BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.toorcon.net//toorcon21
BEGIN:VTIMEZONE
TZID:PST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T100000Z
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T110000Z
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-toorcon21-C8R8BV@talks.toorcon.net
DTSTART;TZID=PST:20191108T090000
DTEND;TZID=PST:20191108T092500
DESCRIPTION:Come early to get registered and hang out with us while we get 
 ready for the event!
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Registration - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/C8R8BV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-XBSPDK@talks.toorcon.net
DTSTART;TZID=PST:20191108T093000
DTEND;TZID=PST:20191108T095500
DESCRIPTION:Listen to some of our announcements for the day at the opening 
 remarks!
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Opening Remarks - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/XBSPDK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-BFT7QS@talks.toorcon.net
DTSTART;TZID=PST:20191108T100000
DTEND;TZID=PST:20191108T102500
DESCRIPTION:In this talk\, we discuss the relationship between information 
 combined under mosaic theory in finance and unintentional disclosures face
 d by security teams. After the talk\, you should be able to present concer
 ns about potentially-risky information to business stakeholders using a fr
 amework they may already know.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Mosaic Theory of Information Security - Margaret Fero
URL:https://talks.toorcon.net/toorcon21/talk/BFT7QS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-WLZ378@talks.toorcon.net
DTSTART;TZID=PST:20191108T103000
DTEND;TZID=PST:20191108T105500
DESCRIPTION:Lets take inventory ... \nMoney: 0\nStaff dedicated to securi
 ty: 0\nIT staff: 0\nYour adversary: Nation-state actors + \nGood luck!\n\n
 Human rights organizations across the globe face an uphill battle trying t
 o detect nation-state actors trying to compromise their systems. What can 
 we do to support them and how does this impact the rest of us?
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Blue Teaming for Human Rights - Megan DeBlois
URL:https://talks.toorcon.net/toorcon21/talk/WLZ378/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-FKJ8BP@talks.toorcon.net
DTSTART;TZID=PST:20191108T110000
DTEND;TZID=PST:20191108T111000
DESCRIPTION:A look at all the ways API's are used in the attack process\, f
 rom ATO (account takeover) and credential abuse automation\, to BOT operat
 ions for inventory sniping and checkout procedures. This can all be automa
 ted and abused thanks to the speed\, ease of use\, and extensibility of AP
 I's.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:API's are not just the 21st century developers mullet\, they're als
 o how you are getting PWND - Tony Lauro
URL:https://talks.toorcon.net/toorcon21/talk/FKJ8BP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-JXT88P@talks.toorcon.net
DTSTART;TZID=PST:20191108T113000
DTEND;TZID=PST:20191108T115500
DESCRIPTION:Developers often do not know what the common issues are with th
 e framework they are using. At the same time\, most common frameworks ship
  with easy ways to shoot your applications security in the foot. In this
  world we live in\, developer education will fail if even one mistake is m
 ade\, which will expose a dangerous vulnerability. In this talk\, well s
 how how you can dramatically reduce the chance developers will shoot thems
 elves in the foot by giving them safer versions of their common tools so y
 our company can ship more secure code.\n	We will write wrapper classes and
  safe versions of common tools to eliminate XSS vectors\, open redirects\,
  XXE\, SSRF\, LFI\, and other dangerous bugs in your codebase. After that 
 well show simple steps to educate developers and gain traction in your o
 rganization. Then well show how easy it is to integrate SAST tools in yo
 ur CI/CD pipeline to ensure your developers use your safe tools rather tha
 n the footguns built into common frameworks.\n	This session is ideal for s
 ecurity engineers interested in eliminating entire classes of security bug
 s inside their code base.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Dont run with scissors: how to standardize the way your developer
 s use dangerous aspects of your framework - Morgan Roman
URL:https://talks.toorcon.net/toorcon21/talk/JXT88P/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-CASQRL@talks.toorcon.net
DTSTART;TZID=PST:20191108T120000
DTEND;TZID=PST:20191108T122500
DESCRIPTION:Dive into a typical Kubernetes cluster by messing with the popu
 lar sidecar containers and supporting infrastructure.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Down the sinkhole with Kubernetes - Alex Ivkin
URL:https://talks.toorcon.net/toorcon21/talk/CASQRL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-G88NTB@talks.toorcon.net
DTSTART;TZID=PST:20191108T123000
DTEND;TZID=PST:20191108T125500
DESCRIPTION:This talk introduces TLSMy.net\, a new DNS-based service that a
 llows home network devices to automatically request certificates that can 
 be used with non-routable or dynamic IP addresses.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:TLSMy.net: Enabling HTTPS for home network devices - Karl Koscher
URL:https://talks.toorcon.net/toorcon21/talk/G88NTB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-TC3YWL@talks.toorcon.net
DTSTART;TZID=PST:20191108T130000
DTEND;TZID=PST:20191108T135500
DESCRIPTION:Go grab a quick bite nearby in Mission Bay or Pacific Beach or 
 at one of the food trucks we'll have available in the parking lot
