BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: ElectroVolt: Pwning popular desktop apps while uncov
 ering new\n   attack surface on Electron\n   When: Sunday\, Aug 14\, 13:00
  - 13:45 PDT\n   Where: Caesars Forum - Academy 401-410\, 421 (Track 3) - 
 [1]Map\n   Speakers:Max Garrett\,Aaditya Purani\n\n   SpeakerBio:Max Garre
 tt \, Application Security Auditor\, Cure53\n   No BIO available\n\n   Spe
 akerBio:Aaditya Purani \, Senior Security Engineer\, Tesla\n   Aaditya Pur
 ani is a senior security engineer at a leading automotive\n   company. Aad
 itya's primary areas of expertise are web/mobile\n   application penetrati
 on testing\, product security reviews\, blockchain\n   security\, and sour
 ce code review.\n\n   He contributes to responsible disclosure programs an
 d is included in\n   the hall of fame for Apple\, Google and AT&T. He also
  participates in\n   capture the flag (CTF) from perfect blue which is a g
 lobally ranked\n   top-1 CTF team since 2020.\n\n   As a researcher\, his 
 notable public findings include BTCPay Pre-Auth\n   RCE\, Brave Browser Ad
 dress Bar Vulnerability\, and Akamai Zero Trust\n   RCE. As a writer\, Aad
 itya has authored articles for InfoSec Institute\,\n   Buzzfeed\, and Haki
 n9. In the past\, Aaditya has interned for Bishop Fox\n   and Palo Alto Ne
 tworks.\n\n   Twitter: [2]@aaditya_purani\n\n   Description:\n   Electron 
 based apps are becoming a norm these days as it allows\n   encapsulating w
 eb applications into a desktop app which is rendered\n   using chromium. H
 owever\, if Electron apps load remote content of\n   attackers choice eith
 er via feature or misconfiguration of Deep Link\n   or Open redirect or XS
 S it would lead to Remote Code Execution on the\n   OS.\n\n   Previously\,
  it was known that lack of certain feature flags and\n   inefficiency to a
 pply best practices would cause this behavior but we\n   have identified s
 ophisticated novel attack vectors within the core\n   electron framework w
 hich could be leveraged to gain remote code\n   execution on Electron apps
  despite all feature flags being set\n   correctly under certain circumsta
 nces.\n\n   This presentation covers the vulnerabilities found in twenty c
 ommonly\n   used Electron applications and demonstrates Remote Code Execut
 ion\n   within apps such as Discord\, Teams(local file read)\, VSCode\, Ba
 secamp\,\n   Mattermost\, Element\, Notion\, and others.\n\n   The speaker
 's would like to thank Mohan Sri Rama Krishna Pedhapati\,\n   Application 
 Security Auditor\, Cure53 and William Bowling\, Senior\n   Software Develo
 per\, Biteable for their contributions to this\n   presentation.\n\n   '\n
 \n   1. https://defcon.outel.org/consolidated_page.html#CaesarsAcademyBR\n
    2. https://twitter.com/aaditya_purani\n\n\n
DTEND:20220814T204500Z
DTSTART:20220814T200000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:ElectroVolt: Pwning popular desktop apps while uncovering new attac
 k surface on Electron
END:VEVENT
END:VCALENDAR
