{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.1.2"}, "schedule": {"url": "https://cfp.hackfest.ca/hf2023/schedule/", "version": "0.3.12", "base_url": "https://cfp.hackfest.ca", "conference": {"acronym": "hf2023", "title": "Hackfest 2023 - Back to the Future", "start": "2023-10-13", "end": "2023-10-14", "daysCount": 2, "timeslot_duration": "00:05", "time_zone_name": "Canada/Eastern", "colors": {"primary": "#FF412F"}, "rooms": [{"name": "Track #1", "slug": "11-track-1", "guid": "a85147b3-5077-56b1-949e-fcadf114be10", "description": null, "capacity": 300}, {"name": "Track #2", "slug": "12-track-2", "guid": "e809644b-0286-5bfa-9e77-ed883a8bd743", "description": null, "capacity": 300}, {"name": "Workshops & Speed", "slug": "13-workshops-speed", "guid": "8d7e8810-8b3b-5b9f-b9c9-74dd294f70db", "description": null, "capacity": 100}], "tracks": [{"name": "Offensive", "slug": "16-offensive", "color": "#F70F47"}, {"name": "Defensive", "slug": "17-defensive", "color": "#1703FF"}, {"name": "Threat Intelligence / OSINT", "slug": "18-threat-intelligence-osint", "color": "#000000"}, {"name": "Mental Health", "slug": "19-mental-health", "color": "#FE13D1"}, {"name": "Security Programs/Management", "slug": "21-security-programsmanagement", "color": "#A1A1A1"}, {"name": "Sponsor", "slug": "22-sponsor", "color": "#99A100"}, {"name": "Security 101", "slug": "23-security-101", "color": "#00AB07"}, {"name": "Hardware/IoT", "slug": "20-hardwareiot", "color": "#6D0C9A"}, {"name": "Privacy", "slug": "24-privacy", "color": "#BF9002"}, {"name": "Ai Security", "slug": "25-ai-security", "color": "#4426C6"}], "days": [{"index": 1, "date": "2023-10-13", "day_start": "2023-10-13T04:00:00-04:00", "day_end": "2023-10-14T03:59:00-04:00", "rooms": {"Track #1": [{"guid": "56c6b3ac-2893-5bb6-aeee-1d959294cc41", "code": "Q9MVYT", "id": 217, "logo": null, "date": "2023-10-13T09:00:00-04:00", "start": "09:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-217-weaponizing-and-auditing-secret-servers-for-further-compromise", "url": "https://cfp.hackfest.ca/hf2023/talk/Q9MVYT/", "title": "Weaponizing and auditing secret servers for further compromise", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "en", "abstract": "Applications use secret servers to store the credentials required for their day-to-day operations. Their usage increases as businesses improve application security and follow best practices. When permissions given to an application are too broad, the secret server becomes a central point of failure that can represent a new kind of weak link for an organization. It may be used as a stepping stone to further compromise the network.\r\n\r\nAs an attacker, when you compromise an application that can access a secret server and leak its credentials, the next logical step is to remotely access the secrets contained in the secret server. However, it can be tedious to thoroughly abuse secret servers within the duration of a security assessment. Even more so when credentials obtained in the secret server can connect to the secret server themselves, and recursivity comes into play. Recursive extraction of credentials is useful to get the full potential out of your obtained accesses. A tool to tackle the issue will be released and detailed.", "description": "The target audience of this presentation is security professionals, application developers and application owners.\r\n\r\nThe presentation will start by explaining the concept of a secret server, or vault, and highlight why they are part of the current application security best practices. They empower administrators in the management of application credentials, they offer better storage options than the traditional methods such as on-disk storage and help greatly in maintaining an accurate inventory of accounts. Applications are given initial credentials, which may be Windows domain credentials, to connect to the secret server and gather all the other secrets they require for their normal operations. These new secrets can be usernames, passwords, RSA keys, certificates, files, etc.\r\n\r\nAs an attacker, when you compromise an application that can access a secret server and leak its credentials, the next logical step is to remotely access the secrets contained in the secret server. Doing so, you may gain access to hundreds of secrets. The obtained new secrets may also be able to connect to the secret server, and leak even more secrets, and so on and so forth. Some of them you may already have, some of them may be new. It results in a lot of data that requires processing, and a lot of attack surface to explore. It quickly gets tedious to audit and perform a thorough assessment. The recursive process of abusing secret server secrets in a tree-like fashion to gather an exponential number of secrets is a new concept that requires proper tooling and needs to be exploited in offensive security engagements.\r\n\r\nCurrently, there are no tools available to remotely interact with the secret server APIs and extract secrets recursively. Current tools dump and decrypt the databases when accessed on the local file system, but it is not a scenario that happens often as it requires compromising the secret server's machine itself. To tackle the problem, I developed a tool called SSCrawl. It is a multi-threaded recursive secret gatherer for secret servers. It supports multiple secret server vendors and is extendable to support even more. It will gather secrets for an account and use the found secrets to attempt to connect to the secret server recursively. An overview of the tool's implementation and features will be presented, along with a demo.\r\n\r\nSSCrawl also generates graphs of the compromised secrets for better visualization and to facilitate presenting the results to stakeholders. Graph demos will be shown to visualize the exploitation paths.\r\n\r\nSSCrawl will be released after the presentation.\r\n\r\nThe presentation will end with recommendations on how to prevent the issue by hardening accounts and monitoring secret server accesses.", "recording_license": "", "do_not_record": false, "persons": [{"code": "Q9EHAP", "name": "Simon Lacasse", "avatar": null, "biography": "Simon Lacasse works as a pentester at Desjardins, with a focus on company-wide objective-oriented security tests. He has a strong interest in web application and infrastructure security. With a background in software engineering, he enjoys making his own tools to solve the different problems at hand. When possible, he likes to give back to the community by making his tools public and open source. He is an alumni of the PolyHack/PolyHx cybersecurity club from Polytechnique Montreal.", "public_name": "Simon Lacasse", "guid": "d9693a7f-1f4b-5e04-9a6c-92090baf3aba", "url": "https://cfp.hackfest.ca/hf2023/speaker/Q9EHAP/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/Q9MVYT/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/Q9MVYT/", "attachments": []}, {"guid": "f7db7cdc-2266-537b-979f-79c2c775ae5a", "code": "DTF3C8", "id": 179, "logo": null, "date": "2023-10-13T10:00:00-04:00", "start": "10:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-179-agir-avant", "url": "https://cfp.hackfest.ca/hf2023/talk/DTF3C8/", "title": "Agir AVANT", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "fr", "abstract": "La cybers\u00e9curit\u00e9, ce n'est pas important ; jusqu'\u00e0 ce que \u00e7a le devienne. Nous allons voir le cas d'une PME qui a d\u00e9cider d'agir AVANT que quelque chose arrive en implantant les contr\u00f4les CyberS\u00e9curitaire Canada !", "description": "\u00c0 la base, la cybers\u00e9curit\u00e9 repose sur une bonne hygi\u00e8ne TI : s'occuper de ses syst\u00e8mes, de mettre en place des bons outils mais aussi des bonnes pratiques, faire en sorte que la cybers\u00e9curit\u00e9 fasse partie de la discussion corporative de tous les jours. Trop d'entreprises attendent qu'il soit trop tard - elles d\u00e9cident de se pr\u00e9occuper des ces enjeux seulement APR\u00c8S qu'il ait eu un \u00e9v\u00e8nement important.\r\nDans cette pr\u00e9sentation, nous allons examiner comment et pourquoi les PME sont si vuln\u00e9rables, et comment un entrepreneur a d\u00e9cid\u00e9 de prendre en main sa s\u00e9curit\u00e9 et de prioriser les efforts. Ensemble, nous avons implanter les contr\u00f4les de CyberS\u00e9curitaire Canada (non, on ne va pas passer \u00e0 travers tous les contr\u00f4les - il y a d\u00e9j\u00e0 eu des pr\u00e9sentations \u00e0 ce sujet !) ; nous allons voir le \"pratico-pratique\" de prot\u00e9ger son entreprise.\r\nEt bien s\u00fbr, pourquoi il est important d'agir AVANT !", "recording_license": "", "do_not_record": false, "persons": [{"code": "BWSKXG", "name": "Jacques Sauve", "avatar": null, "biography": "Jacques est un v\u00e9t\u00e9ran de 30 ans des technologies de l\u2019information. Il a \u00e9t\u00e9 chef d\u2019entreprise pendant 24 ans, \u00e0 la t\u00eate d\u2019une firme de consultation qui se sp\u00e9cialisait dans la gamme de produits Novell. Son \u00e9quipe et lui ont desservit des clients \u00e0 travers l\u2019Am\u00e9rique du nord, allant de la tr\u00e8s petite PME jusqu\u2019\u00e0 la grande entreprise. Il a travaill\u00e9 avec des syst\u00e8mes d\u2019exploitation NetWare, Linux, Windows, des solutions de courriel, de collaboration, de gestion d\u2019identit\u00e9s, de s\u00e9curit\u00e9, et autres services d\u2019infrastructure r\u00e9seau. Maintenant, apr\u00e8s une absence de 6 ans du Qu\u00e9bec, ayant v\u00e9cu et travaill\u00e9 en Alberta et en Irlande, Jacques s\u2019est install\u00e9 en Estrie et se concentre maintenant sur la cybers\u00e9curit\u00e9 pour les PMEs, voulant aider celles-ci \u00e0 mitiger le risque d\u2019une cyberattaque", "public_name": "Jacques Sauve", "guid": "e26afff3-2f59-5239-8c74-b6271ef98a84", "url": "https://cfp.hackfest.ca/hf2023/speaker/BWSKXG/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/DTF3C8/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/DTF3C8/", "attachments": []}, {"guid": "c1e05b3c-21a9-5d2d-9dc9-fd76c9a415d9", "code": "RUNDRV", "id": 203, "logo": "https://cfp.hackfest.ca/media/hf2023/images/RUNDRV/profile_jdPVBSK.jpg", "date": "2023-10-13T11:00:00-04:00", "start": "11:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-203-dans-le-monde-de-git-de-zero-a-heros", "url": "https://cfp.hackfest.ca/hf2023/talk/RUNDRV/", "title": "Dans le monde de Git - De Z\u00e9ro \u00e0 H\u00e9ros", "subtitle": "", "track": "Security Programs/Management", "type": "Regular Talk", "language": "fr", "abstract": "# R\u00e9sum\u00e9:\r\nNous avons tous des parcours diff\u00e9rents, cela fait que nous n'avons pas le m\u00eame niveau de connaissances de Git. Certains ont fait un parcours r\u00e9seau, administratif, s\u00e9curit\u00e9 offensive/d\u00e9fensive ou encore en programmation. Cela explique la diff\u00e9rence de niveau et c'est normal. La chose que j'ai d\u00e9couverte avec le temps c'est qu'il y a peu de gens qui sont confortables \u00e0 utiliser Git, malgr\u00e9 que plusieurs de ces personnes l'utilisent pour fr\u00e9quemment.\r\n\r\nLe but de cette pr\u00e9sentation est de vous familiariser avec certains aspects de Git, du d\u00e9veloppement de type DevOps avec les pipelines (CI/CD) en plus de vous donnez des avenues de solution pour vous permettre de vous am\u00e9liorer.", "description": "La pr\u00e9sentation se divise en **2** portions, la premi\u00e8re est sur **Git** et la deuxi\u00e8me est sur le d\u00e9veloppement de type DevOps en utilisant les **pipelines CI/CD**. La pr\u00e9sentation va se terminer sur les avenues de solution afin d'am\u00e9liorer son Git-fu.\r\n\r\n* Qu'est-ce que GIT?\r\n* Level 1 - Commandes Git\r\n* Level 2 - Les petites subtilit\u00e9s\r\n* Level 3 - Conflicts, Branches, Merge Request, Stash, etc.\r\n* Pipelines - CI/CD\r\n* Avenues de solutions\r\n\u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e \u200e", "recording_license": "", "do_not_record": false, "persons": [{"code": "RU8BEP", "name": "F\u00e9lix Lehoux", "avatar": null, "biography": "F\u00e9lix est un op\u00e9rateur Red Team chez Desjardins et il est passionn\u00e9 d'informatique, de s\u00e9curit\u00e9 et de d\u00e9fis. C'est avec la DCI (D\u00e9l\u00e9gation des comp\u00e9titions en informatique) qu'il a particip\u00e9 \u00e0 plusieurs CTF tout au long de son parcours acad\u00e9mique \u00e0 l'\u00c9TS. Entre les certifications en s\u00e9curit\u00e9 et le travail, F\u00e9lix a commenc\u00e9 une cha\u00eene YouTube orient\u00e9e sur la s\u00e9curit\u00e9, le Homelabing et le r\u00e9seautage. Ce projet le passionne et il a pour but de partager des connaissances avec les gens qui ont une passion, comme lui, pour l'informatique.", "public_name": "F\u00e9lix Lehoux", "guid": "3dc5a6f2-f66b-58fe-978a-23174073b63c", "url": "https://cfp.hackfest.ca/hf2023/speaker/RU8BEP/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/RUNDRV/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/RUNDRV/", "attachments": []}, {"guid": "45b82c28-ee45-5961-b794-d46cb28e0041", "code": "Q9WGGG", "id": 174, "logo": null, "date": "2023-10-13T13:30:00-04:00", "start": "13:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-174-android-application-and-apis-hacking", "url": "https://cfp.hackfest.ca/hf2023/talk/Q9WGGG/", "title": "Android Application and APIs hacking", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "en", "abstract": "As mobile devices have become increasingly prevalent, the security of Android applications has become a critical concern. \r\nPentesting is an essential process for identifying and mitigating potential vulnerabilities in these applications, but Android app hacking is a specialized area that is less well-documented than other pentesting techniques. \r\nIn this session, the focus will be on how to pentest Android apps and their APIs. \r\n\r\nThe presentation will address key questions such as what Android pentesting is, how to set up an Android App pentest lab, and how to pentest an Android App and its APIs from start to finish. \r\n\r\nParticipants will leave the session with tips and resources for learning, practicing, and setting up a complete set of tools for Android application pentesting, including detailed examples on a purposefully vulnerable application. \r\nThe goal is to equip attendees with the knowledge and skills necessary to conduct thorough and effective pentests of Android applications.", "description": "Outline\r\nWho am I?\r\nFrom blogger to pentester\r\nWhat is Android\r\nWhat is an Android App Pentest?\r\nWhy Android App Pentest? (example for KellyTech malware)\r\nSome figures (Impactful key figures in the Android vulnerabilities and attacks)\r\nWhat about Android APIs?\r\nAndroid App pentest process (Presentation of the different phases for this type of pentest)\r\nThe importance of the lab (Why this lab is different from labs of other pentests)\r\nWhich tools will you need (Presentation of Jadx, ADB, Android Studio and Burpsuite)\r\nHow to set up the lab\r\n\tInstallations\r\n\tCreate an emulator (video demo)\r\n\tConfigure Burp (video demo)\r\nDeep dive in the process\r\nPresentation of the vulnerable Apps used for the examples\r\nStatic Analysis\r\n\tHow to check the code\r\n\tExample Android Manifest, permissions\r\n\tExample Android Manifest, allow backup and debuggable\r\n\tFind the API endpoints\r\n\tHow are APIs called - Example\r\n\tFetch API Javascript - Example\r\n\tAPI vulnerabilities\r\n\tExample - Strings.xml (hardcoded API key)\r\n\tGrep it (how to use grep to search for secrets\r\n\tGeneral tips for static Analysis\r\n\tTools for static analysis (firebase enum, firebaseScanner, Cloud Enum)\r\nDynamic Analysis\r\n\tFind API endpoints\r\n\tExample - Background Capture (video demo)\r\n\tCommon API vulnerabilities to look for\r\n\tUse checklists\r\nAutomatic tools (Mobsf Qark)\r\nWhat about Mobile API vulnerabilities (A focus on specific API vulnerabilities and attack)\r\nHow to report\r\n\tMethodology\r\n\tExample of reporting (for the vulnerability BG capture)\r\nResources\r\n\tPractice\r\n\tCourses and Misc\r\n\tReferences and Reads\r\n\tTools\r\n\tGo Further with certificate pinning\r\nQuiz to go (a link to a an online quiz will be given)", "recording_license": "", "do_not_record": false, "persons": [{"code": "8NHMWW", "name": "Gabrielle Botbol", "avatar": null, "biography": "Gabrielle Botbol is a Pentester at Desjardins, the largest financial cooperative in North america. With a deep focus on the banking industry, Gabrielle specializes in exploring mobile applications and API.\r\nGabrielle is an avid blog writer who advocates for access to education for all. In addition, she has a large following on social media, where she shares many educational resources about technical training and many other cyber topics.\r\nShe actively contributes to various organizations as a member of their Advisory Board, such as APIsec University. She is a speaker and trainer at global events and prestigious universities, like Blackhat, APIsecure, Apidays, Bsides, Owasp, Cuny University, Toronto University\u2026\r\nWith her contributions to the community, Gabrielle has been the recipient of multiple prestigious awards. Among them, she was honored as one of the Top 20 women in cybersecurity in Canada, Pentest Ninja at WSCJ, Educator of the Year at AYA, Top Influencer in Cybersecurity by IFSEC Global, and Woman Hacker of the Year by CSWY.", "public_name": "Gabrielle Botbol", "guid": "56a356fa-d194-5c1f-be86-ee5892f04ec3", "url": "https://cfp.hackfest.ca/hf2023/speaker/8NHMWW/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/Q9WGGG/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/Q9WGGG/", "attachments": []}, {"guid": "d38cf3dd-a628-5865-ab47-4cafc6f4fd0b", "code": "BWKUFD", "id": 211, "logo": null, "date": "2023-10-13T14:30:00-04:00", "start": "14:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-211-exploring-ram-forensic-analysis-for-effective-digital-investigations", "url": "https://cfp.hackfest.ca/hf2023/talk/BWKUFD/", "title": "Exploring RAM Forensic Analysis for Effective Digital Investigations", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "en", "abstract": "In the field of digital forensics, the analysis of volatile memory, commonly known as RAM, has emerged as a powerful technique for uncovering critical digital evidence. As cybercriminals become increasingly sophisticated in their methods, traditional disk-based forensic approaches may miss crucial information stored solely in the volatile memory. This talk aims to shed light on the significance of RAM forensic analysis and its role in modern investigations.\r\nDuring the presentation, we will explore the intricacies of RAM forensic analysis, from its foundations to advanced techniques used to extract valuable artifacts. Attendees will gain insights into the wealth of information stored in RAM, such as running processes, network connections, open files, and cryptographic keys, and how it can be leveraged to reconstruct events and attribute actions to specific actors.\r\nThe talk will cover a range of topics, including the acquisition and preservation of RAM, memory imaging, analysis methodologies, and the utilization of specialized tools for efficient examination. Real-world case studies will be presented to showcase the practical application of RAM forensic analysis in various scenarios, such as malware investigations, data breaches, and incident response.\r\nFurthermore, the presentation will delve into the challenges and limitations associated with RAM forensic analysis,\r\n\r\nBy attending this talk, forensic professionals, incident responders, and cybersecurity experts will gain a deeper understanding of the immense value of RAM forensic analysis in modern investigations. They will acquire practical knowledge, techniques, and tools that can enhance their capabilities in uncovering digital footprints, attributing actions, and ultimately, advancing the field of digital forensics.", "description": "As a Threat Hunter, RAM forensic analysis is crucial in carrying out digital investigations for Rapid Incident Response as I often need to respond swiftly to emerging threats and security incidents and RAM forensic analysis enables quick access to volatile memory, providing valuable insights into the state of the system at the time of the incident. This allows Threat Hunters to identify active processes, network connections, malicious artifacts, and other critical indicators of compromise, facilitating faster incident response\r\n\r\nSophisticated attackers employ advanced techniques to evade detection, such as fileless malware and memory-resident threats. RAM forensic analysis enables me as a Threat Hunter to identify and analyze these stealthy attacks by examining memory artifacts and uncovering hidden indicators of compromise. This empowers Threat Hunters to detect and mitigate advanced threats that may bypass traditional security measures.RAM contains a wealth of digital artifacts, including running processes, network connections, and cryptographic keys. These artifacts can provide crucial insights into the activities and intentions of threat actors. \r\n\r\n\r\n\r\nI leverage RAM forensic analysis techniques to extract and analyze these artifacts, enabling deeper investigation and threat intelligence gathering.Some threats specifically target and reside in memory to carry out malicious activities. By focusing on memory analysis, I proactively hunt for memory-based threats, such as in-memory malware, code injection, or process hollowing techniques. This approach allows for the detection and remediation of threats that may go undetected by traditional signature-based security solutions. After an incident, I often engage in post-incident analysis and attribution to understand the root cause, scope, and impact of the attack. RAM forensic analysis provides valuable forensic evidence that can aid in this process. Memory artifacts can reveal attacker behaviors, persistence mechanisms, and even clues regarding their identity or affiliation. This information enhances the ability to attribute attacks to specific threat actors or groups. Through this presentation, I want to emphasize on how Memory forensics is  a powerful technique to augment every cybersecurity professional with  threat detection and response capabilities. By leveraging memory analysis, one can gain deeper insights into active threats, enhance incident response speed, and proactively hunt for memory-based attacks, ultimately strengthening their organization's overall cybersecurity posture. \r\n\r\nThe target audience for this talk on RAM forensic analysis can include Digital Forensic Analysts, Threat Hunters, Incident Responders, Cybersecurity Professionals, Law Enforcement Personnel and Security Researchers. \r\n\r\nFlow of the Talk:\r\n\r\nIntroduction (5 minutes):\r\n\u25cf\tOverview of the significance of RAM forensic analysis in digital investigations\r\n\u25cf\tExplanation of the objectives and structure of the talk\r\nUnderstanding Volatile Memory (5 minutes):\r\n\u25cf\tDefinition and explanation of volatile memory\r\n\u25cf\tDiscussion of the types of information stored in volatile memory\r\nMemory Acquisition Techniques (10 minutes)\r\n\u25cf\tLive memory acquisition: Explanation of the process and its advantages\r\n\u25cf\tMemory imaging: Overview of creating forensic images of volatile memory\r\nIntroduction to Memory Analysis Tools (5 minutes)\r\n\u25cf\tOverview of popular memory analysis tools such as Volatility\r\n\u25cf\tExplanation of the functionalities and capabilities of these tools\r\nAnalyzing Memory Artifacts (10 minutes)\r\n\u25cf\tExamination of key artifacts found in volatile memory\r\n\u25cf\tDemonstration of analyzing running processes, network connections, and open files\r\n\u25cf\tShowcase of extracting cryptographic keys and sensitive data from memory\r\n\r\n\r\nChallenges and Mitigation Strategies (5 minutes)\r\n\u25cf\tOverview of challenges faced in RAM forensic analysis\r\nConclusion and Takeaways (5 minutes)\r\n\u25cf\tRecap of key points discussed throughout the talk\r\n\u25cf\tEmphasis on the value of RAM forensic analysis in digital investigations\r\n\u25cf\tEncouragement for attendees to apply these techniques in their own work\r\nQ&A Session (5 minutes)\r\nOpportunity for the audience to ask questions and seek clarification on any topic covered in the talk\r\n\r\nKey Takeaways:\r\n\r\n\t- Memory Analysis Tools: Explore popular memory analysis tools like Volatility, and understand their functionalities and capabilities for efficient analysis of volatile memory.