<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>LB9CZS@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-LB9CZS</pentabarf:event-slug>
            <pentabarf:title>Welcome</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T134500</dtstart>
            <dtend>20210705T140000</dtend>
            <duration>0.01500</duration>
            <summary>Welcome</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Special</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/LB9CZS/</url>
            <location>Zoom room</location>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>LQDHNS@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-LQDHNS</pentabarf:event-slug>
            <pentabarf:title>Jailbreak detection mechanisms and how to bypass them</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T140000</dtstart>
            <dtend>20210705T143500</dtend>
            <duration>0.03500</duration>
            <summary>Jailbreak detection mechanisms and how to bypass them</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/LQDHNS/</url>
            <location>Zoom room</location>
            
            <attendee>Eloi Benoist-Vanderbeken</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MGCYPT@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MGCYPT</pentabarf:event-slug>
            <pentabarf:title>Pithus: let&#x27;s open the Android pandora&#x27;s box</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T144000</dtstart>
            <dtend>20210705T151500</dtend>
            <duration>0.03500</duration>
            <summary>Pithus: let&#x27;s open the Android pandora&#x27;s box</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/MGCYPT/</url>
            <location>Zoom room</location>
            
            <attendee>U039b</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>CTWBB8@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-CTWBB8</pentabarf:event-slug>
            <pentabarf:title>Hook as you want it</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T152000</dtstart>
            <dtend>20210705T155500</dtend>
            <duration>0.03500</duration>
            <summary>Hook as you want it</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/CTWBB8/</url>
            <location>Zoom room</location>
            
            <attendee>Benoit Forgette</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>LA9V9Y@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-LA9V9Y</pentabarf:event-slug>
            <pentabarf:title>PatrowlHears and Survival tips for prioritizing threats</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T161000</dtstart>
            <dtend>20210705T164500</dtend>
            <duration>0.03500</duration>
            <summary>PatrowlHears and Survival tips for prioritizing threats</summary>
            <description>Solutions must be found to face the overall growing threat of attacks, talent shortage and cost optimization challenges in cybersecurity. The current trend is to rely on automation and orchestration of security operations.

The fact is automating SecOps activities leads to manage more security alerts. The downside is that potentially a bunch of new security alerts every day. By the way, with hundreds of vulnerabilities with critical or high severity to deal with,  the daily security reports look like a shining Christmas tree. It could definitely lead to jaded teams or, even worse, bad decisions in vulnerability handling.

Obviously, it is not realistic to hope that all vulnerabilities will be fixed. A line have to be drawn by the business owners according with the security teams. Prioritization is an essential success factor for improving efficiency and continue to provide the highest quality and relevant service in security incident response and vulnerability management. Because the CVSS score is not enough, which are the relevant metrics ? How to collect them ? Which decision should be made ? How to review efficiency of this process and adapt it ?

This talk is about to share insights on a risk-based methodology in vulnerability management and a new open-source tool PatrowlHears. This approach is enabled by a balanced usage of SecOps automation to keep us updated for vulnerabilities, exploits and other threat information, and prioritization using vulnerability metrics, threat topicality and asset criticality. Also, it will be discussed on examples of events that should conduct us to consider reprioritization of a vulnerability handling.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/LA9V9Y/</url>
            <location>Zoom room</location>
            
            <attendee>Nicolas Mattiocco</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JDP7LB@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JDP7LB</pentabarf:event-slug>
            <pentabarf:title>Forensics Low Level - Having fun with Linux onboard tools</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210705T165000</dtstart>
            <dtend>20210705T172500</dtend>
            <duration>0.03500</duration>
            <summary>Forensics Low Level - Having fun with Linux onboard tools</summary>
            <description>The presentation will consists out of 3 live demos. All the demos based on Linux standard tools like &#x27;dd&#x27;, &#x27;hexedit&#x27; and alike.

1. In Forensics a HW write-blocker is necessary. Just mounting the device in RO mode is not sufficient. I will connect a USB stick to my laptop and mount it RO. After this I will modify some data on the USB stick.

2. I have a standard USB stick and simply modify some (3) bytes on it. The result, Linux will mount up to 250 partitions. Some tools either hang or simply display wrong information. You need to read the bytes of the partition table to understand whats going wrong.

