{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2025.2.2"}, "schedule": {"url": "https://cfp.pass-the-salt.org/pts2021/schedule/", "version": "1.1", "base_url": "https://cfp.pass-the-salt.org", "conference": {"acronym": "pts2021", "title": "PTS2021", "start": "2021-07-05", "end": "2021-07-07", "daysCount": 3, "timeslot_duration": "00:05", "time_zone_name": "Europe/Paris", "colors": {"primary": "#3aa57c"}, "rooms": [{"name": "Zoom room", "slug": "1-zoom-room", "guid": "e84956a8-e7c8-5cd2-8cf0-21049ebdc025", "description": "Zoom virtual room", "capacity": 200}], "tracks": [], "days": [{"index": 1, "date": "2021-07-05", "day_start": "2021-07-05T04:00:00+02:00", "day_end": "2021-07-06T03:59:00+02:00", "rooms": {"Zoom room": [{"guid": "09320d8d-fb1a-5805-a56c-7a7f591fd472", "code": "LB9CZS", "id": 33, "logo": null, "date": "2021-07-05T13:45:00+02:00", "start": "13:45", "duration": "00:15", "room": "Zoom room", "slug": "pts2021-33-welcome", "url": "https://cfp.pass-the-salt.org/pts2021/talk/LB9CZS/", "title": "Welcome", "subtitle": "", "track": null, "type": "Special", "language": "en", "abstract": "Welcome talk by org team", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/LB9CZS/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/LB9CZS/", "attachments": []}, {"guid": "c4e581eb-aa37-5f18-85df-e6f431a996a3", "code": "LQDHNS", "id": 25, "logo": null, "date": "2021-07-05T14:00:00+02:00", "start": "14:00", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-25-jailbreak-detection-mechanisms-and-how-to-bypass-them", "url": "https://cfp.pass-the-salt.org/pts2021/talk/LQDHNS/", "title": "Jailbreak detection mechanisms and how to bypass them", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Some iOS mobile applications try to detect whether they are running on a jailbroken device in order to protect intellectual property, defend against bots or make sure that they run on a relatively secure device.\r\n\r\nHowever jailbroken devices are very useful to observe and reverse applications. Those protected with anti-jailbreak code are then more tedious to reverse thus complicating their security assessment or the development of alternatives.\r\n\r\nIn this talk we will first present how specific iOS restrictions complicate reverse engineering but also reduce the number of tools that can be used by software protection. Then, we will list different methods available to detect jailbreak. Finally, we will describe how to study and bypass a real-world anti-jailbreak solution with the famous opensource dynamic instrumentation framework Frida.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "JCUTHV", "name": "Eloi Benoist-Vanderbeken", "avatar": "https://cfp.pass-the-salt.org/media/avatars/elvanderb_400x400_KrwQ7h6.jpeg", "biography": "Eloi (@elvanderb) is one of the Synacktiv's reverse-engineering team tech lead.", "public_name": "Eloi Benoist-Vanderbeken", "guid": "8ecc34fe-d0a5-5a83-914c-f7db081b92cb", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/JCUTHV/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/LQDHNS/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/LQDHNS/", "attachments": []}, {"guid": "adad71f7-4e33-5528-889c-5d4619cf54ee", "code": "MGCYPT", "id": 22, "logo": "https://cfp.pass-the-salt.org/media/pts2021/submissions/MGCYPT/2021-04-27_12-16_r6R4T6W.png", "date": "2021-07-05T14:40:00+02:00", "start": "14:40", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-22-pithus-let-s-open-the-android-pandora-s-box", "url": "https://cfp.pass-the-salt.org/pts2021/talk/MGCYPT/", "title": "Pithus: let's open the Android pandora's box", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Pithus is the answer to the exponential growth of mobile threats. Malicious apps, fake apps, data laundering are the main threats when it comes to mobile security. Their detection and analysis should be available for all and not the property of a private company. Unlike some commercial solutions with exorbitant prices, Pithus is a entirely open platform supported and maintained by the community.\r\n\r\nThreats such as permanent tracking and data laundering are made possible by the total lack of transparency and the lack of understanding around what and how data is gathered. Pithus brings transparency through clear and structured reports. Activists, journalists, NGOs, and any other technical community can easily generate these reports and leverage them to better understand the threat landscape.\r\n\r\nDuring this talk, we will discuss the need of free and open-source mobile threat intelligence platforms and how we could build them. Beyond analysis, we will dig into how data-science could help us to efficiently identify similar or new threats.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "AFRRV8", "name": "U039b", "avatar": "https://cfp.pass-the-salt.org/media/avatars/me_8n0OcI8.jpg", "biography": "Expert in Android security and reverse engineering, Esther Onfroy a.k.a U039b is a French hacktivist, speaker and co-founder of Defensive Lab Agency, Exodus Privacy, Echap, PiRanhaLysis and Pithus. She actively works with journalists, academics, NGOs and private companies. She helps them better understand and respond to today's cybersecurity threats on mobile devices.