\r\n\r\n\t- Analyzing Memory Artifacts: Discover the types of valuable artifacts stored in volatile memory, including running processes, network connections, open files, cryptographic keys, and sensitive data, and learn techniques for extracting and analyzing these artifacts.\r\n\r\n\t- Detection of Memory-based Threats: Understand the concept of memory-based threats, such as in-memory malware and code injection, and learn proactive hunting techniques to detect and mitigate these stealthy threats.\r\n\r\n\t- Overcoming Challenges: Identify the challenges faced in RAM forensic analysis, including anti-forensic techniques and encryption, and gain insights into effective mitigation strategies and best practices.\r\n\r\n\t- Practical Application: Recognize the practical application of RAM forensic analysis in digital investigations, and be inspired to leverage these techniques to enhance incident response, threat hunting, and forensic analysis in your own work.\r\nBy the end of the talk, attendees will have a comprehensive understanding of RAM forensic analysis, its technical aspects, its value in digital investigations, and the practical knowledge to effectively utilize this technique in their own work.", "recording_license": "", "do_not_record": false, "persons": [{"code": "W3AF3D", "name": "Sneha Banerjee", "avatar": null, "biography": "I work as a Cyber Threat Hunt Analyst at Microsoft where I take proactive and iterative approach to research, hunt, and remove advanced threats that evade existing security solutions in Azure infrastructure. I focus on external adversaries (APT) and engage with threat intelligence to validate the existence of APT through research and hunt of Indicators of Compromise (IoCs), exploratory analysis of Tactics, Techniques, and Procedures (TTPs) and vectors, and discovery and analysis of potential adversary activity. I also conduct deep dive analysis into internal adversaries (Red Team)attacks to determine Breach Paths and respond to confirmed deconflictions of Red Team activitythrough penetration test research and purple operations, such as  Incident Reponse tabletop exercises. I also review detections and work on visualizing and operationalizing threats for future operations and correlation analysis. I was recently recognized as the Cyber Security Women Influencer of the Year by BSides I have mentored  several Cyber Security aspirants, to guide and assist in their development of cybersecurity skills, personality development, technical guidance, and career guidance. I am committed to promoting diversity and inclusion in Cyber Security, which has led to accolades such as being recognized as the Cybersecurity Women Influencer of the Year by BSides, being nominated for the SANS Difference Makers Award, being recognized as India Philanthropies CSR Champion by Microsoft, and being awarded the Women Leader in InfoSec Scholarship by Nullcon.", "public_name": "Sneha Banerjee", "guid": "366d06c6-76fe-583a-85ce-ca8917be98f1", "url": "https://cfp.hackfest.ca/hf2023/speaker/W3AF3D/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/BWKUFD/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/BWKUFD/", "attachments": []}, {"guid": "eb7a57e4-e1e4-58da-8591-6ed4492c213a", "code": "F7FZUR", "id": 202, "logo": "https://cfp.hackfest.ca/media/hf2023/images/F7FZUR/emilio-gonzalez_t7prko6.png", "date": "2023-10-13T15:30:00-04:00", "start": "15:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-202-automatiser-la-cyberdefense-feuille-de-route-et-trucs-pour-bien-s-en-soartir", "url": "https://cfp.hackfest.ca/hf2023/talk/F7FZUR/", "title": "Automatiser la Cyberd\u00e9fense: feuille de route et trucs pour bien s'en SOARtir", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "fr", "abstract": "Dans un contexte de p\u00e9nurie de talents en cybers\u00e9curit\u00e9 et de menaces de plus en plus complexes, l'automatisation est un concept tr\u00e8s important dans n'importe quel centre d'op\u00e9rations de cyberd\u00e9fense (SOC). Un SOAR est un outil d'automatisation pour les SOCs. Dans ce talk, nous allons d\u00e9mystifier ce qu'est un SOAR, ce que \u00e7a permet de faire et de ne pas faire, proposer une feuille de route pour maximiser la valeur qu'un SOC peut tirer de cet outil et partager des astuces pour bien choisir et utiliser un SOAR. Le contenu est tir\u00e9 de notre exp\u00e9rience des trois derni\u00e8res ann\u00e9es \u00e0 d\u00e9velopper des automatisations pour notre grand SOC.", "description": "Durant le talk, on va introduire le concept de SOAR, clarifier ce que \u00e7a fait et pourquoi on le fait. Le plus possible, \u00e7a sera pr\u00e9sent\u00e9 avec des exemples concrets et/ou des cas v\u00e9cus.\r\n\r\n- Introduction & Agenda (2 minutes)\r\n- Pourquoi automatiser? (4 minutes)\r\n- C'est quoi un SOAR, exemples de SOARs et les diff\u00e9rents types de SOAR (7 minutes)\r\n- Types d'automatisations et exemples (20 minutes)\r\n  - Contextualisation\r\n  - Priorisation\r\n  - Automatisation de la r\u00e9ponse\r\n- Qui devrait d\u00e9velopper dans un SOAR? (7 minutes)\r\n- Automatiser ne remplace pas des bons processus (4 minutes)\r\n- \u00c9tude de cas d'un grand SOC apr\u00e8s trois ans (5 minutes)", "recording_license": "", "do_not_record": false, "persons": [{"code": "SEBKHW", "name": "\u00c9milio Gonzalez", "avatar": null, "biography": "\u00c9milio travaille dans une *blue team* d'une grande organisation canadienne. Il aime participer \u00e0 des CTFs et cr\u00e9er des d\u00e9fis pour introduire les gens \u00e0 des aspects d\u00e9fensifs de la cybers\u00e9curit\u00e9. Il co-organise Montr\u00e9Hack, un atelier de CTF mensuel \u00e0 Montr\u00e9al. Vous le croiserez en ville, se promenant en trottinette \u00e9lectrique, r\u00eavant d'un monde plus r\u00e9silient, o\u00f9 la voiture n'est pas une n\u00e9cessit\u00e9 pour les d\u00e9placements quotidiens.", "public_name": "\u00c9milio Gonzalez", "guid": "082acee7-dcc4-5505-80c9-ef2cef783987", "url": "https://cfp.hackfest.ca/hf2023/speaker/SEBKHW/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/F7FZUR/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/F7FZUR/", "attachments": []}, {"guid": "94e46a1b-6966-553b-85ad-017c440a5ce1", "code": "KUUB8L", "id": 207, "logo": "https://cfp.hackfest.ca/media/hf2023/images/KUUB8L/War_From_Home_Resize_pr8IgON.jpg", "date": "2023-10-13T16:30:00-04:00", "start": "16:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-207-war-from-home-la-technologie-au-service-de-la-mobilisation-ukrainienne", "url": "https://cfp.hackfest.ca/hf2023/talk/KUUB8L/", "title": "War from home: la technologie au service de la mobilisation ukrainienne", "subtitle": "", "track": "Threat Intelligence / OSINT", "type": "Regular Talk", "language": "fr", "abstract": "D\u00e9couvrez l'impressionannte mobilisation technologique ukrainienne: combat dans le cyberespace et sur les r\u00e9seaux sociaux, drones modifi\u00e9s, IT Army et OSINT.", "description": "La pr\u00e9sentation mettra en lumi\u00e8re les aspects uniques de la mani\u00e8re dont les Ukrainiens mobilisent la technologie pour amener le combat dans le cyberespace et dans l\u2019infosph\u00e8re (guerre hybride). Chacune des sections comportera au moins une \u00e9tude de cas, et des images originales pour appuyer la pr\u00e9sentation.\r\n\r\nR\u00e9seaux Sociaux (10 minutes): Exploration de l'utilisation des r\u00e9seaux sociaux pour la diffusion d'informations, la coordination des efforts, et la lutte contre la d\u00e9sinformation. \u00c9tude de cas : NAFO, Saint-Javelin\r\n\r\nDrone (10 minutes): Modification hardware/software: pr\u00e9sentation des innovations technologiques dans la modification de drones civils pour des op\u00e9rations de reconnaissance et de guerre psychologique. \u00c9tude de cas : Follow Me\r\n\r\nIT Mobilisation (10 minutes): Discussion sur la formation et le r\u00f4le de l'IT Army dans la cyberguerre. Exploration de leurs strat\u00e9gies et de leurs succ\u00e8s dans la d\u00e9fense contre les cyberattaques. \u00c9tude de  cas: Engineers for Ukraine, IT army of Ukraine (objectifs des organisations, m\u00e9thodes d\u2019op\u00e9rations, fonctions). \r\n\r\nOSINT (10 minutes): Analyse de l'utilisation de l'OSINT. Comment l'intelligence open source a fa\u00e7onn\u00e9 la guerre et contribu\u00e9 \u00e0 informer le publique et l\u2019aider \u00e0 rester en s\u00e9curit\u00e9. \u00c9tude de cas : Monitor War, Twitter spaces, Deepstatemap\r\n\r\nQuestions et R\u00e9ponses (10 minutes): session interactive o\u00f9 les participants peuvent poser des questions et discuter des sujets abord\u00e9s.\r\n\r\nLa pr\u00e9sentation mettra en \u00e9vidence la mani\u00e8re dont la technologie est utilis\u00e9e de mani\u00e8re innovante et efficace dans le contexte du conflit ukrainien. Elle soulignera \u00e9galement l'importance de la collaboration internationale et de l'\u00e9thique dans la conduite de la guerre dans le cyberespace.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GRQYVN", "name": "Gabrielle Joni Verreault", "avatar": null, "biography": "Gabrielle Verreault, a bioethics student at Universit\u00e9 de Montr\u00e9al's School of Public Health, is concentrating on the societal and health impacts of digital technologies and AI. Her master's research-creation delves into the Montreal Declaration for Responsible AI Development, with a story being published by Atelier 10. This publication, paired with a teaching guide, aims to educate on AI ethics engagingly.\r\n\r\nSince February 2022, Gabrielle has been aiding Ukraine from Canada, Poland, and Ukraine amidst Russia's invasion. Her experiences have shaped her doctoral project on civil mobilization via modern technologies. By examining initiatives like the IT army, cybersecurity, and drones, she's capturing the values and motivations of civilians opposing Russia. _\r\nGabrielle Verreault, \u00e9tudiante en bio\u00e9thique \u00e0 l'\u00c9cole de sant\u00e9 publique de l'Universit\u00e9 de Montr\u00e9al, se concentre sur les impacts soci\u00e9taux et sanitaires des technologies num\u00e9riques et de l'IA. Sa recherche-cr\u00e9ation de ma\u00eetrise porte sur la D\u00e9claration de Montr\u00e9al pour un d\u00e9veloppement responsable de l'IA, dont le r\u00e9cit est publi\u00e9 par Atelier 10. Cette publication, jumel\u00e9e \u00e0 un guide d'enseignement, vise \u00e0 \u00e9duquer sur l'\u00e9thique de l'IA de fa\u00e7on engageante.\r\n\r\nDepuis f\u00e9vrier 2022, Gabrielle aide l'Ukraine depuis le Canada, la Pologne et l'Ukraine au milieu de l'invasion russe. Ses exp\u00e9riences ont fa\u00e7onn\u00e9 son projet de doctorat sur la mobilisation civile via les technologies modernes. En examinant des initiatives telles que La IT Army, la cybers\u00e9curit\u00e9 et les drones, elle s'int\u00e9resse aux valeurs et aux motivations des civils qui s'opposent \u00e0 la Russie.", "public_name": "Gabrielle Joni Verreault", "guid": "b6d3b2ed-71a6-5f5d-8de8-92c544b1aad6", "url": "https://cfp.hackfest.ca/hf2023/speaker/GRQYVN/"}, {"code": "JUAQQP", "name": "Luc Lefebvre", "avatar": null, "biography": "Geek humaniste. Luc a eu plusieurs vies mais sa carri\u00e8re suit le m\u00eame fil conducteur : service public, bien commun, protection de la vie priv\u00e9e et d\u00e9fense de la d\u00e9mocratie.\r\n\r\nRSSI et expert en gouvernance de la s\u00e9curit\u00e9 de l'information le jour, p\u00e8re et co-fondateur de Crypto.Qu\u00e9bec la nuit.\r\n\r\nSes int\u00e9r\u00eats sont le renseignement, la politique, la s\u00e9curit\u00e9 internationale, la technologie, la d\u00e9mocratie, le progr\u00e8s, les droits de l'homme et l'astronomie. Il a notamment co-\u00e9crit deux livres sur la s\u00e9curit\u00e9 de l'information, qui ont \u00e9t\u00e9 des best-sellers dans leurs cat\u00e9gories : \"On vous voir\" en 2018 ainsi que \"On vous trompe\" en 2022, tous deux publi\u00e9s aux \u00c9ditions Tr\u00e9carr\u00e9.", "public_name": "Luc Lefebvre", "guid": "be0e95c9-4e24-5d39-b1d6-f534c8fb2489", "url": "https://cfp.hackfest.ca/hf2023/speaker/JUAQQP/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/KUUB8L/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/KUUB8L/", "attachments": []}, {"guid": "661bb90a-781e-5690-bd49-2d5a6437d113", "code": "SWWCDY", "id": 229, "logo": "https://cfp.hackfest.ca/media/hf2023/images/SWWCDY/DSCF5931_3_YbCoVr9.JPG", "date": "2023-10-13T17:30:00-04:00", "start": "17:30", "duration": "00:20", "room": "Track #1", "slug": "hf2023-229-rubber-duckhunt-detection-d-un-classique", "url": "https://cfp.hackfest.ca/hf2023/talk/SWWCDY/", "title": "Rubber DuckHunt - D\u00e9tection d'un classique", "subtitle": "", "track": "Defensive", "type": "Speed Talk", "language": "fr", "abstract": "\"Rubber DuckHunt\", un outil innovant pour d\u00e9tecter et contrer les attaques de keystroke injection, une menace souvent n\u00e9glig\u00e9e depuis sa popularisation par le Rubber Ducky; je souhaite pr\u00e9senter et partager cet outil en exclusivit\u00e9 lors de la conf\u00e9rence.", "description": "Lors de cette pr\u00e9sentation, nous explorerons divers outils et techniques de Keystroke Injection, incluant le Rubber Ducky et ses nouvelles fonctionnalit\u00e9s, le Key Crocs associ\u00e9 \u00e0 Cloud C2, le MouseJacking, et d'autres outils pertinents.\r\nNous discuterons de la mani\u00e8re dont les syst\u00e8mes actuels d\u00e9tectent ces attaques. \r\nJe d\u00e9voilerai \u00e9galement un outil innovant que j'ai d\u00e9velopp\u00e9, nomm\u00e9 \"Rubber Duck Hunt\", con\u00e7u pour d\u00e9tecter le comportement des attaques de Keystroke Injection. Cet outil utilise plusieurs m\u00e9thodes d'analyse comportementale, telles que le pattern de frappe (vitesse, combinaisons de touches, mots-cl\u00e9s, etc.), la d\u00e9tection de nouveaux claviers connect\u00e9s.  De plus, un journaux windows est g\u00e9n\u00e9r\u00e9, ce qui permet l'aggr\u00e9gation dans un SIEM ce qui permet une d\u00e9tection dans une grande entreprise. L'outil sera rendu disponible au public \u00e0 la suite de cette pr\u00e9sentation.", "recording_license": "", "do_not_record": false, "persons": [{"code": "AGL8RL", "name": "Eric M. Gagnon", "avatar": null, "biography": "Eric M. Gagnon est un professionnel de la cybers\u00e9curit\u00e9 hautement exp\u00e9riment\u00e9 avec plus de 15 ans d'expertise. Actuellement en poste en tant que Conseiller Principal et Op\u00e9rateur Red Team au sein de l'\u00e9quipe ETTIC chez Desjardins, et il enseigne le \"Piratage \u00c9thique et Contre-Mesure\" au CCNB.  Il se sp\u00e9cialise dans le Threat Hunting, la r\u00e9ponse aux incidents, l'enqu\u00eate num\u00e9rique, la s\u00e9curit\u00e9 offensive et la gestion des vuln\u00e9rabilit\u00e9s. D\u00e9tenteur de certifications dans multiples domaine de la cybers\u00e9curit\u00e9, notamment  OSCP, OSCE, GBFA, et GCFA, \u00c9ric apporte une riche connaissance en mati\u00e8re de d\u00e9fense et d'attaque, ainsi qu'une passion pour encourager la collaboration entre les \u00e9quipes. Avec sa vaste exp\u00e9rience et son \u00e9tat d'esprit collaboratif, il se consacre \u00e0 garantir la s\u00e9curit\u00e9 et la r\u00e9silience des organisations face aux cybermenaces.", "public_name": "Eric M. Gagnon", "guid": "41892322-a8b1-5950-9208-c6237cdbe326", "url": "https://cfp.hackfest.ca/hf2023/speaker/AGL8RL/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/SWWCDY/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/SWWCDY/", "attachments": []}, {"guid": "b6f26841-8bf4-59e8-a268-190f4486239a", "code": "CXGCQZ", "id": 240, "logo": null, "date": "2023-10-13T20:55:00-04:00", "start": "20:55", "duration": "02:00", "room": "Track #1", "slug": "hf2023-240-podcast-la-french-connection-episode-live-salle-201a", "url": "https://cfp.hackfest.ca/hf2023/talk/CXGCQZ/", "title": "Podcast La French Connection - \u00c9pisode LIVE (salle 201A)", "subtitle": "", "track": null, "type": "Workshop - 120 minutes", "language": "fr", "abstract": "Joignez-vous \u00e0 nous pour cette tradition annuel du Podcast en direct lors de la 2e soir\u00e9e du Hackfest!\r\nOpinions, actualit\u00e9s, poutine et assur\u00e9ment quelques d\u00e9rapages seront au rendez-vous pour discuter de tout ce qui entour la s\u00e9curit\u00e9 de l'information!", "description": "La French Connection (https://securite.fm)\r\n\r\nRejoignez-nous ici en direct le samedi 14 octobre \u00e0 21h00 EST\r\n\r\nSujets couverts:\r\n- Retour sur le Hakfest 2023\r\n- Retour sur l'ann\u00e9e 2023\r\n- Give me ransomware, loads of ransomware\r\n- Cybers\u00e9curit\u00e9 du gouvernement du Qu\u00e9bec\r\n- Nouvelles infosec\r\n- Recrutement en s\u00e9curit\u00e9 informatique\r\n- La Friends Connection\r\n- Questions du public\r\n- Poutine\r\n- Poolcast stories\r\n- Le dude du Hackfest\r\n- D\u00e9fions le statu quo\r\n- D'la pizza aux ananas\r\n- Over 'n' out\r\n- Et plus encore!!!", "recording_license": "", "do_not_record": false, "persons": [{"code": "LEQZSF", "name": "L'\u00e9quipe de La French Connection", "avatar": null, "biography": null, "public_name": "L'\u00e9quipe de La French Connection", "guid": "853b8376-d9d9-5387-8a81-25bd98ed7280", "url": "https://cfp.hackfest.ca/hf2023/speaker/LEQZSF/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/CXGCQZ/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/CXGCQZ/", "attachments": []}], "Track #2": [{"guid": "c2f705f0-3cad-5f0a-b7c7-8b2ccd597349", "code": "F783UL", "id": 228, "logo": "https://cfp.hackfest.ca/media/hf2023/images/F783UL/ABergeron2_CDWHDUB.jpg", "date": "2023-10-13T09:00:00-04:00", "start": "09:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-228-une-surveillance-rdp-sans-precedent-revele-le-savoir-faire-des-attaquants", "url": "https://cfp.hackfest.ca/hf2023/talk/F783UL/", "title": "Une surveillance RDP sans pr\u00e9c\u00e9dent r\u00e9v\u00e8le le savoir-faire des attaquants", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "fr", "abstract": "Le protocole RDP (Remote Desktop Protocol) est un vecteur d'attaque critique utilis\u00e9 par des acteurs malveillants, notamment par les groupes de ran\u00e7ongiciel.  Pour \u00e9tudier les attaques RDP, nous avons cr\u00e9\u00e9 PyRDP, un outil d'interception RDP open source dot\u00e9 de capacit\u00e9s in\u00e9gal\u00e9es qui nous a permis de collecter plus de 100 heures de s\u00e9quences vid\u00e9o d'attaquants en action.\r\n\r\nPour d\u00e9crire les comportements des attaquants, nous avons caract\u00e9ris\u00e9 les diff\u00e9rents arch\u00e9types d'attaquants en fonction de leurs caract\u00e9ristiques \u00e0 travers une analogie de Donjon et Dragon : 1) les bardes effectuant des recherches obtuses; 2) les rodeurs explorent furtivement les ordinateurs et effectuent de la reconnaissances ; 3) les voleurs tentent de mon\u00e9tiser l'acc\u00e8s RDP ; 4) les barbares utilisent une large gamme d'outils pour attaquer davantage d'ordinateurs ; et 5) les magiciens utilisent leur acc\u00e8s RDP comme portail magique pour dissimuler leurs origines.\r\n\r\nCette pr\u00e9sentation d\u00e9montre l\u2019impressionnante capacit\u00e9 d'interception RDP pour les b\u00e9n\u00e9fices de la recherche et les \u00e9quipes de d\u00e9fense.", "description": "Lors de l\u2019\u00e9criture de cette pr\u00e9sentation, nous n\u2019Avons pas pu nous emp\u00eacher de faire des parall\u00e8les avec l'univers de Donjon et Dragon qui a \u00e9t\u00e9 popularis\u00e9 r\u00e9cemment par Stranger Things et le film Honor Among Thieves. Nous avons pens\u00e9 que ce r\u00e9cit soutiendrait bien notre histoire.\r\n\r\n1)\tLe protocole RDP (Remote Desktop Protocol) comme vecteur d'attaque critique dans les groupes de ran\u00e7ongiciel.\r\n2)\tExploiter la profondeur des captures RDP \r\n3)\tPr\u00e9sentation de notre outil d'interception. open source appel\u00e9 PyRDP et de ses capacit\u00e9s.\r\nCapacit\u00e9s d'\u00e9cran, de clavier, de souris, de presse-papiers et de collecte de fichiers\r\nPr\u00e9sentation de notre honeynet et de notre architecture syst\u00e8me\r\n4)\tM\u00e9thode de collecte de donn\u00e9es (plus de 150 millions d'\u00e9v\u00e9nements, dont 20 millions de hachages NetNTLMv2 captur\u00e9s, 3 200 sessions de connexion r\u00e9ussies analys\u00e9es, 570 fichiers transf\u00e9r\u00e9s, 21 705 captures RDP collect\u00e9es et plus de 100 heures de vid\u00e9os.\r\n5)\tCaract\u00e9riser les attaquants\r\nPr\u00e9sentation des diff\u00e9rents types d'attaquants, de leurs caract\u00e9ristiques et s\u00e9quence vid\u00e9o de leurs actions.\r\n-Les bardes, sans comp\u00e9tences apparentes en mati\u00e8re de piratage informatique, effectuent des recherches obtuses ou regardent des vid\u00e9os pour adultes. Ils ont potentiellement achet\u00e9 l'acc\u00e8s RDP \u00e0 quelqu'un qui a compromis le syst\u00e8me pour eux, alias Initial Access Brokers (IAB).\r\n-Les rodeurs explorent furtivement les ordinateurs et effectuent de la reconnaissance, ouvrant ainsi la voie \u00e0 d'autres types d\u2019attaquants.\r\n-Les voleurs tentent de mon\u00e9tiser l'acc\u00e8s RDP par diverses m\u00e9thodes cr\u00e9atives, telles que des mon\u00e9tiseurs de trafic ou des cryptomineurs.\r\n-Les barbares utilisent une large gamme d'outils pour attaquer davantage d'ordinateurs.\r\n-Les magiciens, s\u00e9curisant leur identit\u00e9 via d\u2019autres h\u00f4tes compromis, utilisent leur acc\u00e8s RDP comme portail magique pour dissimuler leurs origines.