BSides Portland
BSides Portland
  • 113
  • 78 659
BSides PDX 2023 - A Gentle Introduction to Understanding Fuzzers (Allison Naaktgeboren)
Allison Naaktgeboren (www.linkedin.com/in/anaaktge/)
Fuzzing is a popular automated bug finding technique. Frequently Vulnerability Researchers’ tool of choice, it can be confusing and frustrating for newcomers, particularly developers. In this talk, we’ll discuss what fuzzing is (and what it isn’t), its strengths and weaknesses, how to break down the important features of different fuzzers, how those factors influence optimizing a fuzzer, who’s using fuzzers for what purposes, what fuzzers suit the needs of each group, how to pick the fuzzer for your needs. There will be an optional fuzzing lab based on docker. Those interested in the lab should have a GCP account ready for about ~30 minutes of use.
Allison Marie Naaktgeboren is a PhD researcher at Portland State University advised by Dr. Andrew Tolmach. Her research agenda is to make security tools more practical & pragmatic. Or, to atone for all the security sins she committed over the years as a developer at Draper Labs, Signal Sciences, Mozilla, FactSet Research Systems, Amazon, and Cisco. Her current focus is improving the quality & actionability of fuzzer bug reports and expanding fuzzer bug detection beyond memory safety to higher level classes using the PIPE hardware reference monitor. She holds a Masters in Computer Science & Cybersecurity from Portland State and a Bachelor’s Degree in Computer Science from Carnegie Mellon University and is a founder of PSU’s CTF team, the void* vikings.
---
BSides Portland is a tax-exempt charitable 501(c)(3) organization founded with the mission to cultivate the Pacific Northwest information security and hacking community by creating local inclusive opportunities for learning, networking, collaboration, and teaching.
bsidespdx.org
มุมมอง: 126