\r\n\r\n- [https://esther.codes/about-me/](https://esther.codes/about-me/)\r\n- [https://defensive-lab.agency/](https://defensive-lab.agency/)\r\n- [https://exodus-privacy.eu.org/en/](https://exodus-privacy.eu.org/en/)\r\n- [https://echap.eu.org/](https://echap.eu.org/)\r\n- [https://piranhalysis.github.io/](https://piranhalysis.github.io/)\r\n- [https://beta.pithus.org/](https://beta.pithus.org/)", "public_name": "U039b", "guid": "9ae4eb17-002d-568c-8e36-98cbd90dfdb9", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/AFRRV8/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/MGCYPT/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/MGCYPT/", "attachments": []}, {"guid": "a3f128f8-27ca-584c-8755-10fafccf19ee", "code": "CTWBB8", "id": 12, "logo": "https://cfp.pass-the-salt.org/media/pts2021/submissions/CTWBB8/logo_eCZagUg.png", "date": "2021-07-05T15:20:00+02:00", "start": "15:20", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-12-hook-as-you-want-it", "url": "https://cfp.pass-the-salt.org/pts2021/talk/CTWBB8/", "title": "Hook as you want it", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "In the context of my work, it is often required to audit the solution as an entire entity. Today, the main gateway used to connect a device to a web server, for example, is our dear smartphone. It has become an important vector of attack, for our phones themselves as well as for the devices with which it will interconnect.\r\nSeveral open source projects exist, each with their own particularities, but today, I haven't found any tool that fully suits me. So I started to develop ASThook (https://madsquirrels.gitlab.io/mobile/asthook/index.html), a tool for static and dynamic analysis of Android application designed to link static analysis to dynamic analysis. \r\nIts second goal is the possibility for the community to add features without requiring high programming skills or a deep understanding of the tool.\r\nFor instance, the community will be able to add plugins using the automatic APK generation features for POC, tree traversal or Frida hook addition directly in the application without risking to slow down the analysis.\r\nAs my job is mainly focused on auditing physical equipment, I sometimes meet more and more regularly embedded systems running on Android. I have therefore implemented the possibility to adapt the tool to run the analysis on more exotic platforms such as car headunits or microsystems.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "9UMAT8", "name": "Benoit Forgette", "avatar": "https://cfp.pass-the-salt.org/media/avatars/benoit_40sZvJM.png", "biography": "Passionate about how systems work since my childhood and with an initial education in computer science, I gradually moved to the security of these systems and the electronic part of these equipments.Today, I work as a Cybersecurity Engineer in software and hardware reverse engineering at Digital S\u00e9curity, where my daily work consists in disassembling equipments sent by our clients, then inspecting all their attack surfaces (hardware, radio, software, cloud). Then, we help our clients to find the best way to protect their systems and their equipments. \r\n\r\nIn this work, the part that seems to me the most interesting is the automation/instrumentation/hijacking part. It is fascinating to see how much it is possible to hijack a piece of equipment from its original purpose. This is even more impressive when we talk about physical equipment which has an impact on its environment.", "public_name": "Benoit Forgette", "guid": "9a9d5d64-f0df-5f46-935b-a52fef0babfb", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/9UMAT8/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/CTWBB8/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/CTWBB8/", "attachments": []}, {"guid": "527bde32-4cae-573b-9e86-f9f5aeb05afb", "code": "LA9V9Y", "id": 4, "logo": null, "date": "2021-07-05T16:10:00+02:00", "start": "16:10", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-4-patrowlhears-and-survival-tips-for-prioritizing-threats", "url": "https://cfp.pass-the-salt.org/pts2021/talk/LA9V9Y/", "title": "PatrowlHears and Survival tips for prioritizing threats", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "With hundreds of vulnerabilities with critical or high severity to deal with, the daily security reports look like a shining Christmas tree. Prioritization of vulnerabilities is a top success factor for ensuring an efficient security incident response and vulnerability management program. \r\nPatrOwl community provides scalable, free and open-source solutions for orchestrating Security Operations and providing Threat Intelligence feeds. A new tool has been publicly released for supporting these challenges: PatrowlHears is an advanced and real-time Vulnerability Intelligence platform, including CVE, exploits and threats news monitoring.", "description": "Solutions must be found to face the overall growing threat of attacks, talent shortage and cost optimization challenges in cybersecurity. The current trend is to rely on automation and orchestration of security operations.\r\n\r\nThe fact is automating SecOps activities leads to manage more security alerts. The downside is that potentially a bunch of new security alerts every day. By the way, with hundreds of vulnerabilities with critical or high severity to deal with,  the daily security reports look like a shining Christmas tree. It could definitely lead to jaded teams or, even worse, bad decisions in vulnerability handling.\r\n\r\nObviously, it is not realistic to hope that all vulnerabilities will be fixed. A line have to be drawn by the business owners according with the security teams. Prioritization is an essential success factor for improving efficiency and continue to provide the highest quality and relevant service in security incident response and vulnerability management. Because the CVSS score is not enough, which are the relevant metrics ? How to collect them ? Which decision should be made ? How to review efficiency of this process and adapt it ?