\r\n6)\tArmement des attaquants\r\nNous couvrirons les outils utilis\u00e9s par les diff\u00e9rents attaquants comme MassScan GUI, NLBrute, SilverBullet, XMRig (cryptominer), Traffmonetizer, DControl et plus encore.", "recording_license": "", "do_not_record": false, "persons": [{"code": "H89NBP", "name": "Andreanne Bergeron", "avatar": null, "biography": "Andr\u00e9anne Bergeron has a Ph.D. in criminology from the University of Montreal and works as a cybersecurity researcher at GoSecure. Acting as the social and data scientist of the team, she is interested in online attackers\u2019 behaviors. She is involved in the infosec community as the VP engagement and outreach for Northsec. Her experience as a speaker includes BlackHat USA, DefCon, BSides Montreal, NorthSec, CypherCon and Human Factor in Cybercrime among others.", "public_name": "Andreanne Bergeron", "guid": "7956adc6-686b-5e7c-be32-22704e7871da", "url": "https://cfp.hackfest.ca/hf2023/speaker/H89NBP/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/F783UL/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/F783UL/", "attachments": []}, {"guid": "612babbf-3af1-5323-8d00-215cf761059b", "code": "HAK8SR", "id": 213, "logo": null, "date": "2023-10-13T10:00:00-04:00", "start": "10:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-213-jedi-contre-les-hackers", "url": "https://cfp.hackfest.ca/hf2023/talk/HAK8SR/", "title": "Jedi Contre les hackers", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "fr", "abstract": "Jedi contre les hackers est un conf\u00e9rence sur le Darkweb et les groupes de hackers. Elle permet d'apprendre \u00e0 rechercher des informations exfiltr\u00e9 facilement sur les sites de 50 groupes de hackers actif. Elle d\u00e9montre la facilit\u00e9 et comment agir avec un client ou une personne qui se retrouve avec des informations exfiltr\u00e9s. Elle a \u00e9t\u00e9 donn\u00e9 \u00e0 travers le monde : Las Vegas, R\u00e9publique dominicaine, Calgary, Toronto, New York bient\u00f4t Paris et Dubai. Elle est en fran\u00e7ais ou anglais.", "description": "- L'histoire de Groupe ISM et son Cybercrime majeure en 2017\r\n- Comment rechercher sur sur le Darkweb et le naviguer de fa\u00e7on s\u00e9curitaire\r\n- D\u00e9couvrir le comportement des hackers actifs au Qu\u00e9bec en ce moment \u00e0 travers des Cybercrime d'ici\r\n- Parcourir les exfiltration de donn\u00e9es des entreprises qu\u00e9b\u00e9coise ou canadienne disponible\r\n- Validation de la s\u00e9curit\u00e9 et l'int\u00e9grit\u00e9 suite \u00e0 un  Cybercrime majeure ou une exfiltration des donn\u00e9es\r\n\r\nBIO : En tant que PDG du Groupe ISM situ\u00e9 au Canada. Le groupe ISM et Simon David Williams ont surv\u00e9cu \u00e0 un cybercrime majeur et ont aujourd'hui contribu\u00e9 \u00e0 37 cybercrimes majeurs. L'objectif est d'aider l'industrie des TI \u00e0  prot\u00e9ger et conscientiser les personnes de leur r\u00e9seaux, avant, apr\u00e8s et pendant une attaque active de Ransomware.  Dans cette conf\u00e9rence, vous naviguerez sur le Darkweb et verrez comment s\u00e9curiser votre organisation et vous-m\u00eame en apprenant comment les pirates publient et agissent dans un cybercrime et de quelle fa\u00e7on les Script-Kiddie les utilisent", "recording_license": "", "do_not_record": false, "persons": [{"code": "3LYLUR", "name": "Simon David Williams", "avatar": null, "biography": "En tant que PDG du Groupe ISM situ\u00e9 au Canada. Le groupe ISM et Simon David Williams ont surv\u00e9cu \u00e0 un cybercrime majeur et ont aujourd'hui contribu\u00e9 \u00e0 37 cybercrimes majeurs. L'objectif est d'aider l'industrie des TI \u00e0  prot\u00e9ger et conscientiser les personnes de leur r\u00e9seaux, avant, apr\u00e8s et pendant une attaque active de Ransomware.  Dans cette conf\u00e9rence, vous naviguerez sur le Darkweb et verrez comment s\u00e9curiser votre organisation et vous-m\u00eame en apprenant comment les pirates publient et agissent dans un cybercrime et de quelle fa\u00e7on les Script-Kiddie les utilisent", "public_name": "Simon David Williams", "guid": "601d8775-0681-51b2-8853-b5ebad0833e3", "url": "https://cfp.hackfest.ca/hf2023/speaker/3LYLUR/"}, {"code": "3D3LZS", "name": "Audrey Shink", "avatar": null, "biography": null, "public_name": "Audrey Shink", "guid": "518b1302-e1a9-5db5-a7c2-cb1953b52860", "url": "https://cfp.hackfest.ca/hf2023/speaker/3D3LZS/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/HAK8SR/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/HAK8SR/", "attachments": []}, {"guid": "c45f5918-dd3f-52e6-a8b4-f40764685f9d", "code": "AEQMVB", "id": 215, "logo": null, "date": "2023-10-13T11:00:00-04:00", "start": "11:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-215-you-won-t-own-passwords-and-you-ll-like-it", "url": "https://cfp.hackfest.ca/hf2023/talk/AEQMVB/", "title": "You Won\u2019t Own Passwords, and You\u2019ll Like It", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "en", "abstract": "Passkeys are the future of authentication. Moving beyond passwords to Passkeys and WebAuthN provides a significant security upgrade for end users. But what are penetration testers that have relied on weak passwords to do? In this talk I will explore the attack surface of Passkeys and identify the viable paths to help pentesters identify vulnerabilities and achieve account takeovers. A new BurpSuite plugin will also be dropped to automate the tricky parsing of Passkey objects and identify vulnerabilities in Passkey implementations.", "description": "1) Intro: Why Passwords Suck\r\n\r\nThe motivation for this talk is to introduce passkeys to the audience and explore the available attack surface for a penetration tester.\r\n \r\nA quick review of the reasons passwords are difficult for users to handle and manage securely. This argument will be supported by statistics about the number of breaches caused by compromised password credentials.\r\n\r\nPasskeys are the future of passwordless authentication because they have been adopted by Google, Microsoft and Apple, and are built into all modern consumer platforms. Passkeys will address the major security concerns of passwords with the following properties:\r\n-\tAsymmetric secret sharing for breach containment.\r\n-\tPhishing resistance\r\n-\tSimple user experience with biometrics user verification, cross device authentication flows and recoverability.\r\n\r\n2)\tWhat are Passkeys\r\n\r\nHow passkeys build on the WebAuthN standard leveraging UAF. Definitions of the components, their dependencies and interactions:\r\n-\tUniversal Authentication Framework (UAF)\r\n-\tUniversal Second Factor (U2F)\r\n-\tWeb Authentication (WebAuthN)\r\n-\tClient to Authenticator Protocol (CTAP/CTAP2)\r\n-\tPasskeys\r\nHow Google, Apple and Microsoft implement passkey portability and recovery based on public security architecture documents.\r\n\r\n3)\tPasskey\u2019s Attack Surface\r\n\r\nThe passkey API implements two actions \u201cCreate\u201d and \u201cAuthenticate\u201d. I\u2019ll review the fields in each of these API calls and discuss its role in the protocol and how a penetration tester may be able to attack it.\r\n\r\n4)\tPenetration Testing Passkeys with BurpSuite Plugin\r\n\r\nI have developed a new BurpSuite Plugin that identifies WebAuthN/Passkeys in web traffic and scans them for vulnerabilities.\r\nI will discuss several of the vulnerabilities including:\r\n-\tWeak public key algorithms \r\n-\tSufficient entropy and randomness for challenges\r\n-\tAuthentication weakness for public keys\r\n-\tWeak account authentication enumeration\r\n-\tDomain/Sub-domain scoping\r\nAfter covering the attack surface for passkeys, I\u2019ll look at the most viable attack paths for a penetration test to achieve account takeover.", "recording_license": "", "do_not_record": false, "persons": [{"code": "AKBUDV", "name": "Alex Cowperthwaite", "avatar": null, "biography": "Alex is the Technical Director at Kroll's Offensive Security - Cyber Risk group. After 7 years of hands-on penetration testing, Alex is responsible for research and development of tools, techniques, skills and methodologies for the team of Kroll's pen testers.", "public_name": "Alex Cowperthwaite", "guid": "6093b340-e6c0-5f9e-8d5e-37800d221873", "url": "https://cfp.hackfest.ca/hf2023/speaker/AKBUDV/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/AEQMVB/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/AEQMVB/", "attachments": []}, {"guid": "fa1a033b-e09c-5c68-af90-af1a297e9866", "code": "WN3KKJ", "id": 193, "logo": "https://cfp.hackfest.ca/media/hf2023/images/WN3KKJ/steve-2018-300_kKlC0NE.jpeg", "date": "2023-10-13T13:30:00-04:00", "start": "13:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-193-avons-nous-ameliore-notre-resilience-a-l-evolution-technologique-en-25-ans", "url": "https://cfp.hackfest.ca/hf2023/talk/WN3KKJ/", "title": "Avons-nous am\u00e9lior\u00e9 notre r\u00e9silience \u00e0 l\u2019\u00e9volution technologique en 25 ans ?", "subtitle": "", "track": "Security Programs/Management", "type": "Regular Talk", "language": "fr", "abstract": "Les entreprises par leur transformation num\u00e9rique se doivent de prendre conscience tout comme tout le monde, que nous sommes tr\u00e8s d\u00e9pendants des TI maintenant et nous nous devons au quotidien toujours avoir un plan \"B\". \r\n\r\nRemplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // \r\nRemplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // \r\nRemplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // \r\nRemplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots // Remplissage 150 mots //", "description": "Cette pr\u00e9sentation se veut une r\u00e9flexion commune afin de changer nos perceptions en vue d\u2019une meilleure pr\u00e9paration \u00e0 ces risques. En 1998, le nord-est de l\u2019Am\u00e9rique du Nord a subi un \u00e9v\u00e8nement m\u00e9t\u00e9orologique hors du commun soit une temp\u00eate de verglas, avec de grandes cons\u00e9quences sur l\u2019\u00e9conomie de 3 provinces et 3 \u00e9tats am\u00e9ricains. Il y a eu heureusement peu de d\u00e9c\u00e8s (la majorit\u00e9 attribuable \u00e0 la mauvaise utilisation de chauffage d\u2019appoint) et notre soci\u00e9t\u00e9 d\u00e9butait \u00e0 peine \u00e0 d\u00e9couvrir l\u2019Internet. Pendant pr\u00e8s d\u2019un mois, beaucoup ont eu \u00e0 apprendre \u00e0 composer avec des difficult\u00e9s d\u2019organisation logistique (nourriture, carburant, m\u00e9dicaments) et comment se tenir au chaud si la vie de refuge d\u2019urgence n\u2019\u00e9tait pas possible. \r\n\r\n25 ans plus tard, nous avons re\u00e7u cet hivers un autre \u00e9pisode de verglas qui a simplement cr\u00e9er des probl\u00e8mes avec des coupures \u00e9lectriques de quelques jours due aux arbres mal entretenus. Devant ce constat, si l\u2019\u00e9pisode de verglas 2023 aurait \u00e9t\u00e9 aussi grave qu\u2019en 1998, consid\u00e9rant la d\u00e9pendance de notre soci\u00e9t\u00e9 au num\u00e9rique et comment l\u2019\u00e9conomie est bas\u00e9e sur du \u00ab just in time \u00bb, est-ce que notre soci\u00e9t\u00e9, notre \u00e9conomie et nos gouvernances \u00e0 tous les niveaux, pr\u00eat \u00e0 y faire face de mani\u00e8re \u00e0 r\u00e9duire les cons\u00e9quences \u00e0 un niveau acceptable ? \r\n\r\nRemplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // \r\nRemplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // \r\nRemplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // \r\nRemplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots // Remplissage 500 mots //", "recording_license": "", "do_not_record": false, "persons": [{"code": "8SAAVE", "name": "Steve Waterhouse", "avatar": null, "biography": "PDG d\u2019INFOSECSW, \r\nAncien SMA \u00e0 la s\u00e9curit\u00e9 de l\u2019information et \u00e0 la cybers\u00e9curit\u00e9 du Qu\u00e9bec au MCN, \r\nChroniqueur m\u00e9dia en cybers\u00e9curit\u00e9 et \r\nCharg\u00e9 de cours \u00e0 l\u2019Universit\u00e9 de Sherbrooke\r\n\r\n'est au cours de sa carri\u00e8re militaire au sein du Royal 22e R\u00e9giment que le Capt(ret) Steve Waterhouse a troqu\u00e9 son arme contre un clavier et est devenu l'un des premiers cyber-soldats au Canada. Apr\u00e8s avoir travaill\u00e9 \u00e0 la formation de soldats et d'officiers aux armes de combat, Steve a ensuite travaill\u00e9 \u00e0 la mise en place des premiers r\u00e9seaux administratifs militaire au QGSQFT, \u00e0 la base de Montr\u00e9al et au Coll\u00e8ge militaire royal de Saint-Jean avec les Forces arm\u00e9es canadiennes, ainsi qu'\u00e0 la mise en \u0153uvre de pratiques modernes de cybers\u00e9curit\u00e9 comme premier Officier de S\u00e9curit\u00e9 des Syst\u00e8mes d\u2019information (OSSI). Il continue \u00e0 partager sa passion et son exp\u00e9rience en tant que charg\u00e9 de cours \u00e0 l'Universit\u00e9 de Sherbrooke dans le cadre du microprogramme de ma\u00eetrise en s\u00e9curit\u00e9 de l\u2019information - volet pr\u00e9vention. Il est invit\u00e9 \u00e0 apporter son exp\u00e9rience et son expertise aux commissions de la Chambre des communes du Canada et \u00e0 l'Assembl\u00e9e nationale du Qu\u00e9bec et est fr\u00e9quemment sollicit\u00e9 dans les m\u00e9dias canadiens pour commenter les questions de cybers\u00e9curit\u00e9. M. Waterhouse a aussi \u00e9t\u00e9 le premier sous-ministre-adjoint \u00e0 la s\u00e9curit\u00e9 gouvernementale et \u00e0 la cybers\u00e9curit\u00e9 du minist\u00e8re de la cybers\u00e9curit\u00e9 et du num\u00e9rique du Qu\u00e9bec jusqu\u2019au d\u00e9but 2023.", "public_name": "Steve Waterhouse", "guid": "86ba292d-9ec5-5640-b60a-d265f138c12a", "url": "https://cfp.hackfest.ca/hf2023/speaker/8SAAVE/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/WN3KKJ/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/WN3KKJ/", "attachments": []}, {"guid": "3f7b53b6-5638-5c33-8792-8e2bce454858", "code": "Q99AGU", "id": 234, "logo": null, "date": "2023-10-13T14:30:00-04:00", "start": "14:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-234-vpns-are-internet-snake-oil", "url": "https://cfp.hackfest.ca/hf2023/talk/Q99AGU/", "title": "VPNs are Internet snake oil", "subtitle": "", "track": "Privacy", "type": "Regular Talk", "language": "en", "abstract": "Many information security professionals recommend VPN services to end-users, especially to protect against the dreaded man-in-the-middle attack on your local coffee shop's open Wi-Fi network.  The commercial VPN vendors advertise heavily, making bold statements such as  \"we encrypt your network data so no one can see what you\u2019re doing\",  \"surf the web without a trace!\", \"avoid government eavesdropping\", and assure you that  \"your web traffic can't be tracked anymore\".   These claims are all \"snake oil\", and attendees will watch them be debunked. The actual benefits and limitations of VPNs will be reviewed, and a discussion of the myriad ways that are  used to surveil your online activities that go far beyond browser cookies . Some tactics to minimize and mitigate this online tracking will be discussed, as well as what it takes to be truly untraceable online.", "description": "Brief outline\r\n- History lesson on \u201csnake oil\u201d & Virtual Private Networks (VPNs). Why people may want to hide their identity online\r\n- What a commercial Virtual Private Network (VPN) service can and cannot do for you.\r\n- The surveillance problem in your pocket.\r\n- Beyond VPNs: Recommendations to help limit online tracking and surveillance, for various levels of paranoia\r\n\r\nThis talk is a rapid-fire and comprehensive takedown of the entire concept that use of commercial VPN services create any real privacy or security benefits for most users. \r\n\r\nIt will give a summary of what things a VPN service can and cannot do to hide your online activities and footprint. It will provide an overview of the many methods used by advertisers and social media companies for tracking and monitoring end-uses that go far beyond browser cookies. It will also offer suggestions on mitigations against these methods, and a short discussion of how to truly be anonymous or untraceable online -- a harder problem than you think.\r\nBelow is a collection of information fragments to be organized into the final presentation format.\r\n\r\nThe reality is that VPNs actually do almost nothing to improve your security online.\r\n\r\nUsing a VPN can hide your IP address and make it appear that you are connecting from another location, but by itself a VPN doesn't hide your identity or your online activities, browsing patterns, or websites site visit.\r\n\r\nYes, VPNs can provide some limited value when dealing with public Wi-Fi networks that do not use any encryption. \r\nThis defends against the \"coffee shop\" sort of attacks with a compromise of the NAT router or a man-in-the-middle attack, or against passive surveillance of your traffic. Most endpoint Internet traffic is encrypted with TLS these days, making it hard to intercept.\r\n\r\nA commercial VPN services primary use case is to present a different geographic location to the various content providers and governments that try to control access based on geoip lookup. However, most VPN services utilize IPv4 blocks in data centers that are easily blocked by the content providers. VPN services buy and deploy new IPv4 subnets, but it is \"whack a mole\". Legitimate ISPs are also caught up in the geo blocking game, and are often banned by content providers erroneously.\r\n\r\nSome VPN services have very murky ownership. There are free VPN services (who is the product here?). Foriegn purchase and ownership of VPn services and motivations is an entire rabbit hole.\r\nWeb and advertising tracking -- hard to escape.\r\n\r\nTracking cookies are everywhere and if you are not using a clean browser without cookies, you will be tracked. DNS traffic can still be monitored by the VPN service unless DoH/DoT is in use.\r\n\r\nBrowser fingerprinting methods - can get your down to a unique down to 1 out of 250k+ browsers. Things you don\u2019t think about that can get you, what fonts you have installed can be used to help provide that unique fingerprint\r\nOk, ok, so I use a VPN and a clean browser in a Virtual machine, I\u2019m good right? I can do the shady thing safely, right? No.\r\n\r\n Your traffic is still visible from the source point of the VPN provider, and even the ones that say they don\u2019t do logging are doing logging (or the local government is) plus the wire tapping going.\r\n\r\nYes, much of your session traffic will be HTTPS encrypted, but that leaks data with SNI and certificate checks. DNS queries can leak.\r\n\r\nwiretapping... known legal and otherwise. Room 641A and others all over the place. NSL and other government powers to compel cooperation. https://en.m.wikipedia.org/wiki/Room_641A\r\nThe USA is far from the only government doing this sort of broad traffic collection. Some are also doing censorship/filtering at the national level (deep packet inspection and also DNS based). In some places, ISPs are required to install \"middle boxes\" that not only try to censor information, but are also used for survelliance.\r\nnetflow data aggregation currently in the hands of corporations and governments. What is netflow? Records to sample activities based on 5 Tuple src/dst ip and and port, plus interface source, protocol type. There are broadband equipment vendors that use netflow data to report on subscriber online activity, and have interesting privacy policies. Some are selling these data streams to traffic intelligence services. Think of it as Nielsen ratings for online activities. There are ISPs that use netflow cloud services (Kentik) . Which make convenient Central places to send NSLs if you want some data..\r\n\r\nListen carefully to statements or legal policies. Hairs are split. \u201cWe don\u2019t listen to all your phone calls\u201d \u2014 no, but you can record them and listen to them later.\r\n\r\nspecial browsers for privacy. Browser plugins for ad blocking and tracking. Discuss all the options in detail.\r\nVPN technical requirements (ciphers and strength) that are desirable and NIST guidlines. .\r\n\r\nSome recommendations for actual security, which is much harder, but recommended if you are wanting to do shady things online or your threat model includes nation state actor risks. Journalist discussion.\r\n1. Use a dedicated local hardware device (NAT routers) for your VPN to your own cloud VPS (small home router or rasp PI). Change your external faciny MAC address, and you can double-NAT this through your normal firewall.\r\n\r\n2. Use TAILs on an old laptop, connected to your VPN device with zero state, via ethernet wire. Could be an entire discussion.\r\n \r\n3. Make your last mile as untraceable to you as possible \u2014 long distance wireless, business/school etc without cameras and logging. Not easy to do.\r\n\r\n4. Many ISPs keep DHCP logs with MACs.. Sometimes for years. CGNAT translation, records of all session traffic. . They can tie your physical location and account to your Ethernet MAC of your router. For subpoenas.\r\n\r\n5. Disable laptop camera and microphone in hardware.\r\n\r\n6. Don\u2019t do shady things from your home or work or anyplace else that can be\r\ntraced to you.\r\n\r\n7. Best way to do shady things is use other people\u2019s computers remotely over\r\ncovert channels, from additional other untraceable locations (I'm behind seven proxies!)\r\n\r\nSome resources that will be used:\r\nhttps://coveryourtracks.eff.org \r\nhttps://freedom.press/training/choosing-a-vpn/ \r\nhttps://ssd.eff.org\r\nhttps://www.privacyguides.org\r\nhttps://pixelprivacy.com/resources/browser-fingerprinting/", "recording_license": "", "do_not_record": false, "persons": [{"code": "VWRV33", "name": "James Troutman", "avatar": null, "biography": "Troutman is an Internet \"Old Timer.\" His first online experiences involved a paper TTY with a 300 bps acoustic coupler modem in 1982. A user of the Internet and UNIX since 1987, he has been tasked with building and running Internet infrastructure off and on since the early '90s. He has held a wide variety of senior roles at various regional ISPs, telcos, and cable companies, as well as founding a few of them. He is most often found roaming the countryside as a freelance consultant, solving problems for a wide variety of organizations, with a focus on Internet infrastructure and broadband. His volunteer activities include Director of the regional Internet Exchange for Maine and Northern New England (NNENIX.NET), board member for the Maine Technology Users Group (MTUG.ORG), and Director of Operations for the Skytalks Village at DEF CON (Skytalks.info and defcon.org).", "public_name": "James Troutman", "guid": "1173d2cc-c17f-5b5f-b8e4-e8d610fc06f1", "url": "https://cfp.hackfest.ca/hf2023/speaker/VWRV33/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/Q99AGU/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/Q99AGU/", "attachments": []}, {"guid": "94643ebf-7aa2-5f03-b872-029529d4e1ae", "code": "U8AXSF", "id": 201, "logo": null, "date": "2023-10-13T15:30:00-04:00", "start": "15:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-201-combattre-la-violence-technologique", "url": "https://cfp.hackfest.ca/hf2023/talk/U8AXSF/", "title": "Combattre la violence technologique", "subtitle": "", "track": "Security 101", "type": "Regular Talk", "language": "fr", "abstract": "\u00c9pi\u00e9es, suivies, tourment\u00e9es : 70% des victimes de violence conjugales rapportent de la violence technologique. Alors que l'environnement techno autour des victimes se complexifient, comment peut-on travailler \u00e0 augmenter la litt\u00e9ratie num\u00e9rique aupr\u00e8s des populations vuln\u00e9rables et mettre en place des outils de soutien.", "description": "<p><b>\u00c9pi\u00e9es, suivies, tourment\u00e9es : 70% des victimes de violence conjugales rapportent de la violence technologique. Alors que l'environnement techno autour des victimes se complexifient, comment peut-on travailler \u00e0 augmenter la litt\u00e9ratie num\u00e9rique aupr\u00e8s des populations vuln\u00e9rables et mettre en place des outils de soutien. </b></p>\r\n\r\n<p><b>Introduction au ph\u00e9nom\u00e8ne et ampleur</b></p>\r\nComment peut-on reconna\u00eetre la violence technologique, quels sont les impacts sur la victime et les proches de celle-ci et qu'est-ce qui explique que ce soit d\u00e9sormais une r\u00e9alit\u00e9 omnipr\u00e9sente pour les victimes de violence conjugale. \r\n\r\n<p><b>\u00c9tudes de cas r\u00e9els (anonymis\u00e9s) et potentiels</b></p>\r\nComment reconna\u00eetre la violence technologique et pr\u00e9sentation de situations bien r\u00e9elles - attention, contenu sensible.