BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Iconv\, set the charset to RCE: exploiting the glibc
  to hack\n   the PHP engine\n   When: Saturday\, Aug 10\, 17:30 - 18:15 PD
 T\n   Where: LVCC West/Floor 1/Hall 1/Track 3 - [1]Map\n\n   Description:\
 n\n   Upon its discovery\, CVE-2024-2961\, a very old buffer overflow in t
 he\n   glibc\, seemed like a terrible bug. Within the prism of the PHP eng
 ine\,\n   however\, the vulnerability shone\, and provided both a new remo
 te code\n   execution vector and a few 0-days.\n\n   This talk will first 
 walk you through the discovery of the bug and its\n   limitations\, before
  describing the conception of remote binary PHP\n   exploits using this bu
 g\, and through them offer unique insight in the\n   internal of the engin
 e of the web language\, and the difficulties one\n   faces when exploiting
  it.\n\n   After this\, it will reveal the impact on PHP's ecosystem\, fro
 m\n   well-known functions to unsuspected sinks\, by showcasing the\n   vu
 lnerability on several popular libraries and applications.\n\n   SpeakerBi
 o:  Charles "cfreal" Fol\, Security Researcher at LEXFO /\n   AMBIONICS\n\
 n   Charles Fol\, also known as cfreal\, is a security researcher at LEXFO
  /\n   AMBIONICS. He has discovered remote code execution vulnerabilities\
 n   targeting renowned CMS and frameworks such as Drupal\, Magento\, Symfo
 ny\n   or Laravel\, but also enjoys binary exploitation\, to escalate\n   
 privileges (Apache\, PHP-FPM) or compromise security solutions\n   (DataDo
 g’s Sqreen\, Fortinet SSL VPN\, Watchguard). He is the creator\n   for P
 HPGGC\, the go-to tool to exploit PHP deserialization\, and an\n   expert 
 in PHP internals.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20240811T011500Z
DTSTART:20240811T003000Z
LOCATION:DC - LVCC West/Floor 1/Hall 1/Track 3
SUMMARY:Iconv\, set the charset to RCE: exploiting the glibc to hack the PH
 P engine
END:VEVENT
END:VCALENDAR
