{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsides-cape-town-2024/schedule/", "version": "0.5", "base_url": "https://pretalx.com", "conference": {"acronym": "bsides-cape-town-2024", "title": "BSides Cape Town 2024", "start": "2024-12-06", "end": "2024-12-07", "daysCount": 2, "timeslot_duration": "00:05", "time_zone_name": "Africa/Johannesburg", "colors": {"primary": "#0EA0FE"}, "rooms": [{"name": "Workshop 3", "slug": "3627-workshop-3", "guid": "c2561e99-b8d3-5cbc-b5a3-7530249be626", "description": null, "capacity": 30}, {"name": "Workshop 2", "slug": "3626-workshop-2", "guid": "99731125-19bc-51b3-b6d5-2aeff85b7c63", "description": null, "capacity": 30}, {"name": "Track 1", "slug": "3593-track-1", "guid": "7fb9d121-e957-58ec-9011-d40640582488", "description": null, "capacity": 200}, {"name": "Workshop 1", "slug": "3625-workshop-1", "guid": "83ee0535-49c2-554a-8a4b-66156f74c6b7", "description": null, "capacity": 30}, {"name": "Track 2", "slug": "3594-track-2", "guid": "3d034bb8-4a18-5bfd-956f-c3250d9cadae", "description": null, "capacity": 150}], "tracks": [{"name": "Track 1", "slug": "4891-track-1", "color": "#EE1919"}, {"name": "Track 2", "slug": "4892-track-2", "color": "#DB8615"}, {"name": "Workshops", "slug": "4893-workshops", "color": "#18B423"}], "days": [{"index": 1, "date": "2024-12-06", "day_start": "2024-12-06T04:00:00+02:00", "day_end": "2024-12-07T03:59:00+02:00", "rooms": {}}, {"index": 2, "date": "2024-12-07", "day_start": "2024-12-07T04:00:00+02:00", "day_end": "2024-12-08T03:59:00+02:00", "rooms": {"Track 1": [{"guid": "8cf30179-e43a-518e-8829-b988f6ef26bb", "code": "RYA3LS", "id": 54683, "logo": null, "date": "2024-12-07T09:30:00+02:00", "start": "09:30", "end": "2024-12-07T10:15:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-54683-zen-and-the-art-of-cognitive-defense-zero-trust-mindsets-and-cyber-mindfulness", "url": "https://pretalx.com/bsides-cape-town-2024/talk/RYA3LS/", "title": "Zen and the Art of Cognitive Defense: Zero-Trust Mindsets and Cyber-Mindfulness", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "This talk will delve into the critical findings from the speaker's Cyber psychology Master\u2019s research thesis, exploring the human susceptibility factors to social engineering and deception. It will touch on how scientifically evidenced mindfulness practices can effectively 'patch' many (23 out of 33) of these human vulnerabilities. Additionally, we will share practical insights from a 1.5-year journey into implementing a cyber mindfulness campaign at Nedbank.", "description": "I previously wrote about how I failed a phishing simulation test during an Uber ride and how this led me to research human susceptibility factors to social engineering and cyber-mindfulness. I wanted to dig into the real reason why I clicked on a phishing email as a security person with 22+ years of experience in cybersecurity. (By the way, the Uber incident was not the only phishing test I failed - there were quite a few more examples). My theory back then was that it wasn't my lack of skills that made me click, but rather a distracted and multi-tasking state of mind. And some initial research confirmed this theory. Motivated by these findings, I decided to make this question the focus of my research thesis for my Cyberpsychology Master's program. The talk will provide the key highlights from the thesis, such as: \n1. Findings from the literature review to identify factors contributing to susceptibility to phishing and SE. Factors found were classified into cognitive, behavioural, psychological, situational, and demographic categories\n2.  these were then mapped against validated benefits of mindfulness\u2014such as improved attentional control, enhanced meta-awareness, reduced stress, and emotional regulation. \n3. Existing literature covering mindfulness in cybersecurity specifically confirmed that participants who underwent mindfulness training were better in detecting phishing attempts compared to control groups, indicating a clear link between mindfulness practices and reduced susceptibility to SE tactics.\n\nThrough interviews with 20 experts in cybersecurity and mindfulness and using inductive qualitative analysis, themes and categories related to the integration of mindfulness in cybersecurity awareness programmes and general organisational settings were identified. While the interviews confirmed many of the theoretical benefits, they also uncovered significant challenges, such as resistance from employees to terminology, ensuring consistent adoption, difficulties in communication and quantifying the effectiveness. Based on the findings, I recommend a companywide culture shift to one that favours deliberation over immediacy and one that integrates mindfulness into the broader organisational and cybersecurity agenda. \nLastly we will also share some real-world examples of organisations that have embraced this concept, such as Nedbank.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GBWRGJ", "name": "Anna", "avatar": "https://pretalx.com/media/avatars/GBWRGJ_DXWsYLe.webp", "biography": "Anna Collard is the SVP of Content Strategy and Evangelist for KnowBe4 Africa. She founded Popcorn Training, acquired by KnowBe4 in 2018, and holds a Master of Science in Cyber Psychology, alongside various security certifications such as CISSP, CISA, CIPP/IT, ISO 27k and PCI DSS QSA. Recognized among the Top 20 Women in Cyber (2024), she also won the Global Cybersecurity Women of the Year Award (2023). Anna is a member of the World Economic Forum\u2019s Global Future Councils and co-founded the MiDO Cyber Academy Programme, focusing on closing the cyber skills gap in underserved communities", "public_name": "Anna", "guid": "f58af38c-8922-524c-a9bc-b7da99b32cbf", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/GBWRGJ/"}, {"code": "PHQJN3", "name": "Christine Gordon-Bennett", "avatar": "https://pretalx.com/media/avatars/PHQJN3_paHRtzA.webp", "biography": "Christine Gordon-Bennett is a passionate, creative, energetic and enthusiastic cyber security awareness expert currently working in the CISO Office at Nedbank. She has a passion for helping people understand the value of safe cyber security practices and educating them on human behavioural changes to avoid being the target in a cyber-attack at work, and in their personal lives.\n \nChristine has thoroughly enjoyed developing and implementing a comprehensive security awareness programme at Nedbank over the past 8 years. Cyberpsychology, understanding human behaviour and the role mindfulness plays in securing organisations and the community is a topic she is deeply passionate about.\nChristine is Project Management Professional (PMP) certified and holds her Security Awareness Professional (SSAP) certification through the SANS Institute.", "public_name": "Christine Gordon-Bennett", "guid": "af19bfed-e042-5597-9b05-b71d457b4c25", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/PHQJN3/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/RYA3LS/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/RYA3LS/", "attachments": []}, {"guid": "cd3701eb-4569-59b4-8474-ad8e8ef8866a", "code": "BNAFAV", "id": 55696, "logo": null, "date": "2024-12-07T10:30:00+02:00", "start": "10:30", "end": "2024-12-07T11:15:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-55696-ignorantia-juris-non-excusat-understanding-the-impact-of-the-law-on-the-sa-hacker-community", "url": "https://pretalx.com/bsides-cape-town-2024/talk/BNAFAV/", "title": "Ignorantia Juris Non Excusat - Understanding the Impact of the Law on the SA Hacker Community", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Many cybersecurity researchers and ethical hackers are becoming the target of criminal prosecutions and litigation, essentially for trying to do the right thing, and acting in an ethical manner. The reality is that cybersecurity researchers, practitioners and ethical hackers do run the risk of running afoul of both criminal and civil law in South Africa. This talk will explore the various laws and legal actions that could impact on them, and how to work within the framework of the law in South Africa, and essentially keep them safe from legal harm.", "description": "The talk will cover the various activities that cybersecurity researchers, practitioners and ethical hackers undertake, and explore the various legal issues that may impact on these activities. The focus of the talk is to educate the community of how our actions can inadvertently break the law or leave us open to litigation, simply for trying to make the world a safer place.\n\nThe talk will start with an introduction highlighting some case studies from around the world and then looking at the South African situation and how we expose ourselves to risks.