Loading…
BSides Boston 2016 has ended
Training [clear filter]
Friday, May 20
 

10:00am EDT

Advanced Web Hacking [Full day class]

GuidePoint Security’s Advanced Web Hacking class heavily emphasizes hands on learning through an instructor led, simulated Web Application Assessment against a proprietary web application that was built specifically for this course. Throughout the course, students will perform OSINT gathering, Application Discovery, manual vulnerability identification, and various exploitation techniques. The course moves beyond the basic OWASP Top 10 Web Application Vulnerabilities, by introducing advanced forms of these common vulnerabilities, built from our own penetration testing experience. Focus is also placed on creating realistic Proof of Concepts to show higher impact and what an attacker could do if the vulnerabilities were exposed. Topics Covered:


Application Discovery

  • Information Gathering
  • Application Functionality 
  • OSINT 
  • Fingerprinting 
  • Identifying Application Entry Points

Vulnerability Identification
  • Automated Scanning Limitations
  • Manual Vulnerability Identification Techniques


Vulnerability Exploitation

  • Blind SQLi
  • Advanced XSS
  • Server Side Template Injection (SSTI)
  • Privilege Escalation
  • Account Hijacking
  • Writing Proof of Concept Exploits

Course Requirements: Course attendees are required to have a laptop with an up to date Kali Linux Virtual Machine. This class is open to attendees of all skill levels, however, we assume prior knowledge of common web vulnerabilities and their exploitation.

 


Speakers
DB

David Bressler

David Bressler is a Managing Consultant at GuidePoint Security within the Application Security Team. He has more than 8 years of broad-based experience managing application penetration testing, source code review, architecture review, network penetration testing, digital and physical... Read More →
CD

Casey Dunham

Casey Dunham is a Security Consultant at GuidePoint Security with 10 years of experience as a full stack software developer in various industries managing development projects and building DevOps and Security initiatives into the Software Development Lifecycle. Before joining GuidePoint... Read More →


Friday May 20, 2016 10:00am - 5:30pm EDT
NERD 1 Memorial Dr

10:00am EDT

Introduction to Hardware Hacking [Full day class]

This training will introduce the audience to the field of reverse engineering electronics. Attendees will learn in a hands on environment how to identify areas of circuit boards to target and perform the extraction of firmware and data at rest, and interception of data in transit. The workshop will introduce and explain various ICs such as microcontrollers and radio transceivers, JTAG, common embedded flash storage solutions, and various types of communication buses. Registration cost includes some hardware hacking tools that may be kept by attendees. The target audience for this workshop has little to no experience in electronics. 

Attendees will receive:
- A Bus Pirate or GoodFET
- Hookup wire and EZ-hooks for connecting components to target hardware
 

Speakers
BD

Brent Dukes

Brent Dukes (@TheDukeZip) has over a decade of experience in systems engineering designing both hardware and software for radio applications. He has a passion for reverse engineering, and spends his free time competing in CTFs and modifying consumer electronics to suit his own needs... Read More →


Friday May 20, 2016 10:00am - 5:30pm EDT
NERD 1 Memorial Dr

1:00pm EDT

CTF: Learn to Hack for Fun and Profit! [Half day class]

Learn about Capture The Flag (CTF) competitions and how you can participate. This training will provide a background on what CTFs are and how they operate.  This training will then guide participants through several real CTF challenges from previous competitions to help build an intuition for how to approach CTF problems and teach real world hacking skills that are used to defeat the challenges. Completion of this training should prepare participants for competing in the BSides Boston CTF.


Speakers
JF

John-Nicholas Furst

John-Nicholas Furst is a Hardware Engineer at Akamai with a long history of participation in CTFs. As a founding member of the hackerspace BUILDS at Boston University, he honed his skills in competing in various CTFs internationally. He eventually moved into running CTFs as a co-founder... Read More →


Friday May 20, 2016 1:00pm - 5:30pm EDT
NERD 1 Memorial Dr

1:00pm EDT

Physical Security Testing [Half day class]

This training presentation will be a complete walk through on how to perform physical security tests. This is NOT a lock-picking class. We will be covering common tools and tactics used to gain access to target facilities as well as provide videos from real world testing and hands on demonstrations of physical and electronic tools. Additionally, common issues that penetration testers encounter into will also be discussed, such as personal psychological issues (insertion mentality), manipulating people efficiently and and understanding the most common physical security controls encountered during testing.

Additional topics to include:
- Onsite and remote advance work (recon/surveillance)
- Penetration of the external barriers
- Penetrating the facility/internal barriers
- Penetrating the people (security personnel and attacking human targets)
- Deploying low power boxes on the network for remote network access and audio/video surveillance.


Speakers
KP

Keith Pachulski

Keith Pachulski is currently working for Dell SecureWorks as a Principal Security Consultant. He performs physical security services and executive security services independently. With more than 22 years of experience in physical and information security, He is currently responsible... Read More →


Friday May 20, 2016 1:00pm - 5:30pm EDT
NERD 1 Memorial Dr
 
Filter sessions
Apply filters to sessions.