BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: You Have One New Appwntment - Hacking Proprietary iC
 alendar\n   Properties\n   When: Saturday\, Aug 13\, 15:00 - 15:45 PDT\n  
  Where: Caesars Forum - Academy 401-410\, 421 (Track 3) - [1]Map\n\n   Spe
 akerBio:Eugene Lim \, Cybersecurity Specialist\, Government\n   Technology
  Agency of Singapore\n   Eugene (spaceraccoon) hacks for good! At GovTech 
 Singapore\, he\n   protects citizen data and government systems through se
 curity\n   research. He also develops SecOps integrations to secure code a
 t\n   scale. He recently reported remote code execution vulnerabilities in
 \n   Microsoft Office and Apache OpenOffice and discussed defensive coding
 \n   techniques he observed from hacking Synology Network Attached Storage
 \n   devices at ShmooCon.\n\n   As a bug hunter\, he helps secure products
  globally\, from Amazon to\n   Zendesk. In 2021\, he was selected from a p
 ool of 1 million registered\n   hackers for HackerOne's H1-Elite Hall of F
 ame. Besides bug hunting\, he\n   builds security tools\, including a mali
 cious npm package scanner and a\n   social engineering honeypot that were 
 presented at Black Hat Arsenal.\n   He writes about his research on [2]htt
 ps://spaceraccoon.dev.\n\n   He enjoys tinkering with new technologies. He
  presented "Hacking\n   Humans with AI as a Service" at DEF CON 29 and att
 ended IBM's Qiskit\n   Global Quantum Machine Learning Summer School.\n\n 
   Twitter: [3]@spaceraccoonsec\n\n   Description:\n   First defined in 199
 8\, the iCalendar standard remains ubiquitous in\n   enterprise software. 
 However\, it did not account for modern security\n   concerns and allowed 
 vendors to create proprietary extensions that\n   expanded the attack surf
 ace.\n\n   I demonstrate how flawed RFC implementations led to new\n   vul
 nerabilities in popular applications such as Apple Calendar\, Google\n   C
 alendar\, Microsoft Outlook\, and VMware Boxer. Attackers can trigger\n   
 exploits remotely with zero user interaction due to automatic parsing\n   
 of event invitations. Some of these zombie properties were abandoned\n   y
 ears ago for their obvious security problems but continue to pop up\n   in
  legacy code.\n\n   Furthermore\, I explain how iCalendar’s integrations
  with the SMTP\n   and CalDAV protocols enable multi-stage attacks. Despit
 e attempts to\n   secure these technologies separately\, the interactions 
 that arise from\n   features such as emailed event reminders require a ful
 l-stack approach\n   to calendar security. I conclude that developers shou
 ld strengthen\n   existing iCalendar standards in terms of design and impl
 ementation.\n\n   I advocate for an open-source and open-standards approac
 h to secure\n   iCalendar rather than proprietary fragmentation. I will re
 lease a\n   database of proprietary iCalendar properties and a technical\n
    whitepaper.\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page
 .html#CaesarsAcademyBR\n   2. https://spaceraccoon.dev.\n   3. https://twi
 tter.com/spaceraccoonsec\n\n\n
DTEND:20220813T224500Z
DTSTART:20220813T220000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:You Have One New Appwntment - Hacking Proprietary iCalendar Propert
 ies
END:VEVENT
END:VCALENDAR