\n\nI will then look at the various statutes, common law offences, and civil causes of action that can be used against us and the consequences of these. I will discuss the aspects of these in way will be understandable to a technical audience using practical examples.\n\nI will then discuss ways in which we can perform our activities in a manner that will insulate us from legal action in both the criminal and civil sphere, as well as what to do if we ever find ourselves on the wrong side of the law for doing something ethical.\n\nOne thing that I will also discuss is the upcoming Cybersecurity Bill that the SA Government is pushing forward.", "recording_license": "", "do_not_record": false, "persons": [{"code": "CHUWTE", "name": "Jason Jordaan", "avatar": "https://pretalx.com/media/avatars/CHUWTE_VP5WlkE.webp", "biography": "Jason Jordaan is leading digital forensics, incident response, and cybercrime investigation specialist. He has been acknowledged in as an expert witness in the High Court of South Africa. He began his digital forensics career in the early days of the development of the digital forensics discipline when he combined his love for computers and technology with his role as a police detective. He served as a detective with the South African Police Service Commercial Branch, before moving to the Special Investigating Unit, where he established their digital forensics laboratory. In 2014, after being instrumental in multiple high-profile investigations over 23 years of service, he resigned from his position as National Head of Cyberforensics to establish DFIRLABS. As the founder and Principal Forensic Analyst of DFIRLABS, Jason leads the practice, and continues to conduct high-level digital forensics engagements throughout the globe. \nJason is also an active academic, researcher, author, speaker, advisor, and trainer. He is a member of the faculty of the SANS Technology Institute. He teaches digital forensics, and is a course author, for the SANS Institute, and has taught digital forensics to some of the leading law enforcement agencies, intelligence services, and military units in the world, including the FBI, US Secret Service, London Metropolitan Police, UK National Crime Agency, US Special Operations Command, Australian Air Force, the German Army, and more. He is actively involved in mentoring law enforcement digital forensic practitioners as a member of IACIS. His author has been published in several peer reviewed journals, with his recent research focusing on quality assurance in digital forensics. Jason is also a co-author and contributing author to several books. He is a member of the Advisory Board for the University of Pretoria, the SANS Institute, and served as an advisor to the South African Deputy Minister of Justice for the development of the South African Cyber Crime Act. Jason is also an assessor for the Netherlands Register of Court Experts, where he is responsible for assessing the competence of digital forensic experts for the purposes of testifying in Dutch criminal trials.\nJason holds a MSc degree in Computer Science (Cum Laude), a MTech degree in Forensic Investigation, a BComHons degree in Information Systems, a BSc degree in Criminal Justice Computer Science (Summa Cum Laude), and a BTech degree in Policing. He is a member of several professional bodies and hold the following certifications and post-nominals: CFCE, CFE, MCSFS, PMIITPSA, FP (SA), and M.INST.D(SA). He also holds the following GIAC certifications: GBFA, GCFE, GCFA, GCIH, and GCCC.", "public_name": "Jason Jordaan", "guid": "a04d5d66-9c86-5d3c-b94c-c7ffdbde0771", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/CHUWTE/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/BNAFAV/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/BNAFAV/", "attachments": [{"title": "Profile Pic", "url": "/media/bsides-cape-town-2024/submissions/BNAFAV/resources/Jason21c_5Jun21_Web_2UYm6Ps.jpg", "type": "related"}, {"title": "Short Bio", "url": "/media/bsides-cape-town-2024/submissions/BNAFAV/resources/Short_BioJason_Jordaan_suchqkZ.docx", "type": "related"}]}, {"guid": "0864c712-c15b-58f2-b673-83e9c29540e8", "code": "N83V7V", "id": 54802, "logo": "https://pretalx.com/media/bsides-cape-town-2024/submissions/N83V7V/DevOps_or_DevO_8O7YMFU.png", "date": "2024-12-07T11:30:00+02:00", "start": "11:30", "end": "2024-12-07T12:15:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-54802-devops-or-devoops-securing-a-pipeline-without-losing-your-mind", "url": "https://pretalx.com/bsides-cape-town-2024/talk/N83V7V/", "title": "DevOps or DevOops? Securing a Pipeline Without Losing Your Mind", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "This talk will follow a light-hearted take on the mistakes and solutions I had while setting up a Gitlab to Jenkins to Tomcat CICD pipeline this year. Many of the configurations were insecure by default and when approached a mentality of \"Make it work\" it just compounds the issue. The talk will go through each stage of the pipeline, the issues I found, the issues I caused and the solutions for both.", "description": "Introduction:\n\nThe introduction will paint a background of how this talk came about and the components in the pipeline. The idea is that Source Code from Gitlab sends a webhook on merge to Jenkins. Jenkins then pulls the code and builds it, then deploys it to the Tomcat web server. Tomcat itself is hosted on localhost port 8080 which is served to the internet using an NGINX reverse proxy. If that sounds like a whole lot of technical gibberish, don't worry we'll understand it by the end of the talk.\n\nGitlab:\n\nGitlab is a source code repository on Linux, much like GitHub it can store your code and your code changes. However, by default it has a few problems. For example anyone can register on the application. We'll look into some of these common problems as well as common mistakes that I made while configuring a repository. Even though Jenkins is only meant to be exposed internally, that doesn't mean that everyone internally should see your typos in your commit messages.\n\nSome of the misconfigurations I made included the creation of a public repo, being able to create and accept my own merge requests and allowing developers to see information. So by the time I had a working pipeline, anyone with access could compromise each host in the pipeline.\n\n\nJenkins:\n\nJenkins is a automation server which in my pipeline is used to build and deploy code from Gitlab to web servers (in the case of this example). It is basically RCE as a feature with a few added security issues on top. One of my favourites was creating a webhook that had my Jenkins Admin creds in it. We'll look at what attack paths exist in Jenkins and against Jenkins and build it back to the access an might have have with Gitlab.\n\nApart from embedding my credentials into a webhook I also had to work out ways to move code from the build agent to the web server. This started with some very bad ideas, like python simple server, and ended up with ssh.\n\nDeployments:\n\nFinally with deployments, I'll give a brief overview of the pain I experienced with trying to get Tomcat working in the first place, but then we'll go through some attacks that work and are fairly under the radar if you can deploy malicious code to production. We will also tackle the problem of how you block client-side code from calling out to a specific domain.\n\nSome interesting things here is that any Javascript I've written for key logging, information stealing, and the works are never detected by any controls. Especially with attacks like dependency confusion attacks: How do you block a domain client-side if you can't necessarily remove the malware yourself?\n\n\nConclusions:\n\nFor the conclusions we'll take a look at where the network started, and the amount of issues it had (Security and others). Then compare it to where the network ended and how non-intuitive the fixes were. To end off, the attacks will be mapped back to a DevOps pipeline to see what type of risks each stage of the pipeline could introduce.", "recording_license": "", "do_not_record": false, "persons": [{"code": "HHDF3D", "name": "Jonathon Everatt", "avatar": "https://pretalx.com/media/avatars/HHDF3D_yYXJysS.webp", "biography": "I'm a technically inclined ocean enthusiast who looks forward to the day I can play video games on my surfboard. And then probably also try hack said surfboard.", "public_name": "Jonathon Everatt", "guid": "22b34c0f-df8a-5470-9173-22d477869c32", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/HHDF3D/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/N83V7V/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/N83V7V/", "attachments": []}, {"guid": "9f61503f-cdc4-5aca-b836-bc7aa56a97f5", "code": "MLQWTA", "id": 54758, "logo": null, "date": "2024-12-07T13:15:00+02:00", "start": "13:15", "end": "2024-12-07T14:00:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-54758-attack-of-the-clones-modern-deepfake-phishing", "url": "https://pretalx.com/bsides-cape-town-2024/talk/MLQWTA/", "title": "Attack of the clones: Modern deepfake phishing", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Recent trends have shown that the next evolution in phishing is the abuse of AI tooling to create realistic and believable deepfake clones. Organisational resilience against deepfake phishing is drastically behind the curve.