Andy Lewis - 3cx: lessons learned
46:24
Пікірлер
@cybersec9345
@cybersec9345 2 ай бұрын
Water
@jasonl9266
@jasonl9266 4 ай бұрын
This is bS!
@jasonl9266
@jasonl9266 4 ай бұрын
Next search will be "how to not get my door break in by the nsa swat team . Lol
@Sudha-pa25
@Sudha-pa25 4 ай бұрын
Great content 😊
@koriandyr
@koriandyr 5 ай бұрын
Was this work ever open sourced...and if so where? Thanks!
@kaushit
@kaushit 6 ай бұрын
The beauty is he started from history and explained how these things evolved. thanks for posting.
@pea3080
@pea3080 7 ай бұрын
"how to hack an api in 15 minutes" *the video is 47 minutes* hmmmmm
@jermainex364
@jermainex364 8 ай бұрын
Promo_SM 💋
@vadhirajkulkarni8498
@vadhirajkulkarni8498 8 ай бұрын
Very Impressive presentation. Best of Luck guys!
@kevinminus5638
@kevinminus5638 8 ай бұрын
Good talk
@user-pc4kk3ju9v
@user-pc4kk3ju9v 9 ай бұрын
Very informative...
@camerongreen9328
@camerongreen9328 9 ай бұрын
Interesting talk, enjoyed the attack vectors from a mobile perspective
@magzimuz
@magzimuz 9 ай бұрын
Way to go Vis 👏🏼👏🏼👌🏽
@chvasu1812
@chvasu1812 3 ай бұрын
Thank you!
@kymnippes4555
@kymnippes4555 9 ай бұрын
Great job Andy!
@pipi_delina
@pipi_delina 9 ай бұрын
Nice talk
@camerongreen9328
@camerongreen9328 9 ай бұрын
Probably my favorite talk from the con. Jim is just too passionate, which talkers would understand this is how you have to give a presentation! Down like 6 cups of coffee before!!!
@camerongreen9328
@camerongreen9328 9 ай бұрын
Very interesting points on GPT and how attackers will create the third party lib do what it thought it should and then insert malware! Great TAlk!
@camerongreen9328
@camerongreen9328 9 ай бұрын
Great panel, wish there were more freeform talks at LASCON
@camerongreen9328
@camerongreen9328 9 ай бұрын
I really enjoyed this talk! Metrics are Key and we need to start talking how AppSec is not a cost center but a way to increase revenue
@camerongreen9328
@camerongreen9328 9 ай бұрын
Great Talk!
@camerongreen9328
@camerongreen9328 9 ай бұрын
Audio got worse when they changed his mic!
@camerongreen9328
@camerongreen9328 9 ай бұрын
Great Talk!
@avig2009
@avig2009 10 ай бұрын
get new app then diff with old
@user-jr3kw5ui8b
@user-jr3kw5ui8b Жыл бұрын
Excelent explanaition about DevSecOps!!
@MohsinKhan-rc6ys
@MohsinKhan-rc6ys Жыл бұрын
I would argue on the agents part , "agents do not utilise much server resources." Also they would not impact opeations at all. The vulnerability management idustry again keeps on improvising day by day. One such agent based scanning is provided by Qualys, while they also deal with suite of quality security by products, vulnerability management detection and response has been their key specialization.
@ysachin
@ysachin Жыл бұрын
Love it. Leaders inspire. Inspire someone! Taking notes is an underrated skill. Our memories are fallible. We all need to embrace it.
@Audionic1
@Audionic1 Жыл бұрын
Did you have tool's
@brettmulligan
@brettmulligan Жыл бұрын
Super helpful framework. Thank you!
@evanschumba3061
@evanschumba3061 Жыл бұрын
Great presentation.Been wondering if there is a video guide/tutorial on the end to end installation of packet fence. The existing documentation is high level and may not be good for the newbies
@FarisALHashmi-qb6lr
@FarisALHashmi-qb6lr Жыл бұрын
wtf
@piotrstasinskij2929
@piotrstasinskij2929 Жыл бұрын
Good presentation, thanks for job
@1stmillionaireinmyfamily331
@1stmillionaireinmyfamily331 Жыл бұрын
What do you guys think about the qualys cloud scanners
@MohsinKhan-rc6ys
@MohsinKhan-rc6ys Жыл бұрын
There are very few leading vendors specialising in the field of cloud scanners and Qualys is one of the leader. They provide great support and a lot goes on with research,plus they offers range of cybersecurity products.