\r\n\r\nThis talk is about to share insights on a risk-based methodology in vulnerability management and a new open-source tool PatrowlHears. This approach is enabled by a balanced usage of SecOps automation to keep us updated for vulnerabilities, exploits and other threat information, and prioritization using vulnerability metrics, threat topicality and asset criticality. Also, it will be discussed on examples of events that should conduct us to consider reprioritization of a vulnerability handling.", "recording_license": "", "do_not_record": false, "persons": [{"code": "9HTJ9X", "name": "Nicolas Mattiocco", "avatar": "https://cfp.pass-the-salt.org/media/avatars/PhotoNico500kb_C9B7ZGZ.jpg", "biography": "Nicolas is an information security expert since 13 years and was involved in various security consulting engagements, from penetration tests to global risk assessments and security operations implementation. Today, he is currently working as a red teamer and in automating security operations at a large scale with PatrOwl solutions.", "public_name": "Nicolas Mattiocco", "guid": "05f0fb4a-165e-579b-8e2d-35619f059aa8", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/9HTJ9X/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/LA9V9Y/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/LA9V9Y/", "attachments": []}, {"guid": "9effe493-60b4-5c8e-b055-77de623e527b", "code": "JDP7LB", "id": 14, "logo": null, "date": "2021-07-05T16:50:00+02:00", "start": "16:50", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-14-forensics-low-level-having-fun-with-linux-onboard-tools", "url": "https://cfp.pass-the-salt.org/pts2021/talk/JDP7LB/", "title": "Forensics Low Level - Having fun with Linux onboard tools", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "In this presentation I will cover some curiosities I stumble over while working in forensics. One goal is to show that you can not always relay on tools and should be able to read the data on byte level to understand what's going wrong.", "description": "The presentation will consists out of 3 live demos. All the demos based on Linux standard tools like 'dd', 'hexedit' and alike.\r\n\r\n1. In Forensics a HW write-blocker is necessary. Just mounting the device in RO mode is not sufficient. I will connect a USB stick to my laptop and mount it RO. After this I will modify some data on the USB stick.\r\n\r\n2. I have a standard USB stick and simply modify some (3) bytes on it. The result, Linux will mount up to 250 partitions. Some tools either hang or simply display wrong information. You need to read the bytes of the partition table to understand whats going wrong.\r\n\r\n3. If you connect another USB stick to a Windows, file A, B and C have content X, Y and Z. If you connect the same USB stick to Linux, file A, B and C have content U, V, W. Analyzing and understanding the Master Boot Record will reveal the secret.", "recording_license": "", "do_not_record": false, "persons": [{"code": "C37TXE", "name": "Michael Hamm", "avatar": null, "biography": "Since 2010, Michael has worked as an operator and analyst at CIRCL \u2013 Computer Incident Response Center Luxembourg where he is working on forensic examinations and incident response.", "public_name": "Michael Hamm", "guid": "5ab493be-cb6e-5385-bd63-0de0cb8bd0d8", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/C37TXE/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/JDP7LB/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/JDP7LB/", "attachments": []}]}}, {"index": 2, "date": "2021-07-06", "day_start": "2021-07-06T04:00:00+02:00", "day_end": "2021-07-07T03:59:00+02:00", "rooms": {"Zoom room": [{"guid": "84e29da8-8c26-5fdb-9f50-cdb2f6df1398", "code": "PGEJ7T", "id": 9, "logo": null, "date": "2021-07-06T14:00:00+02:00", "start": "14:00", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-9-fedora-coreos-a-container-focused-os-to-securely-deploy-and-run-applications", "url": "https://cfp.pass-the-salt.org/pts2021/talk/PGEJ7T/", "title": "Fedora CoreOS, a container focused OS to securely deploy and run applications", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Fedora CoreOS is an automatically updating, minimal, monolithic, container-focused operating system, designed for clusters but also operable standalone, optimized for Kubernetes but also great without it. It aims to combine the best of both CoreOS Container Linux and Fedora Atomic Host, integrating technology like Ignition from Container Linux with rpm-ostree and SELinux hardening from Project Atomic. Its goal is to provide the best container host to run containerized workloads securely and at scale.\r\n\r\nThis talk will describe how Fedora CoreOS is built and maintain and will explain what makes it particularly well suited to securely host modern applications in containers.