\n\nIn this talk, we will investigate the state of the art, present case studies of actual deepfake attacks, examine the practical feasibility and ease of execution of these kinds of attacks as well as possible solutions to these problems.", "description": "1. Introduction to the current state of the art\n- An overview of what attackers are capable of with current techniques and technology (AI specific)\n- Case studies of specific incidents where deepfake phishing has been abused successfully\n\n2. Technical Overview\n- Detailed overview of how an attacker could accomplish same results\n--Specific attention to whether it is possible without extensive training data\n\n3. Demonstration\n- Recorded demonstrations of all of the above\n- (Hardware Permitting) Live demonstration of an audience member made to look like one of the authors\n\n4. Remediation\n- Possible Social, Corporate and Technical solutions to fight this issue\n- Tools and techniques for detection\n\nTakeaways\n\n- Understanding the current state of the art:\n    * Attendees will gain a solid understanding of the current capabilities of deepfakes and AI models.\n- Identifying and Mitigating Risks:\n    * Participants will learn how to identify these kinds of threat actors. \n    * Participants will gain an understanding of what technical and organisational controls can be used to mitigate such threats", "recording_license": "", "do_not_record": false, "persons": [{"code": "QD7VCV", "name": "Johan VD Merwe", "avatar": "https://pretalx.com/media/avatars/QD7VCV_qf1NTkX.webp", "biography": "I am a computer engineering graduate who joined MWR CyberSec in 2021 to dedicate myself to supporting and assisting people in becoming more secure. I have a particular fascination with artificial intelligence (specifically generative AI) that has led me to this intersection of security and machine learning. I have an inquisitive nature and love to question the security implications of emerging technologies.", "public_name": "Johan VD Merwe", "guid": "bab040d4-8d7e-5727-a94b-493f01ef8fe3", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/QD7VCV/"}, {"code": "SBBJ9N", "name": "Jacob Simmons", "avatar": "https://pretalx.com/media/avatars/SBBJ9N_91SkiRZ.webp", "biography": "Cybersecurity consultant at MWR CyberSec", "public_name": "Jacob Simmons", "guid": "447e91fd-bed9-597a-95c4-d00842da8fac", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/SBBJ9N/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/MLQWTA/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/MLQWTA/", "attachments": []}, {"guid": "b7ce1054-b060-58c1-9329-7132c9195992", "code": "SM333W", "id": 56507, "logo": null, "date": "2024-12-07T14:10:00+02:00", "start": "14:10", "end": "2024-12-07T14:55:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-56507-cloud-security-theater-rising-above-the-noise-of-misguided-strategies", "url": "https://pretalx.com/bsides-cape-town-2024/talk/SM333W/", "title": "Cloud Security Theater: Rising above the noise of misguided strategies", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "To secure cloud environments effectively, a modern operating model needs to be created to solve the real security challenges faced during cloud adoption. However, are security teams focusing on the right problems when it comes to cloud security or we are just doing Cloud Security Theater?", "description": "Cloud adoption is booming, with many organizations migrating to the cloud for cost efficiency, scalability and agility. This shift requires a critical review of traditional IT operating models and the cybersecurity controls that go along with it. However, many organizations are struggling to operationalize cloud effectively which often leads to unmitigated risks and an over reliance on technology when it comes to securing their cloud environments.\n\nIn this talk, I will share my learnings around the common missteps and pitfalls that organizations make securing their cloud environment. The first part of my talk will focus on background including:\n* A high level overview of why people adopt cloud\n* The mind set change that needs to occur when using cloud\n* The change of ownership and responsibility in cloud environments\n\nThe second part of my talk will focus on highlighting the problems and missteps that we see organizations make. This includes:\n* The problems with relying on compliance frameworks\n* Tackling the nuances in multi-account environments\n* Understanding attack vectors and paths\n* Baseline controls including Guard Rails, Network Security & IAM\n* Regulatory Compliance Gaps\n* Automation Fallacies\n* Products and services not fit for cloud\n\nThe third and final part of my talk will focus on sharing ideas for strategies and approaches that organizations should consider.", "recording_license": "", "do_not_record": false, "persons": [{"code": "NC8LQU", "name": "Jared Naude", "avatar": "https://pretalx.com/media/avatars/NC8LQU_07o4jYI.webp", "biography": "Jared is the Head of Security at Synthesis, where he specializes in enterprise cloud architecture. Jared is passionate and deeply committed to guiding large organizations through the complexities of architecting, securing and operationalizing enterprise cloud environments. Beyond Jared\u2019s professional responsibilities, Jared is an enthusiastic advocate for community building, serving as the organizer of several local security events, including 0xcon, BSides Cape Town, and BSides Joburg. Jared\u2019s research focuses on cybersecurity topics that intersect with national security and foreign policy issues such as encryption, privacy, surveillance, disinformation, and nation-state activity.", "public_name": "Jared Naude", "guid": "e6f21261-d4f1-5305-954d-f40752d9fc9b", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/NC8LQU/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/SM333W/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/SM333W/", "attachments": []}, {"guid": "4a6fb1a5-de1d-5a87-a278-bfef3327d31c", "code": "YMABRP", "id": 55110, "logo": null, "date": "2024-12-07T15:05:00+02:00", "start": "15:05", "end": "2024-12-07T15:35:00+02:00", "duration": "00:30", "room": "Track 1", "slug": "bsides-cape-town-2024-55110-attacking-graphql-a-guide-for-penetration-testers", "url": "https://pretalx.com/bsides-cape-town-2024/talk/YMABRP/", "title": "Attacking GraphQL : A guide for penetration testers", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "Whats GraphQL? How do pwn it? And what do I write in my pentest report if I get this in a test? If these questions get your heart racing, fret not, this stalk is for you!\n\nGraphQL is at minimum, yet another API technology your company can get horribly wrong. The technology has grown considerably has an API interface technology in the last few years. With the growing interest, security engineering has been a keen focus for deployments because the technology is new, promises a lot (i.e. strict data typing, query batching and nesting, rapid adaptability etc.) and may not deliver the same impact in all environments or use cases. Futhermore, in the contemporary landscape there are a number of services, and open source projects that make this accessible each with their own set of complexities and pitfalls.  With all these new fangled environments, a novel query language, and wildly variable backends, pentesters and security engineers need a good overview in order to navigate a security assessment or deployment. The talk here aims to provide guidance to pentesters in navigating these environments, using the open source and free tooling on offer and delivering a good quality penetration test against GraphQL environments.", "description": "GraphQL was released and developed at Facebook just under 10 years ago, but has only really seen a surge in public interest over the latest 5 years of its life. Being adopted by the likes of Amazon AWS, Microsoft and IBM as well as many more big names. GraphQL grew rapidly due to its proactive approach to many problematic aspects of API deployment and design, namely: Data typing, Query formatting, Data Source independence and many others.