Time-efficient assessment of open-source projects for Red Teamers
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Show slide in full page or toggle automatic source change | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
It is more and more common to face opensource projects during Red Team engagements. Due to time and efficiency constraints related to such assessments, it is always enjoyable to discover “quick-win” 0day vulnerabilities that will allow progressing in the intrusion and pivoting to critical networks or services. In this talk, we try to describe a methodology that allowed us to quickly discover numerous critical vulnerabilities in a widely-adopted project, GLPI. We will also discuss these findings and the security mechanisms that were implemented and how they were defeated.
Speakers
Thomas Chauchefoin (Synacktiv), Julien Szlamowicz (Synacktiv)
Bio
Thomas and Julien are two security researchers working at Synacktiv. They are mostly interested in web security and they had the possibility to practice it during several years of penetration testing and red team engagements.
Other media in the channel "2019"
- 989 views, 7 this year, 1 this monthPatrOwl - Orchestrating SecOps with an open-source SOAR platformJuly 3rd, 2019
- 139 views, 3 this year, 2 this monthBetter curl !July 3rd, 2019
- 114 views, 12 this yearManaging a growing fleet of WiFi routers combining OpenWRT, WireGuard, Salt and ZabbixJuly 3rd, 2019
- 33 views, 1 this yearNo IT security without Free SoftwareJuly 3rd, 2019
- 34 views, 1 this yearD4 Project - Design and Implementation of an Open Source Distributed and Collaborative Security MonitoringJuly 3rd, 2019
- 15 viewsProgramming research, a missed opportunity for secure and libre software?July 3rd, 2019