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Lunch Break - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/TC3YWL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-BTNGWY@talks.toorcon.net
DTSTART;TZID=PST:20191108T140000
DTEND;TZID=PST:20191108T142500
DESCRIPTION:The healthcare industry is traditionally viewed as slow to adop
 t new technologies\, with precious few examples to the contrary! This talk
  is about unfettering the modern (security) engineer\, even in an environm
 ent as restrictive as healthcare\, and without breaking (all the) things.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Real Life Devsecops - pookie
URL:https://talks.toorcon.net/toorcon21/talk/BTNGWY/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-JBKWUZ@talks.toorcon.net
DTSTART;TZID=PST:20191108T143000
DTEND;TZID=PST:20191108T145500
DESCRIPTION:Most commercial static analysis tools today are generic and ine
 ffective. They are not developer oriented as they are built for security p
 rofessionals. In this presentation\, well discuss how we made the proces
 s developer friendly by building a code analysis platform that provides re
 levant findings during code review\, with the help of open source static a
 nalysis tools.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Static code analysis should work for developers\, not for you - Ara
 vind Sreenivasa
URL:https://talks.toorcon.net/toorcon21/talk/JBKWUZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-KFUMNA@talks.toorcon.net
DTSTART;TZID=PST:20191108T150000
DTEND;TZID=PST:20191108T152500
DESCRIPTION:Why do local governments constantly get compromised? What I've 
 learned after leaving my glamorous pentesting job to join a local municipa
 lity.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:From private to public\, working in local government. - Kos (Kyle O
 sborn)
URL:https://talks.toorcon.net/toorcon21/talk/KFUMNA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-FCPGVF@talks.toorcon.net
DTSTART;TZID=PST:20191108T153000
DTEND;TZID=PST:20191108T155500
DESCRIPTION:Someone great once said "pentesting doesn't have to be all drop
 ping exploits and launching shells." I disagree. Not many people truly und
 erstand the grueling task of developing a new campaign\, designing sick do
 cs\, building killer malware\, or why the Red Team operates the way they d
 o during a spearphishing campaign to get those shells. This talk will 
 cover what the Red Team is really doing when they are trying to gain a foo
 thold through social engineering as well as how Blue Teams can leverage th
 is technical insight to combat the dreaded spearphish.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Purple Haze: The SpearPhishing Experience - bash explode
URL:https://talks.toorcon.net/toorcon21/talk/FCPGVF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-8XKVLK@talks.toorcon.net
DTSTART;TZID=PST:20191108T160000
DTEND;TZID=PST:20191108T165500
DESCRIPTION:Registration opens for Red Day and Conference Reception Party s
 tarts. Reception talks start off with 2 Tools Talks\, then Demo / Lightnin
 g Talks\, and then Hacker Jeopardy.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Red Day Registration & Reception Begins - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/8XKVLK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-YPLU3C@talks.toorcon.net
DTSTART;TZID=PST:20191108T163000
DTEND;TZID=PST:20191108T165500
DESCRIPTION:USB seems hard -- and it shouldn't. A serious lack of inexpensi
 ve tooling has made this relatively simple (and near-omnipresent) protocol
  seem overwhelming -- to the point where even 'highly-secured' targets ign
 ore USB as a vector for hacking and reverse engineering. In this talk\, we
  discuss our efforts to dispel USB's aura of mystery -- and empower hacker
 s and engineers to observe and interact directly with USB using a set of o
 pen-source tools that includes analyzers\, fuzzers\, and a variety of othe
 r USB-poking hardware and software.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Hacking Even More USB with USB-Tools - Kate Temkin & Mikaela Szekel
 y
URL:https://talks.toorcon.net/toorcon21/talk/YPLU3C/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-FW7CTM@talks.toorcon.net
DTSTART;TZID=PST:20191108T170000
DTEND;TZID=PST:20191108T172500
DESCRIPTION:Ive created an open source web interface to the Proxmark3-rdv
 4 hardware that makes it easy for anyone to work with the tools. I do a qu
 ick overview of technologies\, and a live demo of the tool.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Card cloning doesn't have to be hard. - David M. N. Bryan - Aka Vid
 eoMan
URL:https://talks.toorcon.net/toorcon21/talk/FW7CTM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3FJ89R@talks.toorcon.net
DTSTART;TZID=PST:20191108T173000
DTEND;TZID=PST:20191108T174000
DESCRIPTION:Even in these modern times\, we still trade credentials for aut
 hentication or session tokens. In typical applications\, session tokens re
 ceived on the client side are stored in either the browser's local storage
  or as cookies. As an attacker\, I want to steal a user's auth token\, hij
 ack their session and then take over their account. The browser and a naiv
 e user are good attack vectors. Well run through how to architect your w
 ebsite to take advantage of various browser-based protections that reduce 
 the impact of common attacks\, such as cross-site scripting and privilege 
 escalation.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Token Up: Keeping Hands out of the Cookie Jar - Erin Browning
URL:https://talks.toorcon.net/toorcon21/talk/3FJ89R/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-PEMWVR@talks.toorcon.net
DTSTART;TZID=PST:20191108T174000
DTEND;TZID=PST:20191108T175000