\r\n\r\nThis talk will be illustrated by several examples: how to easily run a Matrix server on a single node, how to deploy Nomad on three nodes and how to use it as part of a Kubernetes distribution (OKD or Typhoon).", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "9QJRWR", "name": "Timoth\u00e9e Ravier", "avatar": "https://cfp.pass-the-salt.org/media/avatars/profile_picture_cut2_wsUfNp3.jpg", "biography": "Timoth\u00e9e Ravier is a Linux system and security engineer interested in safe programming languages and container focused operating systems. He is currently working at Red Hat as a CoreOS engineer. He created and maintains Fedora Kinoite, an rpm-ostree based variant of Fedora with the KDE Plasma desktop and is packaging KDE applications in Flatpaks for Flathub and Fedora.", "public_name": "Timoth\u00e9e Ravier", "guid": "d5fe5ad2-486e-5713-a56c-0756ed0000e9", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/9QJRWR/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/PGEJ7T/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/PGEJ7T/", "attachments": []}, {"guid": "1737de83-790a-557d-a1c5-98e8b950864c", "code": "YPKX9Q", "id": 6, "logo": null, "date": "2021-07-06T14:40:00+02:00", "start": "14:40", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-6-hosting-identity-in-the-cloud-with-free-softwares", "url": "https://cfp.pass-the-salt.org/pts2021/talk/YPKX9Q/", "title": "Hosting Identity in the Cloud with free softwares", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Identity and Access Management (IAM) is a critical service often hosted inside the company IT, for historical reasons and also security concerns. But we see a recent move in this area, IAM can now be run as any SaaS application, most of the case by choosing private firms (and mainly American ones). Is this the only option?", "description": "I will talk here about a new initiative, which relies on FusionIAM project, that gathers well known IAM free softwares like OpenLDAP, LemonLDAP::NG, LDAP Tool Box and Fusion Directory. We will see how deploy and use these components in the Cloud to offer an alternative to proprietary solutions.", "recording_license": "", "do_not_record": false, "persons": [{"code": "TMEVBC", "name": "Cl\u00e9ment Oudot", "avatar": null, "biography": "Contributor to [LemonLDAP::NG](https://lemonldap-ng.org/), [LDAP Tool Box](https://ltb-project.org/), [LDAP Synchronization Connector](https://lsc-project.org/), [FusionIAM](https://fusioniam.org/), Identity Solutions Manager by [Worteks](https://www.worteks.com).\r\n\r\nBut also musician and singer ([KPTN](https://kptn.org)),actor [DonJon Legacy](https://www.donjonlegacy.com), Improv [Improcit\u00e9](https://improcite.com).", "public_name": "Cl\u00e9ment Oudot", "guid": "2690ec68-c290-55dd-bee5-1b66c7250200", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/TMEVBC/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/YPKX9Q/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/YPKX9Q/", "attachments": []}, {"guid": "8eb22742-df88-545a-a463-03dcea63a276", "code": "DASVEW", "id": 26, "logo": null, "date": "2021-07-06T15:20:00+02:00", "start": "15:20", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-26-biscuit-pubkey-signed-token-with-offline-attenuation-and-datalog-authz-policies", "url": "https://cfp.pass-the-salt.org/pts2021/talk/DASVEW/", "title": "Biscuit: pubkey signed token with offline attenuation and Datalog authz policies", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Biscuit is a new kind of authorization token that merges the public key signatures of JWT, with offline attenuation and caveats from macaroons. It comes with a Datalog based language to express policies, that can be provided by the token or the server side.\r\nThis feature set unlocks powerful use cases like multitenant systems that need flexible authorization policies, or chains of microservices requests with locked down bearer tokens", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "CTTVRY", "name": "Geoffroy Couprie", "avatar": "https://cfp.pass-the-salt.org/media/avatars/AWP_3631_g5adzhg.jpg", "biography": "R&D and security at Clever Cloud. I mess with Rust, parsers and cryptography", "public_name": "Geoffroy Couprie", "guid": "1dad51be-1056-53db-92e2-f2778d914411", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/CTTVRY/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/DASVEW/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/DASVEW/", "attachments": []}, {"guid": "20f7770e-5ac9-5f77-bd5e-be75b7a6c4dc", "code": "UCN3C9", "id": 13, "logo": "https://cfp.pass-the-salt.org/media/pts2021/submissions/UCN3C9/gwf_G2DGfrD.png", "date": "2021-07-06T16:10:00+02:00", "start": "16:10", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-13-generating-weird-files", "url": "https://cfp.pass-the-salt.org/pts2021/talk/UCN3C9/", "title": "Generating Weird Files", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "This talk covers various ways of bypassing security by fooling filetype identification, either by signatures via mock files, or by dual formats via binary polyglots.\r\nNear polyglots are also covered and how when combined with standard cryptographic operations, they can produce uncommon results such as surviving encryption or getting different valid contents from the same ciphertext via authenticated decryption.\r\n\r\nThis talk also introduces Mitra, an open-source file mixer, the combination strategies that it uses, and how little it knows about file formats to do its magic.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "D9PG33", "name": "Ange Albertini", "avatar": null, "biography": "File formats enthusiast - author of Corkami.\r\nCurrently Infosec Engineer at Google.", "public_name": "Ange Albertini", "guid": "819d6c8e-5ad8-55f1-ab9a-b16e7ba3ec4e", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/D9PG33/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/UCN3C9/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/UCN3C9/", "attachments": []}, {"guid": "2d19601a-54c0-55a6-9b92-d7a24dea7b90", "code": "GGLJSS", "id": 20, "logo": null, "date": "2021-07-06T16:50:00+02:00", "start": "16:50", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-20-home-made-distributed-blocklist", "url": "https://cfp.pass-the-salt.org/pts2021/talk/GGLJSS/", "title": "Home-Made Distributed Blocklist", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "When implementing security solutions, there are many ways to integrate a blocklist and improve the detection of suspicious/malicious activity. If there exists many blocklist available online, sometimes their content does not fit exactly with your expectation (false positives, too complex, etc). So, I implemented my own blocklist based on a REST API. This allow me to interconnect it with many tools/scripts/devices to  fetch or update its content. In this presentation, I\u2019ll explain how and why I implemented it with only one goal : automation & improvement of the security perimeter.