วีดีโอ

BSides PDX 2023 - From Patch to Shell: Twists & Turns of Exploiting a Hardened Platform (Ron Bowes)
มุมมอง 8211 หลายเดือนก่อน
From Patch to Shell: The Twists and Turns of Exploiting a Hardened Platform Ron Bowes (@iagox86 on every major platform) In July of 2023, SonicWall released an advisory for multiple vulnerabilities in their GMS platform. As security researchers, it’s our job to help the community understand just how bad these vulnerabilities are (spoiler alert: they’re pretty bad). We didn’t realize it at the t...
BSides PDX 2023 - We Have C2 at Home - Leveraging Microsoft’s C2 Framework (Garrett Foster)
มุมมอง 12611 หลายเดือนก่อน
Garrett Foster (@garrfoster on Twitter) For attackers, Microsoft’s enterprise device management software SCCM is a high value target, and a large amount of research has been published over the last year that demonstrates how a site can be taken over. However, identifying the various servers and server roles deployed in an environment to achieve this privilege escalation can be a difficult task....
BSides PDX 2023 - Karl Anderson (Futel.net)
มุมมอง 13111 หลายเดือนก่อน
How And Why To Gain Technological Advantages By Harvesting Entropy From An Unsuspecting Public Karl Anderson (futel.net) To be a successful engineer requires creativity. How can we develop creativity? We can do things outside of our day jobs that help us explore new ideas. What if we aren’t privileged enough to have the capacity for under-paid extra work? We need to find a way to get rewarded f...
BSides PDX 2023 - From Light to Router: Reversing an IoT Smart Switch (Cameron Howell)
มุมมอง 13911 หลายเดือนก่อน
Cameron Howell "This is the story of how I exploited a smart light switch to make it into a malicious router thanks to a hard coded encryption key. I present my journey starting as someone with minimal hardware hacking experience to being able to create open routers from light switches without the owner knowing of the new hole opened up in their network. Oftentimes, to practice hardware hacking...
BSides PDX 2023 - Hacks, Leaks & Revelations: The Art of Analyzing Hacked & Leaked Data (Micah Lee)
มุมมอง 51911 หลายเดือนก่อน
Hacks, Leaks, and Revelations: The Art of Analyzing Hacked and Leaked Data Micah Lee (@micahflee@infosec.exchange on Mastodon. @micahflee.com on Bluesky. @micahflee on Twitter) The world is awash with hacked and leaked datasets from governments, corporations, and extremist groups. In many cases they’re freely available online and waiting for anyone with an internet connection, a laptop, and eno...
BSides PDX 2023 - License to Pwn: How Two Muppets Hacked into a Fortune 500 Company (Mike Stringer)
มุมมอง 22211 หลายเดือนก่อน
License to Pwn: How Two Muppets Hacked into a Fortune 500 Company in under 6 hours Mike Stringer (@script_nomad on Twitter, www.linkedin.com/in/leestringer1/) Despite over 40 years of evolution in the InfoSec industry, it is still possible for even a small team of hackers to compromise the most security-hardened organizations in the world with the right knowledge and a small budget. This talk i...
BSides PDX 2023 - Biking past vendor lock-in (Will Dillon)
มุมมอง 9711 หลายเดือนก่อน
Will Dillon (tech.lgbt/@hpux735) As e-bike manufacturers try to differentiate themselves they’ve turned to cloud- and app-based features. While these features make great press releases, what happens when they go out of business? Are customers left with expensive junk? In the last year, one of the biggest e-bike makers, VanMoof, went out of business. Not only did the industry have to reckon with...
BSides PDX 2023 - So you want to hack AI… (Alex Ivkin)
มุมมอง 14011 หลายเดือนก่อน
As AI and ML become more powerful, so too do the threats to their security. Ever felt curious of what the brave new world of hacking AI/ML is shaping to be? Let me take you on a cruise of what is possible in that space, and what are the state-of-the-art defenses. Alex Ivkin does secure architecture, design and development of software and hardware for an internet search company. Alex has two dec...
BSides PDX 2023 - Improving UEFI Binary Analysis within Ghidra (Brent Holtsclaw)
มุมมอง 13511 หลายเดือนก่อน