\n\nAlthough providing a myriad of technological improvements deployments still suffer from common vulnerabilities and misconfigurations. Whats more beyond the vulnerabilities which stem from common misconfigurations, many security problems also source from complex integrations between traditional API tech (like REST, SOAP etc). In an effort to help users be aware of these problems the talk here will walk through many of the scenarios that may introduce vulnerability as well as ways they can avoid incurring more risk.\n\nIn this talk, the speaker will talk through:\n(i) The recent history of GraphQL, its adoption rate, the innovations and APIs that currently make use of this tech.\n(ii) Common GraphQL setups and projects (what to expect in the wild)\n(iii) How to threat model a GraphQL deployment, where to expect things to go wrong.\n(iv) A detailed enumeration of common issues like Query batching, nesting, incorrect usage of the typing system and other problems - some of which will be supported by real world examples.\n(v) Exploitation patterns and tools that will enhance a penetration testers ability to assess and exploit vulnerabilities mentioned in the talk.", "recording_license": "", "do_not_record": false, "persons": [{"code": "AHTHZZ", "name": "Keith Makan", "avatar": "https://pretalx.com/media/avatars/AHTHZZ_uOq1IWN.webp", "biography": null, "public_name": "Keith Makan", "guid": "ded6f1b6-7fae-5f5a-b290-a7c33a7c2b6a", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/AHTHZZ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/YMABRP/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/YMABRP/", "attachments": []}, {"guid": "f48d8118-36ab-5543-a503-c4d1e8266981", "code": "PHMBBP", "id": 56556, "logo": null, "date": "2024-12-07T15:35:00+02:00", "start": "15:35", "end": "2024-12-07T15:50:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-cape-town-2024-56556-find-and-fix-vulnerabilities-within-open-source-projects", "url": "https://pretalx.com/bsides-cape-town-2024/talk/PHMBBP/", "title": "Find and fix Vulnerabilities within open source projects", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "It's actually pretty easy to find and fix vulnerabilities within open-source projects. With the right tools and techniques, identifying security flaws and patching them can be a straightforward process. \n\nIn this talk, we\u2019ll explore practical methods to detect vulnerabilities, from automated scanning to manual code review, and guide you through the steps to address them effectively. \n\nWhether you\u2019re a seasoned developer or new to open source, you\u2019ll learn how to contribute to making projects more secure. \n\nLet's commit to securing open-source code\u2014starting today, with your next pull request!", "description": "In this talk, I will provide a brief but comprehensive introduction on how to find and fix vulnerabilities in open-source projects.\n\nWe'll explore not only the techniques for identifying and addressing security flaws but also how anyone\u2014regardless of experience\u2014can contribute to improving open-source software. \n\nWhether you're scanning for vulnerabilities, submitting patches, or helping with code reviews, you'll discover practical ways to get involved and make a meaningful impact in the open-source community.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZPZTZT", "name": "Callian Berends", "avatar": "https://pretalx.com/media/avatars/ZPZTZT_S7hWFEE.webp", "biography": "I'm Callian, also known as Kallie, a dedicated DevSecOps Engineer with a development background and are passionate about application security. \n\nMy journey is fueled by an enduring curiosity and a passion for embracing new challenges that foster both personal and professional growth. \n\nAs the leader of the DevSecCon Cape Town Community, I assist in bringing together developers, operations teams, and security practitioners to collaborate, share knowledge, and shape the future of secure development", "public_name": "Callian Berends", "guid": "3046f029-b137-5f30-94b0-338423de011a", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/ZPZTZT/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/PHMBBP/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/PHMBBP/", "attachments": []}, {"guid": "5488867e-238c-5ba7-a90e-8ead45f9b35a", "code": "SZU8GJ", "id": 56343, "logo": null, "date": "2024-12-07T16:00:00+02:00", "start": "16:00", "end": "2024-12-07T16:15:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-cape-town-2024-56343-going-beyond-your-own-barriers", "url": "https://pretalx.com/bsides-cape-town-2024/talk/SZU8GJ/", "title": "Going Beyond your own Barriers", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "How do you recognise your own barriers and things that are holding you back? And more importantly, once you know those barriers, how are you able to overcome them?", "description": "For my talk, I'd like to identify the most common things people face when trying to progress. I have helped and coached many people, and want to share what I have seen and learnt to a wider audience. My talk will include:\n- Barriers to getting into Cyber - where to start?\n- Barriers related to Job Posts/Spec - Unreasonable expectations\n- Are certifications a Barrier/Are certifications needed upfront?\n- Human barriers, such as neuro diversity and imposter syndrome\n- Emotional Barriers - Are your emotions keeping you back\n- Skills barrier (related to certifications above)\n\nAnd while discussing this, will be providing some experiences I have had and tips and tricks from talking to people and coaching others in this industry.\n\n These are all subjects I am passionate about and things that I would like to pass on to the next generation of hackers. This talk isn't aimed at those who are established, but for the students and newcomers to BSides who may be wondering how to make the next career move.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MNNNNS", "name": "Roberto Arico", "avatar": "https://pretalx.com/media/avatars/MNNNNS_ZJis8NR.webp", "biography": "Just a guy who likes talking about Cybersecurity and believes in helping others and building a strong cyber tribe.", "public_name": "Roberto Arico", "guid": "5f6f4a6d-7270-5673-8e19-b4d56a2492f6", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/MNNNNS/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/SZU8GJ/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/SZU8GJ/", "attachments": []}, {"guid": "86b56388-3a0e-5140-ab34-8c45a5ad6029", "code": "GHTA9V", "id": 55863, "logo": null, "date": "2024-12-07T16:15:00+02:00", "start": "16:15", "end": "2024-12-07T16:30:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-cape-town-2024-55863-rite-of-passage-my-journey-from-bsides-volunteer-to-black-hat-asia-attendee", "url": "https://pretalx.com/bsides-cape-town-2024/talk/GHTA9V/", "title": "Rite of Passage: My Journey from BSides Volunteer to Black Hat Asia Attendee", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "From volunteering at BSides Cape Town to being sponsored to attend Black Hat Asia, I\u2019ll share my unexpected journey and the power of community involvement in shaping my career in cybersecurity. Through this talk, I aim to inspire students to take that first step into getting involved with the cybersecurity community.", "description": "In 2023, I volunteered at BSides Cape Town as a way to immerse myself in the cybersecurity community. What I didn\u2019t anticipate was that my involvement would lead to an incredible opportunity: being selected for the Rite of Passage Initiative and getting sponsored to attend Black Hat Asia 2024. This talk will take attendees on a journey from my beginnings as a volunteer to attending one of the most prestigious cybersecurity conferences in the world. I\u2019ll reflect on my personal experiences, the invaluable lessons I learned, and the connections I made, all of which have had a profound impact on my career and personal growth.\n\nDuring the talk, I will cover:\n\n1. Volunteering at BSides Cape Town 2023: How volunteering introduced me to the wider cybersecurity community, and why this experience was so transformative.\n2. The Rite of Passage Initiative: What this initiative is and how it provides opportunities for students passionate about cybersecurity. I\u2019ll share my own experience of being selected and how that set the stage for my trip to Black Hat Asia.\n3. Black Hat Asia 2024: I\u2019ll highlight key moments from my experience at the conference\u2014everything from the talks I attended to the incredible people I met from across the globe. \n4. The Value of Community: I\u2019ll dive into how community involvement\u2014through volunteering and attending conferences\u2014has been instrumental in my career growth. Whether it's learning new skills, networking with professionals, or simply gaining exposure to the global cybersecurity scene, I\u2019ll emphasize the power of being part of a supportive community.