DESCRIPTION:We present the results of our government-funded R&D to develop 
 an intelligent automated **vulnerability assessor and penetration tester
  (VAPT)**\, usable as a virtual appliance for use on enterprise networks o
 r cyber ranges\, and as a portable device for use on embedded systems. It 
 consists of two parts\, an* AI-supported vulnerability assessor* and an *A
 I-supported penetration tester*. In one use case it intelligently automate
 s software vulnerability assessment for embedded systems\; in another use 
 case\, it intelligently automates the tasks of an ethical hacker (penetrat
 ion tester) via the network\, finding systems on the network\, discovering
  vulnerabilities\, and exposing them.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:AI HACKER! Automatic vulnerability assessment & pen-testing of embe
 dded & other systems - Ulrich Lang\, PhD
URL:https://talks.toorcon.net/toorcon21/talk/PEMWVR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-ESEYYL@talks.toorcon.net
DTSTART;TZID=PST:20191108T175000
DTEND;TZID=PST:20191108T180000
DESCRIPTION:The application of IoT security to medical devices fails from a
  clinical perspective. This session will explore the growing debate on whe
 ther the use of X.509 certificates is the right solution to securing medic
 al devices.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Challenges of X.509 certs - Mike
URL:https://talks.toorcon.net/toorcon21/talk/ESEYYL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-KRKYCT@talks.toorcon.net
DTSTART;TZID=PST:20191108T180000
DTEND;TZID=PST:20191108T181000
DESCRIPTION:This is a discussion about closing the gap between the search f
 or the right job in Infosec\, and resolving the [perceived] shortage in av
 ailable talent.  Well discuss the challenges on both sides\, for employe
 rs and candidates\, touch on some points and truths that are constant\, an
 d identify some tactics for success.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Navigating the Infosec Job Search - Kirsten Sireci Renner
URL:https://talks.toorcon.net/toorcon21/talk/KRKYCT/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-JWDKGW@talks.toorcon.net
DTSTART;TZID=PST:20191108T181000
DTEND;TZID=PST:20191108T182000
DESCRIPTION:[Burp Suite](https://portswigger.net/burp) is the standard tool
  for manipulating HTTP traffic\, but it focuses on manually manipulating r
 equests and responses. This talk presents a Burp extensions that bridges t
 he gap and allows you to automatically manipulate requests using external 
 software\, all within Burp.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Mocking HTTP Services with Burp - Shea Polansky
URL:https://talks.toorcon.net/toorcon21/talk/JWDKGW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-NTKTAJ@talks.toorcon.net
DTSTART;TZID=PST:20191108T182000
DTEND;TZID=PST:20191108T183000
DESCRIPTION:By performing brute force crypt-analysis on public keys to disc
 over private keys we stumbled on someone doing the same thing\, holding ov
 er 8 million USD worth of stolen cryptocurrency.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Ethercombing - Blockchain brute force cryptanalysis - Adrian Bednar
 ek
URL:https://talks.toorcon.net/toorcon21/talk/NTKTAJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-77KKCF@talks.toorcon.net
DTSTART;TZID=PST:20191108T183000
DTEND;TZID=PST:20191108T184000
DESCRIPTION:A 25 minute run-down of everything you need to know to understa
 nd why you should set up a retirement account in your 20s or 30s\, how the
  different ones work (a 401k vs. Roth IRA vs. Traditional IRA) to pick wha
 t's best for you\, how to get you started\, and how to leverage index fund
 s to get you investing without having to make predictions about stocks.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:You're probably a young professional and you should probably be inv
 esting. Here's how. - Mike Arnoult
URL:https://talks.toorcon.net/toorcon21/talk/77KKCF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-BJ3XMP@talks.toorcon.net
DTSTART;TZID=PST:20191108T184000
DTEND;TZID=PST:20191108T185000
DESCRIPTION:What if spotting vulnerabilities in your VPN\, was as easy as c
 hecking for allergens in your applesauce? A Software Bill of Materials (SB
 OM) brings proven supply chain principles to modern software systems.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Blue Team Set Us Up The SBOM - Beau Woods
URL:https://talks.toorcon.net/toorcon21/talk/BJ3XMP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-Q8RFHF@talks.toorcon.net
DTSTART;TZID=PST:20191108T185000
DTEND;TZID=PST:20191108T190000
DESCRIPTION:This talk will focus on the security and attacks against kiosk 
 systems.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Kiosk Red Pills - Somerset Recon
URL:https://talks.toorcon.net/toorcon21/talk/Q8RFHF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-HTMJP9@talks.toorcon.net
DTSTART;TZID=PST:20191108T190000
DTEND;TZID=PST:20191108T191000
DESCRIPTION:Humans are prone to fail\, and fails can happen anywhere. This 
 is a whimsical adventure in severe fails that Pookie has personally encoun
 tered within the past year. We'll describe real "accidental" scenarios whe
 re escalation from partial trust to full systems compromise is possible. (
 no shodan needed)
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:Exploratory Penetration - pookie
URL:https://talks.toorcon.net/toorcon21/talk/HTMJP9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-AZQU7Z@talks.toorcon.net
DTSTART;TZID=PST:20191108T191500
DTEND;TZID=PST:20191108T230000
DESCRIPTION:**Hacker Jeopardy** is back! Get a team together\, test your br
 ains\, and win a place in Vegas at DefCon in 2020.
