Conference: Nov 13-15, 2017
Workshops: Nov 16-17, 2017
Workshop: Continuous dis-Integration: Red Team attacks
Location:
- Marina
When:
- Friday
Prerequisites
Do you write code? Do you have code? Do you ever stay awake at night wondering how evil hackers might steal it all for nefarious purposes? Are you interested in learning some super 1337 skills for yourself? Well, you’re in luck. Two evil hackers are ready to share and teach you few tricks they have used during live Red Team engagements to penetrate network defenses and find unexpected entry points. Join us in hacking the Gibson in this hands on workshop that will teach Penetration Testing skills and mitigations specifically tailored for the development community.
This Red Team workshop will provide students perspective and hands on experience with attack simulation tactics used to uncover vulnerabilities, also known as Red Teaming. Students can expect to cover topics such as social engineering (human manipulation), pivoting through network environments, attacking build pipelines, bypassing authentication, and looting systems for secrets.
Takeaways:
- Into to the Concept of Red Teaming
- Story Time: Social Engineering
- Social Engineering Mitigations
- Concepts of post exploitation and system looting
- Lab: Abusing Github CLI
- Lab: Bypassing Jenkins Google Authentication
- Lab: Abusing the Jenkins Script Console and Shelling your first box
- Mitigating the Jenkins Script Console Issues
- Lab: Abusing build jobs to Shell that box again
- Mitigating Controls and the Concept of Least Privilege
- Challenge Lab: Competitive Post Exploitation / Looting Lab
Other Workshops:
.
Tracks
Monday Nov 7
-
Architectures You've Always Wondered About
You know the names. Now learn lessons from their architectures
-
Distributed Systems War Stories
“A distributed system is one in which the failure of a computer you didn't even know existed can render your own computer unusable.” - Lamport.
-
Containers Everywhere
State of the art in Container deployment, management, scheduling
-
Art of Relevancy and Recommendations
Lessons on the adoption of practical, real-world machine learning practices. AI & Deep learning explored.
-
Next Generation Web Standards, Frameworks, and Techniques
JavaScript, HTML5, WASM, and more... innovations targetting the browser
-
Optimize You
Keeping life in balance is a challenge. Learn lifehacks, tips, & techniques for success.
Tuesday Nov 8
-
Next Generation Microservices
What will microservices look like in 3 years? What if we could start over?
-
Java: Are You Ready for This?
Real world lessons & prepping for JDK9. Reactive code in Java today, Performance/Optimization, Where Unsafe is heading, & JVM compile interface.
-
Big Data Meets the Cloud
Overviews and lessons learned from companies that have implemented their Big Data use-cases in the Cloud
-
Evolving DevOps
Lessons/stories on optimizing the deployment pipeline
-
Software Engineering Softskills
Great engineers do more than code. Learn their secrets and level up.
-
Modern CS in the Real World
Applied, practical, & real-world dive into industry adoption of modern CS ideas
Wednesday Nov 9
-
Architecting for Failure
Your system will fail. Take control before it takes you with it.
-
Stream Processing
Stream Processing, Near-Real Time Processing
-
Bare Metal Performance
Native languages, kernel bypass, tooling - make the most of your hardware
-
Culture as a Differentiator
The why and how for building successful engineering cultures
-
//TODO: Security <-- fix this
Building security from the start. Stories, lessons, and innovations advancing the field of software security.
-
UX Reimagined
Bots, virtual reality, voice, and new thought processes around design. The track explores the current art of the possible in UX and lessons from early adoption.