n|u Hyderabad Meet - June 2022
Saturday, 25 Jun 2022 · 09:45 IST — 13:30 IST
Invesco
About this event
About null
null is an open security community for ethical hackers, security professionals, and security enthusiasts, born out of the need for:
Promoting advanced security research.Spreading security awareness among the netizens.A Centralized knowledge base for security related information.All our Null Hyderabad meets are Free and Open to all, just register and join us.
Venue Details:
Invesco
Survey # 66/1, 12th Floor, Block 7, North Tower DivyaSree Orion, SEZ Raidurgam, Madhura Nagar Colony, Serilingampalle (M), Telangana 500032
https://goo.gl/maps/tvVH45nsTB4biG9U6
Note:
Don't forget to carry below docs for smooth security checks and entry in to the venue. Also, Please reach the venue at-least 20 mins early for the security checks.
1. Original ID proof
2. [Soft Copy] Vaccination Certificate
Topics:
1. Introductions.
2. News Bytes by Sivasai
3. Exploit Development : The Art of Exploitation by Manish Sharma
In this talk, Speaker will cover several types of exploit development which exist in Linux as well as Windows Operating System. I'll be presenting about various topics such as basics, Shell coding, Stack Smashing, SEH based overflow and egg hunter. Also, will be covering the little bit on the types of exploit development defense bypassing techniques.
4. Networking Break
5. The Egg Series: How Eggxactly Insecure Deserialization Exploits Work by Pavan Mohan
In this talk, Pavan will demonstrate Insecure Deserialization vulnerability with Python Pickle and Django. This is the Egg Series with the goal of explaining the vulnerability with a detailed yet simplest way. The talk will cover the basics of Serialize - Deserialization, then demonstrate the risks with the Pickle load() method and apply the learning on a deliberately developed insecure Django Web application.
6. Feedbacks & Suggestions.
About Speakers:
Sivasai Maragani is pursuing his 3rd year of B.Tech in CMRIT college. He has experience in websecurity, AWS, and also well versed in Linux and windows privilege escalation. he also has skillset in scripting languages Javascript, bash, python.
Manish Sharma is working as Associate Information Security Engineer at Gainsight with 2+ years of experience in Application Security i.e., Web, API, Mobile and thick client, Secure Code Review and Application as well as Network Penetration Testing. He is interested in Exploit Development and DevSecOps.
Pavan Mohan is a developer turned bug hunter and leads the Product Security team at ServiceNow. He is one of the core members of Null Hyderabad chapter and he has been contributing to the info sec community by presenting at Defcon and null events. He leads an open source security tool: Sh00t. He tries his luck in bug bounty programs when he goes out of T-Shirts and made it to some Hall of Fame.
Please feel free to reach out to us for any additional info. mahesh at null.co.in or hari at null.co.in
Don't forget to carry Original ID proof and vaccination certificate for smooth security checks. Please reach the venue at-least 20 mins early for the security checks.
Event schedule
| Time | Session | Speaker | |
|---|---|---|---|
| Exploit Development : The Art of Exploitation | Manish Sharma | ||
| The Egg Series: How Eggxactly Insecure Deserialization Exploits Work | pavanw3b | ||
| News Bytes | Null Hyderabad |