DTSTAMP:20260717T211306Z
LOCATION:Blue Day
SUMMARY:HACKER JEOPARDY: The Road to Vegas\, Baby! - Geo... Mark? Hardly!!
URL:https://talks.toorcon.net/toorcon21/talk/AZQU7Z/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-LCEZAZ@talks.toorcon.net
DTSTART;TZID=PST:20191109T090000
DTEND;TZID=PST:20191109T092500
DESCRIPTION:Come early to get registered and hang out with us while we get 
 ready for the event!
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Registration - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/LCEZAZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-L7UZHW@talks.toorcon.net
DTSTART;TZID=PST:20191109T093000
DTEND;TZID=PST:20191109T095500
DESCRIPTION:Listen to some of our announcements for the day at the opening 
 remarks!
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Opening Remarks - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/L7UZHW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-KYY8TV@talks.toorcon.net
DTSTART;TZID=PST:20191109T100000
DTEND;TZID=PST:20191109T102500
DESCRIPTION:Utilizing UEFI Firmware Variables to hide malicious payloads fr
 om EDR solutions on both Linux and Windows platforms.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:EDR Is Coming\; Hide Yo Sh!t - Topher Timzen
URL:https://talks.toorcon.net/toorcon21/talk/KYY8TV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-HCVKG7@talks.toorcon.net
DTSTART;TZID=PST:20191109T103000
DTEND;TZID=PST:20191109T105500
DESCRIPTION:The year is 2019. Mainframes rule the world. They've ruled the 
 world since the 1960s\, but i bet you can't even name a single vuln or exp
 loit. This talk aims to change that by presenting current and cutting edge
  research in to mainframe (specifically the big boy itself z/OS) attacks. 
 New techniques and tools will be released.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Cutting Edge Techniques to Pwn the Gibson - Soldier of FORTRAN
URL:https://talks.toorcon.net/toorcon21/talk/HCVKG7/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-UCNHBM@talks.toorcon.net
DTSTART;TZID=PST:20191109T110000
DTEND;TZID=PST:20191109T140000
DESCRIPTION:I'll be available to help you spiff up your resume and do pract
 ice interviews. Come find me on the patio (Patio Track) to discuss.
DTSTAMP:20260717T211306Z
LOCATION:The Patio
SUMMARY:Mock Interview Resume Review Workshop - Kirsten Sireci Renner
URL:https://talks.toorcon.net/toorcon21/talk/UCNHBM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-JACXUM@talks.toorcon.net
DTSTART;TZID=PST:20191109T110000
DTEND;TZID=PST:20191109T112500
DESCRIPTION:On Halloween\, October 31\, 2018\, 2 Black Hills Security Resea
 rchers\, Beau Bullock and Michael Felch disclosed\, step-by-step to Google
  how anyone with a gmail account could add an event\, as "accepted" to any
  Google Calendar via the Google Calendar API.  Google called it a feature.
   Why\, a year later is this not fixed?  This talk will demonstrate how th
 is "calishing" attack can be utilized in a Red Team operation where the ta
 rget organization uses G-Suite.  I will demonstrate this by leveraging an 
 open source python tool that I have developed\, G-Calisher\, based on Beau
  Bullock's and Michael Felch's PowerShell module "Invoke-InjectGEventAPI" 
 from their MailSniper tool.  I will lead the audience through the entire k
 ill chain from recon (How to determine if an organization is using G-suite
  for its email) through Command and Control.  I will also discuss how the 
 organization can stop this attack.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Gone Calishing:  A Red Team Approach to Weaponizing Google Calendar
  and How to Stop It. - Antonio Piazza
URL:https://talks.toorcon.net/toorcon21/talk/JACXUM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-QVNBGH@talks.toorcon.net
DTSTART;TZID=PST:20191109T113000
DTEND;TZID=PST:20191109T115500
DESCRIPTION:Red Teaming inside Google Cloud Platform (GCP): Breach into Tar
 gets\, Expand Access within Kubernetes (K8s) environments\, & Persist!
