BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Secrets and Shadows: Leveraging Big Data for Vulnera
 bility\n   Discovery at Scale\n   When: Saturday\, Aug 10\, 16:00 - 16:45 
 PDT\n   Where: LVCC West/Floor 1/Hall 1/Track 4 - [1]Map\n\n   Description
 :\n\n   When we consider the conventional approaches to vulnerability\n   
 discovery\, be it in software or websites\, we tend to confine ourselves\n
    to a specific target or platform. In the case of software\, we might\n 
   reverse engineer an application's attack surfaces for untrusted input\,\
 n   aiming to trigger edge cases. For websites\, we might enumerate a\n   
 domain for related assets and seek out unpatched\, less defended\, or\n   
 occasionally abandoned resources.\n\n   This presentation explores the unt
 apped potential of scaling security\n   research by leveraging unconventio
 nal data sources. We'll walk through\n   design flaws that enable two exam
 ples: forgotten cloud assets and\n   leaked secrets. Instead of starting w
 ith a target and finding\n   vulnerabilities\, we'll find vulnerabilities 
 and relate them to our\n   targets. We won't just stop at discovery. We'll
  also discuss the\n   incentives that create them and how to solve the eco
 system issues as\n   an industry.\n\n   While you can't easily scale every
  issue\, this project has led to tens\n   of thousands of highly significa
 nt yet seemingly trivial weaknesses in\n   some of the world's largest org
 anizations. Prepare to shift your\n   perspective on vulnerability discove
 ry\, learn scalable approaches to\n   address commonly overlooked bugs\, a
 nd understand how even the simplest\n   misconfiguration can have a devast
 ating impact.\n\n     * Toomey\, Patrick. “Behind the Scenes of Github T
 oken Scanning.”\n       The GitHub Blog\, 17 Oct. 2018\, [2]link.\n\n   
   * Meli\, Michael\, et al. “How Bad Can It Git? Characterizing Secret\n
        Leakage in Public Github Repositories.” Proceedings 2019 Network\
 n       and Distributed System Security Symposium\, 19 Feb. 2019\, [3]link
 .\n\n     * Awslabs. “Awslabs/Git-Secrets: Prevents You from Committing\
 n       Secrets and Credentials into Git Repositories.” GitHub\, 2015\,\
 n       [4]link.\n\n     * Rice\, Zachary. “Zricethezav/Gitleaks: Scan G
 it Repos (or Files)\n       for Secrets Using Regex and Entropy.” GitHub
 \, 2018\, [5]link.\n\n     * Ballenthin\, Willi\, and Moritz Raabe. “Man
 diant/Flare-Floss:\n       Flare Obfuscated String Solver - Automatically 
 Extract Obfuscated\n       Strings from Malware.” GitHub\, 2016\, [6]lin
 k.\n\n     * Squarcina\, Marco\, et al. “Can I Take Your Subdomain? Expl
 oring\n       Same-Site Attacks in the Modern Web.” USENIX Security Symp
 osium\,\n       vol. 30\, Aug. 2021\, pp. 2917–2934.\n\n     * MDN contr
 ibutors. “Subdomain Takeovers - Web Security | MDN.”\n       Developer
 .mozilla.org\, 14 Oct. 2021\, [7]link.\n\n     * “Prevent Subdomain Take
 overs with Azure DNS Alias Records and\n       Azure App Service’s Custo
 m Domain Verification.”\n       Learn.microsoft.com\, Microsoft\, 16 Jun
 e 2020\, [8]link.\n\n     * Shah\, Shubham. “Eliminating Dangling Elasti
 c IP Takeovers with\n       Ghostbuster.” Assetnote\, 13 Feb. 2022\, [9]
 link.\n\n     * Claudius\, Jonathan. “‘Deep Thoughts’ on Subdomain T
 akeover\n       Vulnerabilities.” Claudijd.github.io\, 3 Feb. 2017\, [10
 ]link.\n\n     * Victor Le Pochat\, Tom Van Goethem\, Samaneh Tajalizadehk
 hoob\,\n       Maciej Korczyński\, and Wouter Joosen. 2019. "Tranco: A\n 
       Research-Oriented Top Sites Ranking Hardened Against\n       Manipul
 ation\," Proceedings of the 26th Annual Network and\n       Distributed Sy
 stem Security Symposium (NDSS 2019). [11]link\n\n     * Hallam-Baker\, Phi
 llip\, et al. “RFC 8659 - DNS Certification\n       Authority Authorizat
 ion (CAA) Resource Record.”\n       Datatracker.ietf.org\, IETF\, Nov. 2
 019\, [12]link.\n\n   SpeakerBio:  Bill Demirkapi\, Independent Security R
 esearcher\n\n   Bill is an independent security researcher with a passion 
 for finding\n   bugs at scale. His interests include reverse engineering a
 nd\n   vulnerability research\, ranging from low-level memory corruption t
 o\n   systemic flaws with catastrophic consequences. He started his journe
 y\n   in high school and has since published his work at\n   international
 ly-recognized conferences like DEF CON and Black Hat USA.\n   In his pursu
 it to make the world a better place\, Bill constantly looks\n   for the ne
 xt significant vulnerability\, following the motto "break\n   anything and
  everything".\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n   2. https://github.b
 log/2018-10-17-behind-the-scenes-of-github-token-scanning/\n   3. https://
 doi.org/10.14722/ndss.2019.23418\n   4. https://github.com/awslabs/git-sec
 rets\n   5. https://github.com/zricethezav/gitleaks\n   6. https://github.
 com/mandiant/flare-floss\n   7. https://developer.mozilla.org/en-US/docs/W
 eb/Security/Subdomain_takeovers\n   8. https://learn.microsoft.com/en-us/a
 zure/security/fundamentals/subdomain-takeover\n   9. https://blog.assetnot
 e.io/2022/02/13/dangling-eips/\n   10. https://claudijd.github.io/2017/02/
 03/deep-thoughts-on-subdomain-takeovers/\n   11. https://doi.org/10.14722/
 ndss.2019.23386\n   12. https://datatracker.ietf.org/doc/html/rfc8659\n\n\
 n
DTEND:20240810T234500Z
DTSTART:20240810T230000Z
LOCATION:DC - LVCC West/Floor 1/Hall 1/Track 4
SUMMARY:Secrets and Shadows: Leveraging Big Data for Vulnerability Discover
 y at Scale
END:VEVENT
END:VCALENDAR
