BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Write Once\, Shell Everywhere: Turning Arbitrary Fil
 e Writes\n   into RCE\n   Tags: Bug Bounty Village | Creator Talk/Panel\n 
   When: Friday\, Aug 7\, 12:00 - 12:30 PDT\n   Where: LVCCW Level 1 Hall 3
  1102 (Creator Stage 6) - [1]Map\n\n   Description:\n\n   Arbitrary file w
 rite bugs are often treated as “almost critical”\n   findings: interes
 ting\, dangerous\, but most times it’s hard to prove\n   impact when the
  target does not let you write a web shell to an\n   obvious location or o
 verwrite some magic configuration file to achieve\n   code execution. This
  talk is about closing that gap for black box\n   approaches.\n\n   Instea
 d of focusing on a single framework\, we will present novel\n   primitives
  that will make you able to pop shells across the most\n   popular program
 ming languages and frameworks in different ecosystems\,\n   all with as li
 ttle information as possible about the target\n   application.\n\n   The s
 ession will start by assessing the current state of the art of\n   arbitra
 ry file write in bug bounty style scenarios. This will set the\n   stage f
 or the rest of the talk as we will start building a methodology\n   to cor
 rectly identify exploitation capabilities and obtain as much\n   informati
 on as possible about the target.\n\n   From there\, we will move into show
 casing new techniques to abuse file\n   write primitives and achieve the u
 ltimate goal of code execution. We\n   will go over novel techniques that 
 apply both to the most popular\n   interpreted languages and to the most u
 sed runtime environments.\n\n   Bug Bounty Hunters who join this talk will
  not only leave with fresh\n   techniques to apply in their engagements\, 
 but with a reusable mental\n   model for identifying their target’s exec
 ution context and proving\n   maximum impact when faced with arbitrary fil
 e write scenarios.\n\n   Speakers:Bruno Mendes\,Rafael Castilho Silva\n\n 
   SpeakerBio:  Bruno Mendes\, Head of Hacking\, Ethiack\n\n   Bruno Mendes
  is the Head of Hacking at Ethiack. He began his work\n   career as an Off
 ensive Security Researcher on Intel's IPAS Cloud\n   Security team in 2024
 . In bug bounty\, back in 2023 placed 5th overall\n   in the teams categor
 y and won the "Not Dead Yet" award at an Intigriti\n   Live Hacking Event 
 in Lisbon\, and most recently co-authored a critical\n   RCE with André B
 aptista (0xacb) that earned over $100k+ in a single\n   program. He has an
  extensive CTF background being a three-time winner\n   of the Cybersecuri
 ty Challenge Portugal (2021-2023)\, captain of Team\n   Portugal at the Eu
 ropean Cybersecurity Challenge (2022\, 2023\, 2025)\,\n   and won the 2023
  International Cybersecurity Challenge with Team\n   Europe. He also capta
 ined the Instituto Superior Técnico CTF team\n   (STT) from 2022 to 2024.
 \n\n   SpeakerBio:  Rafael Castilho Silva\, Ethiack\n\n   Security Reseach
 er at Ethiack fucosed on Vulnerability Research\n\n   '\n\n   1. #LVCCW_Le
 vel1_Hall3\n\n\n
DTEND:20260807T193000Z
DTSTART:20260807T190000Z
LOCATION:Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6)
SUMMARY:Write Once\, Shell Everywhere: Turning Arbitrary File Writes into R
 CE
END:VEVENT
END:VCALENDAR
