Загрузка страницы

Nullcon Berlin 2023 | Why I Write My Own Security Tooling & Why You Should Too! by James Forshaw

Abstract:
---------------
It's easy to be impatient when doing security research, you want bugs now! But where to start? Is there source code to review? Do you have binaries to disassemble? My opinion, start by writing some domain specific tooling. There are many advantages to writing your own tooling for a research project. It'll help you better understand the technologies you're investigating which in turn helps you find more interesting vulnerabilities.

In this presentation I'll discuss the many benefits of writing your own tooling even if it delays that first, amazing find. I'll show examples of tools I've written to aid in my Windows research career and take a peek at some bugs I wouldn't have found without them. Finally I'll make the case for why writing your own tools will make you a better researcher.

#securitytools #opensource #Infosec #NullconBerlin
------------------------------------------------------------------------------------------------------
Follow nullcon on Facebook: https://www.facebook.com/nullcon
Twitter: https://twitter.com/nullcon
LinkedIn: http://linkedin.com/company/nullcon/
Website: https://nullcon.net

Видео Nullcon Berlin 2023 | Why I Write My Own Security Tooling & Why You Should Too! by James Forshaw канала nullcon
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
3 апреля 2023 г. 14:00:09
00:41:49
Другие видео канала
Tech Startups/Businesses and Infonomics | CXO Panel | Nullcon Security Conference March 2021Tech Startups/Businesses and Infonomics | CXO Panel | Nullcon Security Conference March 2021Nullcon Berlin 2023 | Not So Famous Attack Vectors In The World Of Smart Contract Security!Nullcon Berlin 2023 | Not So Famous Attack Vectors In The World Of Smart Contract Security!Saikat Datta at NULLCON | #Nullcon2020 DiarySaikat Datta at NULLCON | #Nullcon2020 DiaryAI vs. Pandemic by Sneha Banerjee | Winja Talks 2021AI vs. Pandemic by Sneha Banerjee | Winja Talks 2021CXO Panel | Securing India The CERTIn Way | Nullcon Goa 2022CXO Panel | Securing India The CERTIn Way | Nullcon Goa 2022nullcon Goa 2017 - DevOpSec: Rapid Security In The AWS Cloud by Mikhail Advani and Rajesh Tamhanenullcon Goa 2017 - DevOpSec: Rapid Security In The AWS Cloud by Mikhail Advani and Rajesh TamhaneNullcon Goa 2021 is back in TownNullcon Goa 2021 is back in TownCloud Security Posture Management & Threat Protection | Suman & Sakaldeep | Nullcon Webinars 2022Cloud Security Posture Management & Threat Protection | Suman & Sakaldeep | Nullcon Webinars 2022Nullcon Goa 2023 | Uncovering Azure's Silent Threats: A Journey Into Cloud Vulnerabilities by NiteshNullcon Goa 2023 | Uncovering Azure's Silent Threats: A Journey Into Cloud Vulnerabilities by NiteshBhadra framework: Threat modeling for mobile communication systems by Sid Rao | Nullcon Webinar 2021Bhadra framework: Threat modeling for mobile communication systems by Sid Rao | Nullcon Webinar 2021nullcon Goa 2014: Flowinspect  A Network Inspection Tool by Ankur Tyagi @7h3rAmnullcon Goa 2014: Flowinspect A Network Inspection Tool by Ankur Tyagi @7h3rAmnullcon Goa 2015: The NSA Playset  RF Retroreflectors by Michael Ossmannnullcon Goa 2015: The NSA Playset RF Retroreflectors by Michael OssmannReversing and De-Obfuscating Malware with Software Emulation | Nullcon Webinar 2022Reversing and De-Obfuscating Malware with Software Emulation | Nullcon Webinar 2022nullcon Goa 2018 - Talk with Expertsnullcon Goa 2018 - Talk with ExpertsmacOS Security Features Bypasses by Example | Jonathan Bar Or (JBO) | Nullcon Webinars 2022macOS Security Features Bypasses by Example | Jonathan Bar Or (JBO) | Nullcon Webinars 2022nullcon Goa 2017 - CXO Panel 'Digital Warriors: India And The Future Of Conflict On The Internet'nullcon Goa 2017 - CXO Panel 'Digital Warriors: India And The Future Of Conflict On The Internet'What is Cyber Threat Intelligence | Rishika Desai | Winja UnpluggedWhat is Cyber Threat Intelligence | Rishika Desai | Winja UnpluggedSecuring the Human Factor | CXO Panel Discussion | NULLCON Goa 2020Securing the Human Factor | CXO Panel Discussion | NULLCON Goa 2020Taking the guess out of Glitching! | Adam Laurie | NULLCON Goa 2020Taking the guess out of Glitching! | Adam Laurie | NULLCON Goa 2020A Kernel Hacker Meets Fuchsia OS | Alexander Popov | Nullcon Goa 2022A Kernel Hacker Meets Fuchsia OS | Alexander Popov | Nullcon Goa 2022Threat Research & Fortnite Scams  | Ben Herzberg | nullcon InterviewsThreat Research & Fortnite Scams | Ben Herzberg | nullcon Interviews
Яндекс.Метрика