\n5. Encouraging Students: The heart of this talk is to inspire students and young professionals to get involved in their local cybersecurity communities. I\u2019ll share actionable advice on how they can volunteer, apply for scholarships, and make connections that could change the trajectory of their careers.", "recording_license": "", "do_not_record": false, "persons": [{"code": "WAGZYE", "name": "Blessing Mufaro Kashava", "avatar": "https://pretalx.com/media/avatars/WAGZYE_RVwRkIo.webp", "biography": "Blessing is a cybersecurity consultant by day and a community-builder by night. As a recent Information Security graduate, Blessing now works with BDO Zimbabwe, navigating the complex world of cybersecurity risks as a penetration tester. A passionate advocate for all things cyber, Blessing is the founder of the Evolve Cybersecurity Club, where students transform from curious learners to security-savvy professionals.\n\nWhen not dissecting vulnerabilities, you can find Blessing volunteering at BSides conferences, picking locks (in Capture the Flag games, of course), or playing RPGs to save virtual worlds. A serial volunteer and two-time Black Hat Asia & USA 2024 student scholarship recipient, Blessing is always on a quest for new knowledge, community connections, and the next sitcom to binge-watch.", "public_name": "Blessing Mufaro Kashava", "guid": "67f9576d-de73-57c2-804a-3ebba9b6cdc7", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/WAGZYE/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/GHTA9V/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/GHTA9V/", "attachments": []}, {"guid": "1e105a0a-03d5-5f3d-bcbd-5032addbba21", "code": "QC8SGL", "id": 56236, "logo": null, "date": "2024-12-07T16:40:00+02:00", "start": "16:40", "end": "2024-12-07T17:25:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-cape-town-2024-56236-ai-in-osint-zero-snake-oil", "url": "https://pretalx.com/bsides-cape-town-2024/talk/QC8SGL/", "title": "AI in OSINT - Zero snake oil", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "In this blink-and-you'll-miss-it talk we cut all the introductions and waffle and, just like this abstract, get straight to the point :) Can we use AI in OSINT? Spoiler - yes and its pretty magical. We'll show, on screen, how AI helped solved real(ish) world cases. That's it.", "description": "In the talk, I'll demo how we've build software that uses RAG AI to create an assistant that you can query about (deep, eg post authentication) web pages. I will show how the software works and then I will show results that were interesting. \n\nI'll end the talk with my predictions on how AI will impact OSINT in the near future.", "recording_license": "", "do_not_record": false, "persons": [{"code": "CHEDEA", "name": "Roelof Temmingh", "avatar": "https://pretalx.com/media/avatars/CHEDEA_WUiaQpq.webp", "biography": "Urgh, bios. Three things you don't know about me - 1) I wrote super emo poetry in the late 90s and an industrial/metal band used it as lyrics on one of their songs. 2) I have a real NSA challenge coin 3) I drove a yellow VW beetle in 1992.\n\nFor reals tho - https://www.osint-tool.com/conferences-talks-workshops/", "public_name": "Roelof Temmingh", "guid": "a7242728-4bcc-5399-9aff-a39466addb56", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/CHEDEA/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/QC8SGL/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/QC8SGL/", "attachments": []}], "Track 2": [{"guid": "857e89b1-6d98-5a23-9f93-1156bb09e47e", "code": "H9YVRY", "id": 56394, "logo": null, "date": "2024-12-07T10:30:00+02:00", "start": "10:30", "end": "2024-12-07T11:15:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-56394-breaking-the-barrier-exploring-modern-wafs", "url": "https://pretalx.com/bsides-cape-town-2024/talk/H9YVRY/", "title": "Breaking the Barrier: Exploring modern WAFs.", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "In an era where web threats evolve as quickly as the technologies we deploy, the temptation to rely on Web Application Firewalls (WAFs) to mitigate holes in a web application's security is high. But how effective are these digital shields? Could they be more prone to error than we think? This talk will uncover the gaps within our WAF defenses, examining a variety of WAF bypass techniques, both complex and simple. By showcasing these potential weaknesses, we can get a better understanding of the state of modern WAFs so that teams know what to expect when choosing to fall back on WAFs for \"protection\".", "description": "**Introduction**:\nThe introduction will start with a brief overview of my background and experience in cybersecurity, setting the stage for the discussion to come by giving a high-level overview of Web Application Firewalls. During the WAF overview, the talk will focus on why WAFs don't remediate security vulnerabilities and instead mitigate them. I will give some well known examples and set out the expectation that WAFs are generally expected to cover the OWASP Top 10.\n\n**Understanding WAFs**:\nIn this section, I will introduce the audience to the fundamental aspects of Web Application Firewalls (WAFs), by exploring their architecture and the roles they play in protecting web applications and simply what makes a WAF a WAF. We will discuss how the WAFs are designed to filter and monitor HTTP traffic between a web application and the internet. By understanding the general purpose of WAFs and where we usually find them, we can see how they fit into a broader security environment. I will also go into some security overlaps that exist when choosing a WAF not developed with an organisation's custom implementations (eg: Custom Cryptography, Custom Querying Syntax) in mind, and how this can defeat the purpose of having a WAF.\n\n**WAFs In Modern Times**:\nIt is essential to understand what makes a modern WAF and the key features and improvements that set apart older WAFs from modern ones. I will run through what modern WAFs are expected to cover in contrast to what older and deprecated WAFs cover. We will look at the historical development of WAFs and what evolution WAFs have gone through to get to where they are today. I will also briefly highlight the great value of having a WAF be open-source and the developmental benefits that unlocks through community-driven development.\n\n**The Good**:\nTo start off we will focus on what WAF's generally do well and what expectations we can have for them. We see how WAFs react when given payloads from some common vulnerabilities listed in the OWASP Top 10 and give a high-level overview of how specific payloads are detected. The discussion will include points about what parts of the payload are detected and because of this the audience will better understand why we obfuscate the parts of payloads that we do, in order to get a working bypass.\n\n**The Oopsies**:\nIn contrast to the above section we will focus on modifying the payloads attempted in the previous section, based on the aspects of a payload that were detected. Furthermore we will look at exactly what changes were made to payloads and why those payloads might have worked. This leads to a better understanding as to how bypasses are developed and gives a rough methodology that we can follow when approaching the creation of WAF bypasses.\n\n**Learning from Bypasses**:\nThis section will focus on how we can learn from the bypasses discussed in the previous section and expand on the rough methodology in order to transform it into a more concrete methodology that we can practically use. The methodology will focus on 3 aspects:\n- Identify -- the specific keywords blocked by a WAF\n- Obfuscate -- the keywords in various manners\n- Test -- the obfuscated payloads\n\n**In Denial**:\nIt is also necessary for us to talk about how WAFs are used to mitigate vulnerabilities and why this has the potential to create an illusion of security. This will also highlight the importance of root cause remediations in place of WAFs while still acknowledging the improvement to the overall security posture of a web application that a WAF can provide.