From CTF to CVE by Joe Gray

  Рет қаралды 2,152

Bugcrowd

Bugcrowd

Күн бұрын

Recorded live on January 19, 2019 at LevelUp 0x03.
Learn more: www.bugcrowd.com/resources/ev...
Join Bugcrowd: bit.ly/invitesplz
Have a question related to this talk? Post it on our forum: forum.bugcrowd.com/t/levelup-...
Abstract:
"As an industry, we are always looking for ways to sharpen our skills. We have education, certifications, and mentorship programs. A staple at Defcon as well as most other conferences is the Capture the Flag (CTF) competitions. As a blue teamer, in an effort to sharpen my skills, I started downloading CTF VMs and working through them. For more applicability, I started applying these concepts to things outside the CTF for bug bounties, but to no avail.
As luck would have it, I left Burp on and logged in to configure my lab wireless router to use for testing and learning wireless hacking. While the antennae that I bought to attack wireless were being used, they weren’t being used in the same sense of attack. I logged into the router and noticed several vulnerabilities in the router’s authentication scheme. This presentation breaks down the concepts of the CTF and how I applied them through the research and responsible disclosure process.
"
Follow us on Twitter: / bugcrowd

Пікірлер
Behind the Curtain: Safe Harbor and Department of Defense
57:29
1 or 2?🐄
00:12
Kan Andrey
Рет қаралды 57 МЛН
Best father #shorts by Secret Vlog
00:18
Secret Vlog
Рет қаралды 21 МЛН
Became invisible for one day!  #funny #wednesday #memes
00:25
Watch Me
Рет қаралды 58 МЛН
Was ist im Eis versteckt? 🧊 Coole Winter-Gadgets von Amazon
00:37
SMOL German
Рет қаралды 39 МЛН
Google CTF - BEGINNER Reverse Engineering w/ ANGR
39:47
John Hammond
Рет қаралды 281 М.
Ask A Hacker Anything with Erik de Jong
56:06
Bugcrowd
Рет қаралды 940
When to Report a Bug
16:14
Bugcrowd
Рет қаралды 770
Learn Nuclei in 30 minutes - DEF CON Nuclei Demo
35:48
ProjectDiscovery
Рет қаралды 8 М.
Google CTF - Authentication Bypass
24:27
John Hammond
Рет қаралды 117 М.
🚀  TDD, Where Did It All Go Wrong (Ian Cooper)
1:03:55
DevTernity Conference
Рет қаралды 553 М.
License to Kill: Malware Hunting with the Sysinternals Tools
1:18:10
Mark Russinovich
Рет қаралды 76 М.
What is Common Vulnerabilities and Exposures (CVE)?
4:25
Debricked
Рет қаралды 10 М.
Собери ПК и Получи 10,000₽
1:00
build monsters
Рет қаралды 2,7 МЛН
Где флагманы с IPS?
0:52
Не шарю!
Рет қаралды 66 М.