\r\n\r\n<p><b>Bonnes pratique d'intervention</b></p>\r\nComment reconna\u00eetre les besoins de la victime : intervenir dans un contexte parfois dangereux - comment se prot\u00e9ger soi, savoir quand escalader aux forces de l'ordre et moduler l'intervention en fonction des connaissances techniques de la victime. \r\n\r\n<p><b>Couverture des aspects l\u00e9gaux / Comment pr\u00e9parer un dossier de preuves</b></p>\r\nQu'elles sont les limites de l'aide qui peut \u00eatre offerte? Comment monter un dossier de preuves afin de permettre \u00e0 la victime d'acc\u00e9der \u00e0 des ressources suppl\u00e9mentaires, d'\u00eatre prise au s\u00e9rieux et de porter plainte. \r\n\r\n<p><b>Exploration des outils et ressources disponibles et \u00e0 d\u00e9velopper par la communaut\u00e9</b></p>\r\nQuelles sont les outils et ressources d\u00e9j\u00e0 existants dans l'\u00e9cosyst\u00e8me et que devrions nous d\u00e9velopper en tant qu'experts dans la communaut\u00e9 pour soutenir les refuges, centre d'interventions et les victimes.", "recording_license": "", "do_not_record": false, "persons": [{"code": "9PVSBL", "name": "Catherine Dupont-Gagnon", "avatar": null, "biography": "Co-fondatrice de l'association cybercitoyen.org et co-autrice du livre On Vous Trompe. \r\nJ'aspire \u00e0 rendre accessible le contenu en cybers\u00e9curit\u00e9 et \u00e0 augmenter la litt\u00e9ratie num\u00e9rique du grand public afin de combattre la d\u00e9sinformation, les violences technologiques et les fraudes en ligne.", "public_name": "Catherine Dupont-Gagnon", "guid": "8c4fd95e-212f-52a4-b6ec-a59e07142238", "url": "https://cfp.hackfest.ca/hf2023/speaker/9PVSBL/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/U8AXSF/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/U8AXSF/", "attachments": []}, {"guid": "bb9dbef6-1e95-50e9-83f2-4fa60afbf05e", "code": "ZGFADY", "id": 216, "logo": null, "date": "2023-10-13T16:30:00-04:00", "start": "16:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-216-unconditionally-conditional-strong-authentication-in-azure-ad", "url": "https://cfp.hackfest.ca/hf2023/talk/ZGFADY/", "title": "Unconditionally Conditional - Strong Authentication in Azure AD", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "en", "abstract": "Conditional Access in Microsoft Azure Active Directory, when tied with Mobile Application Management and Mobile Device Management in Microsoft Intune are the core pillars for building zero trust based access controls in Microsoft 365 and Azure published services. We will cover MDM and MAM policies, how Intune device compliance is applied to Conditional Access by Intune, when deploying authentication and most importantly a tested model for layered access, specifically as it relates to M365 in a variety of trust states.", "description": "This could be considered for Defensive or Security 101.\r\n\r\n- Introduction / Agenda / whomi 2 mins\r\n- Overview - why conditional access is important, how relates to zero trust - 3 mins\r\n- Microsoft Intune - start with devices - discuss various aspects of different method of joining devices and assessing device compliance using MS Intune - 15 mins\r\n  - Device join types\r\n  - Requirements for Hybrid Azure joined and Co-Managed\r\n  - MDM vs MAM - differences, similarities and how they relate to one another in a layered approach.\r\n  - MDM policies - details regarding options, successes, and pitfalls when applying device compliance policies.\r\n  - MAM policies - details regarding options, successes, and pitfalls when applying application/container compliance policies.\r\n  - Limitations - notable additional limitations within Intune, especially as it relates to method of onboarding devices, where compliance fits in relation to configuration profiles.\r\n  - What else does Intune do? - reporting, patch management\r\nConditional Access policies - there are a number of complications to how conditional access policies apply. Inclusion vs exclusion of items, objects, etc. Detailed discussion of the various filters and controls, how each is applied and managed - 15 mins\r\n  - Users\r\n  - Applications & Actions\r\n  - Conditions\r\n  - Sessions\r\n  - Controls\r\n  - Device filters\r\n  - Limitations & Challenges - limitations discovered during large scale implementation\r\n- Putting it all together - 10 mins\r\n  - Wide policies vs specific policies - affects of widely applied vs specific policies.\r\n  - OS specific policies \r\n  - Browser only vs App policies - settings that don't work on one or the other.\r\n  - Interesting special cases - things that should never happen, but seem to all the time. Things you will want to block, control, or manage. \r\n- A blueprint from least to most trust across a grid of situations - 5 mins\r\n  - Includes BYOD, On premise, off premise,  fully managed, completely unmanaged and untrusted.\r\n  - How this relates to healthcare settings\r\n  - References\r\nQuestions - 5 mins", "recording_license": "", "do_not_record": false, "persons": [{"code": "XCAVFF", "name": "Don Mallory", "avatar": null, "biography": "Don Mallory has over 30 years of experience in enterprise IT, primarily in critical infrastructure, specializing in operations, data storage, disaster recovery, and security for critical infrastructure. Professionally, Don is a Senior Security Analyst in the healthcare sector. He has been involved in various volunteer activities including C3X as a builder and mentor, co-organizer of Hak4Kidz Toronto and the Latow Photographer's Guild at the Art Gallery of Burlington, where he teaches traditional wet darkroom photography.", "public_name": "Don Mallory", "guid": "4a433e14-e357-5a61-a5ab-36929f406572", "url": "https://cfp.hackfest.ca/hf2023/speaker/XCAVFF/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/ZGFADY/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/ZGFADY/", "attachments": []}, {"guid": "37b755fc-001b-59ff-b6d4-b3cb1626febf", "code": "CGJ3ES", "id": 187, "logo": "https://cfp.hackfest.ca/media/hf2023/images/CGJ3ES/mitmpstnlogo_NxwfuMh.png", "date": "2023-10-13T17:30:00-04:00", "start": "17:30", "duration": "00:20", "room": "Track #2", "slug": "hf2023-187-mitm-on-pstn-novel-methods-for-intercepting-phone-calls", "url": "https://cfp.hackfest.ca/hf2023/talk/CGJ3ES/", "title": "MITM on PSTN -- novel methods for intercepting phone calls", "subtitle": "", "track": "Offensive", "type": "Speed Talk", "language": "en", "abstract": "In this talk the author proposes a novel method for intercepting phone calls over PSTN, including mobile networks.\r\nWe'll briefly each discuss the necessary components of the attack, including Caller ID spoofing, SS7, call diverts, and social engineering, and then join the all together to form the novel attack method.", "description": "Two separate methods will be proposed.\r\nThe author will provide a pre-recorded demo of each attack. \r\n\r\n\r\n1. PSTN / MN / CLIP / CNAM\r\n2. SS7 features and attacks\r\n3. Relevant social engineering techniques\r\n4. Attack 1: Simultaneous ring attack\r\n5. Attack 2: Diversion attack\r\n6. Tactic 1: Interception of phone calls\r\n7. Tactic 2: Alteration of phone calls (content)\r\n8. Tactic 2: Alteration of phone calls (metadata)\r\n9. Proposed solutions\r\n\r\nNote that the presentation includes pre-recorded demos as it's ill-advised to do this live in a conference for legal reasons.", "recording_license": "", "do_not_record": false, "persons": [{"code": "FRZKR3", "name": "Kirils Solovjovs", "avatar": null, "biography": "Kirils Solovjovs is an IT policy activist, bug bounty hunter, and the most visible white-hat hacker in Latvia having discovered and responsibly disclosed or reported multiple security vulnerabilities in information systems of both national and international significance. He has extensive experience in social engineering, penetration testing, network flow analysis, reverse engineering, and the legal dimension.\r\n\r\nHe has developed the jailbreak tool for Mikrotik RouterOS, as well as created e-Saeima, helping the Latvian Parliament become the first parliament in the world that is prepared for a fully remote legislative process. He has spoken at many amazing conferences including Hack In The Box, Hack in Paris, TyphoonCon, MCH2022, 35C3, CONFidence, BalCCon, Nullcon, and of course Hackfest.", "public_name": "Kirils Solovjovs", "guid": "60d34ff6-7be5-5eaf-bab3-484763e8ebb9", "url": "https://cfp.hackfest.ca/hf2023/speaker/FRZKR3/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/CGJ3ES/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/CGJ3ES/", "attachments": []}], "Workshops & Speed": [{"guid": "1eb62642-983e-54cc-b771-c5f4d3022300", "code": "ADCHRP", "id": 185, "logo": null, "date": "2023-10-13T09:00:00-04:00", "start": "09:00", "duration": "00:50", "room": "Workshops & Speed", "slug": "hf2023-185-the-dark-side-of-cloud-attack-tools-underground-style", "url": "https://cfp.hackfest.ca/hf2023/talk/ADCHRP/", "title": "The Dark side of Cloud attack tools (underground style)", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "en", "abstract": "I'll show you an analysis of 3 cloud hacking tools that were taken from the underground. These tools are being used these days by hackers and being sold/downloadable on the Darknet and other hackers forums. You will be amazed how simple to use these tools are and how easy it is to operate them. These tools are the first phase of hacking cloud accounts and emails. We will focus on brute force and password spraying tools, show you the tools, what they are doing and a deep analysis of the tools including decryption of their encrypted communication. To wrap it up we will talk about the current landscape changes of cloud attacks.", "description": "I'll show you an analysis of 3 cloud hacking tools that were taken from the underground. These tools are being used these days by hackers and being sold/downloadable on the Darknet and other hackers forums. You will be amazed how simple to use these tools are and how easy it is to operate them. These tools are the first phase of hacking cloud accounts and emails. We will focus on brute force and password spraying tools, show you the tools, what they are doing and a deep analysis of the tools including decryption of their encrypted communication. To wrap it up we will talk about the current landscape changes of cloud attacks. \r\n\r\n\r\n5 Minutes - Opening\r\n5 Minute - Where did I got the tools\r\n10 Minutes - 1st hacking tool analysis and explanation \r\n10 Minutes - 2st hacking tool analysis and explanation \r\n10 Minutes - 3st hacking tool analysis and explanation \r\n5 Minutes - The current attack landscape of the cloud\r\n5 Minutes Q&A", "recording_license": "", "do_not_record": false, "persons": [{"code": "9Z8P9X", "name": "Yaniv Miron", "avatar": null, "biography": "Yaniv Miron - While finding interest in computers, networks and cyber security from a young age he worked as a security consultant and researcher for years. He holds a CISO certification from The Israeli Institute of Technology in addition to certifications as Certified Expert Penetration Tester (CEPT), Certified Reverse Engineering Analyst (CREA), Certified SCADA Security Architect (CSSA) and Win32 Exploit Development. Mr. Miron found 0-days in Microsoft products, Oracle products and others and have reported and credited for these issues. he is a worldwide speaker in hacking and security conferences as BlackHat, HackFest, Power Of Community, Confidence, IL.Hack and Hacker Halted. Mr. Miron is an entrepreneur and inventor with years of experience managing startups, turning startups from an idea to a fully working solution. LinkedIn profile: https://www.linkedin.com/in/yanivmiron/", "public_name": "Yaniv Miron", "guid": "c7787399-d326-5aba-aaf8-2eaa7204ff08", "url": "https://cfp.hackfest.ca/hf2023/speaker/9Z8P9X/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/ADCHRP/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/ADCHRP/", "attachments": []}, {"guid": "9c944943-3200-556d-a404-b921257223a4", "code": "KQGZLF", "id": 238, "logo": "https://cfp.hackfest.ca/media/hf2023/images/KQGZLF/Art_of_Threat_Hunting_FK4LsdU.png", "date": "2023-10-13T11:00:00-04:00", "start": "11:00", "duration": "00:50", "room": "Workshops & Speed", "slug": "hf2023-238-the-art-science-of-threat-hunting-endpoint-signal", "url": "https://cfp.hackfest.ca/hf2023/talk/KQGZLF/", "title": "The Art & Science of Threat Hunting Endpoint Signal", "subtitle": "", "track": "Sponsor", "type": "Regular Talk", "language": "en", "abstract": "Threat hunting is both an art and a science. In this session, we\u2019ll cover the basics of threat hunting, what a well-architected program looks like, lessons learned, share ideas and concepts, and conduct a live hunt. \r\n \r\nA proactive security team is an effective security team.\r\nLearn how we can reduce adversary dwell time and increase operational tempo with threat hunting over endpoint telemetry.", "description": "The 2022 cyber threat landscape was defined by persistence, increased target\r\nscope and relentless determination. As businesses began to ease pandemic-driven\r\noperating environments and adjust to geopolitical shifts and growing economic\r\nhardships, adversaries supporting nation-state, eCrime and hacktivist motivations started\r\n2022 with a relentless show of effort that endured throughout the year.\r\nNation-state adversaries engaged in relentless computer network operations throughout\r\n2022, emphasizing the integral role these operations play in supporting state goals.\r\nRussian state-nexus adversaries combined destructive, espionage and information\r\noperations (IO) attacks in constant support of the Ukraine war, and China statenexus adversaries dominated the cyber threat landscape with a significant increase\r\nin espionage operation volume and target scope. Iran continued to focus on regional\r\nespionage campaigns and their now-signature destructive \u201clock-and-leak\u201d operations\r\nleveraging ransomware, and Democratic People\u2019s Republic of Korea (DPRK) state-nexus\r\nadversaries persisted in cryptocurrency theft campaigns to supplement state funds in the\r\nwake of the COVID-19 pandemic and the nation\u2019s long-standing economic hardship.\r\nOver the course of 2022, eCrime adversaries continued to prove their ability to adapt,\r\nsplinter, regroup and flourish in the face of defensive measures. After some of the biggest\r\nand most notorious ransomware enterprise shutdowns, ransomware affiliates moved to new\r\nransomware-as-a-service (RaaS) operations. Additionally, more than 2,500 advertisements\r\nfor access were identified across the criminal underground, representing a 112% increase\r\ncompared to 2021 and demonstrating a clear demand for access broker services.", "recording_license": "", "do_not_record": true, "persons": [{"code": "KYCF7S", "name": "Andrew Munchbach", "avatar": null, "biography": "Andrew is a computer scientist with over fifteen years of experience in endpoint security and related competencies. Andrew joined CrowdStrike in 2015 and currently serves as Vice President of Field Engineering.", "public_name": "Andrew Munchbach", "guid": "ba461415-0b35-5c9f-a813-b3f7d1439980", "url": "https://cfp.hackfest.ca/hf2023/speaker/KYCF7S/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/KQGZLF/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/KQGZLF/", "attachments": []}, {"guid": "802d034d-fa2c-50da-ad0e-efff869d392f", "code": "9BXV9C", "id": 241, "logo": null, "date": "2023-10-13T12:00:00-04:00", "start": "12:00", "duration": "01:30", "room": "Workshops & Speed", "slug": "hf2023-241-ultimate-test-drive-next-generation-firewalls", "url": "https://cfp.hackfest.ca/hf2023/talk/9BXV9C/", "title": "Ultimate Test Drive - Next-Generation Firewalls", "subtitle": "", "track": "Sponsor", "type": "Workshop - 120 minutes", "language": "en", "abstract": "///EN\r\nThis is your chance to get behind the driver\u2019s seat of the industry\u2019s leading network security solutions. This workshop is customized to enhance your understanding of how our products work and how they can improve your organization\u2019s security posture. We\u2019ll take you step-by-step through each of our solutions, with an expert instructor to guide you.\r\n\r\n///FR\r\nVoici l'opportunit\u00e9 de prendre le volant du pare-feu chef de file de l'industrie de la s\u00e9curit\u00e9 des r\u00e9seaux. Cette session vous permettra d'augmenter votre compr\u00e9hension de nos pare-feux, comment les op\u00e9rer, en tirer la valeur pour ultimement, augmenter la posture de s\u00e9curit\u00e9 de votre organisation. Nous vous guiderons \u00e9tape par \u00e9tape \u00e0 travers la solution avec un instructeur expert pour vous soutenir.", "description": "///EN\r\n . Learn to ensure application access is by user-IDs. \r\n . Configure Cloud Identity Engine for authentication and identity/User-ID.\r\n . Create application-based policy with Policy Optimizer. \r\n . Setup granular control for Social Media and Sanctioned SaaS Applications.\r\n . Add new decryption policies to decrypt SSL (TLS 1.3) traffic.\r\n . Create a custom report in the Application Command Center.\r\n . Learn to use the new AIOps dashboards.\r\n\r\nAll you need is your own laptop with Internet access.\r\n\r\n///FR\r\n . S'assurer que les acc\u00e8s aux applications sont contr\u00f4l\u00e9s par UserID.\r\n . Utiliser le service Cloud Identity Engine pour l'authentification et identit\u00e9 UserID.\r\n . Cr\u00e9er des politiques de s\u00e9curit\u00e9 applicatives via le Policy Optimizer. \r\n . Cr\u00e9er des contr\u00f4les granulaires pour les applications des r\u00e9seaux sociaux et SaaS.\r\n . Ajouter des politiques de d\u00e9chiffrement SSL (TLS 1.3).\r\n . G\u00e9n\u00e9rer des rapports personnalis\u00e9s dans l'Application Command Center.\r\n . Apprendre \u00e0 utiliser les tableaux de bords d'AI Ops.\r\n\r\nTout ce dont vous avez besoin est de votre ordinateur portable avec acc\u00e8s \u00e0 l'Internet.", "recording_license": "", "do_not_record": false, "persons": [{"code": "9AMCXU", "name": "Guillaume Roy", "avatar": null, "biography": null, "public_name": "Guillaume Roy", "guid": "86beccf5-1df4-5032-9071-982a9132f5d5", "url": "https://cfp.hackfest.ca/hf2023/speaker/9AMCXU/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/9BXV9C/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/9BXV9C/", "attachments": []}, {"guid": "0941f085-80e9-5f24-8f35-0d88cde3061d", "code": "7NFLVW", "id": 243, "logo": null, "date": "2023-10-13T13:30:00-04:00", "start": "13:30", "duration": "01:00", "room": "Workshops & Speed", "slug": "hf2023-243-cortex-xpanse-capture-the-flag-where-in-the-world-are-your-exposures", "url": "https://cfp.hackfest.ca/hf2023/talk/7NFLVW/", "title": "CORTEX XPANSE CAPTURE THE FLAG: Where in the World are Your Exposures?", "subtitle": "", "track": "Sponsor", "type": "Workshop - 120 minutes", "language": "en", "abstract": "Step into the exciting world of the Cortex Xpanse Capture the Flag challenge! This game invites participants to journey through the Expander UI, tackling a series of intricate challenges. For each challenge conquered, players will be rewarded with a \"flag\" and earn valuable points. The ultimate glory goes to the team or individual who unravels the most mysteries and accumulates the highest score. By participating, you not only get a hands-on experience with Cortex Xpanse but also indulge in a fun, immersive competition. This event is tailored to both seasoned pros and enthusiastic newcomers. Are you up for the challenge? Dive in, learn, compete, and emerge victorious!\r\n\r\nThis game, with a duration of one hour, calls on participants to explore the Expander interface. Make sure to bring your laptop to take part in this challenge.\r\n\r\n=========\r\n\r\nEntrez dans l'univers palpitant du d\u00e9fi Capture the Flag de Cortex Xpanse! Ce jeu invite les participants \u00e0 s'aventurer dans l'interface Expander, en affrontant une s\u00e9rie de d\u00e9fis \u00e9labor\u00e9s. Chaque d\u00e9fi surmont\u00e9 r\u00e9compensera les joueurs avec un \"drapeau\" et leur permettra de gagner des points pr\u00e9cieux. La gloire supr\u00eame est d\u00e9cern\u00e9e \u00e0 l'\u00e9quipe ou \u00e0 l'individu qui d\u00e9voile le plus de myst\u00e8res et obtient le score le plus \u00e9lev\u00e9. En participant, vous b\u00e9n\u00e9ficiez non seulement d'une exp\u00e9rience pratique avec Cortex Xpanse, mais vous vous immergez aussi dans une comp\u00e9tition amusante et immersive. Cet \u00e9v\u00e9nement est adapt\u00e9 aussi bien aux professionnels chevronn\u00e9s qu'aux novices enthousiastes. \u00cates-vous pr\u00eat \u00e0 relever le d\u00e9fi? Plongez, apprenez, concourez et triomphez!\"\r\n\r\n\r\nCe jeu, d'une dur\u00e9e d'une heure, sollicite les participants \u00e0 explorer l'interface d'Expander. Assurez-vous d'apporter votre ordinateur portable pour participer \u00e0 ce d\u00e9fi.", "description": "Step into the exciting world of the Cortex Xpanse Capture the Flag challenge! This game invites participants to journey through the Expander UI, tackling a series of intricate challenges. For each challenge conquered, players will be rewarded with a \"flag\" and earn valuable points. The ultimate glory goes to the team or individual who unravels the most mysteries and accumulates the highest score. By participating, you not only get a hands-on experience with Cortex Xpanse but also indulge in a fun, immersive competition. This event is tailored to both seasoned pros and enthusiastic newcomers. Are you up for the challenge? Dive in, learn, compete, and emerge victorious!\r\n\r\nThis game, with a duration of one hour, calls on participants to explore the Expander interface. Make sure to bring your laptop to take part in this challenge.\r\n\r\n=========\r\n\r\nEntrez dans l'univers palpitant du d\u00e9fi Capture the Flag de Cortex Xpanse! Ce jeu invite les participants \u00e0 s'aventurer dans l'interface Expander, en affrontant une s\u00e9rie de d\u00e9fis \u00e9labor\u00e9s. Chaque d\u00e9fi surmont\u00e9 r\u00e9compensera les joueurs avec un \"drapeau\" et leur permettra de gagner des points pr\u00e9cieux. La gloire supr\u00eame est d\u00e9cern\u00e9e \u00e0 l'\u00e9quipe ou \u00e0 l'individu qui d\u00e9voile le plus de myst\u00e8res et obtient le score le plus \u00e9lev\u00e9. En participant, vous b\u00e9n\u00e9ficiez non seulement d'une exp\u00e9rience pratique avec Cortex Xpanse, mais vous vous immergez aussi dans une comp\u00e9tition amusante et immersive. Cet \u00e9v\u00e9nement est adapt\u00e9 aussi bien aux professionnels chevronn\u00e9s qu'aux novices enthousiastes. \u00cates-vous pr\u00eat \u00e0 relever le d\u00e9fi? Plongez, apprenez, concourez et triomphez!