\n\n**Takeaways**:\nIn this final section we will go over and summarise the high-level key points discussed during the talk and how each key point can be applied in the real world:\n- What makes a WAF; a WAF\n- How WAFs should be approached by red/blue teams\n- The importance of remedial actions", "recording_license": "", "do_not_record": false, "persons": [{"code": "AKPENR", "name": "Ethan Havinga", "avatar": "https://pretalx.com/media/avatars/AKPENR_9DqDbPr.webp", "biography": "My name is Ethan Havinga, I recently finished high school and was lucky enough to join an internship at MWR CyberSec where I now work fulltime as a Cybersecurity Consultant with a focus in the web application security space. \n\nI enjoy delving deep into obscure and often overlooked topics, I find that you often find the coolest things in the topics people tend to miss. In my free time I am somewhat of a reader, and enjoy the odd book on historical texts specifically that of religious philosophy.", "public_name": "Ethan Havinga", "guid": "ffb5d31f-9650-5bcc-a583-987a6b8a74b6", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/AKPENR/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/H9YVRY/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/H9YVRY/", "attachments": []}, {"guid": "1c5ed8d0-97d3-5a52-a51c-153997dbcefb", "code": "QUQJME", "id": 54915, "logo": null, "date": "2024-12-07T11:30:00+02:00", "start": "11:30", "end": "2024-12-07T12:15:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-54915-unmasking-the-digital-shadows-osint-techniques-for-cybersecurity-professionals", "url": "https://pretalx.com/bsides-cape-town-2024/talk/QUQJME/", "title": "Unmasking the Digital Shadows: OSINT Techniques for Cybersecurity Professionals", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "The cyber threat landscape is becoming increasingly complex and sophisticated. Cybersecurity professionals are constantly challenged to stay ahead of attackers who exploit the anonymity of the internet to carry out malicious activities. Open Source Intelligence (OSINT) has emerged as a powerful tool in the cybersecurity arsenal, enabling professionals to uncover hidden threats, track malicious actors, and safeguard sensitive information.", "description": "Objective: The primary objective of this keynote is to equip cybersecurity professionals with the basic OSINT techniques that can be used to enhance their threat detection, investigation, and mitigation capabilities. Attendees will gain insights into how OSINT can be leveraged to unmask digital shadows\u2014those elusive and often hidden elements of the cyber world that pose significant risks to organisations and individuals alike.\n\nKey Takeaways:\n1.\tUnderstanding the Power of OSINT:\no\tExplore the evolution of OSINT and its growing significance in cybersecurity.\no\tLearn about the different types of OSINT sources and tools available to cybersecurity professionals.\no\tUnderstand how OSINT can complement traditional cybersecurity measures.\n2.\tAdvanced OSINT Techniques for Cyber Threat Intelligence:\no\tDiscover innovative methods to gather and analyse OSINT data for threat intelligence.\no\tLearn how to trace the digital footprints of cybercriminals and identify patterns in their activities.\no\tExplore case studies that demonstrate the successful application of OSINT in uncovering and mitigating cyber threats.\n\n\n3.\tUnmasking Anonymity: Techniques to Identify Hidden Actors:\no\tDelve into techniques for de-anonymising online identities and uncovering the real personas behind cyber activities.\no\tUnderstand the role of OSINT in tracking down and profiling threat actors, from lone hackers to organised cybercrime groups.\no\tLearn how to use OSINT to uncover connections between seemingly unrelated cyber incidents.\n4.\tLegal and Ethical Considerations in OSINT:\no\tExplore the legal frameworks governing the use of OSINT in cybersecurity.\no\tDiscuss ethical dilemmas and best practices for conducting OSINT investigations responsibly.\no\tUnderstand the importance of balancing privacy concerns with the need for robust cybersecurity measures.\n5.\tFuture Trends in OSINT and Cybersecurity:\no\tGain insights into emerging trends and technologies that will shape the future of OSINT in cybersecurity.\no\tExplore how AI and machine learning are revolutionizing OSINT techniques.\no\tDiscuss the potential challenges and opportunities that lie ahead for cybersecurity professionals in the OSINT domain.\n\nConclusion: This keynote will empower cybersecurity professionals with the knowledge and skills to effectively utilise OSINT in their daily work. By unmasking the digital shadows, they will be better equipped to protect their organisations, clients, and the wider digital ecosystem from the ever-evolving threats posed by cyber adversaries.\n\nTarget Audience: This keynote is designed for cybersecurity professionals, including threat analysts, investigators, incident responders, and security operations centre (SOC) teams, who are looking to enhance their skill sets with advanced OSINT techniques", "recording_license": "", "do_not_record": false, "persons": [{"code": "N9GADJ", "name": "Sharon Knowles", "avatar": "https://pretalx.com/media/avatars/N9GADJ_gf7tkeK.webp", "biography": "Sharon Knowles, a seasoned cybersecurity professional, OSINT investigator, and keynote speaker with extensive experience in cyber threat intelligence and digital forensics. As the CEO of Da Vinci Forensics, Sharon Knowles has been at the forefront of cybersecurity business innovation and has a proven track record in assisting organisations with their cybersecurity posture. Sharon is a certified Cybercrime investigator,Certified Cybercrime Intelligence Analyst and Certified Cryptocurrency investigator.  When Sharon retires it will be to a farm with donkeys, horses and goats where she will film them and make social media videos for everyone.", "public_name": "Sharon Knowles", "guid": "6d6772d9-c804-5f86-8b22-659c1e9b3cae", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/N9GADJ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/QUQJME/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/QUQJME/", "attachments": []}, {"guid": "f94e6156-eb85-5cc2-a446-ec031886952a", "code": "LBDUWJ", "id": 54651, "logo": null, "date": "2024-12-07T13:15:00+02:00", "start": "13:15", "end": "2024-12-07T14:00:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-54651-dependable-red-teaming-by-using-confusion", "url": "https://pretalx.com/bsides-cape-town-2024/talk/LBDUWJ/", "title": "Dependable Red Teaming by using Confusion", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Dependency Confusion, a DevOps supply chain attack path discovered in 2021, hasn't really gotten the attention that it deserves. This is mainly due to a misunderstanding of how large the attack surface can be. In this talk, we will show how dependency confusion can be exploited to not just attack the pipeline, but covertly gain full access to PROD!", "description": "Dependency Confusion attacks leverage confusion that can be created in a package manager's approach to determining where libraries need to be installed from. Simply knowing the name of an internally-hosted package is sufficient for a threat actor to stage such an attack, which can trick a package manager to install a malicious version of the library from an external repository instead.\n\nWhen this vulnerability was first discovered and published, the author was able to show how they infected companies such as the likes of Apple and Microsoft. However, since then, there hasn't been any real traction from the security community to include testing for this in their methodology. This is largely due to the difficulties in explaining the impact that such a vulnerability can have. A key argument made against the vulnerability's impact is that the risk is mitigated since proper CI/CD pipelines make use of ephemeral build agents meaning the threat actor's package would not have the relevant code to pass unit tests. Thus a compromise here would not really amount to anything serious.\n\nThis got us thinking. What if we could weaponise dependency confusion not to compromise a developer installing package or the build agent, but to actually compromise production? Turns out, this is possible and actually not that hard to achieve! This brings a whole new dynamic for red teams looking to deploy a near-silent but incredibly potent backdoor.\n\nThis talk will be beginner friendly by covering what dependency confusion is but then take it further to show in a live network how dependency confusion can be weaponised to blast its way past both the build and deploy stages and into production, providing a fun new breach to goal execution shortcut for red teams!