@SecAware
@SecAware Жыл бұрын
A well-rounded presentation about a sound approach. Thanks Josh! For me, accountability is the key to making this work - specifically, the 'risk owners' (or 'information asset owners' or whatever you call them) need to accept personal accountabilty for the risk treatment decisions and actions arising. Costly but necessary controls need to be funded, so ownership needs to be high enough up the hierarchy to secure the resources and priorise the work appropriately, relative to everything else going on. Linking risk level to management level is a neat way of putting it and hints at the idea of aggregating or rolling-up risk, with lower levels handling the individual risks while management oversees and manages the lot (e.g. all the information risks relating to the HR system in aggregate rightly belong to the HR Director, whereas HR, risk, security, IT and other people may be handling the component risks).
@samsonaghanemuzor5443
@samsonaghanemuzor5443 Жыл бұрын
I think you should be arrested for this🤣🤣
@francism2022
@francism2022 Жыл бұрын
p͓̽r͓̽o͓̽m͓̽o͓̽s͓̽m͓̽ ✅
@helloquestionmark9942
@helloquestionmark9942 Жыл бұрын
great video
@timbuktooley
@timbuktooley Жыл бұрын
Definitely worth the watch!
@shawngee1
@shawngee1 Жыл бұрын
Very good presentation. Thank you.
@cj1871
@cj1871 2 жыл бұрын
Really cool!
@westdu5961
@westdu5961 2 жыл бұрын
This is awesome, I am a vuln analyst and they are spot on
@ThoriumHeavyIndustries
@ThoriumHeavyIndustries 2 жыл бұрын
I handled quite some vulnerability and scanner products from different vendors. The "Risk Score Systems" of all the products, I have seen, are basically a joke. When I see 5 digits risk numbers from a system that does not know what the system is used for and especially what data is on it and to what it is connected I see "Snake Oil" and "Fairy Dust". People doing this software have never got in touch with risk management, risk management methodes & metrics and risk management processes. So basically, those risk scores are not "a better guess" than the CVSS-Score. But it is a point of sale, If I tell my management with the help product I could reduce "risk" (what ever the vendor is considering as risk) by a 5 digit number I might get a bonus for my "great" work. It is simply trading with fear and uncertainties of unaware people - I do not support this. Further more those tool simply cannot do what an attacker would do, chaining in attack trees, they can only understand standalone vulnerabilities but not the interplay between multiple chained attacked vulnerabilities. For this you need a complex model called risk & threat or MFEA... in a digital model based form... that allows you to perform quick simulations by adding or removing factors. As long as this "scanner" do not understand you IT-mized process and it´s components ignore the ratings.
@yegfreethinker
@yegfreethinker 2 жыл бұрын
Thank you for pointing this. I'm so sick of death of things becoming becoming worthless and obsolete because of this certificate error nonsense
@rayg6224
@rayg6224 2 жыл бұрын
I watched, then sent this to my daughter, who will be getting into this career. Excellent presentation.
@ginameyer6297
@ginameyer6297 2 жыл бұрын
❤🌹 God bless you 🙏🙏. Do not waste your time > P r o m o S M !
@timehealthfit1891
@timehealthfit1891 2 жыл бұрын
You're a candle in the darkness, want to be youtube friends?
@angryman9333
@angryman9333 2 жыл бұрын
useful content. thanks man
@kishanbsh
@kishanbsh 2 жыл бұрын
Best ever talk on gpg IMO
@jayak3768
@jayak3768 2 жыл бұрын
I really wished he had compared the flows.
@andreic6250
@andreic6250 2 жыл бұрын
@17:30 cameraman - and instead of zooming in on the slides - and decides - enough of slides - zooms in on the presenter duhhhhh sad