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "RU9UTJ", "name": "Xavier Mertens", "avatar": "https://cfp.pass-the-salt.org/media/avatars/Photo_Xavier_800_Bl1BSrp.jpg", "biography": "Xavier Mertens is a freelance security consultant based in Belgium. With 12+ years of experience in information security, his job focuses on protecting his customers' assets by providing services like incident handling, investigations, log management, security visualization, OSINT). Xavier is also a Senior Handler at the SANS Internet Storm Center, SANS FOR610 instructor, a security blogger  and co-organizer of the BruCON security conference.", "public_name": "Xavier Mertens", "guid": "56915001-aa85-5973-ad1f-3b14a2df40ab", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/RU9UTJ/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/GGLJSS/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/GGLJSS/", "attachments": []}, {"guid": "7e73c411-3847-5cb7-ba44-756c6066bacf", "code": "TMB7XQ", "id": 24, "logo": null, "date": "2021-07-06T17:30:00+02:00", "start": "17:30", "duration": "00:20", "room": "Zoom room", "slug": "pts2021-24-security-alerting-made-easy-using-python", "url": "https://cfp.pass-the-salt.org/pts2021/talk/TMB7XQ/", "title": "Security alerting made easy using Python", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "A common question about sudo and syslog-ng is how to send alerts to various online services. Both of these have supported sending email notifications for a long time, but more recently users have requested real-time alerting to Slack, Telegram, Discord and others. Peter\u2019s talk will introduce you to alerting using the AppRise Python library. You will need to know a bit of Python and at least one of sudo or syslog-ng to understand the examples, but what you learn will help you to implement real-time alerting in a wide range of applications. \r\n\r\nFirst of all, what do we mean by alerting? It is sending notifications about important events in your IT environment. Traditionally, this meant receiving a flood of emails when a problem occurred. These days, there are many more services that can be used to receive alerts. You can send alerts to most of them through HTTP-based protocols.\r\n\r\nSyslog-ng has an http() destination that can be used to send alerts to various online services. However, even when a service\u2019s API is published, figuring out how to actually use it can be difficult. The new python() destination makes it possible to connect to additional services through the use of client libraries, but still requires work for each new service.\r\n\r\nThis is where the AppRise Python library can help. It supports most of the well-known instant messaging services in addition to many other, less well-known services. Once you integrate it into your project you instantly have access to dozens of services that you can send alerts to.\r\n\r\nThrough the sudo and syslog-ng integrations you will learn how to work with AppRise. The included Python code focuses on functionality, but lacks proper error handling to make it easier to read.\r\n\r\nA live demo will show sending alerts to Discord and how easy it is to change the alerting to use other services.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "RRBVLJ", "name": "Peter Czanik, syslog-ng PO at One Identity", "avatar": "https://cfp.pass-the-salt.org/media/avatars/czp_uj_balabit_crop_36wP6Rd.jpg", "biography": "Peter is an engineer working as open source evangelist at Balabit (a One Identity business), the company that developed syslog-ng. He assists distributions to maintain the syslog-ng package, follows bug trackers, helps users and talks regularly about sudo and syslog-ng at conferences (SCALE, All Things Open, FOSDEM, LOADays, and others). In his limited free time he is interested in non-x86 architectures, and works on one of his PPC or ARM machines.", "public_name": "Peter Czanik, syslog-ng PO at One Identity", "guid": "4ebe43d9-92da-56e9-b538-7535b68c3101", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/RRBVLJ/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/TMB7XQ/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/TMB7XQ/", "attachments": []}]}}, {"index": 3, "date": "2021-07-07", "day_start": "2021-07-07T04:00:00+02:00", "day_end": "2021-07-08T03:59:00+02:00", "rooms": {"Zoom room": [{"guid": "6d527461-313d-5c54-8d70-79229e33008c", "code": "MZRXDW", "id": 28, "logo": null, "date": "2021-07-07T14:00:00+02:00", "start": "14:00", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-28-att-cking-kubernetes-a-technical-deep-dive-into-the-new-att-ck-for-containers", "url": "https://cfp.pass-the-salt.org/pts2021/talk/MZRXDW/", "title": "ATT&CKing Kubernetes: A technical deep dive into the new ATT&CK for Containers", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "This presentation aims to talk about different attack scenarios leveraging Kubernetes clusters. We'll dig deeper into a real-world attack scenario using real-world applications to demonstrate different ways attackers and malicious