\"\r\n\r\n\r\nCe jeu, d'une dur\u00e9e d'une heure, sollicite les participants \u00e0 explorer l'interface d'Expander. Assurez-vous d'apporter votre ordinateur portable pour participer \u00e0 ce d\u00e9fi.", "recording_license": "", "do_not_record": false, "persons": [{"code": "AL7S9S", "name": "Patrick Hamel", "avatar": null, "biography": null, "public_name": "Patrick Hamel", "guid": "d941e979-a33c-507e-88c6-f3a7f89aaa04", "url": "https://cfp.hackfest.ca/hf2023/speaker/AL7S9S/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/7NFLVW/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/7NFLVW/", "attachments": []}, {"guid": "61a6554d-d05f-576d-86a6-6eed85e08ba9", "code": "ZTQ7DM", "id": 182, "logo": null, "date": "2023-10-13T14:30:00-04:00", "start": "14:30", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-182-how-a-global-retail-hack-breathed-life-into-static-security-analysis", "url": "https://cfp.hackfest.ca/hf2023/talk/ZTQ7DM/", "title": "How a Global Retail Hack Breathed Life Into Static Security Analysis", "subtitle": "", "track": "Defensive", "type": "Speed Talk", "language": "en", "abstract": "Static Application Security Testing (SAST) enables organizations to detect vulnerabilities in code early; however, interviews with application security analysts indicate that SAST reports are often dense and include little to no visual aids. \r\n\r\nOver the Winter and Spring of 2023, my research partner and I invented the Abstract Syntax Tree Reader and Analyzer (ASTRA) which responds to this need of a value-adding and intuitive visual aid for more rapid and thorough consumption of SAST insights. ASTRA is a collection of Python scripts that transforms certain parts of SAST documentation a Universal Graph Format which can be imported into many graphical visualization tools.\r\n\r\nThe key insight from our research is that vulnerability stack traces, which are spread sparsely in the report and often overlooked by security analysts, can be collected and graphed to provide new vulnerability information. Once graphed, principles of graph theory can be applied to make calculations. These include calculating the substructure entropy to discover surprising occurrences and calculating the modularity for the number of vulnerability communities in code repositories. Further, calculating the eigenvector centrality allows us to see the extent to which each individual vulnerability contributes to the overall vulnerability graph of the application. \r\n\r\nAs a result, the files contributing most to the vulnerability profile of the application will be identified. Sections of the applications that are most vulnerable will also be able to be identified. Our transformed ASTRA data has been successfully uploaded into standard 2D and 3D graphing engines, as well as Virtual Reality (VR) simulations so analysts are able to explore SAST results more intuitively, bringing more humanity and rigorous calculation into cyber analysis.", "description": "DESCRIPTION\r\n[Presentation Flow]\r\n\r\n1...Introductions and Presentation Title - 1 min.\r\n\r\n2...Laying Out the Problem Statement - 3 min.\r\n\r\n3...Tool Demo - 2 min.\r\n\r\n4...Capabilties and Use of Graph Theory - 5 min.\r\n\r\n5...Virtual Reality Plug-In - 2 min.\r\n\r\n6...Feasibility Study - 3 min.\r\n\r\n7...Graph Theory - 2 min.\r\n\r\n8...Conclusion, Invite Audience Members to Use Oculus Headset and Visualize (if permitted by Hackfest) - 2+ min. \r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Introductions and Presentation Title]\r\nMy co-speaker and I will introduce ourselves.\r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Laying Out the Problem Statement]\r\nWe draw the crowd in by telling the story of a security incident we were involved in for a retail company. We will describe the hunt for the elusive root cause during which we combed through application scanning reports that were generated in the last code review. We pulled it up, hoping it would provide the answers we needed. But we scrolled through the 1000+ page report, it became clear that it would take too long to manually analyze the data.\r\n\r\nDetermined to find a solution, we began exploring different ways to analyze the application report data. We tried sorting it by severity, looking for patterns and trends, and manually creating visualizations, but nothing seemed to provide the insight we needed.  That\u2019s when we stumbled on this research idea that promised to revolutionize one part of the way we solve cyber incidents. \r\n\r\nIn consequence, we developed ASTRA \u2013 Abstract Syntax Tree Reader and Analyzer. By leveraging graph theory and advanced data visualization techniques, the solution could transform the complex application data into easy-to-understand visualizations that would highlight the most critical vulnerabilities.\r\n\r\nASTRA builds an explorable world from endless reports of security documentation. When we run these reports through ASTRA code, the data is re-shaped into a graph. We turn the application\u2019s files into the graph nodes while the lines in the graph (called graph edges) represent a connection between two files.\r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Tool Demo]\r\nWe will play the GraphViz graphical representation and interact with it live in front of the Hackfest audience. The result of ASTRA is this visual representation of the application geometry. I can see the files come alive. I can interact with the most vulnerable files and see how they\u2019re connected. The thicker the graph edge, the higher the number of vulnerabilities are being exchanged between the two files.\r\n\r\nInstead of being tailored to answer a specific question, the beauty of the graph visualization is that it\u2019s just the platform on which anyone can bring their domain expertise, their lens, and their hypotheses. Being set free to explore the application and bringing in more humanity to cyber analysis.\r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Capabilities and Use of Graph Theory]\r\nOur users can filter by how much certain files contribute to and bring down the security health of the application. We can automatically draw lines around the number of clusters or communities for the graphs and use anomaly detection to find surprising or unusual occurrences. The takeaway is that seeing and feeling the application geometry unlocks key security information.\r\n\r\nDuring the live demo at Hackfest, we will run ASTRA on the architecture of the problematic application mentioned at the beginning of the presentation. The client was notified of faulty encryption. Now, instead of looking for it in a 1000-page report, we have the luxury of hovering our cursor over the encryption file. And seeing which files it\u2019s connected to. Here, we see that the culprits jump out at us. \r\n\r\nOur use cases expand beyond conducting a root cause analysis. ASTRA is an accelerator to architecture mapping and threat modeling. It engages developers in security awareness programs and enhances the application security tools that many organizations already use. \r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Virtual Reality and Demo of Virtual Reality Experience]\r\nWhat if we push the envelope even further? What if we could take anything you could experience on a screen and stretch it into your entire field of vision. Enter virtual reality where now we interact with the data as if we are a file on this graph, or maybe \u2026 you\u2019re even the attacker\u2019s payload.\r\n \r\nWith VR we can walk around in this world and interact with the once lifeless words in a thousand-page report. In this way we can shine a light on insights that were locked away in piles of information. Turning our attention to our screens, the main source file has many critical vulnerabilities, and we can see all of the other folders that it calls. The value in ASTRA is when it forces us to notice what we never expected to see.  \r\n\r\nHere, we will be providing our own Oculus headset for audience members to try out.\r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Feasibility Study]\r\nIf cyber-crime were a country, it would have the third largest GDP in the world, at $6T dollars in 2021 and growing. So it\u2019s not a surprise there\u2019s a sizable market for defensive cyber tools. Application security tools have a market of $6B and this is the market we\u2019re playing within. We see ASTRA as bundled with an existing application security tool.\r\n\r\nASTRA also satisfies the market trending toward automation. From our own study at a large French-Canadian bank, we found automation in threat modeling can reduce cycles by 35%. Adapting data to ASTRA, we can settle on a conservative ROI of 30%, which means 30% less human time spent on threat modeling, that can be channeled toward productive tasks. \r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Novelty]\r\nTo be clear, graph theory has never been applied before to application security vulnerability analysis. We conducted a literature review and market analysis, including interviews with subject matter experts. The use of graph theory for application security is not currently a feature in any tool on the market, nor in any paper, which we think could increase market attractiveness. \r\n\r\nOur ASTRA technical fundamentals scale to 6000x. That is, our virtual reality simulation would only slow down at 70,000 connections or 6,000 files. The way forward for us is to make it better by bringing in more features, like color coding files in VR. \r\n\r\nASTRA was designed to help visualize threats, but our software can be applied to graphically visualize other kinds of attacks, like those over a network or hardware attacks like IOT devices. \r\n\r\nOur key takeaways are that we can adopt the mindset of genuinely engaging with developers in addition to relying on text-based reports.\r\n\r\nGraph Theory has never been applied before in vulnerability analysis and we are looking forward to what benefits ASTRA could bring.  \r\n\r\n-----------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n[Conclusion]\r\nFuture of work\r\nAs people we have an innate desire to explore and learn on our own. We hope that vision behind ASTRA brings us all one step closer to that future of work.\r\n\r\nIf permitted by Hackfest, we will encourage enthusiastic audience members to come up and experience the virtual reality SAST visualization using a sanitized Accenture-owned Oculus headset that we will provide.", "recording_license": "", "do_not_record": false, "persons": [{"code": "CL9QLE", "name": "Naeem Budhwani", "avatar": null, "biography": "Naeem Budhwani is a cyber defense consultant at Accenture\u2019s Cyber Attack Simulation (CAS) practice. He was previously an associate in PwC Canada\u2019s Cybersecurity & Privacy practice. Across these roles, Naeem has consulted for over a dozen clients, from boutique insurance firms looking to develop IR playbooks to multi-national technology giants undergoing an application security transformation. He is regarded as a Canadian subject matter expert in threat modeling, having been brought in to conduct executive interviews for Crown Corporations and provide large-audience technical application security training to financial institutions.\r\n\r\nNaeem has also delivered guest lectures on application security at Seneca College and York University. He holds a bachelor\u2019s in applied mathematics and computer science from the University of Western Ontario.", "public_name": "Naeem Budhwani", "guid": "d7aa2a3c-c590-5b0a-8cdc-1905d4765140", "url": "https://cfp.hackfest.ca/hf2023/speaker/CL9QLE/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/ZTQ7DM/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/ZTQ7DM/", "attachments": []}, {"guid": "bc3d0de0-0a51-5b53-a9b5-222d716090af", "code": "ASRMBB", "id": 235, "logo": "https://cfp.hackfest.ca/media/hf2023/images/ASRMBB/highlevel_xhkm8oo.png", "date": "2023-10-13T15:00:00-04:00", "start": "15:00", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-235-cryptojacking-defending-against-cloud-compute-resource-abuse", "url": "https://cfp.hackfest.ca/hf2023/talk/ASRMBB/", "title": "Cryptojacking: Defending against cloud compute resource abuse", "subtitle": "", "track": "Defensive", "type": "Speed Talk", "language": "en", "abstract": "As Cloud computing evolves, adversaries can take advantage of new attack surfaces and services. The threat actors are deploying sophisticated campaign strategies to abuse millions of dollars in cloud computing in compromised tenants and subscriptions while avoiding detection. Microsoft's research reveals that targeted organizations faced more than $300,000 in compute fees from cryptojacking attacks.\r\n\r\n\r\nIn this talk, we will explore the attackers\u2019 behaviours that we observed in numerous incidents across many organizations. We will dissect the inner workings of cloud attacks such as cryptojacking and resource abuse. As we move from the Initial Access stage to the Impact stage, we will explore key TTPs (Tactics, Techniques, and Procedures). Additionally, we will explore several ways that threat actors can abuse and hijacking subscriptions that are forensically disruptive. By analyzing footprints and logs, we will provide insights that blue teamers can use to detect and counterattack these at early stage of attacks", "description": "Introduction [3 minutes]\r\n\r\nAs Cloud computing evolves, adversaries can take advantage of new attack surfaces and services. The threat actors are deploying sophisticated campaign strategies to abuse millions of dollars in cloud computing in compromised tenants and subscriptions while avoiding detection. Microsoft's research reveals that targeted organizations faced more than $300,000 in compute fees from cryptojacking attacks. In this presentation, we will share the discovered TTPs (Tactics, Techniques, and Procedures) that we observed in numerous organizations executed by several threat actor groups.\r\n\r\nCryptojacking Anatomy [15 minutes]\r\n\r\nCloud cryptojacking/abuse follows a similar attack lifecycle regardless of the cloud provider. We will dissect the inner workings of cloud these attacks. As we move from the initial access stage to the impact stage, we will explore key TTPs. By analyzing footprints and logs, we will provide insights that blue teamers can use to detect and counterattack these threats especially at early stage of attacks.\r\n\r\n1.\tInitial access - Compromised credentials: Threat actors need compromised credentials with Virtual Machine contributor role to execute attacks, making credential hygiene and cloud hardening crucial. In most of the cases, the compromised accounts did not have multi-factor authentication (MFA) enabled. \r\nAfter gaining access, some threat actors use attacker-controlled virtual machines within legitimate tenants as their operational infrastructure. By using living-off-the-land techniques, threat actors can operate without any infrastructure external to the cloud environment.\r\n2.\tPrivilege escalation - Elevating access: In some cases, threat actors compromise the global administrator account. Global administrator accounts may not possess access to all subscriptions and management groups in the directory; to gain permissions over all resources, the 'elevate access' option must be activated for the account.\r\n3.\tDefense evasion - Subscription hijacking: Once the threat actor compromised the tenant and performed reconnaissance to determine available permissions, the attacker may proceed to transfer (hijack) the subscription to another tenant (attacker-controlled). Subscription hijacking is an evasion technique that allows the threat actor to hide some of their activities from the tenant administrator and security teams. Subscription hijacking is disruptive forensically as all activity logs are stored at subscription level and there would be no events for incident response teams. \r\n4.\tImpact - Increasing core quotas: To boost the cloud compute abuse, the threat actors often increase the Virtual Machine core quota to deploy massive amounts of computing power. GPU compute offerings are often targeted by threat actors. GPU compute provides access to high performance NVIDIA and AMD GPU cores, allowing cryptocurrency mining magnitudes more effective than any CPU compute offering.\r\n5.\tImpact - Deploying compute: Malicious provisioning behavior of compute generally does not match existing compute provisioning patterns within the tenant. Threat actor ultimately needs to provision compute very quickly to make the attack profitable. This time restriction means that patterns in provisioning generally emerge over relatively short periods of time.\r\n6.\tImpact - Mining cryptocurrency: Once subscription is compromise and the compute is created, the threat actor can begin mining cryptocurrency by deploying mining software to the newly created VMs. The installed mining software joins the VM to a mining pool, which allows the threat actor to pool their stolen processing power from multiple compromised tenants. Threat actors may need to install GPU drivers to take full advantage of the graphics card, especially on N-series VMs. Actors have been observed abusing Azure Virtual Machine extensions such as an NVIDIA GPU Driver Extension for Windows or Linux, or an AMD GPU Driver Extension for Windows, to facilitate driver installation.\r\n\r\nKey Take away for:\r\n1.\tBlue Teamers and threat hunters: Take in new TTPs observed by Microsoft experts on several compromised cases and practical information to build high fidelity detections.\r\n2.\tRed Teamers: Get up to speed with related techniques used by ATPs (Advanced persistent threat) which are tracked by Microsoft security experts.\r\n3.\tGRC and Management: Understanding of strategies to strengthen cloud security postures, protect cloud workloads, and defend against a wide range of cloud-based threats and risks.\r\n\r\n\r\nQuestions [2 minutes]", "recording_license": "", "do_not_record": false, "persons": [{"code": "CPLV9R", "name": "Amir Gharib", "avatar": null, "biography": "Amir Gharib is a senior security researcher at Microsoft. His main responsibility is to improve Microsoft\u2019s detection capabilities across different workloads by researching novel attacks and detection mechanisms. As part of his role, he leverages events and signals from a variety of workloads and products to develop high-fidelity detection that can be used to disrupt attacks automatically. In the past, he was a technical manager at PwC performing incident response, threat hunting, and detection engineering. Furthermore, he worked with IBM Qradar to develop UEBA solutions for users and entities. He currently holds GCFA certification and a Master of Computer Science (MCS) degree specialized in cybersecurity. He has published and presented at several international conferences and journals. His publications have received more than 600 citations in recent years. Outside of work, he enjoys spending time with his family (plus his dog) and friends. He is currently training toward his private pilot license (PPL).", "public_name": "Amir Gharib", "guid": "e67b3abe-928a-58b2-bf66-be71e38a5e6b", "url": "https://cfp.hackfest.ca/hf2023/speaker/CPLV9R/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/ASRMBB/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/ASRMBB/", "attachments": []}, {"guid": "d35833ab-3f33-578f-b4a9-c5e678b536d3", "code": "GVFX3J", "id": 184, "logo": null, "date": "2023-10-13T15:30:00-04:00", "start": "15:30", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-184-les-nouveaux-business-du-blackmarket", "url": "https://cfp.hackfest.ca/hf2023/talk/GVFX3J/", "title": "Les nouveaux \"Business\" du blackmarket", "subtitle": "", "track": "Threat Intelligence / OSINT", "type": "Speed Talk", "language": "fr", "abstract": "Concours de tatouage, vol de bus, d\u00e9tournement de panneau publicitaire, \"black friday\" et soldes, Etc. Le blackmarket a \u00e9volu\u00e9, en 30 ans, pour proposer un marketing de la malveillance agressif.", "description": "Dans un monde o\u00f9 le march\u00e9 noir est en expansion constante, il devient essentiel pour les professionnels de la cybers\u00e9curit\u00e9, des chefs d'entreprises ou du \"simple\" citoyen de comprendre les d\u00e9fis qui se pr\u00e9sentent dans ce secteur illicite. La conf\u00e9rence explorera les strat\u00e9gies et les tactiques utilis\u00e9es par les acteurs du march\u00e9 noir pour promouvoir et vendre leurs produits et services (faux papiers, failles, acc\u00e8s, brokers, Etc). Comprendre leur fonctionnement pour mieux s'en prot\u00e9ger !\r\n\r\nPoints cl\u00e9s abord\u00e9s :\r\n\r\nIntroduction au march\u00e9 noir : d\u00e9finition, tendances actuelles et enjeux. [2mns]\r\nLes acteurs du march\u00e9 noir : comprendre leur motivation et leurs cibles. [2 mns]\r\nTechniques de marketing illicites : publicit\u00e9 clandestine, vente en ligne anonyme, vol de bus, promotions, concours (gagner 5 grammes de coca\u00efne ; ...) [10 mns]\r\n\u00c9tudes de cas : exemples concrets de campagnes de marketing dans le black market. [5 mns]\r\n\r\nObjectifs de la conf\u00e9rence :\r\nComprendre les strat\u00e9gies et les tactiques de marketing utilis\u00e9es dans le march\u00e9 noir.\r\nSensibiliser aux risques li\u00e9s \u00e0 ces pratiques.\r\nEncourager la r\u00e9flexion et les d\u00e9bats sur la r\u00e9glementation et la lutte contre le march\u00e9 noir.\r\n\r\nPublic cible :\r\nCette conf\u00e9rence s'adresse aux professionnels du marketing, aux entrepreneurs, aux juristes, aux \u00e9tudiants, ainsi qu'\u00e0 tous ceux qui souhaitent comprendre les dynamiques et les enjeux du marketing dans le march\u00e9 noir.", "recording_license": "", "do_not_record": false, "persons": [{"code": "37ZG99", "name": "Damien Bancal", "avatar": null, "biography": "Damien Bancal est un expert en cyber intelligence fran\u00e7ais. Il est connu pour son travail dans le domaine de la sensibilisation \u00e0 la s\u00e9curit\u00e9 informatique. Depuis plus de 30 ans, il \u00e9vang\u00e9lise sur toutes les questions li\u00e9es \u00e0 la protection des donn\u00e9es personnelles.\r\n\r\nDamien Bancal est le fondateur des sites Internet Zataz.ca, datasecuritybreach.fr et veillezataz.com. Il y partage des informations sur les fuites de donn\u00e9es, les failles de s\u00e9curit\u00e9 \u00e0 corriger et les cyberattaques. \r\nSon objectif principal est d'alerter, informer et \u00e9duquer les utilisateurs sur les menaces li\u00e9es \u00e0 la cybercriminalit\u00e9.\r\n\r\nAuteur de 16 livres, il a travaill\u00e9 1 an \u00e0 Montr\u00e9al et pour une quarantaine de m\u00e9dia de part le monde.