BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//Calagator//EN
CALSCALE:GREGORIAN
X-WR-CALNAME:Calagator
METHOD:PUBLISH
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20170312T020000
RDATE:20170312T020000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
CREATED;VALUE=DATE-TIME:20170522T160032Z
DTEND;TZID=America/Los_Angeles;VALUE=DATE-TIME:20170619T200000
DTSTART;TZID=America/Los_Angeles;VALUE=DATE-TIME:20170619T180000
DTSTAMP;VALUE=DATE-TIME:20170522T160032Z
LAST-MODIFIED;VALUE=DATE-TIME:20170522T160032Z
UID:http://calagator.org/events/1250471956
DESCRIPTION:Abstract&#13\;\n&#13\;\nAll modern software\, but the most tr
 ivial one\, relies on common libraries to perform routine work. Your sof
 tware may be bastion of security\, exhaustively tested and evaluated\, b
 ut once a vulnerability is discovered in a library you depend on\, all b
 ets are off.  These large and pervasive vulnerabilities quickly become p
 opular targets\, exploited by everybody from script kiddies\, to profess
 ional hackers\, to state actors. It is no surprise that the use of vulne
 rable libraries is included in the OWASP Top 10 list. The Australian Sig
 nals Directorate (ASD) lists patching operating systems and applications
  as two of their top four strategies to mitigate security incidents!&#13
 \;\n&#13\;\nDuring a recent hacking game\, we've identified and exploite
 d a vulnerability not anticipated by the developers. One little crack in
  a widely used library gave us the footing we needed to construct an att
 ack chain of remote code execution\, file upload\, data exfil\, source c
 ode disassembly\, and branching into a private network\, all despite ext
 remely high level of hardening on the target from unintended attacks. We
 'll share with you how a safe and fun library exploitation can be in the
  confines of a hacking game\, and how there are serious implications for
  your corporate applications where the stakes are much higher.&#13\;\n&#
 13\;\nSpeakers:&#13\;\n&#13\;\nAlexei Kojenov is a Senior Application Se
 curity Engineer with years of prior software development experience. Dur
 ing his career with IBM\, he gradually moved from writing code to breaki
 ng code. Since late 2016\, Alexei has been working as a consultant at As
 pect Security\, helping businesses identify and fix vulnerabilities and 
 design secure applications.&#13\;\n&#13\;\nAlex Ivkin is a senior securi
 ty architect with experience in a broad array of computer security domai
 ns\, focusing on Identity and Access Governance (IAG/IAM)\, Application 
 Security\, Security Information and Event management (SIEM)\, Governance
 \, Risk and Compliance (GRC). &#13\;\nThroughout his consulting career A
 lex has worked with large and small organizations to help drive security
  initiatives and deploy various types of enterprise-class identity manag
 ement and application security systems. Alex is an established and recog
 nized security expert\, a speaker at various industry conferences\, hold
 s numerous security certifications\, including CISSP and CISM\, two bach
 elor’s degrees and a master’s degree in computer science with a minor in
  psychology.&#13\;\n\n\nTags: owasp\, security\n\nImported from: http://
 calagator.org/events/1250471956
URL:https://www.owasp.org/index.php/Portland
SUMMARY:OWASP: Cheating a Hacking Game for Fun and Profit
LOCATION:WebMD: 2701 Northwest Vaughn Street\, Portland OR 97210 US
SEQUENCE:1
END:VEVENT
END:VCALENDAR
