<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Workshop on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/workshop/</link>
    <description>Recent content in Workshop on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 16 Jan 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/workshop/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS19 Training Teaser: Hacking mobile applications</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</link>
      <pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile applications” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dog Whisperer’s Handbook</title>
      <link>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</guid>
      <description>&lt;p&gt;Generally speaking, I’m more of a Cat type of guy, but I have to say I really love BloodHound. And if you do too, you are in for a treat…&lt;br&gt;&#xA;Last week, the &lt;a href=&#34;https://twitter.com/ERNW_Insight&#34;&gt;ERNW Insight&lt;/a&gt; &lt;strong&gt;Active Directory Security Summit&lt;/strong&gt; took place in Heidelberg. (&lt;a href=&#34;https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/&#34;&gt;More Info&lt;/a&gt;)&lt;br&gt;&#xA;For this occasion, &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;@Enno_Insinuator&lt;/a&gt; asked me if I would like to deliver a &lt;strong&gt;BloodHound Workshop&lt;/strong&gt;, and of course I accepted the challenge…&lt;/p&gt;&#xA;&lt;p&gt;We had a full class, I had a blast training it, and I hope the trainees enjoyed it as much as I did.&lt;br&gt;&#xA;But that’s not all…&lt;br&gt;&#xA;Another part of the deal was that I had to write a &lt;strong&gt;Training Guide&lt;/strong&gt; that we would then &lt;strong&gt;share with the Community&lt;/strong&gt; (aka you).&lt;br&gt;&#xA;So here it is, fresh from the Heidelberg press and available for download:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Virtualized Training Environment with Ansible</title>
      <link>https://insinuator.net/2018/02/virtualized-training-environment-with-ansible/</link>
      <pubDate>Fri, 02 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/virtualized-training-environment-with-ansible/</guid>
      <description>&lt;p&gt;As Kai and I will be holding a &lt;a href=&#34;https://troopers.de/troopers18/trainings/tr18-automation-with-ansible/&#34;&gt;TROOPERS workshop on automation with ansible&lt;/a&gt;, we needed a setup for the attendees to use &lt;a href=&#34;https://www.ansible.com/&#34;&gt;ansible&lt;/a&gt; against virtual machines we set up with the necessary environment. The idea was, that every attendee has their own VMs to run ansible against, ideally including one to run ansible from, as we want to avoid setup or version incompatibilities if they set up their own ansible environment on their laptop.  Also they should only be able to talk to their own machines, thus avoiding conflicts because of accidental usage of wrong IPs or host names but also simplify the setup for the users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Hacking 101</title>
      <link>https://insinuator.net/2017/01/tr17-training-hacking-101/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/tr17-training-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;Like in recent years the popular &lt;a href=&#34;https://www.troopers.de/events/troopers17/735_hacking_101/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS17, too! The workshop will give attendees an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;information gathering&lt;/li&gt;&#xA;&lt;li&gt;network scanning&lt;/li&gt;&#xA;&lt;li&gt;web application hacking&lt;/li&gt;&#xA;&lt;li&gt;low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that is applicable to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diving Into Real-World Security Threats to SAP Systems</title>
      <link>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</link>
      <pubDate>Wed, 01 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security experts of BIZEC. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;On March 20^(th), the first &lt;a href=&#34;http://www.bizec.org/&#34;&gt;BIZEC&lt;/a&gt; workshop will be held at the amazing Troopers conference in Heidelberg, Germany. For those still unfamiliar with BIZEC: the &lt;em&gt;business application security initiative&lt;/em&gt; is a non-profit organization focused on security threats affecting ERP systems and business-critical infrastructures.&lt;/p&gt;&#xA;&lt;p&gt;The main goals of BIZEC are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Raise awareness, demonstrating that ERP security must be analyzed holistically.&lt;/li&gt;&#xA;&lt;li&gt;Analyze current and future threats affecting these systems.&lt;/li&gt;&#xA;&lt;li&gt;Serve as a unique central point of knowledge and reference in this subject.&lt;/li&gt;&#xA;&lt;li&gt;Provide experienced feedback to global organizations, helping them to increase the security of their business-critical information.&lt;/li&gt;&#xA;&lt;li&gt;Organize events with the community to share and exchange information.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “&lt;a href=&#34;http://http://www.troopers.de/troopers12/agenda/bizec-workshop-sap-security-vulnerabilities-exploits-remediation/&#34;&gt;BIZEC workshop at Troopers 2012&lt;/a&gt;” will dive into the security of SAP platforms. Still to this day, a big part of the Auditing and Information Security industries believe that Segregation of Duties (SoD) controls are enough to protect these business-critical systems.&lt;br&gt;&#xA;By attending this session, InfoSec professionals and SAP security managers will be able to stop “flying blind” with regards to the security of their SAP systems. They will learn why SoD controls are not enough, which current threats exist that could be exploited by evil hackers, and how to protect their business-critical information from cyber-attacks.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
