BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Who Contains the “Serverless” Containers?\n   Wh
 en: Saturday\, Aug 13\, 10:40 - 11:20 PDT\n   Where: Flamingo - Sunset-Sce
 nic Ballroom (Cloud Village) - [1]Map\n\n   SpeakerBio:Daniel Prizmant\n  
  Daniel started out his career developing hacks for video games and\n   so
 on became a professional in the information security field. He is an\n   e
 xpert in anything related to reverse engineering\, vulnerability\n   resea
 rch\, and the development of fuzzers and other research tools. To\n   this
  day Daniel is passionate about reverse engineering video games at\n   his
  leisure. Daniel holds a Bachelor of Computer Science from Ben\n   Gurion 
 University.\n   Twitter: [2]@pushrsp\n\n   Description:\n   What is Server
 less? Serverless computing is a cloud computing\n   execution model in whi
 ch the cloud provider allocates machine\n   resources on-demand\, taking c
 are of the servers on behalf of their\n   customers.\n\n   "Serverless" is
  a misnomer in the sense that servers are still used by\n   cloud service 
 providers to execute code for developers.\n\n   How does Serverless work? 
 Where is this Serverless code executed?\n   Who's in charge of securing it
 ? There are many questions surrounding\n   the topic of Serverless computi
 ng.\n\n   In this talk\, I will present to you my research on Serverless\n
    Functions. I will show you how I managed to break the serverless\n   in
 terface barrier and what is hidden behind it. I will also show you\n   how
  I managed to break out of the container that was supposed to\n   contain 
 my possibly malicious code and get to the underlying host.\n\n   I will st
 art by explaining what is Serverless and the idea behind it.\n   I will sh
 ow some prime examples of what Serverless is supposed to be\n   used for. 
 I will continue with a break out of the cloud provider\n   interface to sh
 ow you the infrastructure of the machine\, the server of\n   the serverles
 s function\, that is actually running the code.\n\n   After that\, I will 
 begin walking you through my research and journey\n   from the point of vi
 ew of an attacker. I will show you how I\n   discovered the image that the
  container was running and the steps I\n   took to reverse engineer it.\n\
 n   From there\, the path to an elevation of privileges to root to escapin
 g\n   the container was short. I will walk you through a very old but usef
 ul\n   exploit I used to escalate my containerized root access to a full-o
 n\n   container breakout. To finish the talk\, I will discuss some of the\
 n   mitigations that were in place in this instance by the cloud provider\
 ,\n   and why they were critical in this scenario.\n\n   '\n\n   1. https:
 //defcon.outel.org/consolidated_page.html#FlamingoThirdFloor\n   2. https:
 //twitter.com/pushrsp\n\n\n
DTEND:20220813T182000Z
DTSTART:20220813T174000Z
LOCATION:CLV - Flamingo - Sunset-Scenic Ballroom  (Cloud Village)
SUMMARY:Who Contains the “Serverless” Containers?
END:VEVENT
END:VCALENDAR