users can use to exploit your cluster and the applications running on it. But first, we\u2019ll give an overview about Kubernetes and its architecture, covering the main components from the Control Plane and the Worker Nodes. Then, we'll use the K8s Threat Matrix and the MITRE ATT&CK for Containers published this year to discuss the Tactics, Techniques and Procedures to demonstrate the Recon, Exploitation and Post-Exploitation phases. After that, we'll provide some best practices to securing your cluster based on the scenarios and the CIS Benchmarks for Kubernetes. We'll show how to use Role-based access control (RBAC)  for Access Control, to enable audit logs for security and troubleshooting, and we'll set up some network policies to avoid communication between pods and prevent any lateral movement from attackers.", "description": "\u200bIntroduction to Kubernetes\r\nOutline of K8s Architecture\u200b \r\nControl Plane\r\nKube API Server\r\nKube Controller Manager\r\netcd\r\nKube Scheduler\r\nCloud Controller Manager\r\nWorker Nodes\r\nkubelet\r\nkube-proxy\r\nCRE (Container Runtime  Engine)\r\n MITRE ATT&CK \u200b\r\n- K8s Threat Matrix \u200b\r\n- MITRE ATT&CK for Containers \u200b(and K8s)\r\n- K8s ATT&CK Scenario & Flow\u200b\r\nAttacking K8s\u200b\r\n- Recon / Initial Access\u200b\r\n- Exploitation / Execution\r\n- Post-Exploitation / Persistence\u200b\r\nDefending K8s\u200b\r\n- API Server\u200b\r\n- CIS Benchmark\u200b\r\n- Image Scanning\u200b\r\n- Runtime Protection\u200b\r\n- Network Policy\u200b\r\n- Pod Security Policy (PSP)\u200b - Deprecated\r\n- PSP Alternatives\u200b\r\n- Audit Logs", "recording_license": "", "do_not_record": false, "persons": [{"code": "J3BG8Z", "name": "Magno Logan", "avatar": "https://cfp.pass-the-salt.org/media/avatars/magno-defcon_gfe63kz.jpg", "biography": "Magno Logan works as an Information Security Specialist for Trend Micro. He specializes in Cloud, Container and Application Security Research, Threat Modelling and Red Teaming. He has been tapped as a resource speaker for numerous security conferences around the globe. He is also a member of the CNCF SIG-Security team.", "public_name": "Magno Logan", "guid": "5d6d7c93-4f45-5d39-8f3a-13c505750e70", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/J3BG8Z/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/MZRXDW/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/MZRXDW/", "attachments": []}, {"guid": "328f67d3-1e9f-5889-a5af-e3f1336e7243", "code": "N3EUGV", "id": 5, "logo": null, "date": "2021-07-07T14:40:00+02:00", "start": "14:40", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-5-revisiting-the-art-of-encoder-fu-for-novel-shellcode-obfuscation-techniques", "url": "https://cfp.pass-the-salt.org/pts2021/talk/N3EUGV/", "title": "Revisiting the Art of Encoder-Fu for novel shellcode obfuscation techniques", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "This talk is based around the process of building encoders for shellcodes in this day and age where we are surrounded with NextGen Firewalls, IDS/IPS, and EDR solutions and ever releasing AV detection models (signature & behavior-based detection techniques) incorporating Machine Learning artifacts. Despite the implementation of security controls, some of the forgotten methods of obfuscation works wonders to bypass the latest security mechanism.", "description": "Idea is to develop an understanding of obscure assembly instructions and to be able to associate with the common trends in place in automative tools. The talk focuses on building the ability to see current patterns, trends in evasion, and detection methodologies that also include advanced \"one-way\" shellcode and multi-stage payloads that can evade defenses.\r\n\r\nThe talk also includes a deep dive into the idea of obfuscation of shellcodes and executables as  deliverables/payloads and focusing on techniques categorically - Basic encoding, Morphing/partial-morphing, Cross-compilation, Polymorphism vs Encrypted and Mutated encoders\r\n\r\nAt the end of the talk, we will also cover the analysis of publicly available encoders from MSF that are used in common offensive tradecrafts shows how the fundamentals mentioned above make them relevant in modern attack scenarios.", "recording_license": "", "do_not_record": true, "persons": [{"code": "SGMQMY", "name": "Harpreet Singh", "avatar": "https://cfp.pass-the-salt.org/media/avatars/84203407_3078247522185579_8339089767266254848_n_Br7SneS.jpg", "biography": "Harpreet is the author of \"Hands-On: Web Penetration Testing with Metasploit\" and \"Hands-On: Red Team Tactics\" published by Packt Publishing who has more than 8 years of experience in the field of Ethical Hacking, Penetration Testing, vulnerability research & Red Teaming. He is also a certified CRTP (Certified Red Team Professional), OSCP (Offensive Security Certified Professional) & OSWP (Offensive Security Wireless Professional). Over the years of his experience, Harpreet has acquired the Offensive skill set as well as the Defensive skill set. He is a professional who specializes in Wireless & network exploitation including but not limited to Mobile exploitation, Web Application exploitation and he has also performed few Red Team Engagements in Banks & Financial Groups.", "public_name": "Harpreet Singh", "guid": "5adefe44-c13a-5cfc-90d9-cb3094d20317", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/SGMQMY/"}, {"code": "NKSKJ9", "name": "Yashdeep Saini", "avatar": "https://cfp.pass-the-salt.org/media/avatars/Saini_U7qKquO.jpeg", "biography": "Loves to play with system internals and low level exploitation ideas with couple of years of