BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//chcon-2023//speaker//DGZMSP
BEGIN:VTIMEZONE
TZID:NZST
BEGIN:STANDARD
DTSTART:20000319T040000
RRULE:FREQ=YEARLY;BYDAY=3SU;BYMONTH=3;UNTIL=20070317T150000Z
TZNAME:NZST
TZOFFSETFROM:+1300
TZOFFSETTO:+1200
END:STANDARD
BEGIN:STANDARD
DTSTART:20080406T040000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4
TZNAME:NZST
TZOFFSETFROM:+1300
TZOFFSETTO:+1200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20001001T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=10;UNTIL=20060930T150000Z
TZNAME:NZDT
TZOFFSETFROM:+1200
TZOFFSETTO:+1300
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070930T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=9
TZNAME:NZDT
TZOFFSETFROM:+1200
TZOFFSETTO:+1300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-chcon-2023-3LCTDH@pretalx.com
DTSTART;TZID=NZST:20231124T171500
DTEND;TZID=NZST:20231124T174500
DESCRIPTION:Continuous-integration and continuous-deployment systems. We kn
 ow 'em\, we love 'em. git push\, some magical automation happens\, and BAM
  your code's in the right environment. Glorious.\n\nWhat does this mean fo
 r organisational security though? The days of a surly set of sysadmins hol
 ding the private keys are gone\, and your devs are now also ops. What happ
 ens if a dev is compromised? Scratch that\, what happens if an intern is c
 ompromised!\n\nThis talk is going to walk you through exploiting a modern 
 CI/CD enabled system and show how your latest tranche of Summer-of-Tech in
 terns may just have all the necessary juice to take over... everything! We
 ’ll look at compromising CI/CD infrastructure\, credential harvesting\, 
 lateral movement and compromising the production systems.\n\nBy showing ho
 w to practically loot a CI/CD enabled environment\, we can elucidate the h
 acking voodoo and start some robust discussions around how to keep a moder
 n deployment system safe.
DTSTAMP:20260416T084123Z
LOCATION:Ngaio Marsh Theatre
SUMMARY:OMGCICD - From Intern to Production - Denis Andzakovic
URL:https://pretalx.com/chcon-2023/talk/3LCTDH/
END:VEVENT
END:VCALENDAR
