BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hook Crook - Extracting More From Discord Webhooks\n
    Tags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team |\
 n   Threat Intel/Hunting | DEF CON Demo Labs\n   When: Saturday\, Aug 8\, 
 13:00 - 13:45 PDT\n   Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) 
 - [1]Map\n\n   Description:\n\n   A webhook URL is often thought to be wri
 te-only â€” post a message\,\n   nothing more. So when one leaks through a
  misconfigured repo\, a paste\n   site\, or breached infrastructure\, it's
  written off as a\n   spam-or-phishing nuisance and left to rot. Hook Croo
 k shows that\n   assumption is the vulnerability â€” and that "write-only"
  was never\n   really the case.\n\n   By abusing how Discord resolves refe
 rences\, what it returns when you\n   query users and messages\, and how i
 ts error and rate-limit responses\n   differ\, the write-only token quietl
 y becomes a read primitive â€”\n   leaking by design\, not by bug. With no
 thing but the URL â€” no\n   account\, no additional authentication\, no i
 nteraction from anyone on\n   the target server â€” Hook Crook fingerprint
 s the host guild\,\n   enumerates and confirms members\, pulls profile dat
 a on known users\n   (including their home-server tag)\, and in some cases
  recovers message\n   content. The same behaviors let it bypass the server
 's posting\n   restrictions\, stage convincing impersonation and phishing\
 , quietly\n   edit or delete messages to scrub the evidence\, and â€” on t
 he way out\n   â€” delete the webhook itself. None of it breaks Discord â€
 ” it just\n   reads Discord more carefully than its designers intended.\n\
 n   Speakers:Jeremy Banker - K0JLB\,Arity0\n\n   SpeakerBio:  Jeremy Banke
 r - K0JLB\n   Bio: Jeremy Banker is a Senior Security Software Engineer at
 \n   Horizon3.ai\, focused on the reliability and resiliency of Horizon3's
 \n   automated penetration testing platform. He previously spent nearly a\
 n   decade at VMware\, where he co-founded the Security Product Engineerin
 g\n   group and led efforts to secure VMware's software supply chain. His\
 n   open source security tooling\, including Build Inspector for CI/CD\n  
  pipeline anomaly detection and Tommyknocker for automated security\n   co
 ntrol validation\, has been featured at Black Hat Arsenal and DEF CON\n   
 Demo Labs. A licensed amateur radio operator since 2010\, he built\n   ope
 n-packet\, an MIT licensed Python client for packet messaging\, after\n   
 becoming frustrated with the existing closed-source options.\n   SpeakerBi
 o:  Arity0\n\n   Arity0 is an independent security researcher specializing
  in the\n   Discord platform. A self-taught hacker\, he focuses on uncover
 ing\n   undocumented behaviors\, edge cases\, and design-level privacy\n  
  implications in Discord's API and rendering pipeline. His long-running\n 
   exploration of Discord's rendering quirks led to the discovery of the\n 
   webhook rendering oracles that form the foundation of the Hook Crook\n  
  identity disclosure technique.\n\n   Links:\n       GitHub - [2]https://g
 ithub.com/HnC-Sec/hook_crook\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. htt
 ps://github.com/HnC-Sec/hook_crook\n\n\n
DTEND:20260808T204500Z
DTSTART:20260808T200000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)
SUMMARY:Hook Crook - Extracting More From Discord Webhooks
END:VEVENT
END:VCALENDAR
