BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsideslv24//talk//M9BHNE
BEGIN:VTIMEZONE
TZID:PST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T100000Z
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T110000Z
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsideslv24-M9BHNE@pretalx.com
DTSTART;TZID=PST:20240806T150000
DTEND;TZID=PST:20240806T152500
DESCRIPTION:When building software integrations\, developers face important
  decisions that are influenced by time\, budget\, and the technologies the
 y know and sometimes these decisions can lead to security vulnerabilities.
  This talk will look into the reasons developers might choose to run other
  programs directly from their code\, rather than using libraries\, SDKs or
  external APIs\, and the security risks this choice can bring.\n\nWe will 
 explore command injection attacks\, a well-known security issue that remai
 ns a major threat. These attacks happen when our code directly runs other 
 programs\, leading to potential security breaches. Our discussion will cov
 er the basic principles of how programs interact with each other and the t
 ools we can use to understand these interactions.\n\nBy examining a real c
 ase of command injection vulnerability I found (CVE-2023-39059) in a popul
 ar open-source project. We will learn the methods\, tools and techniques f
 or finding and exploiting such vulnerabilities.\n\nFinally\, we will talk 
 about ways to detect and prevent these kinds of attacks. We’ll discuss h
 ow to spot these vulnerabilities and the steps we can take to protect our 
 software.
DTSTAMP:20260722T081753Z
LOCATION:Firenze
SUMMARY:A Quick Story Of Security Pitfalls With Exec Commands In Software I
 ntegrations - Lenin Alevski
URL:https://pretalx.com/bsideslv24/talk/M9BHNE/
END:VEVENT
END:VCALENDAR