UEFI binary analysis has grown in popularity in recent years. As a result, many binary tools have gained native support or plugins. Ghidra gained initial third-party support for UEFI, however, it is currently not up to parity with other tools. This talk introduces a new framework to update UEFI support within Ghidra by improving four distinct areas: preparation of the UEFI image, preparation of...
BSides PDX 2023 - Fun With Zero Knowledge Execution Environments (Dean Pierce)
มุมมอง 12111 หลายเดือนก่อน
Dean Pierce (deanpierce at everything) “Zero Knowledge” is a hot new buzzword, but how are ZK Proofs being practically used today, and what technologies will they unlock in the near future? Dean Pierce is an offensive security researcher in Portland Oregon. BSides Portland is a tax-exempt charitable 501(c)(3) organization founded with the mission to cultivate the Pacific Northwest information s...
BSides PDX 2023 - Building a programming environment for privacy (Lateef Jackson)
มุมมอง 7211 หลายเดือนก่อน
Building a programming environment for privacy and iterative learning Lateef Jackson (@lateefjackson on Twitter, bsd.network/web/@lhj, lateefjackson.com/) Why do cell phones ask for permission when installing an application for access to the internet, yet any software dependency can just access the internet willy-nilly? It doesn’t have to be this way. You will see a working prototype that prior...
BSides PDX 2023 - Engineering Privacy From the Get-Go (Christina Liu)
มุมมอง 3011 หลายเดือนก่อน
BSides PDX 2023 - Engineering Privacy From the Get-Go (Christina Liu)
BSides PDX 2023 - Purple-teaming outbound HTTPS (Anon Hacker)
มุมมอง 7711 หลายเดือนก่อน
BSides PDX 2023 - Purple-teaming outbound HTTPS (Anon Hacker)
BSides PDX 2023 - Following the metadata trail (Guilherme Venere)
มุมมอง 3811 หลายเดือนก่อน
BSides PDX 2023 - Following the metadata trail (Guilherme Venere)
BSides PDX 2023 - Essential Logs Pyramid SIEM (Eric Goldstrom)
มุมมอง 3711 หลายเดือนก่อน
BSides PDX 2023 - Essential Logs Pyramid SIEM (Eric Goldstrom)
BSides PDX 2023 - Using Sigma as a Gateway to Detection Engineering (Micah Babinski)
มุมมอง 13611 หลายเดือนก่อน
BSides PDX 2023 - Using Sigma as a Gateway to Detection Engineering (Micah Babinski)
BSides PDX 2023 - Gone Tishing: Abusing Microsoft Teams (Jessa Gegax)
มุมมอง 14411 หลายเดือนก่อน
BSides PDX 2023 - Gone Tishing: Abusing Microsoft Teams (Jessa Gegax)
BSides PDX 2023 - Securing your Open Source Project (Jose Palafox)
มุมมอง 5311 หลายเดือนก่อน
BSides PDX 2023 - Securing your Open Source Project (Jose Palafox)
BSides PDX 2023 - Take control of your career: A panel with Industry Leaders
มุมมอง 35ปีที่แล้ว
BSides PDX 2023 - Take control of your career: A panel with Industry Leaders
BSides PDX 2023 - Keynote: A Blameless Retro on Security (Kymberlee Price)
มุมมอง 96ปีที่แล้ว
BSides PDX 2023 - Keynote: A Blameless Retro on Security (Kymberlee Price)
BSides PDX 2023 - Saturday Opening Remarks
มุมมอง 23ปีที่แล้ว
BSides PDX 2023 - Saturday Opening Remarks
BSides PDX 2023 - Easy Mode Deception Technology Deployments @ Scale (Sasha Levy)
มุมมอง 67ปีที่แล้ว
BSides PDX 2023 - Easy Mode Deception Technology Deployments @ Scale (Sasha Levy)
BSides PDX 2023 - China Recon 101: Finding Nation State Infra w/ Almost Free Tools (Jonathan Reiter)
มุมมอง 81ปีที่แล้ว
BSides PDX 2023 - China Recon 101: Finding Nation State Infra w/ Almost Free Tools (Jonathan Reiter)
BSides PDX 2023 - LAPSUS$ is winning (Jason Craig)
มุมมอง 186ปีที่แล้ว
BSides PDX 2023 - LAPSUS$ is winning (Jason Craig)
BSides PDX 2023 - Come Together: A framework for a shared security language (Lea Snyder)
มุมมอง 48ปีที่แล้ว
BSides PDX 2023 - Come Together: A framework for a shared security language (Lea Snyder)
BSides PDX 2023 - This Chip Does Not Exist: Pre-Silicon Fuzzing (Rowan Hart)
มุมมอง 158ปีที่แล้ว
BSides PDX 2023 - This Chip Does Not Exist: Pre-Silicon Fuzzing (Rowan Hart)
BSides PDX 2023 - Keynote (Joe Grand)
มุมมอง 361ปีที่แล้ว
BSides PDX 2023 - Keynote (Joe Grand)
BSides PDX 2023 - Opening Remarks
มุมมอง 104ปีที่แล้ว
BSides PDX 2023 - Opening Remarks
Opening Remarks - BSides Portland 2022
มุมมอง 1572 ปีที่แล้ว
Opening Remarks - BSides Portland 2022