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:May the Cloud be with You: Red Teaming GCP (Google Cloud Platform) 
 - Bryce Kunz (@TweekFawkes)
URL:https://talks.toorcon.net/toorcon21/talk/QVNBGH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3DBPXG@talks.toorcon.net
DTSTART;TZID=PST:20191109T120000
DTEND;TZID=PST:20191109T122500
DESCRIPTION:During real world attacks and red team engagements using vulner
 able drivers to read\, write\, and allocate is a powerful tool.  This talk
  will cover how to a) load a vulnerable driver in Windows via code samples
  and b) use said vulnerable driver to perform some basic actions (read lsa
 ss\, turn off a service) that a threat actor might do.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Using drivers for kernel operations during a Red Team operation - C
 aleb McGary
URL:https://talks.toorcon.net/toorcon21/talk/3DBPXG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-7DTG9K@talks.toorcon.net
DTSTART;TZID=PST:20191109T123000
DTEND;TZID=PST:20191109T125500
DESCRIPTION:NAT Pinning is a combination of techniques to allow an attacker
  to remotely access any TCP/UDP services bound on a victim machine\, bypas
 sing the victims NAT/firewall (arbitrary firewall pinhole control)\, jus
 t by the victim visiting a website.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:NAT Pinning 2.0: bypassing routers & firewalls via web+NAT abuse - 
 Samy Kamkar
URL:https://talks.toorcon.net/toorcon21/talk/7DTG9K/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-Z3URPX@talks.toorcon.net
DTSTART;TZID=PST:20191109T130000
DTEND;TZID=PST:20191109T135500
DESCRIPTION:Go grab a quick bite nearby in Mission Bay or Pacific Beach or 
 at one of the food trucks we'll have available in the parking lot
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Lunch Break - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/Z3URPX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-9GY7GJ@talks.toorcon.net
DTSTART;TZID=PST:20191109T140000
DTEND;TZID=PST:20191109T142500
DESCRIPTION:Pen testing doesn't have to be all dropping exploits and launch
 ing shells. Learning to ask the right questions at the right time can lead
  to a better understanding of vulnerabilities on your targets than actuall
 y running tests.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Pen testing by asking questions: the Art of Elicitation - Bruce Pot
 ter
URL:https://talks.toorcon.net/toorcon21/talk/9GY7GJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-CVYNXS@talks.toorcon.net
DTSTART;TZID=PST:20191109T143000
DTEND;TZID=PST:20191109T145500
DESCRIPTION:Meltdown (BlackHat USA 2018) was the first instance of a hardwa
 re vulnerability which broke the security guarantees of modern CPUs. Meltd
 own allowed attackers to leak arbitrary memory by exploiting that Intel CP
 Us use lazy fault handling and continue transient execution with data retr
 ieved by faulting loads. With stronger kernel isolation\, a software worka
 round to prevent Meltdown attacks\, and new CPUs with this vulnerability f
 ixed\, Meltdown seemed to be a solved issue. \n\nIn this talk\, we show th
 at Meltdown is still an issue\, on current off-the-shelf CPUs.  We present
  ZombieLoad\, a Meltdown-type attack which leaks data across multiple priv
 ilege boundaries: processes\, kernel\, SGX\, hyperthreads\, and even acros
 s virtual machines. We show that Meltdown mitigations do not affect Zombie
 Load. \nThe ZombieLoad attack can be mounted without any user interactions
  from an unprivileged application\, both on Linux and Windows. \n\nTo demo
 nstrate the danger of the ZombieLoad attack\, we present multiple attacks\
 , such as monitoring the browsing behavior\, stealing cryptographic keys\,
  and leaking the root-password hash on Linux.  In a live demo\, we show th
 at such attacks are not only practical but also easy to mount. We will the
 n discuss mitigations against the ZombieLoad attack. \n\nWe outline challe
 nges for future research on Meltdown-type attacks and mitigations. Finally
 \, we will discuss the short-term and long-term implications for hardware 
 vendors\, software vendors\, and users.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:ZombieLoad: Leaking Data on Intel CPUs - Daniel Moghimi
URL:https://talks.toorcon.net/toorcon21/talk/CVYNXS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-KE9SYU@talks.toorcon.net
DTSTART;TZID=PST:20191109T150000
DTEND;TZID=PST:20191109T152500
DESCRIPTION:Talk will mainly focus on how to write proof-of-concepts for re
 cent processor software side-channels and discovery of MDS attacks rather 
 than explaining processor vulnerabilities themselves.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Writing PoCs for processor software side-channels - Volodymyr Pikhu
 r
URL:https://talks.toorcon.net/toorcon21/talk/KE9SYU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-NPRVVF@talks.toorcon.net
DTSTART;TZID=PST:20191109T153000
DTEND;TZID=PST:20191109T155500
DESCRIPTION:PERCH is a tool that adds a new peripheral layer to Ghidra. The
  parsing of Trace32's .per files enables the augmentation of Ghidra projec