\r\nIl a adore la poutine !", "public_name": "Damien Bancal", "guid": "93e2c1fc-8732-50ad-88be-ea3801076a84", "url": "https://cfp.hackfest.ca/hf2023/speaker/37ZG99/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/GVFX3J/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/GVFX3J/", "attachments": []}, {"guid": "e3582705-3280-54a1-a0b5-c6bae5989241", "code": "GHPW9Y", "id": 242, "logo": null, "date": "2023-10-13T16:00:00-04:00", "start": "16:00", "duration": "01:30", "room": "Workshops & Speed", "slug": "hf2023-242-ultimate-test-drive-cloud-delivered-security-services", "url": "https://cfp.hackfest.ca/hf2023/talk/GHPW9Y/", "title": "Ultimate Test Drive - Cloud Delivered Security Services", "subtitle": "", "track": "Sponsor", "type": "Workshop - 120 minutes", "language": "en", "abstract": "///EN\r\nThis is your chance to get behind the driver\u2019s seat of the industry\u2019s leading network security solutions. This workshop is customized to enhance your understanding of how our products work and how they can improve your organization\u2019s security posture. We\u2019ll take you step-by-step through each of our solutions, with an expert instructor to guide you. Learn how to protect your network and detect known, unknown and zero-day threats 180X faster than any other platform or point solution \u2013 all within a single, integrated best-of-breed security platform.\r\n\r\n///FR\r\nVoici l'opportunit\u00e9 de prendre le volant du pare-feu chef de file de l'industrie de la s\u00e9curit\u00e9 des r\u00e9seaux. Cette session vous permettra d'augmenter votre compr\u00e9hension de nos pare-feux, comment les op\u00e9rer, en tirer la valeur pour ultimement, augmenter la posture de s\u00e9curit\u00e9 de votre organisation. Nous vous guiderons \u00e9tape par \u00e9tape \u00e0 travers la solution avec un instructeur expert pour vous soutenir.", "description": "///EN\r\nExperience the value firsthand and see how you can:\r\n . Prevent 60% more unknown injection attacks that traditional IPS solutions miss.\r\n . Stop 26% more zero-day malware than traditional sandboxes.\r\n . Apply predictive analytics to disrupt attacks that attempt to exploit DNS traffic to cause harm.\r\n . Detect and prevent 40% more threats than traditional web filtering databases with inline \r\n   machine learning (ML)-powered web security that blocks new and evasive malicious websites.\r\n . Discover 90% of devices in the first 48 hours and expand visibility to all devices for IT and security teams \u2013 even devices never seen before.\r\n\r\nAll you need is your own laptop with Internet access.\r\n\r\n///FR\r\n\r\nApprenez comment prot\u00e9ger votre r\u00e9seau et d\u00e9tecter les attaques inconnues et zero day 180x plus rapidement qu'avec toute autre plateforme et ce, avec une console centralis\u00e9e de gestion.\r\n. Pr\u00e9venir 60% plus d'attaques d'injections que les solutions IPS traditionnelles.\r\n. Bloquer 26% plus d'attaques zero day de logiciels malveillants que les solutions de d\u00e9tonation traditionnelles.\r\n. Appliquer des techniques d'analyses pr\u00e9ventives sur les attaques exploitant le traffic DNS.\r\n. D\u00e9tecter et pr\u00e9venir 40% plus de menaces \u00e9vasives avec l'apprentissage machine (ML) que les solution traditionnelles de filtrage URL.\r\n. D\u00e9couvrir 90% des \u00e9quipements r\u00e9seaux lors des premi\u00e8res 48h et continuellement augmenter la visibilit\u00e9 de vos \u00e9quipements de l'Internet des objets.\r\n\r\nTout ce dont vous avez besoin est de votre ordinateur portable avec acc\u00e8s \u00e0 l'Internet.", "recording_license": "", "do_not_record": false, "persons": [{"code": "9AMCXU", "name": "Guillaume Roy", "avatar": null, "biography": null, "public_name": "Guillaume Roy", "guid": "86beccf5-1df4-5032-9071-982a9132f5d5", "url": "https://cfp.hackfest.ca/hf2023/speaker/9AMCXU/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/GHPW9Y/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/GHPW9Y/", "attachments": []}]}}, {"index": 2, "date": "2023-10-14", "day_start": "2023-10-14T04:00:00-04:00", "day_end": "2023-10-15T03:59:00-04:00", "rooms": {"Track #1": [{"guid": "3537d418-1468-55f8-877d-03e3126132e8", "code": "8B3QB8", "id": 197, "logo": "https://cfp.hackfest.ca/media/hf2023/images/8B3QB8/profile_L0qicIx.jpg", "date": "2023-10-14T09:00:00-04:00", "start": "09:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-197-gamepwn-101-introduction-to-game-hacking", "url": "https://cfp.hackfest.ca/hf2023/talk/8B3QB8/", "title": "GamePwn 101 - Introduction to Game Hacking", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "en", "abstract": "In the rapidly evolving landscape of gaming, understanding the realm of game hacking is essential, especially in multiplayer games. While some people engage in game hacking for fun or as a hobby, others use it to cheat and gain an advantage in online multiplayer games, which can ruin the experience for other players. As we delve together into this captivating subject, I will explore the fundamentals of game hacking, including its definition, real-world examples, common methods employed by hackers, and the measures implemented to counter such exploits.\r\n\r\nDiscover the intriguing world of cheats, bots, and exploits that have impacted the gaming industry. I will showcase notable instances where game hacking has disrupted fair play and affected player experiences. By examining these examples, I aim to raise awareness about the potential consequences and implications of game hacking. Furthermore, we will delve into the various techniques employed by hackers, such as memory editing, code injection, and packet manipulation. Understanding these methods is vital to recognize vulnerabilities and formulating effective countermeasures.\r\n\r\nThe discussion will also encompass the proactive steps taken by game developers to combat cheating, including encryption, client-server validation, behavior monitoring, and regular updates. By understanding these anti-cheat measures, we can gain insights into the ongoing battle between game developers and hackers. Lastly, we will explore the future of game hacking within the broader information security landscape, considering emerging technologies, evolving security measures, and the potential impact on the gaming industry.", "description": "This talk will be divided into the following five sections.\r\n\r\n1) What is game hacking?\r\n\r\nThis section serves as a brief introduction to game hacking. I will explain that game hacking involves modifying game code, data, or mechanics to gain an unfair advantage or access hidden content. I will also explore the motivations behind game hacking, such as achieving high scores, gaining prestige, or economic incentives in online games. The importance of understanding game hacking within the broader context of information security is emphasized.\r\n\r\n2) Real-world examples of game hacking (cheats, bots, exploits)\r\n\r\nThis segment showcases a range of real-world examples to illustrate the impact of game hacking. It covers cheats like aimbots, which provide enhanced aiming abilities, wallhacks that allow players to see through walls, and speed hacks that increase movement speed. The discussion also highlights the usage of bots for automated gameplay and farming resources. Additionally, it delves into exploits, such as duplication glitches or accessing restricted areas. Each example is explained in detail, discussing how they disrupt fair play and affect player experiences.\r\n\r\n3) Common game hacking methods\r\n\r\nThis section provides an in-depth exploration of the common methods employed by game hackers. It starts with memory editing, where hackers manipulate values stored in a game's memory to gain advantages like infinite health or unlimited resources. Code injection is then explained, involving the injection of custom code into a game's executable to modify its behavior. The discussion further includes techniques like packet manipulation, where network packets are intercepted and modified to gain unfair advantages. The inner workings of each method are described, emphasizing the technical aspects and their implications for game security.\r\n\r\n4) Anti-cheat measures\r\n\r\nHere, the focus shifts to the countermeasures implemented by game developers to combat cheating. Encryption is discussed as a means to protect game data and prevent unauthorized access. Client-server validation is explained, involving checks performed between the game client and server to detect inconsistencies and cheating attempts. The role of behavior monitoring systems in identifying suspicious player actions is highlighted. Continuous updates are emphasized as a crucial aspect of anti-cheat measures to patch vulnerabilities and stay ahead of hackers. The discussion also touches on the challenges faced by developers in balancing security measures with player experience.\r\n\r\n5) Future of game hacking\r\n\r\nThe final section explores the future landscape of game hacking within the broader context of information security. I will discuss emerging technologies and trends that may shape game hacking, such as the integration of artificial intelligence and machine learning. The potential impact of blockchain technology on securing in-game economies and preventing cheating is examined. The importance of ongoing research, collaboration among game developers, and the adoption of innovative security measures is emphasized to mitigate evolving threats in the dynamic world of game hacking.", "recording_license": "", "do_not_record": false, "persons": [{"code": "V3QHKR", "name": "James Li", "avatar": null, "biography": "James is currently a security advisor at an insurance company in Montreal. He has worked in the field of both offensive and defensive security. His interest in information security initially developed through video games. Subsequently, he decided to pursue this path by studying Computer Science with a focus on infosec. Along the way, James has obtained various certifications such as OSCP, CISSP, CBBH, etc. He also has a strong interest in game hacking, also known as \"Gamepwn\". This is a relatively lesser-known area within the broader context of information security, and James aims to bring this topic to a wider audience.", "public_name": "James Li", "guid": "7ad386cb-ba29-54af-b763-311edc8116d6", "url": "https://cfp.hackfest.ca/hf2023/speaker/V3QHKR/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/8B3QB8/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/8B3QB8/", "attachments": []}, {"guid": "44d789b0-70d2-554b-83a7-3c10029badd1", "code": "WQMGUN", "id": 233, "logo": null, "date": "2023-10-14T10:00:00-04:00", "start": "10:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-233-lessons-from-lastpass-beyond-secure-password-management", "url": "https://cfp.hackfest.ca/hf2023/talk/WQMGUN/", "title": "Lessons from LastPass: Beyond Secure Password Management", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "en", "abstract": "LastPass is a popular password manager used from individuals through corporate levels. However, in 2022 it suffered two breaches, and only recently was the extent of the damage made known. An unknown attacker was able to take the literal keys to the kingdom, compromising everything stored in the LastPass vaults.  This talk will bring to light why the LastPass events matter to everyone, even those who think they are safe using other password managers or no password managers. There are lessons here about sophisticated staged attacks that bypass defenses in place, and the increasing onus on businesses to manage IAM and BYOD", "description": "We hear it all the time - secure your passwords best with an application dedicated to just that. LastPass is a popular password manager used from individuals through corporate levels. However, in 2022 it suffered two breaches, and only recently was the extent of the damage made known. An unknown attacker was able to take the literal keys to the kingdom, compromising everything stored in the LastPass vaults. We will examine what was made known by LastPass and the media as we walk through the details available on both attacks. We will walk through the timeline of events and disclosures because it's important to note what came to light when, and how that changed the narrative.  We will also examine the role played by BYOD, logging, and why we need to change with the times to detect behavoral anomalies.\r\n\r\nThis talk is presented in a \"Lord of the RIngs\" theme\r\nOUTLINE\r\nPassword Managers: What and Why\r\n- What they are and why we need to use them\r\nWhat Could go Wrong\r\n- A timeline of who's been hacked and multiple occurrences\r\n- My personal experience using LastPass and switching to Bitwarden\r\nLastPass: What Did go Wrong\r\n- A basic anatomy of attack and timeline of events to show how what was stolen in Attack 1 was used in Attack 2\r\n- They took both encrypted and unencrypted data\r\n- They took data on browsing habits of users\r\n- The engineer used his own device to access his corporate vault. \r\n- This happens far more than we realize and we cannot effectively secure \r\nA Tale of 2 Attacks\r\n- A detailed discussion of what was discovered against what statements were made by LastPass over the months following the attacks\r\n- Highlight where perceived security failed\r\n- Call out how the crucial time to act at the beginning was lost \r\nKey Takeaways\r\n- Dwell Time matters\r\n- BYOD \u2013 how do you manage\r\n- Leverage logging and alerts\r\n- Track for behaviour and anomalies\r\n- What\u2019s accessible in your dev environment\r\n- Attacks are evolving past our defences", "recording_license": "", "do_not_record": false, "persons": [{"code": "NKNGZL", "name": "Cheryl Biswas", "avatar": null, "biography": "Cheryl Biswas is a Strategic Threat Intel Specialist with a major bank in Canada.  She has experience with security audits and assessments, privacy, DRP, project management, vendor management and change management. Cheryl engages in the security community as a conference speaker and volunteer, mentors, and champions women and diversity in Cyber Security as a founding member of the \"The Diana Initiative\".", "public_name": "Cheryl Biswas", "guid": "19321f53-7674-553c-8ea5-96e10a380999", "url": "https://cfp.hackfest.ca/hf2023/speaker/NKNGZL/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/WQMGUN/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/WQMGUN/", "attachments": []}, {"guid": "2cf833eb-828d-5a9c-9299-e03157364124", "code": "XARKMK", "id": 230, "logo": null, "date": "2023-10-14T11:00:00-04:00", "start": "11:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-230-hacking-reality-countercloud-s-ai-driven-disinformation-campaign", "url": "https://cfp.hackfest.ca/hf2023/talk/XARKMK/", "title": "Hacking Reality: CounterCloud's AI-Driven Disinformation Campaign", "subtitle": "", "track": "Threat Intelligence / OSINT", "type": "Regular Talk", "language": "en", "abstract": "Ever wondered if Skynet could run a fake news empire and win a Pulitzer? This is CounterCloud, a two month online experiment that is part 'Terminator,' part 'Black Mirror,' and takes us deep into the wild frontier of totally autonomous AI-generated disinformation.", "description": "This presentation aims to provide an in-depth exploration of CounterCloud, a groundbreaking autonomous AI system designed to generate and disseminate disinformation. \r\n\r\nPart 1 | \u201cLiar Liar, Pants on Fire.\u201d\r\n\r\nThe talk will kick off with an overview of the current landscape of AI in disinformation campaigns, highlighting specific case studies and limitations. At this point, nearly all AI-based disinformation campaigns require human interaction and support. So, if we could remove as many humans from the equation, the AI system could operate much faster. The presentation will then introduce CounterCloud, from its architecture and technical aspects to its ethical implications and potential risks.\r\n\r\nPart 2 |  \u201cDeus Ex Machina\u201d\r\n\r\nThe presentation will then dissect how CounterCloud uses large language models like ChatGPT to autonomously scrape, generate, and distribute disinformation at scale. It will cover the system's architecture, including its backend setup, the role of cloud computing, and the gatekeeper module that decides what content to target. The output capabilities of CounterCloud, such as generating fake articles, comments, images, and social media posts, will also be discussed in detail. \r\n\r\nPart 3 |  \u201cThe Wolf at the Door?\u201d\r\n\r\nConcluding the talk, the focus will shift to the public\u2019s response to the experiment. First broken to the public in an article from The Debrief, and also covered by Wired, the presentation will shift to the social reaction to, ethical considerations of, and risks associated with autonomous AI disinformation systems like CounterCloud. Whether one thinks this is awesome tech or the end of the world as we know it, this experiment proves mass AI-powered disinformation is possible. So now what? The presentation will emphasize the need for public awareness, regulatory challenges, and potential ethical solutions to mitigate the risks.", "recording_license": "", "do_not_record": true, "persons": [{"code": "YNRYV7", "name": "MJ Banias", "avatar": null, "biography": "MJ Banias is a journalist, podcaster, and senior intelligence analyst with Sapper Labs Group.", "public_name": "MJ Banias", "guid": "9f2dab10-3583-5288-855d-a9339ff2b20c", "url": "https://cfp.hackfest.ca/hf2023/speaker/YNRYV7/"}, {"code": "JZMKZC", "name": "N", "avatar": null, "biography": null, "public_name": "N", "guid": "6c681acf-52f0-53f5-921e-741d3cc7f10d", "url": "https://cfp.hackfest.ca/hf2023/speaker/JZMKZC/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/XARKMK/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/XARKMK/", "attachments": []}, {"guid": "f340f475-6abb-5015-9545-38096510f217", "code": "MXJBJB", "id": 244, "logo": null, "date": "2023-10-14T13:30:00-04:00", "start": "13:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-244-enchantment-under-the-c", "url": "https://cfp.hackfest.ca/hf2023/talk/MXJBJB/", "title": "Enchantment under the C", "subtitle": "", "track": "Security Programs/Management", "type": "Regular Talk", "language": "en", "abstract": "How the placement of your security program may be impacting your organization.\r\n\r\nLorraine: Marty, this may seem a little forward, but I was wondering if you would ask me to the Enchantment Under the Sea Dance on Saturday?", "description": "Linda: Yeah Mom, we know, you've told us this story a million times. You felt sorry for him, so you decided to go with him to The Fish Under the Sea Dance.\r\n\r\nLorraine: [thoughtfully, remembering] No, it was The Enchantment Under the Sea Dance. Our first date. I'll never forget, it was the night of that terrible thunderstorm, remember George?\r\n\r\n[He's not listening, completely focused on the show.]\r\n\r\nYour father kissed me for the very first time on that dance floor. It was then I realized I was going to spend the rest of my life with him.\r\n\r\n[Again, George laughs at the show, Marty and Linda exchange a look.]", "recording_license": "", "do_not_record": false, "persons": [{"code": "N97AYA", "name": "Patrick", "avatar": null, "biography": null, "public_name": "Patrick", "guid": "99f747e0-c80a-5867-98fc-ed3f403ff50d", "url": "https://cfp.hackfest.ca/hf2023/speaker/N97AYA/"}, {"code": "QXQZLK", "name": "Kendra Cooley", "avatar": null, "biography": null, "public_name": "Kendra Cooley", "guid": "1c93d713-ed26-5de9-91ef-a8e1f75a8d6b", "url": "https://cfp.hackfest.ca/hf2023/speaker/QXQZLK/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/MXJBJB/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/MXJBJB/", "attachments": []}, {"guid": "f0c344b4-d9df-5029-ae89-910eeb491165", "code": "9MHUNS", "id": 195, "logo": null, "date": "2023-10-14T14:30:00-04:00", "start": "14:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-195-artificial-intelligence-real-threats", "url": "https://cfp.hackfest.ca/hf2023/talk/9MHUNS/", "title": "Artificial Intelligence / Real Threats", "subtitle": "", "track": "Ai Security", "type": "Regular Talk", "language": "en", "abstract": "A buzzword for years, Artificial intelligence (AI) has evolved into a powerful, accessible tool and, like any tool, it can be used for evil. How can AI technology be harnessed by adversaries (or you) as part of sophisticated information security attacks? What sort of attacks are we seeing in the wild and how can we prepare for the new offensive techniques?", "description": "After the initial Title and Introduction slides the presentation:  \r\n- Layout: Talking about what we are talking about. Giving the audience the basic layout of the talk and what we'll be covering. All high level info but sets expectations for the talk.  \r\n- History: Recapping how we got to this point and our (new) problem. \r\n- Video: Covering video AI technology, real world attacks examples, and means to leverage the tech to prepare for attacks. \r\n- Audio: Covering audio (voice) AI technology, real world attacks examples, and means to leverage the tech to prepare for attacks. \r\n- Text/Code: Covering the use of text AI in social engineering attacks and development efforts.\r\n- Recap: Running over the key takeaways again in the hope that something sticks.\r\n- Thanks + A fun Q&A", "recording_license": "", "do_not_record": false, "persons": [{"code": "F7W7YF", "name": "Johnny Xmas", "avatar": null, "biography": null, "public_name": "Johnny Xmas", "guid": "27c1d1f5-cf0a-57fa-a5de-d8bb853f6a02", "url": "https://cfp.hackfest.ca/hf2023/speaker/F7W7YF/"}, {"code": "ERHSTX", "name": "Chris Carlis", "avatar": null, "biography": "Chris Carlis is an unrepentant penetration tester with an extensive background in network, wireless and physical testing. Across his career, Chris has worked to expand the value offensive testing provided via open communication and goal driven engagements. These experiences lead Chris to co-found Dolos Group with a focus on Red/Purple Teaming, security education and training. Additionally, Chris has presented at a variety of conferences, including Thotcon, Hushcon, Hackfest, FS-ISAC, and various B-Side events. He is a perennial volunteer at the Thotcon conference in his native Chicago and helps to organize multiple Chicagoland \u201cBurbSec\u201d information security monthly gatherings.", "public_name": "Chris Carlis", "guid": "6c2d6bfb-d4cd-579f-9278-9c34764c178a", "url": "https://cfp.hackfest.ca/hf2023/speaker/ERHSTX/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/9MHUNS/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/9MHUNS/", "attachments": []}, {"guid": "73a0bdcc-6b3b-5b5e-a10a-bd92a9df65be", "code": "BHXGYC", "id": 209, "logo": "https://cfp.hackfest.ca/media/hf2023/images/BHXGYC/1626989466489_hinO39U.jpeg", "date": "2023-10-14T15:30:00-04:00", "start": "15:30", "duration": "00:50", "room": "Track #1", "slug": "hf2023-209-cloud-environments-red-team-perspectives", "url": "https://cfp.hackfest.ca/hf2023/talk/BHXGYC/", "title": "Cloud environments: Red Team perspectives", "subtitle": "", "track": "Offensive", "type": "Regular Talk", "language": "fr", "abstract": "This presentation delves into the realm of cloud computing's security challenges and the Red Team perspective. It sheds light on intrusion testing, shared security models, and vulnerabilities unique to cloud systems. The discussion covers cloud intrusion testing's importance, methodologies, and distinctiveness compared to traditional approaches. Identity and Access Management's crucial role will be highlighted and explain through the 3 main CSP AWS/Azure/GCP, their main differences and security implication. The talk will outlines reasons for conducting Red Team engagements focusing on critical resource access. Applied assessment methodologies are proposed, including BlackBox, AssumBreach, and White Box approaches. Attack scenarios, based on the Mitre Att&ck Cloud Matrix framework, are explored, encompassing various stages. The presentation also delves into using the cloud offensively (Redirectors, storage and delivery), cloud-based phishing and Oauth abuse. The aim is to facilitate knowledge exchange, encourage research, and enhance cloud security by leveraging Red Team insights.", "description": "Cloud computing has become an integral part of modern infrastructure, offering scalable and flexible solutions for businesses. However, this new paradigm brings its own set of security challenges. This presentation aims to explore the Red Team perspectives in cloud environments, focusing on various aspects such as intrusion testing, shared security models, and the unique vulnerabilities and attack vectors associated with cloud-based systems (AWS/GCP/Azure).