ความคิดเห็น

  • @broski40
    @broski40 3 วันที่ผ่านมา

    honestly how hard would it be to make these usb, cables clear? also a pi detector? omg

  • @johnandersen4214
    @johnandersen4214 หลายเดือนก่อน

    AMEN!!!

  • @MrSubielove
    @MrSubielove หลายเดือนก่อน

    so, we buy cables in amazon to replace the one that no longer work. How can we know if the cable is legit and not loaded with any program?

  • @marlinshanklin-ww7em
    @marlinshanklin-ww7em 3 หลายเดือนก่อน

    I'm taking notes excellent information.

  • @thilotech
    @thilotech 4 หลายเดือนก่อน

    Hey, I couldn't find the Twitter of him, does anyone have it?

  • @davidsharpness9990
    @davidsharpness9990 6 หลายเดือนก่อน

    Anton just did a vlog about a bacteria that has been seen with electron microscope making a fractal, just like that pyramids within in a pyramid...here it is a diagram, there it is a protein...and here noted is a game about folded proteins...go figure!

  • @MegaHax
    @MegaHax 8 หลายเดือนก่อน

    I highly recommend the book titled 'Hacks, Leaks, Revelations' to both junior developers and individuals interested in gaining insight into real-world dataset dynamics. The author meticulously curates essential information elucidating how hackers engineer tools and orchestrate strategies to breach law enforcement data. Throughout my engagement with the material, I found myself not merely reading, but actively learning how to utilize bash scripts and implement automation in Python. I strongly urge acquiring this book promptly, as there exists a possibility of its cancellation by the US government

  • @SleepyMarshmallow-nj9su
    @SleepyMarshmallow-nj9su 9 หลายเดือนก่อน

    The event viewer many many events that are populating on my PC with absolutely no networking hardware installed all have some aspects of the event labeled as InputHID. Could this be relevant?

  • @SleepyMarshmallow-nj9su
    @SleepyMarshmallow-nj9su 9 หลายเดือนก่อน

    Are cell phone companies intentionally sending out malicious USB charging cables? More particularly, companies that are US GOVERNMENT CONTRACTS providing ACP/Lifeline cellular service to MILLIONS of unsuspecting, low-income US citizens?? I have a couple of these. My PC starts making software changes to hardware elements like power and system devices EVEN AFTER REMOVING MY WIFI AND BLUETOOTH ADAPTERS COMPLETELY FROM THE INSIDE. (I.E. no external peripherals plugged in at all EXCEPT the USB that I got from SafeLink, then from AirVoice Wireless, not to mention that other company called Excess Telecom. Yeah, all of these companies are seemingly not even located in the US, but are offering free devices under the United States ACP and Federal Lifeline benefits. At this point, I think the damage is irreversible if I'm right at all.) Can I share images of my USB cables anywhere for expert opinion??

    • @benchristian3634
      @benchristian3634 6 หลายเดือนก่อน

      no dude youre schizophrenic the government wouldn't waste money on implants when all your data is at their fingertips

  • @PoRkch0p523
    @PoRkch0p523 11 หลายเดือนก่อน

    😮😮😮

  • @teknojo
    @teknojo 11 หลายเดือนก่อน

    Hack the planet! ...this includes bicycles... The future is weird.

  • @lightsabermario
    @lightsabermario 11 หลายเดือนก่อน

    Confused me a lot when you said that Josh Anderson was "no longer with us" and then later said if you get a chance to meet him, tell him you said hi. I thought you meant he passed away!

  • @JeffGrimes-i1s
    @JeffGrimes-i1s 11 หลายเดือนก่อน

    i think i am in love, j/k, great presentation

  • @rawdod
    @rawdod ปีที่แล้ว

    Rowan Hart is fresh! (I am a bit rotted ;)

  • @mkxto
    @mkxto ปีที่แล้ว

    Very good talk

  • @ClickClack_Bam
    @ClickClack_Bam ปีที่แล้ว

    How about the guy who had the commemorative plaque on his wall that was bugged by the Russians? Averell Harriman, was the U.S. Ambassador to the Soviet Union. The plaque was bugged with a technology that in 1946 was unknown to the US intelligence agencies. The thing was battery-less & ran on radio signals. So when they were wanting to spy they'd come into the area & hit the device with radio signals & it would activate the mic & they'd listen.

  • @YoogmunCyberTech
    @YoogmunCyberTech ปีที่แล้ว

    Hi i am enthusiastic to learn about security did you know how to install or run this Rastrea2r

  • @vishnuvardhan1020
    @vishnuvardhan1020 ปีที่แล้ว

    The best one ❤️❤️❤️

  • @Mtaalas
    @Mtaalas ปีที่แล้ว

    2k views? This should have 20 million.... This is truly scary stuff....

  • @huzifaahmed1426
    @huzifaahmed1426 ปีที่แล้ว

    still worth 💔

  • @huzifaahmed1426
    @huzifaahmed1426 ปีที่แล้ว

    still worth 💔

  • @wandwan1241
    @wandwan1241 ปีที่แล้ว

    this turned my brain into spaghetti with a side of melted cheese....above my comprehension.