\n\nThe talk overview is as follows:\n\n1. Introduction to dependency confusion\n2. Why the security community overlooks dependency confusion\n3. Reevaluating the threat of dependency confusion\n4. Weaponising dependency confusion\n5. Mitigation strategies and best practice to prevent and detect dependency confusion\n\nTakeaways:\n\nThose attending this talk will better understand the true impact that dependency confusion can have and how its discovery can be weaponised to showcase this true impact. Equipped with this knowledge, attendees will be able to supplement their testing methodologies and understand how to better protect their organisations from this attack vector.", "recording_license": "", "do_not_record": false, "persons": [{"code": "PDD89G", "name": "Tinus Green", "avatar": "https://pretalx.com/media/avatars/PDD89G_ywHasbM.webp", "biography": "I am the Head of Consultancy at MWR and have a passion for deeply understanding how things work, taking them apart, and sometimes being able to put them back together.", "public_name": "Tinus Green", "guid": "04985167-c634-5976-8eb3-240f8f9b302a", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/PDD89G/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/LBDUWJ/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/LBDUWJ/", "attachments": []}, {"guid": "bf7cb2c2-9373-59f9-811c-6b0ae5ad4016", "code": "K8FETB", "id": 56561, "logo": null, "date": "2024-12-07T14:10:00+02:00", "start": "14:10", "end": "2024-12-07T14:55:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-56561-lolgrid-don-t-bring-your-own-network-one-already-exists", "url": "https://pretalx.com/bsides-cape-town-2024/talk/K8FETB/", "title": "LOLGrid: Don\u2019t bring your own network, one already exists.", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "A fun look at network over powerline systems. The use and abuse of these solutions, what kind of attacks are possible, what are the limits, and how can you defend yourself?", "description": "Sometimes things just need to be looked at differently. \n\nEthernet over power lines (IEEE 1901, Powerline, PowerPlug, you might or might not know it under different names) has been around for quite some time. That being said, while maybe might have heard of it, it seems to be a technology that never took off.\n\nThe technology allows for Ethernet traffic to be routed over alternating current (AC) power lines. This can help avoid clumsy cabling in small flats, or remove the need for long cable runs, providing a neat alternative to running new Ethernet cables. It can also be viewed as an interesting attack vector.\n\nWhile work has been done to stop different power line devices intercepting other devices traffic, allowing multiple networks to be hosted together, this leads to new problems when it comes to securing your own infrastructure.\n\nThe talk will do into some background on the tech (very briefly) to explain its intended purpose and use cases. We will then look at how it can be used as part of attacks/engagements. We will then look at how one can defend against this.\n\nWe will looks at some interesting things I discovered along the way.", "recording_license": "", "do_not_record": false, "persons": [{"code": "JGPCEM", "name": "Brent Shaw", "avatar": "https://pretalx.com/media/avatars/JGPCEM_35mWy4W.webp", "biography": "I am a Cyber Security Researcher working for Nedbank. I'm a big fan of learning and pulling things apart. I have previously given talks on at BSides: \"Securing the Industrial Internet of Things\", \"Hearing the Internet Background Radiation\" and \"Hashing the $#!+ out of firmware\".", "public_name": "Brent Shaw", "guid": "64aed352-9b61-5180-8407-40592fa9b2cb", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/JGPCEM/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/K8FETB/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/K8FETB/", "attachments": []}, {"guid": "e2f94dd4-b776-5304-9b2d-4657d3a6e2fa", "code": "DM7THC", "id": 56513, "logo": null, "date": "2024-12-07T15:05:00+02:00", "start": "15:05", "end": "2024-12-07T15:50:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-56513-attacking-pipelines-large-scale-exploitation-of-workflow-files", "url": "https://pretalx.com/bsides-cape-town-2024/talk/DM7THC/", "title": "Attacking Pipelines: Large Scale Exploitation of Workflow Files", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "In this talk, we present a tool designed to perform large-scale scanning of GitHub repositories to identify potential expression injection vulnerabilities within their workflow files. Our system efficiently scrapes repositories, concurrently pulling and analysing workflow configurations for insecure patterns. Through this mining process, we have discovered that expression injection vulnerabilities are surprisingly prevalent, even among popular projects, and often go unnoticed. We have reached out to affected vendors for remediation and hypothesis this prevalence attributed to a lack of in detection mechanisms and key documentation on GitHub\u2019s end. Additionally, we found that even when vulnerabilities are patched, they can be easily reintroduced by interpolating sanitised values. Our findings underscore the need for better tooling and awareness around securing GitHub workflows. Finally, we make our tool available to open-source for both blue and red team security researchers to benefit from.", "description": "In this talk, we introduce a powerful tool that we developed for performing large-scale scanning of GitHub repositories, aimed at identifying expression injection vulnerabilities within workflow files. The motivation for this project arose from an incident where a client was exploited by a white-hat hacker who leveraged such a vulnerability to patch it through exploitation. This incident highlighted the prevalence and potential severity of expression injection in GitHub workflows, where attackers can inject malicious code through interpolated GitHub variables. This type of vulnerability can lead to the unauthorised exposure of sensitive information, such as the highly privileged `GITHUB_TOKEN`.\n\nOur tool is designed to efficiently scrape repositories, interacting with the GitHub API to concurrently pull and analyse workflow configuration files. By parsing these YAML files and detecting insecure patterns, we were able to uncover a surprising prevalence of expression injection vulnerabilities across a wide range of repositories, including some of the most popular open-source projects. Through the process of continuous mining, our system adheres to GitHub's rate limits, allowing it to run in the background without overwhelming the platform.\n\nA key aspect of our findings is that even when these vulnerabilities are patched, they are often reintroduced through seemingly benign changes, such as interpolating sanitized values back into workflows. This creates a cyclical security risk that many teams may not even realise. We observed that existing mitigations, such as restricting permissions for each step and cautiously using the `env` directive to safely insert GitHub variables, are not prioritised in the documentation and inadequately enforced in real-world projects.\n\nWritten entirely in Scala, our application serves as a robust scanner that not only parses and identifies risky patterns but, allows for an interactive review process of the findings. Through this ongoing effort, we hope to drive awareness around this often-overlooked class of security issues in CI/CD pipelines. Additionally, we have made this tool open-source, allowing both blue team (defensive) and red team (offensive) security researchers to benefit from it.\n\nKey Takeaways:\n\n* Expression injection vulnerabilities in GitHub workflows are more common than previously thought, even in widely used repositories.\n* Attackers can exploit this vulnerability to extract privileged data like the `GITHUB_TOKEN`, leading to further compromise.\n* Patching vulnerabilities is not always enough\u2014reintroductions of sanitised values can recreate the problem.\n* Proper mitigations, such as limiting permissions and safely handling GitHub variables, require more comprehensive documentation and awareness.\n* Our tool, written in Scala, interfaces with the GitHub API and is capable of continuous background mining while adhering to API rate limits.\n* We are open-sourcing this tool to promote better security practices and aid both security researchers and developers in safeguarding their workflows.", "recording_license": "", "do_not_record": false, "persons": [{"code": "VV9TSE", "name": "David Baker Effendi", "avatar": "https://pretalx.com/media/avatars/VV9TSE_MdnE3BY.webp", "biography": "David is the Director of Research & Development at Whirly Labs, specialising in static program analysis. He develops automated tools for vulnerability detection and code exploration, used by both internal teams and external clients, including pentesters and SAST vendors. David has presented his research at leading international conferences like ICSE and ESORICS, and delivered his first BSides CPT talk in 2023.", "public_name": "David Baker Effendi", "guid": "97aececd-effb-5c3e-b39e-a4d4b4354c76", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/VV9TSE/"}, {"code": "HAKKMH", "name": "Rohan Dayaram", "avatar": "https://pretalx.com/media/avatars/HAKKMH_HfC8TZy.webp", "biography": "\ud83d\udd10 Software Developer and Security Professional, merging development expertise with offensive security skills. Transforming a childhood passion for Arduino tinkering into a career in tech innovation and application security.