3. If you connect another USB stick to a Windows, file A, B and C have content X, Y and Z. If you connect the same USB stick to Linux, file A, B and C have content U, V, W. Analyzing and understanding the Master Boot Record will reveal the secret.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/JDP7LB/</url>
            <location>Zoom room</location>
            
            <attendee>Michael Hamm</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PGEJ7T@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PGEJ7T</pentabarf:event-slug>
            <pentabarf:title>Fedora CoreOS, a container focused OS to securely deploy and run applications</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T140000</dtstart>
            <dtend>20210706T143500</dtend>
            <duration>0.03500</duration>
            <summary>Fedora CoreOS, a container focused OS to securely deploy and run applications</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/PGEJ7T/</url>
            <location>Zoom room</location>
            
            <attendee>Timothée Ravier</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YPKX9Q@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YPKX9Q</pentabarf:event-slug>
            <pentabarf:title>Hosting Identity in the Cloud with free softwares</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T144000</dtstart>
            <dtend>20210706T151500</dtend>
            <duration>0.03500</duration>
            <summary>Hosting Identity in the Cloud with free softwares</summary>
            <description>I will talk here about a new initiative, which relies on FusionIAM project, that gathers well known IAM free softwares like OpenLDAP, LemonLDAP::NG, LDAP Tool Box and Fusion Directory. We will see how deploy and use these components in the Cloud to offer an alternative to proprietary solutions.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/YPKX9Q/</url>
            <location>Zoom room</location>
            
            <attendee>Clément Oudot</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DASVEW@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DASVEW</pentabarf:event-slug>
            <pentabarf:title>Biscuit: pubkey signed token with offline attenuation and Datalog authz policies</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T152000</dtstart>
            <dtend>20210706T155500</dtend>
            <duration>0.03500</duration>
            <summary>Biscuit: pubkey signed token with offline attenuation and Datalog authz policies</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/DASVEW/</url>
            <location>Zoom room</location>
            
            <attendee>Geoffroy Couprie</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UCN3C9@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UCN3C9</pentabarf:event-slug>
            <pentabarf:title>Generating Weird Files</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T161000</dtstart>
            <dtend>20210706T164500</dtend>
            <duration>0.03500</duration>
            <summary>Generating Weird Files</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/UCN3C9/</url>
            <location>Zoom room</location>
            
            <attendee>Ange Albertini</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GGLJSS@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GGLJSS</pentabarf:event-slug>
            <pentabarf:title>Home-Made Distributed Blocklist</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T165000</dtstart>
            <dtend>20210706T172500</dtend>
            <duration>0.03500</duration>
            <summary>Home-Made Distributed Blocklist</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/GGLJSS/</url>
            <location>Zoom room</location>
            
            <attendee>Xavier Mertens</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>TMB7XQ@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-TMB7XQ</pentabarf:event-slug>
            <pentabarf:title>Security alerting made easy using Python</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210706T173000</dtstart>
            <dtend>20210706T175000</dtend>
            <duration>0.02000</duration>
            <summary>Security alerting made easy using Python</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Short Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/TMB7XQ/</url>
            <location>Zoom room</location>
            
            <attendee>Peter Czanik, syslog-ng PO at One Identity</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MZRXDW@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MZRXDW</pentabarf:event-slug>
            <pentabarf:title>ATT&amp;CKing Kubernetes: A technical deep dive into the new ATT&amp;CK for Containers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210707T140000</dtstart>
            <dtend>20210707T143500</dtend>
            <duration>0.03500</duration>
            <summary>ATT&amp;CKing Kubernetes: A technical deep dive into the new ATT&amp;CK for Containers</summary>
            <description>​Introduction to Kubernetes
Outline of K8s Architecture​ 
Control Plane
Kube API Server
Kube Controller Manager
etcd
Kube Scheduler
Cloud Controller Manager
Worker Nodes
kubelet
kube-proxy
CRE (Container Runtime  Engine)
 MITRE ATT&amp;CK ​
- K8s Threat Matrix ​
- MITRE ATT&amp;CK for Containers ​(and K8s)
- K8s ATT&amp;CK Scenario &amp; Flow​
Attacking K8s​
- Recon / Initial Access​
- Exploitation / Execution
- Post-Exploitation / Persistence​
Defending K8s​
- API Server​
- CIS Benchmark​
- Image Scanning​
- Runtime Protection​
- Network Policy​
- Pod Security Policy (PSP)​ - Deprecated
- PSP Alternatives​
- Audit Logs</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/MZRXDW/</url>
            <location>Zoom room</location>
            
            <attendee>Magno Logan</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>N3EUGV@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-N3EUGV</pentabarf:event-slug>
            <pentabarf:title>Revisiting the Art of Encoder-Fu for novel shellcode obfuscation techniques</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210707T144000</dtstart>
            <dtend>20210707T151500</dtend>
            <duration>0.03500</duration>
            <summary>Revisiting the Art of Encoder-Fu for novel shellcode obfuscation techniques</summary>
            <description>Idea is to develop an understanding of obscure assembly instructions and to be able to associate with the common trends in place in automative tools. The talk focuses on building the ability to see current patterns, trends in evasion, and detection methodologies that also include advanced &quot;one-way&quot; shellcode and multi-stage payloads that can evade defenses.