experience with Appsec/Prodsec/Redteaming/VAPT.", "public_name": "Yashdeep Saini", "guid": "9ebd8ca1-f0a7-5a49-8d68-d4ada1b47dcc", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/NKSKJ9/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/N3EUGV/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/N3EUGV/", "attachments": []}, {"guid": "a131da5a-6686-522a-9178-5ab94f13978d", "code": "DPKWYA", "id": 11, "logo": null, "date": "2021-07-07T15:20:00+02:00", "start": "15:20", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-11-in-search-of-lost-time-a-review-of-javascript-timers-in-browsers", "url": "https://cfp.pass-the-salt.org/pts2021/talk/DPKWYA/", "title": "In Search of Lost Time: A Review of JavaScript Timers in Browsers", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "JavaScript-based timing attacks have been greatly explored over the last few years. They rely on subtle timing differences to infer information that should not be available inside of the JavaScript sandbox. In reaction to these attacks, the W3C and browser vendors have implemented several countermeasures, with an important focus on JavaScript timers. However, as these attacks multiplied in the last years, so did the countermeasures, in a cat-and-mouse game fashion.\r\n\r\nIn this presentation, we present the evolution and current situation of timing attacks in browsers, as well as statistical tools to characterize available timers. Our goal is to present a clear view of the attack surface and understand what are the main prerequisites and classes of browser-based timing attacks and what are the main countermeasures. We focus on determining to what extent the changes on timing-based countermeasures impact browser security. In particular, we show that the shift in protecting against transient execution attacks has re-enabled other attacks such as microarchitectural side-channel attacks with a higher bandwidth than what was possible just two years ago.", "description": "This research was done in collaboration with Cl\u00e9mentine Maurice and Pierre Laperdrix, and was published at the EuroS&P 2021 conference. \r\nPaper: https://people.irisa.fr/Thomas.Rokicki/publications/timer-paper.pdf\r\nRepository: https://github.com/thomasrokicki/in-search-of-lost-time\r\n\r\nVariations of computation time can reveal information about the state of a system. Research has uncovered a variety of side and covert channels, allowing potential attackers to extract secrets or track user behavior. Timing attacks can aim at different components of the microarchitecture, e.g., cache, DRAM, and are purely software-based. These attacks have two common prerequisites: they run code on the victim's hardware, and they rely on high-resolution timers that can distinguish small timing variations in the order of 100ns. Most of the timing attacks are implemented in native code, allowing the attacker to have great control over the memory and cycle-accurate timers.\r\n\r\nIn contrast, JavaScript is a high-level object-oriented interpreted scripting language, following the ECMAscript standard. Contrary to native code, it is much easier to run JavaScript code on a victim's system as it is a major component of the web, used by billions of people everyday. Almost all websites use JavaScript to execute code on the client side and by visiting a page, a client can download and execute dozens of different scripts. For security purposes, JavaScript code runs inside a sandboxed environment, restricting access to local files, virtual or physical memory addresses and native instructions. These restrictions make it harder to implement microarchitectural attacks. However, fully JavaScript-based timings attacks, running entirely in the browser, were implemented, bypassing the sandbox restrictions. These attacks include cache attacks, attacks on shared software resources, and even transient execution attacks like Spectre.\r\n\r\nTo try and mitigate JavaScript-based timing attacks, browser vendors have developed countermeasures, specifically targeting timers. Notably, they decreased the resolution of timers to make them less precise and introduced jitter to add noise in measurements. Other security features like site isolation were added to reinforce the security of browsers and act as a novel line of defense against timing attacks. After the publication of such countermeasures, browser vendors reallowed access to high resolution timers. Amid all these changes, it can be hard to keep track of all the different evolutions that browsers underwent. Particularly, it is unclear how the attacks described in the literature are impacted by current countermeasures.\r\n\r\nIn this presentation, we will introduce the various ways to create high resolution timers in JavaScript. Then, we will present the major classes of browser-based timing attacks, followed by the browser-based countermeasures. Finally, we will evaluate the efficiency of the evolution of countermeasures in the later releases of Firefox and Chrome.", "recording_license": "", "do_not_record": false, "persons": [{"code": "RUW8SS", "name": "Thomas Rokicki", "avatar": null, "biography": "I'm a french PhD Student in IRISA Rennes, in the SPICY team. I currently work on micro-architectural attacks, particularly based on JavaScript.", "public_name": "Thomas Rokicki", "guid": "9b526036-686a-5222-9281-ca58c90a7ef4", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/RUW8SS/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/DPKWYA/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/DPKWYA/", "attachments": []}, {"guid": "ae752f1f-36e0-5e9c-aed3-a46367788ae7", "code": "NQDAJF", "id": 18, "logo": null, "date": "2021-07-07T16:10:00+02:00", "start": "16:10", "duration": "00:35", "room": "Zoom room", "slug": "pts2021-18-oramfs-achieving-storage-agnostic-privacy", "url": "https://cfp.pass-the-salt.org/pts2021/talk/NQDAJF/", "title": "ORAMFS: Achieving Storage-Agnostic Privacy", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "You may believe traditional storage encryption is enough to protect the privacy of your data at rest, even in untrusted environments. Think twice: Access pattern leakage can, in many cases, reveal sensitive information to an attacker. For example, a malicious cloud provider can still see whether a user performs read or write operations and which part of the data is accessed, even if all of the data is encrypted.