 ts with labeled MMIO mappings from thousands of different processors.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:PERCH: Adding a peripheral layer to Ghidra - Rick Housley
URL:https://talks.toorcon.net/toorcon21/talk/NPRVVF/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-DLKBNB@talks.toorcon.net
DTSTART;TZID=PST:20191109T160000
DTEND;TZID=PST:20191109T162500
DESCRIPTION:All smart devices\, from cars to IoT\, are based around process
 ors. Often these processors are not considered as part of the threat model
  when designing a product: There is an implicit trust that they just work 
 and that the security features in the datasheet do what they say. This is 
 especially fatal when the processors are used for security products\, such
  as bitcoin wallets\, cars\, or authentication tokens.\n\nIn this presenta
 tion we will take a look at using fault injection attacks to break some of
  the most popular IoT processors - using less than 100USD of equipment.\n\
 nWe will also release software & hardware tools to do so.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:chip.fail - Thomas Roth and Josh Datko
URL:https://talks.toorcon.net/toorcon21/talk/DLKBNB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-TSSSHV@talks.toorcon.net
DTSTART;TZID=PST:20191109T163000
DTEND;TZID=PST:20191109T165500
DESCRIPTION:First commercially introduced in 2013\, Cisco Trust Anchor modu
 le(TAm) is\na proprietary hardware security module that is used in a wide 
 range of\nCisco products\, including enterprise routers\, switches and fir
 ewalls.\nTAm is the foundational root of trust that underpins all other Ci
 sco\nsecurity and trustworthy computing mechanisms in such devices. We\ndi
 sclose two 0-day vulnerabilities and show a remotely exploitable\nattack c
 hain that reliably bypasses Cisco Trust Anchor. We present an\nin-depth an
 alysis of the TAm\, from both theoretical and applied\nperspectives. We pr
 esent a series of architectural and practical flaws\nof TAm\, describe the
 oretical methods of attack against such flaws. Next\,\nwe enumerate limita
 tions in current state-of-the-art offensive\ncapabilities that made the de
 sign of TAm seem secure.\nUsing Cisco 1001-X series of Trust Anchor enable
 d routers as a\ndemonstrative platform\, we present a detailed analysis of
  a current\nimplementation of TAm\, including results obtained through har
 dware\nreverse engineering\, Trust Anchor FPGA bitstream analysis\, and th
 e\nreverse engineering of numerous Cisco trustworthy computing mechanisms\
 nthat depend on TAm. Finally\, we present two 0-day vulnerabilities within
 \nCisco IOS and TAm and demonstrate a remotely exploitable attack chain\nt
 hat results in persistent compromise of an up-to-date Cisco router.\nWe di
 scuss the implementation of our TAm bypass\, which involves novel\nmethods
  of reliably manipulating FPGA functionality through bitstream\nanalysis a
 nd modification while circumventing the need to perform RTL\nreconstructio
 n. The use of our methods of manipulation creates numerous\npossibilities 
 in the exploitation of embedded systems that use FPGAs.\nWhile this presen
 tation focuses on the use of our FPGA manipulation\ntechniques in the cont
 ext of Cisco Trust Anchor\, we briefly discuss\nother uses of our bitstrea
 m modification techniques.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:100 Seconds of Solitude: Defeating Cisco Trust Anchor With FPGA Bit
 stream Shenanigans - Jatin Kataria\, Ang Cui
URL:https://talks.toorcon.net/toorcon21/talk/TSSSHV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-BQKKRU@talks.toorcon.net
DTSTART;TZID=PST:20191109T170000
DTEND;TZID=PST:20191109T190000
DESCRIPTION:Come join us for a bonfire luau on the beach next to the event 
 venue to watch the sunset.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Beach Bonfire Luau & Fireside Closing Remarks - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/BQKKRU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-D83HEU@talks.toorcon.net
DTSTART;TZID=PST:20191109T210000
DTEND;TZID=PST:20191110T000000
DESCRIPTION:Head on down to the Gaslamp to party with DJ Keith Myers and Ja
 mes Ford at the Hard Rock hotel! They'll be rocking the dance floor until 
 2am.
DTSTAMP:20260717T211306Z
LOCATION:Red Day
SUMMARY:Party @ The Hard Rock - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/D83HEU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-WMMYUD@talks.toorcon.net
DTSTART;TZID=PST:20191110T100000
DTEND;TZID=PST:20191110T130000
DESCRIPTION:Go skydiving with your fellow hackers! This activity has a fee 
 to cover the skydiving costs. Make sure to register before spots run out: 
 https://www.universe.com/events/toorcon-twenty-one-san-diego-2019-tickets-
 san-diego-M6SPYH\n\nCheck-in with us inside the Tower Club next to the poi
 nt:\nhttp://www.pacificcoastskydiving.com/tandem-sky-diving-in-california-
 weight-limit.htm
DTSTAMP:20260717T211306Z
LOCATION:Skydiving
SUMMARY:Skydiving - bash explode\, Volodymyr Pikhur
URL:https://talks.toorcon.net/toorcon21/talk/WMMYUD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-DBDUXD@talks.toorcon.net
DTSTART;TZID=PST:20191110T100000
DTEND;TZID=PST:20191110T173000
DESCRIPTION:We'll have food available between 10:00 and 13:00 and other act
 ivities all day!
