some of the most interesting observations from the past few years\
 , and share surprising answers to the above questions\, and more.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:It was harder to sniff Bluetooth through my mask during the pandemi
 c... - Xeno Kovah
URL:https://cfp.hackfest.ca/hf2023/talk/Y8VWXL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-QC9U39@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T133000
DTEND;TZID=EST:20231014T135000
DESCRIPTION:We'll be taking a look into the history and technical evolution
  of wiper malware\, starting from Shamoon all the way to the modern-day wi
 pers found in the Russia-Ukraine conflict.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:A Primer on Wipers - Ali Maredia
URL:https://cfp.hackfest.ca/hf2023/talk/QC9U39/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-MXJBJB@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T133000
DTEND;TZID=EST:20231014T142000
DESCRIPTION:How the placement of your security program may be impacting you
 r organization.\n\nLorraine: Marty\, this may seem a little forward\, but 
 I was wondering if you would ask me to the Enchantment Under the Sea Dance
  on Saturday?
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Enchantment under the C - Patrick\, Kendra Cooley
URL:https://cfp.hackfest.ca/hf2023/talk/MXJBJB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-8ZYFHT@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T133000
DTEND;TZID=EST:20231014T142000
DESCRIPTION:This talk revisits the theme of personal privacy in the digital
  world\, this time centring around the "I've got nothing to hide" argument
 . A beam of intensive light is shed on the motivation behind caring about 
 one's privacy. We go in depth into what we can do to stay private and shou
 ld we even try to do it at all. We talk about where we as an global societ
 y were able to fix privacy and where we have failed. New topics previously
  not covered are discussed\, such as AI/LLMs.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:NOTH1NG T0 HID3 - Kirils Solovjovs
URL:https://cfp.hackfest.ca/hf2023/talk/8ZYFHT/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-Z9GXQD@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T140000
DTEND;TZID=EST:20231014T142000
DESCRIPTION:Le phénomène de la "fatigue des alertes" ("alert/ticket fatig
 ue" en anglais) est bien réel et affecte probablement la majorité des or
 ganisations possédant un SOC. Les différentes solutions de sécurité g
 énèrent de plus en plus d'alertes et afin d'éviter au maximum l'épuise
 ment de nos équipes qui peuvent traiter des faux positifs à répétition
 \, il faut repenser à notre stratégie vis-à-vis celles-ci. Une piste in
 téressante est la mise en place des alertes basées sur le risque\, somma
 irement\, les deux principaux avantages seraient de réduire le nombre de 
 faux positifs et d'également détecter des événements qui individuellem
 ent n'auraient potentiellement pas levé d'alertes.
DTSTAMP:20260815T124210Z
LOCATION:Workshops & Speed
SUMMARY:Réduire les faux positifs et utiliser les alertes basées sur le r
 isque (Risk-based alerting/RBA) - Jean-Francois Brouillette
URL:https://cfp.hackfest.ca/hf2023/talk/Z9GXQD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-9MHUNS@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T143000
DTEND;TZID=EST:20231014T152000
DESCRIPTION:A buzzword for years\, Artificial intelligence (AI) has evolved
  into a powerful\, accessible tool and\, like any tool\, it can be used fo
 r evil. How can AI technology be harnessed by adversaries (or you) as part
  of sophisticated information security attacks? What sort of attacks are w
 e seeing in the wild and how can we prepare for the new offensive techniqu
 es?
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Artificial Intelligence / Real Threats - Johnny Xmas\, Chris Carlis
URL:https://cfp.hackfest.ca/hf2023/talk/9MHUNS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-K7SXNK@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T143000
DTEND;TZID=EST:20231014T152000
DESCRIPTION:On trouve sur Facebook des annonces ou des vedettes québécois
 es semblent faire la promotion de pilules pour perdre du poids sans effort
 s ou encore « avoir des érections comme dans 18 ans »! Malheureusement\
 , des gens tombent dans le panneau et ça peut leur coûter cher. \n\nL’
 émission d’enquête J.E. nous a demandé de l’aide pour dénicher les
  responsables de ces arnaques. À l’aide du Cycle du renseignement nous 
 allons explorer les bases de l’OSINT. Nous verrons ce que c’est et ce 
 que ce n’est pas\, ainsi que les précautions à prendre durant ce type 
 d’enquête.\n\nUn stratagème comme celui-ci nécessite plusieurs acteur
 s. Nous montrerons les étapes qui ont mené à la cartographie du réseau
 \, à l’identification de certaines personnes impliquées et comment la 
 photo d'un chien nous a mis sur la piste de son adresse.
DTSTAMP:20260815T124210Z
LOCATION:Track #2
SUMMARY:Des pilules pour maigrir? L’OSINT pour démasquer un réseau inte
 rnational de fraude en ligne - Sam Harper
URL:https://cfp.hackfest.ca/hf2023/talk/K7SXNK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-BHXGYC@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T153000
DTEND;TZID=EST:20231014T162000
DESCRIPTION:This presentation delves into the realm of cloud computing's se
 curity challenges and the Red Team perspective. It sheds light on intrusio
 n testing\, shared security models\, and vulnerabilities unique to cloud s
 ystems. The discussion covers cloud intrusion testing's importance\, metho
 dologies\, and distinctiveness compared to traditional approaches. Identit
 y and Access Management's crucial role will be highlighted and explain thr
 ough the 3 main CSP AWS/Azure/GCP\, their main differences and security im
 plication. The talk will outlines reasons for conducting Red Team engageme
 nts focusing on critical resource access. Applied assessment methodologies
  are proposed\, including BlackBox\, AssumBreach\, and White Box approache
 s. Attack scenarios\, based on the Mitre Att&ck Cloud Matrix framework\, a
 re explored\, encompassing various stages. The presentation also delves in
 to using the cloud offensively (Redirectors\, storage and delivery)\, clou
 d-based phishing and Oauth abuse. The aim is to facilitate knowledge excha
 nge\, encourage research\, and enhance cloud security by leveraging Red Te
 am insights.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Cloud environments: Red Team perspectives - Clément Cruchet
URL:https://cfp.hackfest.ca/hf2023/talk/BHXGYC/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-KBCULM@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T163000
DTEND;TZID=EST:20231014T165000
DESCRIPTION:Web 3.0 smart contracts\, like the ones found on Ethereum\, bri
 ng promises of speed\, decentralization\, and security. Although DeFi's mo
 del may seem complex\, these projects still can be vulnerable to relativel
 y simple attacks like domain takeovers. In this beginner-friendly talk\, w
 e discuss how I discovered dangling DNS on several decentralized crypto ex
 changes and my experiences trying to responsibly disclose vulnerabilities 
 to them.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Smart Contracts\, Not So Smart Bugs: Crypto Domain Takeovers - Mich
 ael Be
URL:https://cfp.hackfest.ca/hf2023/talk/KBCULM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2023-WVDD9Y@cfp.hackfest.ca
DTSTART;TZID=EST:20231014T170000
DTEND;TZID=EST:20231014T175000
DESCRIPTION:Hackfest 2023 - La revue du CTF et des activitées\, remises de
 s prix\, black coins\, etc. Hackfest 2023 - La revue du CTF et des activit
 ées\, remises des prix\, black coins\, etc.
DTSTAMP:20260815T124210Z
LOCATION:Track #1
SUMMARY:Hackfest Closing Ceremony - Hackfest Communication
URL:https://cfp.hackfest.ca/hf2023/talk/WVDD9Y/
END:VEVENT
END:VCALENDAR
