Loading…
HackPra [clear filter]
Thursday, May 21
 

09:50 CEST

"Mac Hack Backup Attack - All Your Backed Up Passwords Belong To Us"
TBA

Speakers
avatar for Jonas &quotThe Doctor" Magazinius

Jonas "The Doctor" Magazinius

From Sweden, with a bag full of tricks… Jonas “The Doctor” Magazinius with “Mac Hack backup Attack – All your backed up passwords belong to us”


Thursday May 21, 2015 09:50 - 10:35 CEST
Room E102 Amsterdam RAI

11:05 CEST

"Copy & Pest - A Case Study On The ClipBoard, Blind Trust And Invisible Cross-Application XSS
"Copy & Pest - A case study on the clipboard, blind trust and invinsible cross-application XSS.

Speakers
avatar for Mario Heiderich

Mario Heiderich

Mario Heiderich, handsome heart-breaker, bon-vivant and (as he loves to call himself) “security researcher” is from Berlin, likes everything between lesser- and greater-than, leads the small yet exquisite pen-test company called Cure53 and pesters peaceful attendees on various... Read More →


Thursday May 21, 2015 11:05 - 11:50 CEST
Room E102 Amsterdam RAI

11:55 CEST

"Web Service Workers - Breaking The Web Because It Would Be A Shame To See Such A Cool Feature Go Unused"
Service Workers are an exciting new feature in the open web platform, that will enable many new types of applications. At the same time, they pose very interesting challenges to existing web applications. This talk will give a brief introduction to Service Workers, explain obvious abuse scenarios, potential new security applications, as well as some potential attacks and implementation problems.

Speakers
EV

Eduardo Vela

Eduardo Vela Nava (sirdarckcat) leads Google's Product Security Response team, whose mission is to respond to security issues found in Google products and preventing them from happening ever again. He is a frequent speaker at security conferences and avid web security resea... Read More →


Thursday May 21, 2015 11:55 - 12:40 CEST
Room E102 Amsterdam RAI

13:40 CEST

Server-Side Browsing Considered Harmful
Compromised some large service providers (Facebook, Yahoo, CoinBase,
 Prezi,... ). Pwned their cloud presence and got a few root shells. Using
 only SSRF. Bypassed tons of blacklists. And I'll give you all my tricks.

 ToC: Methodology, Vectors, Targets, Blacklists, Bugs, Toolbox

Speakers
avatar for Nicolas Grégoire

Nicolas Grégoire

Nicolas Gregoire has nearly 15 years of experience in penetration  testing and auditing of networks and (mostly web) applications. A few  years ago, he founded Agarri, a small company where he finds security  bugs for customers and for fun. His research was presented at... Read More →


Thursday May 21, 2015 13:40 - 14:25 CEST
Room E102 Amsterdam RAI

14:30 CEST

Dark Fairytales From A Phisherman
Phishing and client-side exploitation DevOps for all your needs. Combine BeEF, PhishingFrenzy and your fishy business to automate most of the usual phishing workflow while minimizing human interaction.

Speakers
avatar for Michele Orru

Michele Orru

antisnatchor – Michele is the lead core developer and smart-minds-recruiter for the BeEF project. Michele is also the co-author of the "Browser Hacker's Handbook." He has a deep knowledge of programming in multiple languages and paradigms, and is excited to apply this knowledge... Read More →


Thursday May 21, 2015 14:30 - 15:15 CEST
Room E102 Amsterdam RAI

15:45 CEST

XSS Horror Show
My talk is about RPO techniques and a history of XSS vectors
 I've found over the years while testing filters. I will cover mutation
 XSS, browser flaws and cool IE bugs.

Speakers
avatar for Gareth Heyes

Gareth Heyes

Gareth is based in the United Kingdom and is a web security  researcher and works for Portswigger. He has been a speaker at the  Microsoft BlueHat, Confidence Poland, and OWASP conferences, and is the  author of many Web-based tools and sandboxes, including Hackvertor and... Read More →


Thursday May 21, 2015 15:45 - 16:30 CEST
Room E102 Amsterdam RAI

16:40 CEST

Preserving Arcade Games
Old-school arcade games were so protected that hacking is the only way
 to preserve them before all boards are dead, and the games are lost.

 an overview of famous old-school arcade games
 -their incredible hardware
 -the permanent piracy
 -the awesome protections (designed to commit suicide !)
 what was required to preserve some of them from being lost for ever.

Speakers
avatar for Ange Albertini

Ange Albertini

With a bucket full of pixels and crazy animations, it is the one and only Ange Albertini with “Preserving Arcade games”


Thursday May 21, 2015 16:40 - 17:25 CEST
Room E102 Amsterdam RAI
 
Filter sessions
Apply filters to sessions.