\n\n\ud83d\udcbb Technical Portfolio:\nFull-stack development focusing on secure, scalable solutions\nExtensive experience in Python, C++, C#, and Pascal\nWeb application security and exploitation specialist\nActive CTF competitor and security researcher\n\n\ud83d\udee0\ufe0f Beyond The Code:\nMaker and hardware enthusiast: 3D printing, Fusion 360 design\nElectronics and microcontroller projects\nAutomation engineering and IoT solutions\n\nStarted by copy-pasting Arduino code at age 12, evolved into architecting secure applications and hunting vulnerabilities. This journey from curious tinkerer to security-focused developer shapes my approach to every project: hands-on, creative, and security-first.\nCurrently, securing applications at Whirly Labs while pursuing continuous learning in emerging technologies. Always eager to collaborate on projects that push technical boundaries.", "public_name": "Rohan Dayaram", "guid": "d1f3e349-d58f-5f33-a2fd-03bbc896982a", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/HAKKMH/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/DM7THC/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/DM7THC/", "attachments": []}, {"guid": "5794242c-e325-5be1-a95b-40644ee24cb7", "code": "RGS8JW", "id": 54661, "logo": null, "date": "2024-12-07T16:00:00+02:00", "start": "16:00", "end": "2024-12-07T16:30:00+02:00", "duration": "00:30", "room": "Track 2", "slug": "bsides-cape-town-2024-54661-hacking-the-airwaves-beyond-relay-attacks", "url": "https://pretalx.com/bsides-cape-town-2024/talk/RGS8JW/", "title": "Hacking the Airwaves: Beyond Relay Attacks!", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "This talk will dive into the fundamental concepts of the radio frequency (RF) Relay attack and how it could be used to attack different type of systems that make use of radio communication. The Relay Attack allows an attacker to extend the intended range of communication between two devices, deceiving them into believing that they are in close proximity to one another to perform some type sensitive action, such as unlocking or starting cars, or making payments with PoS devices!", "description": "**Introduction:**\n\nAn introduction of the talk and the topics that are going to be covered. A quick glance into my background and how I got interested in radio frequency hacking. Explaining that the talk is mostly going to be focused diving into the fundamental concepts of the Relay attack and then two demonstrations as to how it could be used to target two completely different systems, namely cars and PoS devices.\n\n**Concept of Relay Attack:**\n\nThis section is going to go through a conceptual explanation of what the relay attack is and how it is used to extend the intended range of communication between two devices, deceiving them into believing that they are in close proximity to one another to perform some sensitive action.\n\n**Using the Relay attack to unlock and start cars:**\n\nThis section will explain how the Relay attack could be used to target automotive keyless entry and keyless start systems on cars. This will include a brief explanation of how keyless entry and keyless start systems work, with security footage showing how criminals execute the attack to steal a victim's car while the key remains locked inside the house (Demo 1). \n\n**How far could you relay signals?**\n\nNow that we understand the fundamentals of the Relay attack, we are going to perform the same attack, but in a different way to illustrate that this attack can be performed over great distances. We are going to attempt to relay signals from Cape Town all the way to Pretoria to unlock a car. An explanation will be given of how the signals are relayed from Cape Town to Pretoria, which will follow a demonstration of the actual proof-of-concept. In-case the proof of concept doesn't work due to the demo gods, we are going to show a video of the PoC working between Johannesburg and Pretoria. (Demo 2)\n\n**How does this work on other systems such as a PoS device?**\n\nAfter going through the automotive security explanation, what would this look like on a different device such as a PoS device? This section will give an explanation of how the attack would work when targeting a PoS device's tap-to-pay to make payments over larger distances. The explanation, followed by a demonstration (Demo 3), is going to show that the PoS device doesn't actually have to be near the victim's credit card to make a payment. As long as the signals are correctly relayed, it could be done over any distance. \n\n**Closing remarks**\n\nThis section will be a quick recap of the topics covered during the talk, with a final reminder that this attack could be executed on anything that makes use of radio signals, such as access control system as well. A final note that I hope this talk has brought some insights to radio frequency hacking and raised some security awareness around the topic.\n\n**Takeaways**\n\nSecurity awareness about the Relay attack and how it could be used on any device that makes use of radio communication.", "recording_license": "", "do_not_record": false, "persons": [{"code": "WVYTXV", "name": "Robin Roodt", "avatar": "https://pretalx.com/media/avatars/WVYTXV_Atl66v4.webp", "biography": "I'm a cyber security consultant at MWR CyberSec where my main focus is Application Security. \n\nI started looking at radio signals in University where I got a lot of exposure while studying BEng Computer Engineering. Taking that knowledge to a security company, I thought to myself \"What happens when we hack these signals flying through the air?\". That kick-started my hobby where I immediately started hacking my mom's car!", "public_name": "Robin Roodt", "guid": "bd9efbf7-c0d1-5234-b951-9c815c162afc", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/WVYTXV/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/RGS8JW/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/RGS8JW/", "attachments": []}, {"guid": "7f96bada-00b6-5935-b953-62558ce51858", "code": "HLNZBU", "id": 54811, "logo": null, "date": "2024-12-07T16:40:00+02:00", "start": "16:40", "end": "2024-12-07T17:25:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-cape-town-2024-54811-speedrunners-the-hackers-of-the-gaming-world", "url": "https://pretalx.com/bsides-cape-town-2024/talk/HLNZBU/", "title": "SpeedRunners: The Hackers of the Gaming World", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Speedrunning, the art of completing games with incredible speed, has evolved into more than a gaming feat\u2014it's a showcase of ingenuity, creativity, and technical prowess. This talk delves into the fascinating world of speedrunners, drawing parallels between their methodologies and those of cybersecurity professionals, while highlighting the significant impact on game development and software security.", "description": "In this talk, we'll dive into the fascinating world of speedrunners and uncover the parallels between their methodologies and the techniques used by cybersecurity professionals. We'll explore how speedrunners discover and exploit glitches in games through a combination of accident, experimentation, and deep code analysis - skills that mirror the vulnerability hunting process in software security.\n\nBy understanding the speedrunner's approach, we'll gain insights into the creative, persistent, and collaborative nature of finding and leveraging system vulnerabilities. This talk will not only fascinate gaming enthusiasts, but also illuminate the mindset of those who push the boundaries of what's possible in both the virtual and digital realms.", "recording_license": "", "do_not_record": false, "persons": [{"code": "PLQGW7", "name": "Nunudzai Mrewa", "avatar": "https://pretalx.com/media/avatars/PLQGW7_ZylFZyT.webp", "biography": "Cybersecurity professional with a knack for securing systems\u2014and breaking them (ethically, of course). Python\u2019s my sidekick for scripting, hacking, and the occasional fun experiment. I'm also a community organizer and public speaker", "public_name": "Nunudzai Mrewa", "guid": "cdf2da36-5a3a-5f60-a29c-59af2d510c0a", "url": "https://pretalx.com/bsides-cape-town-2024/speaker/PLQGW7/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cape-town-2024/talk/HLNZBU/feedback/", "origin_url": "https://pretalx.com/bsides-cape-town-2024/talk/HLNZBU/", "attachments": []}]}}]}}}