DTSTAMP:20260717T211306Z
LOCATION:The Patio
SUMMARY:Food and Chill - David Hulton
URL:https://talks.toorcon.net/toorcon21/talk/DBDUXD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-ACMTHB@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Join us for a crazy hacker scavenger hunt around Mission Bay an
 d Pacific Beach! Just meet at the fun day patio next to the event venue.
DTSTAMP:20260717T211306Z
LOCATION:Scavenger Hunt
SUMMARY:Scavenger Hunt - Antonio Piazza
URL:https://talks.toorcon.net/toorcon21/talk/ACMTHB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-Z3MKYU@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Make sure to show up on time with your bike! There are numerous
  bike rental shops nearby as well as dockless bikes in the area that you c
 an book with a phone app (Lime\, Mobike\, Ofo\, Spin\, Bird\, etc) in case
  you don't mind how fancy your bike is. We're setting up this bike ride to
  be relatively slow paced so everyone can bike together and will take roug
 hly 2-3 hours for the full round-trip. See you there!
DTSTAMP:20260717T211306Z
LOCATION:Bike Ride
SUMMARY:Bike Ride - Bruce Potter
URL:https://talks.toorcon.net/toorcon21/talk/Z3MKYU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3TJNRE@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Learn to sail and then race your friends! This activity has a f
 ee for the lesson and boat rental. Make sure to register before spots run 
 out: https://www.universe.com/events/toorcon-twenty-one-san-diego-2019-tic
 kets-san-diego-M6SPYH\n\nCheck-In at the lawn in front of the MBSC
DTSTAMP:20260717T211306Z
LOCATION:Sail Boat Racing
SUMMARY:Sail Boat Racing - Thomas Roth and Josh Datko
URL:https://talks.toorcon.net/toorcon21/talk/3TJNRE/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-QV7NJH@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Get trapped with Samy at Belmont Park's Escapology. Includes Th
 e C0d3 and Budapest Express rooms back to back. This activity has a fee fo
 r use of the rooms. Make sure to register before spots run out: https://ww
 w.universe.com/events/toorcon-twenty-one-san-diego-2019-tickets-san-diego-
 M6SPYH\n\nCheck-in at the bar in the Tower Club
DTSTAMP:20260717T211306Z
LOCATION:Escape Rooms
SUMMARY:Escape Rooms - Samy Kamkar
URL:https://talks.toorcon.net/toorcon21/talk/QV7NJH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3LMDZN@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Check out the world famous San Diego Zoo! This activity has a f
 ee to cover your entry ticket and transportation costs. Make sure to regis
 ter before spots run out: https://www.universe.com/events/toorcon-twenty-o
 ne-san-diego-2019-tickets-san-diego-M6SPYH\n\nCheck in on the lawn in fron
 t of the point.
DTSTAMP:20260717T211306Z
LOCATION:San Diego Zoo
SUMMARY:San Diego Zoo - Caleb McGary\, Megan DeBlois
URL:https://talks.toorcon.net/toorcon21/talk/3LMDZN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-LEBFWG@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Head on over to Sea World to see the amazing sea creatures and 
 theme park attractions. This activity has a fee to cover your entry ticket
  and transportation costs. Make sure to register before spots run out: htt
 ps://www.universe.com/events/toorcon-twenty-one-san-diego-2019-tickets-san
 -diego-M6SPYH
DTSTAMP:20260717T211306Z
LOCATION:Sea World
SUMMARY:Sea World - Kashish Mittal
URL:https://talks.toorcon.net/toorcon21/talk/LEBFWG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-AJJMB7@talks.toorcon.net
DTSTART;TZID=PST:20191110T110000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Take a boat out to Hot Tub Island! Just meet at the dock next t
 o the event venue to catch a ride out.
DTSTAMP:20260717T211306Z
LOCATION:Hot Tub Island
SUMMARY:Hot Tub Island - Jatin Kataria\, Ang Cui
URL:https://talks.toorcon.net/toorcon21/talk/AJJMB7/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-8QJJF3@talks.toorcon.net
DTSTART;TZID=PST:20191110T113000
DTEND;TZID=PST:20191110T140000
DESCRIPTION:Rent a Jet Ski to zip around the bay on! Just meet at the dock 
 next to the event venue. Includes an hour of usage and training with the s
 ports center staff.\n\nCheck-In at the lawn in front of the MBSC
DTSTAMP:20260717T211306Z
LOCATION:Jet Skiing
SUMMARY:Jet Skiing - Daniel Moghimi
URL:https://talks.toorcon.net/toorcon21/talk/8QJJF3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3GKASG@talks.toorcon.net
DTSTART;TZID=PST:20191110T140000
DTEND;TZID=PST:20191110T170000
DESCRIPTION:Take a boat out to Hot Tub Island! Just meet at the dock next t
 o the event venue to catch a ride out.