\r\n\r\nOblivious Random Access Machines (ORAMs) are cryptographic schemes that hide both data and access patterns. This obfuscation is achieved by making redundant read/write operations and encrypting, re-randomizing, and shuffling the blocks composing the storage layer on every access. The resulting loss of performance is a tradeoff that allows to turn untrusted storage into a trusted one solely via software. However, existing solutions are cumbersome for the user, requiring the storage provider to support the ORAM scheme.\r\n\r\nWe implemented oramfs: an open source, cloud- and storage-agnostic, resizable ORAM client written in Rust that offers privacy features beyond encryption. In this talk, we look at how a practical ORAM scheme such as PathORAM works, give some background about oramfs, and show how it can be used to protect data resting on untrusted storage.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "A7JEAC", "name": "Nils Amiet", "avatar": null, "biography": "Nils is a Senior Security Engineer on Kudelski Security\u2019s research team performing research on various topics including privacy, authentication, big data analytics, and internet scanning. He also writes blog posts on various topics for Kudelski\u2019s research blog. Nils likes open source software and has presented his research at DEF CON and Black Hat Arsenal. He was part of creating a massively distributed system for breaking RSA public keys.", "public_name": "Nils Amiet", "guid": "68b95c4e-b7f2-5408-9f0d-599b052fdf2f", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/A7JEAC/"}, {"code": "3MM8SK", "name": "Tommaso Gagliardoni (Tech Lead Cryptography, Kudelski Security)", "avatar": "https://cfp.pass-the-salt.org/media/avatars/me_JwYDXdN.jpg", "biography": "Tommaso Gagliardoni is a cryptographer, privacy hacktivist, and quantum security expert. He works as a researcher and innovation leader at Swiss-American cybersecurity company Kudelski Security. Tommaso published many influential peer-reviewed papers in the areas of cryptography, quantum computing, security, and privacy, and spoke at many international conferences in these fields. He obtained an M.Sc. in Mathematics at the University of Perugia, Italy, and a PhD at the Technical University of Darmstadt, Germany, with a dissertation on the quantum security of cryptographic primitives. Before joining Kudelski Security, he worked in the Security and Privacy group at IBM Research Zurich.", "public_name": "Tommaso Gagliardoni (Tech Lead Cryptography, Kudelski Security)", "guid": "4191272c-dbd8-5744-8baf-66821e6c8abe", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/3MM8SK/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/NQDAJF/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/NQDAJF/", "attachments": []}, {"guid": "1e83cb0b-29e2-547c-be0f-95c18b9653de", "code": "8CAB8G", "id": 19, "logo": null, "date": "2021-07-07T16:50:00+02:00", "start": "16:50", "duration": "00:20", "room": "Zoom room", "slug": "pts2021-19-meet-piotr-a-firmware-emulation-tool-for-trainers-and-researchers", "url": "https://cfp.pass-the-salt.org/pts2021/talk/8CAB8G/", "title": "Meet Piotr, a firmware emulation tool for trainers and researchers", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "Piotr is a tool designed to create, run and share virtual IoT devices that can be used to teach IoT security or research vulnerabilities in firmwares. \r\n\r\nPiotr runs emulated devices inside an emulated host that provides all the tools you may need and creates a fake environment for them. This approach allows remote debugging with gdbserver or fridaserver, provides a steady platform for vulnerability research, exploitation and training.\r\n\r\nMoreover, Piotr is able to package any emulated device into a single file that may be shared and imported by other users, thus sharing its kernel, DTB file or even its host filesystem. This way, it is possible to create new emulated devices based upon existing ones, and to improve all of them by simply changing a single file (kernel, host filesystem, etc.).", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "TNZWVD", "name": "Damien Cauquil (R&D Engineer at Quarkslab)", "avatar": null, "biography": "Damien Cauquil is a security consultant at Quarkslab, specialized in embedded security and hardware/software reverse-engineering. He spoke at various cybersecurity conferences including DEFCON, BruCON, CCC and LeHack. He is also the author of some opensource tools such as Btlejack or Btlejuice.", "public_name": "Damien Cauquil (R&D Engineer at Quarkslab)", "guid": "b50d3796-ed38-53cf-b380-b977f71804b2", "url": "https://cfp.pass-the-salt.org/pts2021/speaker/TNZWVD/"}], "links": [], "feedback_url": "https://cfp.pass-the-salt.org/pts2021/talk/8CAB8G/feedback/", "origin_url": "https://cfp.pass-the-salt.org/pts2021/talk/8CAB8G/", "attachments": []}]}}]}}}