← All Events
Monthly Meet

n|u Hyderabad Meet - January 2023

Saturday, 21 Jan 2023 · 09:30 IST — 14:00 IST

Invesco

About this event

Venue:

Invesco

Survey # 66/1, 12th Floor, Block 7, North Tower DivyaSree Orion, SEZ Raidurgam, Madhura Nagar Colony, Serilingampalle (M), TG, 500032

Google Maps Location

Topics:

Introductions

Security News Bytes by Shaik Arif Ali

An invalid JWT test case by Ashutosh

Ashutosh will discuss about an odd behaviour that he saw when evaluating the security of JWT. He would emphasise new Base64-based weird behaviour in addition to existing general JWT security problems.

4. Node Security Shield - Guarding your NodeJS applications against 0-days by Sukesh

Node Security Shield is a library that provides 0-day exploit protection for Node JS applications. The 0-day could be either be present in code written by the app developers or a vulnerability in any of the npm dependencies used by the application, either direct or transitive. The primary objective of NSS is to prevent the exploitation of these 0-days or at least make it hard as possible for the attacker to exploit them.

5. Writing Detections - Blue Team 101 by Subash Popuri

The agenda of the talk is to take the audience through why and how of Writing detections. The following is a non exhaustive list of items that are covered as a part of the talk:

What is "Writing detections" mean? 

The big picture - how it's used in defending organisations?

Malware analysis v/s Detection writing

Basics: Yara, IOA vs IOC, Sigma, Hash values, etc. 

Demo: Writing detection for 2 exploit kits using various tools to assess behaviour - 1 yara rule & 1 IOA (Sigma)

Note:

Please reach the venue at least 20 mins early for the security checks.

1. Please carry original government-issued ID proof for security checks(The Registered Name should match the ID)

2. Laptops are not allowed for people other than speakers, please do not carry them.

About Speakers:

Shaik Arif Ali, a cyber security enthusiast currently pursuing his final year in computer science engineering at MCET. He is the security researcher who hunts for bugs on the different bug bounty programs. He has completed Security Analyst Fundamental Specialisation from IBM.

Ashutosh works as a product security engineer with Gainsight at Hyderabad. He started his security journey back in his college days, where he was interested in knowing what's happening behind the amazing tech stack. In his free time he watches football and Listen to music.

Sukesh is a Senior Security Engineer at Domdog Security, and his research is primarily focused on web application security. He recently presented about Node Security Shield in BlackHat arsenals. In his eight years of professional experience in Application security, He has worked on the development and assessment of DAST, SAST, IAST, and RASP technologies. His current focus areas are JavaScript Security (Client-side and Server-side) and Content Security Policy. He also authored DrupSnipe, A vulnerability scanner for Drupal along with Node Security Shield.

Subhash P is a Security Engineer with Microsoft. He's interested in Application Security, Incident Response, Security Automation and solving problems at scale.

About null:

null is an open security community for ethical hackers, security professionals, and security enthusiasts, born out of the need for:

Promoting advanced security research. Spreading security awareness among the netizens. A Centralized knowledge base for security-related information. All our Null Hyderabad meets are Free and Open to all, just register and join us.

Please reach out to us for additional information: bheemamahesh [at] gmail [dot] com or vhssunny1 [at] gmail [dot] com or me [at] pavanw3b [dot] com

Event schedule