DTSTAMP:20260717T211306Z
LOCATION:Hot Tub Island
SUMMARY:Hot Tub Island - Rick Housley
URL:https://talks.toorcon.net/toorcon21/talk/3GKASG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-J7TQHU@talks.toorcon.net
DTSTART;TZID=PST:20191110T140000
DTEND;TZID=PST:20191110T170000
DESCRIPTION:Rent a Jet Ski to zip around the bay on! Just meet at the dock 
 next to the event venue. Includes an hour of usage and training with the s
 ports center staff.\n\nCheck-In at the lawn in front of the MBSC
DTSTAMP:20260717T211306Z
LOCATION:Jet Skiing
SUMMARY:Jet Skiing - Alex Ivkin
URL:https://talks.toorcon.net/toorcon21/talk/J7TQHU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-T8Z9KB@talks.toorcon.net
DTSTART;TZID=PST:20191110T143000
DTEND;TZID=PST:20191110T173000
DESCRIPTION:We discovered that the conference venue has a Paddle Pub so we 
 decided to switch this to a Microbrew Boat! We'll be stocking the boat wit
 h some of the best beer from Micro Breweries around San Diego and setting 
 sail just in the afternoon. If you're interested in joining the boat\, go 
 see registration during the con and they may be able to fit you in. The bo
 at trip includes beer and captained boat for 2 hours. Make sure to show up
  at 2:30\, the boat will be leaving dock at 3:00pm sharp! https://paddlepu
 b.com/san-diego/\n\nCheck-In at the Hot Tub Cruizin stand in the bathroom 
 courtyard
DTSTAMP:20260717T211306Z
LOCATION:Micro Brewery Tour
SUMMARY:Micro Brewery Boat - Karl Koscher
URL:https://talks.toorcon.net/toorcon21/talk/T8Z9KB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-GRD9NX@talks.toorcon.net
DTSTART;TZID=PST:20191110T150000
DTEND;TZID=PST:20191110T180000
DESCRIPTION:Make sure to show up on time with your bike! There are numerous
  bike rental shops nearby as well as dockless bikes in the area that you c
 an book with a phone app (Lime\, Mobike\, Ofo\, Spin\, Bird\, etc) in case
  you don't mind how fancy your bike is. We're setting up this bike ride to
  be relatively slow paced so everyone can bike together and will take roug
 hly 2-3 hours for the full round-trip. See you there!
DTSTAMP:20260717T211306Z
LOCATION:Bike Ride
SUMMARY:Bike Ride - David M. N. Bryan - Aka VideoMan
URL:https://talks.toorcon.net/toorcon21/talk/GRD9NX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-XJDN3B@talks.toorcon.net
DTSTART;TZID=PST:20191110T150000
DTEND;TZID=PST:20191110T180000
DESCRIPTION:Learn to sail and then race your friends! This activity has a f
 ee for the lesson and boat rental. Make sure to register before spots run 
 out: https://www.universe.com/events/toorcon-twenty-one-san-diego-2019-tic
 kets-san-diego-M6SPYH\n\nCheck-In at the lawn in front of the MBSC
DTSTAMP:20260717T211306Z
LOCATION:Sail Boat Racing
SUMMARY:Sail Boat Racing - Topher Timzen
URL:https://talks.toorcon.net/toorcon21/talk/XJDN3B/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-3EMTZQ@talks.toorcon.net
DTSTART;TZID=PST:20191110T150000
DTEND;TZID=PST:20191110T180000
DESCRIPTION:Join us for a crazy hacker scavenger hunt around Mission Bay an
 d Pacific Beach! Just meet at the fun day patio next to the event venue.
DTSTAMP:20260717T211306Z
LOCATION:Scavenger Hunt
SUMMARY:Scavenger Hunt - Aravind Sreenivasa
URL:https://talks.toorcon.net/toorcon21/talk/3EMTZQ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-toorcon21-GH7ATQ@talks.toorcon.net
DTSTART;TZID=PST:20191110T150000
DTEND;TZID=PST:20191110T180000
DESCRIPTION:Get trapped with Kos at Belmont Park's Escapology. Includes The
  C0d3 and Budapest Express rooms back to back. This activity has a fee for
  use of the rooms. Make sure to register before spots run out: https://www
 .universe.com/events/toorcon-twenty-one-san-diego-2019-tickets-san-diego-M
 6SPYH\n\nCheck-in at the bar in the Tower Club
DTSTAMP:20260717T211306Z
LOCATION:Escape Rooms
SUMMARY:Escape Rooms - Kos (Kyle Osborn)
URL:https://talks.toorcon.net/toorcon21/talk/GH7ATQ/
END:VEVENT
END:VCALENDAR