The talk also includes a deep dive into the idea of obfuscation of shellcodes and executables as  deliverables/payloads and focusing on techniques categorically - Basic encoding, Morphing/partial-morphing, Cross-compilation, Polymorphism vs Encrypted and Mutated encoders

At the end of the talk, we will also cover the analysis of publicly available encoders from MSF that are used in common offensive tradecrafts shows how the fundamentals mentioned above make them relevant in modern attack scenarios.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/N3EUGV/</url>
            <location>Zoom room</location>
            
            <attendee>Harpreet Singh</attendee>
            
            <attendee>Yashdeep Saini</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DPKWYA@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DPKWYA</pentabarf:event-slug>
            <pentabarf:title>In Search of Lost Time: A Review of JavaScript Timers in Browsers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210707T152000</dtstart>
            <dtend>20210707T155500</dtend>
            <duration>0.03500</duration>
            <summary>In Search of Lost Time: A Review of JavaScript Timers in Browsers</summary>
            <description>This research was done in collaboration with Clémentine Maurice and Pierre Laperdrix, and was published at the EuroS&amp;P 2021 conference. 
Paper: https://people.irisa.fr/Thomas.Rokicki/publications/timer-paper.pdf
Repository: https://github.com/thomasrokicki/in-search-of-lost-time

Variations of computation time can reveal information about the state of a system. Research has uncovered a variety of side and covert channels, allowing potential attackers to extract secrets or track user behavior. Timing attacks can aim at different components of the microarchitecture, e.g., cache, DRAM, and are purely software-based. These attacks have two common prerequisites: they run code on the victim&#x27;s hardware, and they rely on high-resolution timers that can distinguish small timing variations in the order of 100ns. Most of the timing attacks are implemented in native code, allowing the attacker to have great control over the memory and cycle-accurate timers.

In contrast, JavaScript is a high-level object-oriented interpreted scripting language, following the ECMAscript standard. Contrary to native code, it is much easier to run JavaScript code on a victim&#x27;s system as it is a major component of the web, used by billions of people everyday. Almost all websites use JavaScript to execute code on the client side and by visiting a page, a client can download and execute dozens of different scripts. For security purposes, JavaScript code runs inside a sandboxed environment, restricting access to local files, virtual or physical memory addresses and native instructions. These restrictions make it harder to implement microarchitectural attacks. However, fully JavaScript-based timings attacks, running entirely in the browser, were implemented, bypassing the sandbox restrictions. These attacks include cache attacks, attacks on shared software resources, and even transient execution attacks like Spectre.

To try and mitigate JavaScript-based timing attacks, browser vendors have developed countermeasures, specifically targeting timers. Notably, they decreased the resolution of timers to make them less precise and introduced jitter to add noise in measurements. Other security features like site isolation were added to reinforce the security of browsers and act as a novel line of defense against timing attacks. After the publication of such countermeasures, browser vendors reallowed access to high resolution timers. Amid all these changes, it can be hard to keep track of all the different evolutions that browsers underwent. Particularly, it is unclear how the attacks described in the literature are impacted by current countermeasures.

In this presentation, we will introduce the various ways to create high resolution timers in JavaScript. Then, we will present the major classes of browser-based timing attacks, followed by the browser-based countermeasures. Finally, we will evaluate the efficiency of the evolution of countermeasures in the later releases of Firefox and Chrome.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/DPKWYA/</url>
            <location>Zoom room</location>
            
            <attendee>Thomas Rokicki</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NQDAJF@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NQDAJF</pentabarf:event-slug>
            <pentabarf:title>ORAMFS: Achieving Storage-Agnostic Privacy</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210707T161000</dtstart>
            <dtend>20210707T164500</dtend>
            <duration>0.03500</duration>
            <summary>ORAMFS: Achieving Storage-Agnostic Privacy</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/NQDAJF/</url>
            <location>Zoom room</location>
            
            <attendee>Nils Amiet</attendee>
            
            <attendee>Tommaso Gagliardoni (Tech Lead Cryptography, Kudelski Security)</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>8CAB8G@@cfp.pass-the-salt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-8CAB8G</pentabarf:event-slug>
            <pentabarf:title>Meet Piotr, a firmware emulation tool for trainers and researchers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20210707T165000</dtstart>
            <dtend>20210707T171000</dtend>
            <duration>0.02000</duration>
            <summary>Meet Piotr, a firmware emulation tool for trainers and researchers</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Short Talk</category>
            <url>https://cfp.pass-the-salt.org/pts2021/talk/8CAB8G/</url>
            <location>Zoom room</location>
            
            <attendee>Damien Cauquil (R&amp;D Engineer at Quarkslab)</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
