BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Exploring Ancient Ruins to Find Modern Bugs: Discove
 ring a\n   0-Day in an MS-RPC Service\n   When: Saturday\, Aug 13\, 13:00 
 - 13:45 PDT\n   Where: Caesars Forum - Academy 401-410\, 421 (Track 3) - [
 1]Map\n   Speakers:Ben Barnea\,Ophir Harpaz\n\n   SpeakerBio:Ben Barnea \,
  Senior Security Researcher\, Akamai\n   Ben Barnea is a security research
 er at Akamai with interest and\n   experience conducting low-level securit
 y research and vulnerability\n   research across various architectures - W
 indows\, Linux\, IoT and\n   mobile. He likes learning how complex mechani
 sms work and most\n   importantly\, how they fail.\n   Twitter: [2]@nachos
 krnl\n\n   SpeakerBio:Ophir Harpaz \, Senior Security Research Team Lead\,
  Akamai\n   Ophir Harpaz is a security research team lead in Akamai\, wher
 e she\n   manages research projects around OS internals\, exploitation and
 \n   malware analysis. Ophir has spoken in various security conferences\n 
   including Black Hat USA\, Botconf\, SEC-T\, HackFest and more. As an\n  
  active member in Baot - a community for women engineers - she has\n   tau
 ght a reverse-engineering workshop ([3]https://begin.re) to share\n   her 
 enthusiasm for reversing. Ophir has entered Forbes' list of\n   30-under-3
 0 and won the Rising Star category of SC Magazine's Reboot\n   awards for 
 her achievements and contribution to the Cyber security\n   industry.\n   
 Twitter: [4]@OphirHarpaz\n\n   Description:\n   MS-RPC is Microsoft's impl
 ementation of the Remote Procedure Calls\n   protocol. Even though the pro
 tocol is extremely widespread\, and serves\n   as the basis for nearly all
  Windows services on both managed and\n   unmanaged networks\, little has 
 been published about MS-RPC\, its attack\n   surface and design flaws.\n\n
    In this talk\, we will walkthrough and demonstrate a 0-day RCE\n   vuln
 erability which we discovered through our research of MS-RPC. When\n   exp
 loited\, this vulnerability allows an attacker to execute code\n   remotel
 y and potentially take over the Domain Controller. We believe\n   this vul
 nerability may belong to a somewhat novel bug-class which is\n   unique to
  RPC server implementations\, and would like to share this\n   idea as a p
 ossible research direction with the audience.\n\n   To aid future research
  into the topic of MS-RPC\, we will share a deep\,\n   technical overview 
 of the RPC system in Windows\, explain why we\n   decided to target it\, a
 nd point out several design flaws. We will also\n   outline the methodolog
 y we developed around RPC as a research target\n   along with some tools w
 e built to facilitate the bug-hunting process.\n\n   '\n\n   1. https://de
 fcon.outel.org/consolidated_page.html#CaesarsAcademyBR\n   2. https://twit
 ter.com/nachoskrnl\n   3. https://begin.re\n   4. https://twitter.com/Ophi
 rHarpaz\n\n\n
DTEND:20220813T204500Z
DTSTART:20220813T200000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:Exploring Ancient Ruins to Find Modern Bugs: Discovering a 0-Day in
  an MS-RPC Service
END:VEVENT
END:VCALENDAR
