Talks from ShellCon 2019
Jump to:
Main Track Talks
All times are in Pacific Daylight Time (UTC-0700).
ShellCon 101
- Track: A & B: Friday 10/11 @ 0900-0950 PDT
In ShellCon 101 I will explain industry terminology and discuss key aspects of the conference. I am a 17 year old who has been volunteering for ShellCon since the beginning and I want to help newcomers get the most out of the conference and have the full experience. Last year I knew the keynote was really funny but the vocabulary went right over my head. I will go into detail about the Hacker Village, RaiseMe, talks, the layout of the conference, and things to do in downtown San Pedro.
Sara started out as a high school volunteer for ShellCon and is now a student at UC Davis. She has been volunteering for ShellCon since its very beginning and has loved every moment of it.
Are you ready to leverage DevSecOps? Get ready and use it for good.
- Track: A: Friday 10/11 @ 1000-1050 PDT
- Slides
As a security practitioner, the trend of Agile and DevSecOps is coming. Whether developers or management are pushing for it, you should be prepared. DevSecOps sets security as a metric of success for developers and encourages security to be a consideration continually through a project lifecycle. This is a vast improvement to the usual methods of taking security into consideration only at the end, in the beginning, or avoiding talking to security at all. You should be seizing the opportunity to leverage the movement to your advantage. I want to arm you with ideas on education, resources, tools, and practices to do DevSecOps well from a Security department standpoint.
Nicole Schwartz is a Product Manager for the GitLab Secure team. In her career, she has been in Product, System Administration, and Agile coaching. Before her career ever started she was a Hacker. When she isn’t working she volunteers at and attends conventions (you may have known her as @AmazonV) such...
SiestaTime, Automation tool for Generation of Implants, Infrastructure and Reports
Red Team operations require substantial efforts to both create implants and a resilient C2 infrastructure. SiestaTime aims to merge these ideas into a tool with an easy-to-use GUI, which facilitates implant and infrastructure automation alongside its actors reporting.
SiestaTime allows operators to provide registrar, SaaS and VPS credentials in order to deploy a resilient and ready to use Red Team infrastructure. The generated implants will blend in as legitimate traffic by communicating to the infrastructure using SaaS channels and/or common network methods.
Use your VPS/Domains battery to deploy staging servers and inject your favorite shellcode for interactive sessions, clone sites and hide your implants ready to be downloaded, deploy more redirectors if needed. All these jobs/interactions will be saved and reported to help the team members with documentation processes.
LOL We're All Screwed: Mainframe Hacking in 2019
- Track: A: Friday 10/11 @ 1100-1150 PDT
2019 is a hell of a year. Why not make it worse by coming and hearing from one of the world’s foremost experts on mainframe hacking? ‘Hmm’, you’re thinking, ‘mainframes who cares?’ If you’re using any type of credit card (yes even Apple Pay) you care. It is the most important piece of equipment in any enterprise. So how come you still think they’re unhackable?. This talk will go over SNA hacking, VTAM, TSO, CICS, privesc, REXX, and CLISTs, walking through the various techniques successfully used on pentests. Introducing new tools to help conduct penetration tests. You will see how easy it is to get started with mainframe hacking and all the tools currently available today.
Philip Young, aka Soldier of FORTRAN, is a leading expert in all things mainframe hacking. Having spoken and taught at conferences around the world, including DEFCON, RSA, BlackHat and keynoting at both SHARE and GSE Europe, he has established himself as the thought leader in mainframe penetration testing.
Don't Run With Scissors: How to Standardize the Way Your Developers Use Dangerous Aspects of Your Framework
Developers often do not know what the common issues are with the framework they are using. At the same time, most common frameworks ship with easy ways to shoot your application’s security in the foot. In this world we live in, developer education will fail if even one mistake is made, which will expose a dangerous vulnerability. In this talk, we’ll show how you can dramatically reduce the chance developers will shoot themselves in the foot by giving them safer versions of their common tools.
RaiseMe Track Talks
All times are in Pacific Daylight Time (UTC-0700).
Workshops
All times are in Pacific Daylight Time (UTC-0700).
The OWASP Top Ten for Developers
- Track: C: Friday 10/11 @ 0800-1200 PDT
The major cause of API and web application insecurity is insecure software development practices. This highly intensive and interactive 4-hour seminar will provide essential application security training for web application and API developers and architects.
Wireshark for Incident Response & Threat Hunting
- Track: D: Friday 10/11 @ 0800-1200 PDT
This workshop will take student’s Wireshark skills to the next level with a heavy emphasis on incident response, threat hunting, and malicious network traffic analysis. We will begin with a brief introduction to Wireshark and other Network Security Monitoring (NSM) tools/concepts.
Introduction to Linux x64 Memory Corruption
- Track: C: Friday 10/11 @ 1300-1700 PDT
Introduction to Linux Memory Corruption is an introductory workshop aimed at teaching students the basics of reverse engineering and exploiting stack based overflows on modern systems (AMD64). This workshop is aimed at students with no prior reverse engineering or exploitation experience and takes them through writing their first memory corrupting exploit.