  • @montyburns94
    @montyburns94 ปีที่แล้ว

    Is there a circuit diagram of the USB Exposer available anywhere online? Great video, and thanks for sharing!

  • @ghoulism6522
    @ghoulism6522 ปีที่แล้ว

    Great talk

  • @taylorgreen2861
    @taylorgreen2861 ปีที่แล้ว

    Sick tool man, I want it

  • @scottelam9270
    @scottelam9270 2 ปีที่แล้ว

    Really impressive!

  • @c3rb3ru5d3d53c
    @c3rb3ru5d3d53c 2 ปีที่แล้ว

    Awesome talk!

  • @trinitech8660
    @trinitech8660 2 ปีที่แล้ว

    This was exactly what I needed to hear. Congratulation and good luck.

  • @amigosdolimajunior
    @amigosdolimajunior 2 ปีที่แล้ว

    could you list the URLs?

  • @joshuaduplaa9033
    @joshuaduplaa9033 2 ปีที่แล้ว

    Hey I have a question, so how would I go about uploading the firmware to the attiny85? I have programmed an LED program for the tiny through a nano on the arduino IDE, but I don't know much more about programming the tiny than that.

    • @joshuaduplaa9033
      @joshuaduplaa9033 2 ปีที่แล้ว

      I think i found it out, I'm pretty sure i flash the hex file right?

  • @tatyanaragozina3857
    @tatyanaragozina3857 2 ปีที่แล้ว

    Brian Delgado & Tejaswini Vibhute - ABC to XYZ of Writing System Management Mode (SMM) Drivers ОТЛИЧНО

  • @ЮлияДемьяненко-к5у
    @ЮлияДемьяненко-к5у 3 ปีที่แล้ว

    Интересная система, очень информативно

  • @GazakMametdurdyyew
    @GazakMametdurdyyew 3 ปีที่แล้ว

    хороши проект

  • @0xQuito
    @0xQuito 3 ปีที่แล้ว

    this is awesome

  • @ggmaxx66
    @ggmaxx66 3 ปีที่แล้ว

    at 15:15, so that you don't have to type it 3868,3366,8443,8080,9443,9091,3000,8000,5900,8081,6000,10000,8181,3306,5000,4000,8888,5432,15672,9999,161,4044,7077,4040,9000,8089,443,7447,7080,8880,8983,5673,7443

  • @stevenr12
    @stevenr12 3 ปีที่แล้ว

    I really liked your hotel key card analogy, that's going to stick with me.

  • @jamesciccarelli9100
    @jamesciccarelli9100 3 ปีที่แล้ว

    Just wondering

  • @jamesciccarelli9100
    @jamesciccarelli9100 3 ปีที่แล้ว

    If you are a good hacker, could the hacker hack into the lottery

  • @cherielynn9528
    @cherielynn9528 4 ปีที่แล้ว

    Remarkable presentation.

  • @edgeeffect
    @edgeeffect 4 ปีที่แล้ว

    I love Micah's work... but on her Scanlime videos, it's sometimes hard for a casual observer to keep up... But when you invited her to do a talk, she had to put something into a "neat and tidy" story... I wish she did more presentations like this, she's a damn good speaker. At 41:55 I saw "class Packet" flash by on the screen... and I screamed "Nooo... that's can't be Java, can it?!!" ... but it's OK... I rechecked, It's Python... calm down, calm down!

  • @schlickmannedits5922
    @schlickmannedits5922 4 ปีที่แล้ว

    What did you say at 23:24? 'at one point somedrops an ???? ' @Nahamsec

  • @pentestical
    @pentestical 4 ปีที่แล้ว

    Ben looks so innocent cute in this video #nohomo

  • @nicka2097
    @nicka2097 4 ปีที่แล้ว

    Fantastic talk Kevin

  • @lorilevy7471
    @lorilevy7471 4 ปีที่แล้ว

    Great talk that anyone can understand, and needs to understand.

  • @Graze_
    @Graze_ 4 ปีที่แล้ว

    I wana get one just to do this