\r\n\r\nThis presentation will introduce the concept of cloud intrusion testing and its significance in today's technological landscape, from the perspective of an attacker or Red Team operator. Standards and frameworks will be discussed to provide a comprehensive understanding of its purpose, objectives, and main differences compared to more classic approaches such as network, web application, mobile, and wireless intrusion testing. Emphasis will be placed on the heavy reliance on Identity and Access Management (IAM) as a crucial factor in enabling or restricting actions within cloud environments.  \r\n\r\nThe reasons for conducting intrusion tests and Red Team engagements in cloud environments will be outlined, highlighting similar attack surfaces to web applications or external networks. Additionally, the potential access to critical resources will be addressed, including development pipelines, CI/CD systems, sensitive data backups or storage, user accounts synchronized with on-premise domains, synchronization with on-premise Active Directory servers, and management of devices and computers through services like Azure Hybrid Joined and Intune.\r\n\r\nFurthermore, applied methodologies for assessing and testing the security posture of cloud environments will be proposed, offering three distinct approaches or positions: BlackBox, AssumBreach, and White Box. These approaches will provide the audience with practical guidance on how to approach cloud environment assessments and intrusion testing engagements.\r\n\r\nSubsequently, TTPs (Tactics, Techniques, and Procedures) and attack scenarios based on the Mitre Att&ck Cloud Matrix framework will be presented, covering enumeration/discovery, initial access, persistence, and impact. Examples will range from password spray limitation bypass to S3 Ransomware detonation.\r\n\r\nExpanding the scope of the discussion, the concept of the cloud as an offensive tool in Red Team operations and social engineering will be explored. Examples of cloud-based phishing approaches and the offensive use of cloud resources will be presented.\r\n\r\nFinally, the emerging field of Purple Team within the cloud environment will be briefly touched upon. Collaborative approaches that bring together Red and Blue Teams to enhance cloud security will be discussed.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZXURNG", "name": "Cl\u00e9ment Cruchet", "avatar": null, "biography": "Cl\u00e9ment is a passionate speaker and technical security expert, specializing in security testing, offensive security and ethical hacking. Currently technical team leader for security testing and offensive security practice at Bell Canada, he is driven by an unwavering passion for security and hacking. Cl\u00e9ment has carried out numerous assignments and assessments for clients in various sectors such as banking, finance, government, services, industry and energy. Endowed with an insatiable curiosity and unfailing tenacity, Cl\u00e9ment is a passionate hacker who constantly seeks to understand the architecture and fundamentals of the technologies that come his way.", "public_name": "Cl\u00e9ment Cruchet", "guid": "de9d3404-7233-5147-aa9e-8dafc015cad3", "url": "https://cfp.hackfest.ca/hf2023/speaker/ZXURNG/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/BHXGYC/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/BHXGYC/", "attachments": []}, {"guid": "0f0bff6b-f6e0-50c6-be33-c357a628c42d", "code": "KBCULM", "id": 194, "logo": null, "date": "2023-10-14T16:30:00-04:00", "start": "16:30", "duration": "00:20", "room": "Track #1", "slug": "hf2023-194-smart-contracts-not-so-smart-bugs-crypto-domain-takeovers", "url": "https://cfp.hackfest.ca/hf2023/talk/KBCULM/", "title": "Smart Contracts, Not So Smart Bugs: Crypto Domain Takeovers", "subtitle": "", "track": "Offensive", "type": "Speed Talk", "language": "en", "abstract": "Web 3.0 smart contracts, like the ones found on Ethereum, bring promises of speed, decentralization, and security. Although DeFi's model may seem complex, these projects still can be vulnerable to relatively simple attacks like domain takeovers. In this beginner-friendly talk, we discuss how I discovered dangling DNS on several decentralized crypto exchanges and my experiences trying to responsibly disclose vulnerabilities to them.", "description": "Introduction to Dexs (Decentralized Exchanges)\r\n- What are some of the largest Dexs and why are they used? \r\n\t- Uniswap, PancakeSwap, Sushiswap all allow users to trade tokens without having to use a centralized intermediary like Coinbase or Kraken\r\n\t- Users might not want to KYC (share identity) or want to purchase a token that's not listed on an exchange (HarryPotterObamaSonic10Inu)\r\n\t- These organizations are often DAOs (decentralized autonomous organizations) and so development is public on Github.\r\n- What does the user experience look like?\r\n\t- Metamask - prompt to approve tokens, then approve to swap.\r\n\r\nIntroduction to NextJS / Vercel\r\n- Many projects in the space are using the NextJS Javascript framework because it integrates well with common Web3 libraries (like Ethers.js)\r\n- Vercel is a product from NextJS that is something like a CI/CD pipeline for a frontend\r\n\t\t- Each pull request gets a preview deployment\r\n\t\t- Changes merged to main get a production deployment\r\n\r\nDiscovering Vulnerability #1 - Vercel Bugs\r\n- March 2022: A bug in Vercel allowed an attacker to drain $320.000 from EVODeFi, so I began investigating how this might have happened\r\n- It turned out many crypto projects were using Vercel so I decided to take a closer look. If a malicious user took over a Dex, it would be trivial to trick users into approving malicious contracts.\r\n- YearnFi - linked to a Vercel deployment in their Github repositories.\r\n\t- I took over crv.ape.tax; yearn-hub.vercel.app; other deployment URLS\r\n\t- Reward: $500 DAI (had to reach out on Keybase, ImmuneFi did not help)\r\n- Uniswap\r\n\t- Took over uniswap-frontend-beta.vercel.app\r\n\t- No reward\r\n- Sushiswap\r\n\t- Took over full domain of Sushiswap.fi and was able to increase impact by adding mail records\r\n\t- Reward: 100 Sushi not from the foundation, unofficially via Discord\r\n- *.finance\r\n\t- Since most DeFi sites used finance domains, I scanned the entire zone file for dangling Vercel domains. \r\n\t- Took over domains of some defunct projects. Unable to return these to their rightful owners.\r\n\r\nDiscovering Vulnerability #2 - Onename\r\n- Onename.io was used to translate user handles into Bitcoin addresses\r\n- Previously hosted on Heroku - DNS was dangling so it was able to be taken over\r\n- Many high profile twitter users had linked to this service, including crypto CEOs. As an attacker this would be extremely useful for phishing.\r\n- Reported to HackerOne: $100 bounty\r\n\r\nConclusion\r\n- Just start hunting and learning - these bugs did not require uber 1337 hacking skills\r\n- Think about your threat model - don't get stuck thinking of the most complicated exploit scenario when dangling DNS is simple yet impactful\r\n- Crypto and Infosec people should talk more instead of fighting with each other :)", "recording_license": "", "do_not_record": true, "persons": [{"code": "ZFUWEH", "name": "Michael Be", "avatar": null, "biography": "Red Team Manager and Crypto Enthusiast", "public_name": "Michael Be", "guid": "5db4dfa1-df11-570e-8a5f-31f9bd67672a", "url": "https://cfp.hackfest.ca/hf2023/speaker/ZFUWEH/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/KBCULM/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/KBCULM/", "attachments": []}, {"guid": "e95ba949-8966-5051-8a9b-dd387b45a33f", "code": "WVDD9Y", "id": 237, "logo": null, "date": "2023-10-14T17:00:00-04:00", "start": "17:00", "duration": "00:50", "room": "Track #1", "slug": "hf2023-237-hackfest-closing-ceremony", "url": "https://cfp.hackfest.ca/hf2023/talk/WVDD9Y/", "title": "Hackfest Closing Ceremony", "subtitle": "", "track": null, "type": "Regular Talk", "language": "en", "abstract": "Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc. Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.", "description": "Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.Hackfest 2023 - La revue du CTF et des activit\u00e9es, remises des prix, black coins, etc.", "recording_license": "", "do_not_record": false, "persons": [{"code": "LA3MTX", "name": "Hackfest Communication", "avatar": null, "biography": null, "public_name": "Hackfest Communication", "guid": "6b885b5a-8f36-5288-8209-f1c6cbb092a7", "url": "https://cfp.hackfest.ca/hf2023/speaker/LA3MTX/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/WVDD9Y/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/WVDD9Y/", "attachments": []}], "Track #2": [{"guid": "b86885c2-eaea-5036-b323-880ad3304340", "code": "SKGTQ9", "id": 198, "logo": null, "date": "2023-10-14T09:00:00-04:00", "start": "09:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-198-la-meilleure-cyberdefense-c-est-l-att-ck", "url": "https://cfp.hackfest.ca/hf2023/talk/SKGTQ9/", "title": "La meilleure cyberd\u00e9fense, c'est l'ATT&CK\u00ae", "subtitle": "", "track": "Security 101", "type": "Regular Talk", "language": "fr", "abstract": "Outillez votre cyberd\u00e9fense en apprenant \u00e0 naviguer dans la matrice des tactiques et techniques utilis\u00e9es par les cybercriminels et leurs \u00e9cosyst\u00e8mes !\r\n\r\nCette pr\u00e9sentation est con\u00e7ue tant pour les gestionnaires que les professionnels de la cybers\u00e9curit\u00e9 et de la gouvernance de la s\u00e9curit\u00e9 de l'information souhaitant d\u00e9velopper leurs connaissances du domaine des op\u00e9rations de cybers\u00e9curit\u00e9 en commen\u00e7ant par les plus jeunes \u00e0 qui je parlerai du programme MITRE ATT&CK Defender\u2122 (MAD) ATT&CK\u00ae.\r\n\r\nAu fil des ans, le MITRE ATT&CK\u00ae s'est immisc\u00e9 dans les op\u00e9rations de cybers\u00e9curit\u00e9 au point de devenir un standard de facto. Mais de quoi s'agit-il ?\r\n\r\nApprenez comment op\u00e9rationnaliser ce qui n\u2019est ni un produit ni une technologie dans les pratiques de cyberenseignement (CTI), chasse aux cybermenaces (TH) et simulations de cyberattaques (AE) ou encore comment renforcer la valeur du centre de gestion des op\u00e9rations de cybers\u00e9curit\u00e9 (SOC). \r\n\r\nEnfin, que vous disposiez de l'expertise ou que vous fassiez appel \u00e0 un fournisseur de services g\u00e9r\u00e9s, d\u00e9couvrez comment int\u00e9grer l'approche MITRE ATT&CK\u00ae dans votre strat\u00e9gie globale de s\u00e9curit\u00e9 de l'information en \u00e9valuant votre posture de cyberd\u00e9fense afin d'aligner vos contr\u00f4les avec les m\u00e9canismes de d\u00e9tection et de r\u00e9ponse requis.", "description": "Outillez votre cyberd\u00e9fense en apprenant \u00e0 naviguer dans la matrice des tactiques et techniques utilis\u00e9es par les cybercriminels et leurs \u00e9cosyst\u00e8mes !\r\n\r\nCette pr\u00e9sentation int\u00e9ressera autant les gestionnaires que les professionnels de la cybers\u00e9curit\u00e9 et de la gouvernance de la s\u00e9curit\u00e9 de l'information souhaitant d\u00e9velopper leurs connaissances du domaine des op\u00e9rations de cybers\u00e9curit\u00e9.\r\n\r\nDepuis ces derni\u00e8res ann\u00e9es, le MITRE ATT&CK\u00ae s'est immisc\u00e9 dans les op\u00e9rations de cybers\u00e9curit\u00e9 au point de devenir un standard de facto.\r\n\r\nLes \u00e9diteurs de solutions de cybers\u00e9curit\u00e9 l\u2019ont compris et int\u00e8grent de plus en plus cette approche dans leurs produits.\r\n\r\nQu\u2019en est-il de vos pratiques de cybers\u00e9curit\u00e9 ou de celles de votre fournisseur de services cybers\u00e9curit\u00e9 g\u00e9r\u00e9s ?\r\n\r\nQue vous soyez impliqu\u00e9 dans la cybers\u00e9curit\u00e9 offensive ou d\u00e9fensive, apprenez comment penser comme un pirate informatique, comprendre sa motivation, ses actions et ses outils avec l\u2019approche MITRE ATT&CK\u00ae et D3FEND\u00ae.\r\n\r\nQue vous fassiez partie d\u2019une grande entreprise ou d\u2019une PME, prenez conscience de l\u2019importance de connaitre les faiblesses de votre cyberd\u00e9fense, et d\u2019identifier vos besoins afin d\u2019acqu\u00e9rir les technologies appropri\u00e9es pour y r\u00e9pondre.\r\n\r\nQue vous disposiez des ressources ou que vous fassiez appel \u00e0 un fournisseur de services g\u00e9r\u00e9s en cybers\u00e9curit\u00e9, d\u00e9couvrez comment vous assurer de disposer de l\u2019expertise ou des services pour d\u00e9tecter et de r\u00e9pondre aux incidents selon votre contexte.\r\n\r\nLevez le voile sur l\u2019op\u00e9rationnalisation de ce qui n\u2019est ni un produit ni une technologie dans les pratiques de cyberenseignement (CTI), chasse aux cybermenaces (TH) et simulations de cyberattaques (AE) ou encore comment renforcer la valeur du centre de gestion des op\u00e9rations de cybers\u00e9curit\u00e9 (SOC).\r\n\r\nClarifier l\u2019int\u00e9gration de l'approche MITRE ATT&CK\u00ae dans votre strat\u00e9gie globale de s\u00e9curit\u00e9 de l'information en \u00e9valuant votre posture de cyberd\u00e9fense afin d'aligner vos contr\u00f4les avec les m\u00e9canismes de d\u00e9tection et de r\u00e9ponse requis.\r\n\r\nEnfin, appropriez-vous l\u2019\u00e9cosyst\u00e8me en ligne et les nombreuses ressources disponibles pour vous former ou vous faire certifier dans le cadre du programme MITRE ATT&CK Defender\u2122 (MAD).", "recording_license": "", "do_not_record": false, "persons": [{"code": "NMXY9U", "name": "Christophe Reverd", "avatar": null, "biography": "Christophe Reverd a occup\u00e9 des postes de direction dans les op\u00e9rations de cybers\u00e9curit\u00e9 (centre des op\u00e9rations de cybers\u00e9curit\u00e9, r\u00e9ponse aux incidents de criminalistique num\u00e9rique, renseignement sur les cybermenaces, chasse aux cybermenaces, gestion des actifs et des vuln\u00e9rabilit\u00e9s, tests d'intrusion) avant de diriger la fonction s\u00e9curit\u00e9 (RSI) pour Quincaillerie Richelieu Lt\u00e9e (TSX:RCH) dont les op\u00e9rations de distribution s'\u00e9tendent en Am\u00e9rique du Nord.\r\n\r\nTitulaire d\u2019une ma\u00eetrise en administration, concentration gouvernance, audit et s\u00e9curit\u00e9 des technologies de l'information (TI) de l\u2019Universit\u00e9 de Sherbrooke, Christophe est \u00e9galement d\u00e9tenteur de certifications professionnelles en gestion de la s\u00e9curit\u00e9 de l\u2019information (CISSP-ISSMP), audit TI (CISA), gouvernance TI (CGEIT), risque TI (CRISC), MITRE ATT&CK (SOC, CTI, AE, THDE, PTM) et infonuagique (Microsoft Azure).\r\n\r\nSa passion \u00e0 promouvoir les technologies \u00e9mergentes a pris une nouvelle dimension par son implication en \u00e9ducation o\u00f9 il a inculqu\u00e9 les meilleures pratiques en tant que charg\u00e9 de cours en gouvernance des TI \u00e0 l\u2019\u00c9cole de gestion pendant dix ans et en cyber s\u00e9curit\u00e9 au Centre de formation des TI (CEFTI) de la Facult\u00e9 des Sciences de l\u2019Universit\u00e9 de Sherbrooke, parall\u00e8lement \u00e0 son parcours professionnel.", "public_name": "Christophe Reverd", "guid": "3411cadd-51ac-5f58-8822-78100c050223", "url": "https://cfp.hackfest.ca/hf2023/speaker/NMXY9U/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/SKGTQ9/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/SKGTQ9/", "attachments": []}, {"guid": "34cecc90-fa8b-5c8c-8ce4-f43f33acec5a", "code": "XRQDEH", "id": 219, "logo": null, "date": "2023-10-14T10:00:00-04:00", "start": "10:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-219-between-a-log-and-a-hard-place-mis-adventures-in-azure-logs", "url": "https://cfp.hackfest.ca/hf2023/talk/XRQDEH/", "title": "Between a Log and a Hard Place: (mis)Adventures in Azure Logs", "subtitle": "", "track": "Defensive", "type": "Regular Talk", "language": "en", "abstract": "Security monitoring in any environment is made or broken by the signal quality in the event logs. With mass migration to the cloud, defenders are putting all of their logging capability \"eggs\" in one provider's \"basket\". This works when the logging facilities are well designed and work robustly, but what do you do when issues arise?\r\n\r\nIn this talk, we will examine logging facilities in Azure (concentrating on events generated by Azure AD and Microsoft 365) and discuss multiple problems that we have observed in monitoring them. \r\n \r\nThese include:  \r\n- Blind spots hiding critical security events\r\n- Poorly documented events, attributes and magic values \r\n- Missing important information about user actions\r\n- Bugs in log records \r\n- Unannounced changes that break detection queries\r\n- Log pollution opportunities, potentially leading to RCE \r\n- and more \r\n\r\nWe will examine impact of these issues on defense and monitoring, opportunities for red-teamers, and the ways the cloud provider can address the problems going forward.", "description": "Security monitoring in any environment is made or broken by the signal quality in the event logs.\r\n\r\nCloud-based solutions have transformed the computing landscape with advantages like on-demand resource availability, scalability, cost-effectiveness, and enhanced collaboration capabilities. For defenders, this new world offered many benefits: robust identity management, patching at scale, improved incident detection and response, and more. \r\nCloud providers expose detailed logs that are consumed by security monitoring tools and SOC analysts. One would expect a common, streamlined logging solution to be a clear win in attack detection functionality, but the reality is more complicated.  \r\n\r\nWe have spent the last three years studying and monitoring Azure logs and have seen many problems that can complicate incident detection and response. With no alternatives to the provider's logging solution and slow problem mitigation speed, these issues go beyond mere annoyances and can help attackers avoid detection.  \r\n\r\nIn this talk, we will examine logging facilities in Azure, concentrating on events generated by Azure AD and Microsoft 365, and discuss multiple problems that we have observed in monitoring them. \r\n \r\nThese include:  \r\n- Blind spots hiding critical security events\r\n- Poorly documented events, attributes and magic values \r\n- Missing important information about user actions\r\n- Bugs in log records \r\n- Unannounced changes that break detection queries\r\n- Log pollution opportunities, potentially leading to RCE \r\n- and more \r\n  \r\nFor all these issues, we will: \r\n- examine their impact on defense and monitoring \r\n- discuss how attackers (and red teamers) may take advantage of them \r\n- suggest how defenders can mitigate the negative impact, where possible \r\n- and propose ways the cloud provider can address the problems going forward", "recording_license": "", "do_not_record": false, "persons": [{"code": "CKSUDS", "name": "Dmitriy Beryoza", "avatar": null, "biography": "Dmitriy Beryoza is a Senior Security Researcher with Vectra AI, working on threat detection in the cloud and on-prem networks.\r\n\r\nBefore that he was a penetration tester and secure software development advocate at IBM. He has been a software developer for many years, before switching to security full-time.\r\n\r\nDmitriy presented talks at security conferences such as DEF CON Cloud Village, HackFest, BSides, and others.\r\n\r\nHis interests include reverse engineering, secure software development, and CTF competitions.", "public_name": "Dmitriy Beryoza", "guid": "e8393275-3318-5d8c-bd37-b63f57cdb53b", "url": "https://cfp.hackfest.ca/hf2023/speaker/CKSUDS/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/XRQDEH/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/XRQDEH/", "attachments": []}, {"guid": "c0344387-89e7-5cf9-a7e7-af079a2185cc", "code": "Y8VWXL", "id": 180, "logo": null, "date": "2023-10-14T11:00:00-04:00", "start": "11:00", "duration": "00:50", "room": "Track #2", "slug": "hf2023-180-it-was-harder-to-sniff-bluetooth-through-my-mask-during-the-pandemic", "url": "https://cfp.hackfest.ca/hf2023/talk/Y8VWXL/", "title": "It was harder to sniff Bluetooth through my mask during the pandemic...", "subtitle": "", "track": "Hardware/IoT", "type": "Regular Talk", "language": "en", "abstract": "During the pandemic I took up Bluetooth (BT) sniffing as a way to get out of the house. \r\n\r\nBluedriving left me with questions that are different from those you'd ask based on traditional WiFi wardriving. Is there a geographic correlation between poverty, obesity, and BT sleep apnea medical devices? What are the implications of BT on police body cameras? Are fitness trackers still making it easy to track humans instead? Can someone steal heavy-construction equipment thanks to BT keyless ignition? Can hackers be tracked by their \"portable multi-tool[s]\"? Do hotels using BT door locks \"open the door\" to easier assassinations?