n|u Hyderabad Meet - March 2023
Saturday, 18 Mar 2023 · 09:30 IST — 13:30 IST
ADP
About this event
Venue:
ADP Pvt Ltd
One West Building,Sy. No 88/AA & 88/E, Nanakramguda, Village, Mandal, Serilingampalle (M), Hyderabad - 500008
Google Maps Location
Topics:
1. Introductions
2. Finding Web Application vulnerabilities with Burp Suite Scan Profiles by Mohammad Saqlain
Burpsuite Configuration Library library allows to create and manage their own collection of configurations for different tasks, such as scans and fuzzing. Unlike the default settings in previous versions of Burp, users can define which areas will be scanned for detecting and fuzzing web vulnerabilities according to their preferences.
3. Networking Break
4. Curious cases of OAuth misconfigurations by Gurunatha Reddy
The Talk introduces OAuth workflow and covers common misconfigurations and real-world OAuth bugs.
5. Mind the Gap: Identifying and Addressing Weaknesses in Your GCP by Bhagavan Bollina.
The author will practically demonstrate the weaknesses in the development process that can lead to an organization being compromised. Then will try to show how an attacker can move laterally inside the Google Cloud and exfiltrate customer data. The author will provide an attacker's perspective and demonstrate the trial-and-error process used by attackers.
6. The Egg Series: How Eggxactly Insecure Deserialization Exploits Work by Pavan Mohan
Pavan will demonstrate Insecure Deserialization vulnerability with Python Pickle and Django. This is the Egg Series with the goal of explaining the vulnerability in a detailed yet simplest way. The talk will cover the basics of Serialize - Deserialization, then demonstrate the risks with the Pickle load() method and apply the learning on a deliberately developed insecure Django Web application. This is a repeat of the July 2022 speech as per the demand by the community.
7. Feedbacks & Suggestions
Note:
Please reach the venue at least 20 mins early for the security checks.
1. Please carry original government-issued ID proof for security checks (Registered name should match with name in ID)
2. Laptops are allowed only for Speakers, please do not carry them.
About Speakers:
Mohammad Saqlain, Senior Application Security Engineer at TechMahindra and Occasinal bug bounty hunter.
Gurunatha Reddy, Senior Security Engineer, Ethical Hacking Team, Oracle. He is a developer turned Security Engineer who would like to help development teams find and fix security bugs. Loves to speak and discuss Cloud and Container Security
Bhagavan Bollina, aka xcriminal is a passionate security researcher who loves to build and break things. He is well versed in different flavors of Security such as Application, Network, and Cloud. He also loves doing bug bounty hunting, he does bug hunting in crowd source platforms like bugcrowd, hackerone.
Pavan Mohan is a developer turned bug hunter and leads the Product Security team at ServiceNow. He is one of the core members of Null Hyderabad chapter and he has been contributing to the info sec community by presenting at Defcon and null events. He leads an open source security tool: Sh00t. He tries his luck in bug bounty programs when he goes out of T-Shirts and made it to some Hall of Fame.
About null:
null is an open security community for ethical hackers, security professionals, and security enthusiasts, born out of the need for:
Promoting advanced security research. Spreading security awareness among the netizens. A Centralized knowledge base for security-related information. All our Null Hyderabad meets are Free and Open to all, just register and join us.
Please reach out to us for additional information: bheemamahesh [at] gmail [dot] com or vhssunny1 [at] gmail [dot] com or me [at] pavanw3b [dot] com
Event schedule
| Time | Session | Speaker | |
|---|---|---|---|
| The Egg Series: How Eggxactly Insecure Deserialization Exploits Work | pavanw3b | ||
| Finding Web Application vulnerabilities with Burp Suite Scan Profiles | MOHAMMAD SAQLAIN | ||
| Curious cases of OAuth misconfigurations | Null Hyderabad | ||
| Mind the Gap: Identifying and Addressing Weaknesses in Your GCP | Null Hyderabad |