<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Rachelle Boissard on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/rachelle-boissard/</link>
    <description>Recent content in Rachelle Boissard on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 27 Feb 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/rachelle-boissard/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS20 Training Teaser: Attack And Defence In AWS: Chaining Vulnerabilities To Go Beyond The OWASP Top 10</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</link>
      <pubDate>Thu, 27 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</guid>
      <description>&lt;p&gt;Attackers are everywhere. They are now on the cloud too! Attacking the most popular cloud provider – AWS, requires the knowledge of how different services are setup, what defences do we need to bypass, what service attributes can be abused, where can information be leaked, how do I escalate privileges, what about monitoring solutions that may be present in the environment and so on! We try to answer these questions in our intense, hands-on scenario driven training on attacking and subsequently defending against the attacks on AWS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Hacking Node.js &amp; Electron apps, shells, injections and fun!</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</guid>
      <description>&lt;p&gt;Did you know that in the ever evolving field of Web and Desktop apps, it turns out these can all now be powered with JavaScript? You read that right: JavaScript is now used to power both web apps (Node.js) as well as Desktop apps (Electron). What could possibly go wrong?&lt;/p&gt;&#xA;&lt;p&gt;So, the burning question is: how does this affect Web and Desktop app security? If you want to find out, come to our training and you will experience this in a 100% hands-on fashion! 🙂&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Windows &amp; Linux Binary Exploitation</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</link>
      <pubDate>Mon, 04 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</guid>
      <description>&lt;p&gt;We are happy to announce that TROOPERS20 will feature the 5th anniversary of the popular Windows &amp;amp; Linux Binary Exploitation workshop!&lt;/p&gt;&#xA;&lt;p&gt;In this workshop, attendees will learn how to exploit those nasty stack-based buffer overflow vulnerabilities by applying the theoretical methods taught in this course to hands-on exercises. Exercises will be performed for real world (32-bit) software such as the Foxit Reader Plugin for Firefox, Wireshark, and nginx.&lt;/p&gt;&#xA;&lt;p&gt;Each exercise will start with an initially uncontrolled overwrite of the instruction pointer register by a stack-based buffer overflow vulnerability. From there on, we will work our way through many obstacles to finally gain remote code execution. Obstacles that will be encountered during the exercises include modern stack-based buffer overflow defense mechanisms such as stack cookies, data execution prevention (DEP), and address space layout randomization (ASLR). For all of these defense mechanisms, attendees will learn and apply certain methods to bypass the protection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security Summit 2019, 19th of November of 2019</title>
      <link>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</link>
      <pubDate>Wed, 09 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der TROOPERS-Konferenz freuen wir uns, Ihnen heute mit dem Medical Device Security Summit 2019, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Peter Hecko (Leiter der IT-Sicherheit bei HELIOS IT Service GmbH, Podcaster und jahrelanges Mitglied im CCC), gefolgt von Fallstudien und Vorträgen von ERNW Experten und weiteren Referenten aus der Lehre, Industrie und klinischer Praxis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</link>
      <pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;microsoft-it-secure-journey-to-ipv6-only&#34;&gt;Microsoft IT (Secure) Journey to IPv6-Only&lt;/h1&gt;&#xA;&lt;p&gt;Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)&lt;/p&gt;&#xA;&lt;p&gt;The speaker, Veronika McKillop, working at Microsofts network infrastructure services, has given a talk about the process of switching a company network from IPv4 to IPv6-only.&lt;/p&gt;&#xA;&lt;p&gt;Within the talk the following topics were introduced: Dual Stack, Drivers for IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers the reasons why a company would like to switch from IPv4 to IPv6. Technics like NAT64 and DNS64 are introduced. The requirements to software and especially drivers to work in IPv6 environments are described. Also the problems to switch from IPv4 to IPv6-only in heterogeneous networks are addressed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</link>
      <pubDate>Tue, 30 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;from-workstation-to-domain-admin-why-secure-administration-isnt-secure-and-how-to-fix-it-by-sean-metcalf&#34;&gt;From Workstation to Domain Admin: Why Secure Administration Isn’t Secure and How to Fix It by Sean Metcalf&lt;/h1&gt;&#xA;&lt;p&gt;Active Directory is probably used in almost every corporation today to administer all kinds of Authorization, Authentication and Privileges. This means they are valuable targets for attackers, because once compromised they could do whatever they want. This would be the worst case scenario, right? Therefore securing AD is important and this year TROOPERS19 featured a whole track solely for AD Security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Attack &amp; Research Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</link>
      <pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Attack &amp;amp; Research Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;vxlan-security-or-injection-and-protection&#34;&gt;VXLAN Security or Injection, and protection&lt;/h1&gt;&#xA;&lt;p&gt;The talk “VXLAN Security or Injection, and protection” was held by Henrik Lund Kramshøj, who is the owner of Zencurity ApS, a small security company located in Denmark.&lt;/p&gt;&#xA;&lt;p&gt;Henrik gives an overview about lesser known VXLAN insecurities, mostly packet spoofing.&lt;/p&gt;&#xA;&lt;p&gt;In the end he gives advice how to protect against this attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>And Five Talks More Were Accepted at TROOPERS19!</title>
      <link>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</link>
      <pubDate>Mon, 10 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</guid>
      <description>&lt;p&gt;And five talks more were chosen for TROOPERS19! It sounds like it is going to be the best year ever again…&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;——————————–&lt;/p&gt;&#xA;&lt;h1 id=&#34;not-a-security-boundary-breaking-forest-trusts-by-will-schroeder-lee-christensen&#34;&gt;Not A Security Boundary: Breaking Forest Trusts by Will Schroeder, Lee Christensen&lt;/h1&gt;&#xA;&lt;p&gt;Presenting at the Active Directory Security Track&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Abstract:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>First Talks of TROOPERS19 Accepted!</title>
      <link>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</link>
      <pubDate>Thu, 29 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</guid>
      <description>&lt;p&gt;TROOPERS18 was the best year ever (did you check our &lt;a href=&#34;https://troopers.de/archives/&#34;&gt;archives&lt;/a&gt;?) and it will be challenging to do better… However, we accept the challenge!&lt;/p&gt;&#xA;&lt;p&gt;The trainings and talks were from high quality and choices were difficult to make… We hope you will enjoy reading these little teasers!&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Incident Analysis and Digital Forensics Summit 2018, 14th of November of 2018</title>
      <link>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der Troopers-Konferenz freuen wir uns, Ihnen heute mit dem Incident Analysis and Digital Forensics Summit 2018, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Thomas Schreck (Chairman of the Board des internationalen CERT Verbunds FIRST), gefolgt von Fallstudien und Vorträgen durch weitere Referenten aus der Industrie und Strafverfolgung.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