\r\n\r\nIn this talk I will share some of the most interesting observations from the past few years, and share surprising answers to the above questions, and more.", "description": "Quisque et neque a est gravida venenatis. Nullam finibus diam tellus, quis tristique ligula hendrerit eu. Cras ante justo, ornare euismod rhoncus non, dictum vitae ipsum. Sed sit amet molestie sapien. Curabitur eu quam quis massa venenatis convallis. Sed sit amet magna quis sem venenatis molestie. Proin id urna dolor. Pellentesque at tempor orci, quis faucibus elit. Duis gravida eu mi non euismod. Donec sit amet erat sed ante varius egestas nec eget dolor. Ut imperdiet enim maximus mi euismod, vel tincidunt sem blandit. Phasellus a fermentum est. Donec scelerisque felis nec lobortis sagittis. Nulla diam dui, sagittis non turpis.", "recording_license": "", "do_not_record": false, "persons": [{"code": "TVLF3N", "name": "Xeno Kovah", "avatar": null, "biography": "Prior to working full time on OpenSecurityTraining2 (ost2.fyi), Xeno worked at Apple designing architectural support for firmware security; and code auditing firmware security implementations. A lot of what he did revolved around adding secure boot support to the main and peripheral processors (e.g. the Broadcom Bluetooth chip.) He led the efforts to bring secure boot to Macs, first with T2-based Macs, and then with the massive architectural change of Apple Silicon Macs. Once the M1 Macs shipped, he left Apple to pursue the project he felt would be most impactful: creating free deep-technical online training material and growing the newly created OpenSecurityTraining 501(c)(3) nonprofit.", "public_name": "Xeno Kovah", "guid": "a91f23aa-568a-5607-a29c-67b202a1ea38", "url": "https://cfp.hackfest.ca/hf2023/speaker/TVLF3N/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/Y8VWXL/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/Y8VWXL/", "attachments": []}, {"guid": "d188f47f-bb5f-55f0-9899-599f26d8b696", "code": "8ZYFHT", "id": 189, "logo": null, "date": "2023-10-14T13:30:00-04:00", "start": "13:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-189-noth1ng-t0-hid3", "url": "https://cfp.hackfest.ca/hf2023/talk/8ZYFHT/", "title": "NOTH1NG T0 HID3", "subtitle": "", "track": "Privacy", "type": "Regular Talk", "language": "en", "abstract": "This talk revisits the theme of personal privacy in the digital world, this time centring around the \"I've got nothing to hide\" argument. A beam of intensive light is shed on the motivation behind caring about one's privacy. We go in depth into what we can do to stay private and should we even try to do it at all. We talk about where we as an global society were able to fix privacy and where we have failed. New topics previously not covered are discussed, such as AI/LLMs.", "description": "1. Confusion of the inverse logical fallacy (all criminal activity is hidden, so all that  is hidden must be criminal).\r\n1a. Schr\u00f6dinger's video camera\r\n2. Why is privacy important (actual rebuttals to \"if you're doing nothing wrong, you've got nothing to hide\")\r\n2a. Data hoarding \u2192 Blackmail, impersonation\r\n2b. Today\u2019s authority might become totalitarian or inhumane\r\n2c. Herd immunity: many people not hiding anything, make the few stand out more and cause (misplaced) suspicion\r\n3. What do \"normal people\" have to say? What reactions have I've been getting since my previous version of the talk on a similar topic?\r\n4. Real examples of privacy nightmares.\r\n4a. China & Hong Kong (all the weird stuff)\r\n4b. Facebook (court rulings, suicide prevention algorithm)\r\n4c. EU (cookies, GPDR)\r\n4d. UK\r\n5. The end of end-to-end encryption\r\n6. Stories from the privacy zealot (How to achieve privacy and how much it cost me)\r\n6a. Mobile apps\r\n6b. IT certification exams\r\n6c. Airport scanners\r\n6x. more examples to follow\r\n7. Specific examples of where we were able to fix privacy\r\n7a. And where we failed (this is sadly larger than (6))\r\n8. Summary \u2014 do we fix it or what?", "recording_license": "", "do_not_record": false, "persons": [{"code": "FRZKR3", "name": "Kirils Solovjovs", "avatar": null, "biography": "Kirils Solovjovs is an IT policy activist, bug bounty hunter, and the most visible white-hat hacker in Latvia having discovered and responsibly disclosed or reported multiple security vulnerabilities in information systems of both national and international significance. He has extensive experience in social engineering, penetration testing, network flow analysis, reverse engineering, and the legal dimension.\r\n\r\nHe has developed the jailbreak tool for Mikrotik RouterOS, as well as created e-Saeima, helping the Latvian Parliament become the first parliament in the world that is prepared for a fully remote legislative process. He has spoken at many amazing conferences including Hack In The Box, Hack in Paris, TyphoonCon, MCH2022, 35C3, CONFidence, BalCCon, Nullcon, and of course Hackfest.", "public_name": "Kirils Solovjovs", "guid": "60d34ff6-7be5-5eaf-bab3-484763e8ebb9", "url": "https://cfp.hackfest.ca/hf2023/speaker/FRZKR3/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/8ZYFHT/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/8ZYFHT/", "attachments": []}, {"guid": "a8619a81-3cd7-59c5-a1b2-5ccb1b7486b9", "code": "K7SXNK", "id": 208, "logo": null, "date": "2023-10-14T14:30:00-04:00", "start": "14:30", "duration": "00:50", "room": "Track #2", "slug": "hf2023-208-des-pilules-pour-maigrir-l-osint-pour-demasquer-un-reseau-international-de-fraude-en-ligne", "url": "https://cfp.hackfest.ca/hf2023/talk/K7SXNK/", "title": "Des pilules pour maigrir? L\u2019OSINT pour d\u00e9masquer un r\u00e9seau international de fraude en ligne", "subtitle": "", "track": "Threat Intelligence / OSINT", "type": "Regular Talk", "language": "fr", "abstract": "On trouve sur Facebook des annonces ou des vedettes qu\u00e9b\u00e9coises semblent faire la promotion de pilules pour perdre du poids sans efforts ou encore \u00ab avoir des \u00e9rections comme dans 18 ans \u00bb! Malheureusement, des gens tombent dans le panneau et \u00e7a peut leur co\u00fbter cher. \r\n\r\nL\u2019\u00e9mission d\u2019enqu\u00eate J.E. nous a demand\u00e9 de l\u2019aide pour d\u00e9nicher les responsables de ces arnaques. \u00c0 l\u2019aide du Cycle du renseignement nous allons explorer les bases de l\u2019OSINT. Nous verrons ce que c\u2019est et ce que ce n\u2019est pas, ainsi que les pr\u00e9cautions \u00e0 prendre durant ce type d\u2019enqu\u00eate.\r\n\r\nUn stratag\u00e8me comme celui-ci n\u00e9cessite plusieurs acteurs. Nous montrerons les \u00e9tapes qui ont men\u00e9 \u00e0 la cartographie du r\u00e9seau, \u00e0 l\u2019identification de certaines personnes impliqu\u00e9es et comment la photo d'un chien nous a mis sur la piste de son adresse.", "description": "La pr\u00e9sentation se veut une introduction \u00e0 l\u2019OSINT et une d\u00e9monstration d\u2019une enqu\u00eate effectu\u00e9e pour une \u00e9mission journalistique. \r\n\r\nIntro : Gino Chouinard vend des pilules ?!?\r\n\r\nL\u2019\u00e9quipe de l\u2019\u00e9mission d\u2019enqu\u00eate J.E. de TVA nous a approch\u00e9s pour les aider \u00e0 d\u00e9nicher les responsables d\u2019une campagne de fraude qui utilise l\u2019image de vedettes de l\u2019empire Qu\u00e9becor pour votre des pilules. Ces annonces sont diffus\u00e9es via Facebook et renvoient vers des pages h\u00e9berg\u00e9es sur des sites Web clon\u00e9s. Ces sites Web envoient ensuite les visiteurs vers une multitude de magasins en ligne qui proposent des produits amaigrissants, des produits naturels et autres. Lorsqu\u2019on ach\u00e8te un produit sur ces sites, on s\u2019en fait envoyer plus que ce qu\u2019on a demand\u00e9 et les factures gonflent rapidement.\r\n\r\nEn introduction, je veux donc exposer les grandes lignes de la fraude.\r\n\r\n1: Le Cycle du renseignement ou comment ne pas se perdre dans les terriers de lapin.\r\n\r\nLa diff\u00e9rence entre l\u2019OSINT et \u00ab fouiller sur Google \u00bb c\u2019est le Cycle du renseignement. D\u00e9buter avec une question claire et un plan pour y r\u00e9pondre permet de ne pas se perdre. Ce concept qui vient du renseignement est utile pour l\u2019OSINT dans toute sorte de contextes, que ce soit en threat-hunting, en journalisme ou dans un CTF.\r\n\r\n2: C\u2019est quoi l\u2019OSINT ?\r\n\r\nL'OSINT, c\u2019est du renseignement de sources ouvertes. C\u2019est une m\u00e9thode de travail passive et \u00ab sans contact \u00bb. On ne laisse rien derri\u00e8re et on ne prend que des \u00ab screenshots \u00bb.\r\n\r\nL\u2019OSINT regroupe plusieurs sous-sp\u00e9cialit\u00e9s : les r\u00e9seaux sociaux, la g\u00e9olocalisation, les transports a\u00e9riens, maritimes et autres, les enqu\u00eates sur les personnes ou les entreprises, les infrastructures r\u00e9seau.\r\n\r\nIl y a quelques pr\u00e9cautions \u00e0 prendre avant de se lancer dans ce genre d\u2019enqu\u00eate. Nous allons aborder celles-ci de fa\u00e7on rapide : \u00ab sock puppets \u00bb, VPN, machine virtuelle, prise de notes et pr\u00e9servation de l\u2019information.\r\n\r\n3: Qui se cache derri\u00e8re ces annonces ?\r\n\r\n\u00c0 l\u2019aide des donn\u00e9es obtenues de la part de personnes ayant \u00e9t\u00e9 fraud\u00e9es, nous avons cartographi\u00e9 le r\u00e9seau utilis\u00e9 pour ce stratag\u00e8me : les sites Web, les serveurs, les entreprises, les individus.\r\n\r\nL\u2019op\u00e9ration a pu \u00eatre divis\u00e9e en deux grands groupes. D\u2019un c\u00f4t\u00e9, un r\u00e9seau de sites Web servant \u00e0 pousser des annonces frauduleuses sur Facebook et diriger du trafic vers des magasins en ligne. De l\u2019autre, le r\u00e9seau de magasins en ligne, \u00e0 l\u2019apparence ind\u00e9pendants, mais tous li\u00e9s les uns aux autres.\r\n\r\nGr\u00e2ce \u00e0 une petite erreur de sa part, nous avons r\u00e9ussi \u00e0 relier le premier pan de cette op\u00e9ration \u00e0 un individu. Une photo de son chien nous a finalement mis sur la piste de son adresse de r\u00e9sidence.\r\n\r\n4: Conclusion\r\n\r\nLes participants et participants \u00e0 cette conf\u00e9rence en sortiront avec une meilleure compr\u00e9hension de l\u2019OSINT et de son application. Ils comprendront l\u2019importance du cycle du renseignement pour structurer la recherche et travailler de fa\u00e7on efficace.", "recording_license": "", "do_not_record": false, "persons": [{"code": "VZZANR", "name": "Sam Harper", "avatar": null, "biography": "Sam Harper est un m\u00e9decin de famille d\u00e9froqu\u00e9 qui a d\u00e9couvert le journalisme apr\u00e8s un d\u00e9tour en informatique.\r\nIl est journaliste d'enqu\u00eate pour Pivot, un m\u00e9dia ind\u00e9pendant. Il a cofond\u00e9 l'organisme Cyber Citoyen, un organisme qui fait de la vulgarisation et de la formation autour des enjeux de vie priv\u00e9e et de s\u00e9curit\u00e9 et qui accompagne les personnes victimes de violence technologique.", "public_name": "Sam Harper", "guid": "3f900e30-33bc-51ae-8468-226ebcf08c4e", "url": "https://cfp.hackfest.ca/hf2023/speaker/VZZANR/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/K7SXNK/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/K7SXNK/", "attachments": []}], "Workshops & Speed": [{"guid": "8159b2be-855e-5e48-bb3d-150eace1ecc4", "code": "7FMB8N", "id": 236, "logo": null, "date": "2023-10-14T10:00:00-04:00", "start": "10:00", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-236-web-scraping-unleashed-mastering-techniques-for-data-harvesting", "url": "https://cfp.hackfest.ca/hf2023/talk/7FMB8N/", "title": "Web Scraping Unleashed: Mastering Techniques for Data Harvesting", "subtitle": "", "track": "Offensive", "type": "Speed Talk", "language": "en", "abstract": "This talk offers a concise introduction to web scraping techniques using Python, focusing on automated data extraction from websites. Web scraping enables the systematic collection of web data for various purposes, including content aggregation, research, job hunting, social media analysis, and monitoring legal and compliance issues. It is also a valuable tool for preserving government data, as evidenced during Donald Trump's presidency when various government website data, such as climate change information and LGBTQ+ resources, were altered or removed. This comprehensive overview equips attendees with a versatile toolkit for extracting valuable web data.", "description": "This talk presents a brief introduction to various techniques for scraping websites using the Python programming language. Web scraping refers to the automated process of extracting data from websites using software tools or scripts. Web scraping allows you to gather data from multiple sources on the internet and collect it in a structured format for analysis, research, and other purposes.\r\n\r\nThere are numerous legitimate uses for scraping websites, notably content aggregation, research and data analysis, job searching, social media analysis, and legal/compliance monitoring. Backing up government data can also be helpful. Before being indicted four times (so far), Donald Trump was the 45th president of the United States. During his administration, there were several instances where government data was removed from government websites or altered. Some examples of altered or removed data include climate change and environmental data, healthcare enrollment information, animal welfare records, and LGBTQ+ rights and resources.\r\n\r\nWe will provide a brief introduction to three different approaches to website scraping. The simplest involves sending requests and using a library like Beautiful Soup to parse the results. This doesn't always work, though, since some sites use client-side Javascript to interact with the server. There are a couple of ways to deal with this. Browsers can be automated with tools like Selenium, and the results can then be parsed with a Python library. However, the results may not be easy to parse, and the final approach presented will show how to intercept and emulate XHR requests. This can potentially yield more data than the page displays.", "recording_license": "", "do_not_record": false, "persons": [{"code": "NJSCRD", "name": "Wendy Edwards", "avatar": null, "biography": "Wendy is a software developer interested in the intersection of cybersecurity and data science. She\u2019s involved in the NASA Datanauts program and participated in the SANS Women\u2019s Academy, earning GIAC GSEC, GCIH, and GCIA certifications. She has masters degrees in computer science and library and information science from the University of Illinois.", "public_name": "Wendy Edwards", "guid": "142b0a8c-f3da-5485-a785-2900d83232c6", "url": "https://cfp.hackfest.ca/hf2023/speaker/NJSCRD/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/7FMB8N/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/7FMB8N/", "attachments": []}, {"guid": "8d4896c4-c198-5cca-bb91-f6525194924a", "code": "UHGLNE", "id": 214, "logo": "https://cfp.hackfest.ca/media/hf2023/images/UHGLNE/a_train_with_the_texture_of_a_pickle__cyberpunk_st_JV1ZIL20_rXY4Ldz.png", "date": "2023-10-14T10:30:00-04:00", "start": "10:30", "duration": "02:00", "room": "Workshops & Speed", "slug": "hf2023-214-stable-diffusion-workshop", "url": "https://cfp.hackfest.ca/hf2023/talk/UHGLNE/", "title": "Stable Diffusion Workshop", "subtitle": "", "track": "Ai Security", "type": "Workshop - 120 minutes", "language": "en", "abstract": "Let's get hands on and dive into the marvelous world of \"artificial intelligence\" and \"prompt engineering\"!\r\n\r\nThis session will cover two CTF challenges based on Stable Diffusion which is a model capable of generating photo-realistic images given any text input. This will show in a practical fashion some real impact of something otherwise artificial.\r\n\r\nThe challenges are going to be solved step by step alongside a dive into diffusion models and technical details on machine learning.\r\n\r\nWe will provide a dedicated online environment that requires low computing power on your end to do prompt hacking and try out Stable Diffusion.\r\n\r\nPrerequisites:\r\nThis workshop supports three levels of technical readiness:\r\n1) To participate in prompt hacking, bring any laptop or cellphone with a Web browser\r\n2) For a more low-level challenge, bring a laptop with Python installed\r\n3) To optionally play with Stable Diffusion tools locally, a laptop with dedicated 3D graphic card is required\r\n\r\nL'aide aux participants en Fran\u00e7ais sera aussi disponible.", "description": "This workshop uncovers some details about machine learning and models that leads the participants to form a proper yet simple technical understanding of how image related \"AI\" works.\r\n\r\nOutline:\r\n- Intro (15mins)\r\nWhat is Stable Diffusion\r\nWhat is a Model and Prompt Engineering\r\n\r\n- Workshop Part 1 (45mins)\r\nModel RCE\r\nDoable with a laptop and Python\r\nThis will be classic Python Pickling, requires some programming skills\r\nSolution given after 30mins\r\n\r\n- Break (15mins)\r\nWill also be used to catch up with some participants\r\n\r\n- Workshop Part 2 (45mins)\r\nDoable with cellphone or laptop Web browser\r\nThis will be finding what\u2019s hiding in the deep learning brain\r\nThis is bleeding edge prompt hacking and is surprisingly accessible by everyone\r\nSolution given after 30mins\r\n\r\n- Bonus: Hypernetworks\r\nIf time permits, we can look deeper at Hypernetworks and how they are being trained. This is related to the challenges above as the base of it, but also opens the topic to ethical and privacy concerns.", "recording_license": "", "do_not_record": true, "persons": [{"code": "MMM8EQ", "name": "Jonathan Marcil", "avatar": null, "biography": "Jonathan is part of NorthSec as a CTF challenge designer. He is passionate about Application Security and enjoys architecture analysis, code review, threat modeling and debunking security tools. Jonathan holds a bachelor's degree in Software Engineering from ETS Montreal and has 20 years of experience in Information Technology and Security.", "public_name": "Jonathan Marcil", "guid": "5d901a48-e3b2-5282-a6dc-501ea324bd89", "url": "https://cfp.hackfest.ca/hf2023/speaker/MMM8EQ/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/UHGLNE/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/UHGLNE/", "attachments": []}, {"guid": "b812c495-525c-57a6-ab75-bd8a806bb7d9", "code": "QC9U39", "id": 200, "logo": null, "date": "2023-10-14T13:30:00-04:00", "start": "13:30", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-200-a-primer-on-wipers", "url": "https://cfp.hackfest.ca/hf2023/talk/QC9U39/", "title": "A Primer on Wipers", "subtitle": "", "track": "Threat Intelligence / OSINT", "type": "Speed Talk", "language": "en", "abstract": "We'll be taking a look into the history and technical evolution of wiper malware, starting from Shamoon all the way to the modern-day wipers found in the Russia-Ukraine conflict.", "description": "There's several topics we'll cover:\r\n\r\nIn the first section, we'll talk about what wipers are and how they are defined in academic literature as well as security news reporting. We'll establish what the general motive of a wiper attack is, what threat actors tend to use wipers, and what the typical patterns are in terms of tactics and techniques.\r\n\r\nIn the second section, we'll discuss the chronological history of wipers and use it to frame how wiper malware has evolved over time. The central focus of this to highlight the commonalities and recurring themes through history even as the technical sophistication can grow.\r\n\r\nFinally, we'll discuss some of the various types of wiper malware identified in the modern-day, particularly the wiper attacks on Ukraine. \r\n\r\nThroughout the talk, we'll be citing several different sources from academic and industry research. My hope is that this talk can provide a helpful jumpstart for those who are interested to dive deeper, but the presentation itself should provide a helpful summary of what we know about wipers today.", "recording_license": "", "do_not_record": true, "persons": [{"code": "XTFZVA", "name": "Ali Maredia", "avatar": null, "biography": "Ali Maredia is a security engineer, working on enterprise security architecture and developing security tools. Prior to that, he worked as a security engineer in the financial industry, specializing in threat intelligence. With a background in software engineering, Ali holds a bachelor's degree from the University of Texas at Austin. His interests include CTFs and teaching programming to underprivileged youth.", "public_name": "Ali Maredia", "guid": "ee634add-e0c4-52bd-8812-f814555b11d8", "url": "https://cfp.hackfest.ca/hf2023/speaker/XTFZVA/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/QC9U39/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/QC9U39/", "attachments": []}, {"guid": "94ec9c05-f97d-5d4e-b4c2-d7f8857a1da8", "code": "Z9GXQD", "id": 227, "logo": null, "date": "2023-10-14T14:00:00-04:00", "start": "14:00", "duration": "00:20", "room": "Workshops & Speed", "slug": "hf2023-227-reduire-les-faux-positifs-et-utiliser-les-alertes-basees-sur-le-risque-risk-based-alerting-rba", "url": "https://cfp.hackfest.ca/hf2023/talk/Z9GXQD/", "title": "R\u00e9duire les faux positifs et utiliser les alertes bas\u00e9es sur le risque (Risk-based alerting/RBA)", "subtitle": "", "track": "Defensive", "type": "Speed Talk", "language": "fr", "abstract": "Le ph\u00e9nom\u00e8ne de la \"fatigue des alertes\" (\"alert/ticket fatigue\" en anglais) est bien r\u00e9el et affecte probablement la majorit\u00e9 des organisations poss\u00e9dant un SOC. Les diff\u00e9rentes solutions de s\u00e9curit\u00e9 g\u00e9n\u00e8rent de plus en plus d'alertes et afin d'\u00e9viter au maximum l'\u00e9puisement de nos \u00e9quipes qui peuvent traiter des faux positifs \u00e0 r\u00e9p\u00e9tition, il faut repenser \u00e0 notre strat\u00e9gie vis-\u00e0-vis celles-ci. Une piste int\u00e9ressante est la mise en place des alertes bas\u00e9es sur le risque, sommairement, les deux principaux avantages seraient de r\u00e9duire le nombre de faux positifs et d'\u00e9galement d\u00e9tecter des \u00e9v\u00e9nements qui individuellement n'auraient potentiellement pas lev\u00e9 d'alertes.", "description": "- Introduction (~1min)\r\n- Qu'est-ce que la fatigue des alertes et pourquoi il faut en tenir compte? (~2min)\r\n- Comment g\u00e9rer la balance entre le volume d'alertes \u00e0 traiter et la r\u00e9duction des faux positifs? (Est-ce dangereux de r\u00e9duire nos seuils pour recevoir moins d'alertes? Risque-t-on de manquer des alertes importantes?) (~4min)\r\n- Pourquoi est-il possible pour une organisation de ne pas d\u00e9tecter certaines activit\u00e9s suspectes malgr\u00e9 la pr\u00e9sence de centaines de cas d'usage (Use Case)? (~4min)\r\n- Alerte vs. \u00e9v\u00e9nement notable (~3min)\r\n- Attribuer des scores de risque \u00e0 des objets via les \u00e9v\u00e9nements notables et g\u00e9n\u00e9rer des alertes selon un seuil pr\u00e9d\u00e9fini (Les scores peuvent se multiplier selon les phases de l'attaque (MITRE/Cyber Kill Chain) ou la s\u00e9v\u00e9rit\u00e9 des \u00e9v\u00e9nements, notre imagination est la limite.) (~4min)\r\n- Conclusion et questions (~2min)", "recording_license": "", "do_not_record": false, "persons": [{"code": "J8B7SF", "name": "Jean-Francois Brouillette", "avatar": null, "biography": "La carri\u00e8re de Jean-Fran\u00e7ois a d\u00e9but\u00e9 dans la gestion de syst\u00e8mes informatiques il y a un peu plus d\u2019une dizaine d\u2019ann\u00e9es avant de se sp\u00e9cialiser en cybers\u00e9curit\u00e9. Il a pass\u00e9 quelques ann\u00e9es \u00e0 agir \u00e0 titre de consultant (KPMG Egyde) et \u00e0 r\u00e9pondre \u00e0 des situations de crises \u00e0 travers le monde dans des organisations d\u2019envergures lors de cyberattaques. Jean-Fran\u00e7ois s\u2019est ensuite joint \u00e0 l\u2019\u00e9quipe de la Banque Nationale du Canada afin d\u2019appuyer leur \u00e9quipe de cyberd\u00e9fense et aider \u00e0 faire progresser la pratique de r\u00e9ponse aux cyberincidents. Sa motivation a toujours \u00e9t\u00e9 de contribuer, en utilisant ses comp\u00e9tences, \u00e0 pr\u00e9venir les cyberattaques et de compliquer, le plus possible, la vie des cybercriminels.", "public_name": "Jean-Francois Brouillette", "guid": "6834cefb-98ac-5f54-832f-0e42162f587e", "url": "https://cfp.hackfest.ca/hf2023/speaker/J8B7SF/"}], "links": [], "feedback_url": "https://cfp.hackfest.ca/hf2023/talk/Z9GXQD/feedback/", "origin_url": "https://cfp.hackfest.ca/hf2023/talk/Z9GXQD/", "attachments": []}]}}]}}}