CSides Monthly Security Meetups
CSides Monthly Security Meetups provide an opportunity to listen to and share security research within the
Canberra region. The meeting occurs normally on the 2nd Friday of every month. Each meetup consists of 1-2 talks
of around 30 mins each. Talks start at 6pm and are followed by some socialising at a local pub.
New attendees are welcome, just come along! (There are no entry fees, and no tickets to book)
The talks at CSides are technical. CSides welcomes new and interesting speakers to present - the topic will be
on a technical or security issue. As a speaker you can be an expert, a student, someone learning a new area or
maybe a regular speaker on the conference circuit, but we also love to have new and occasional speakers. Please
contact one of the organisers below if you are interested in speaking.
You are very welcome to propose running activites other than talks, such as hands-on workshops, an infosec quiz
or something else relevant to our techie audience!
- Location:
- Canberra Rex Hotel
150 Northbourne Ave
Braddon ACT 2612
- Time:
-
6.00pm
- Afterwards:
- Swan & King Bar
Canberra Rex Hotel
- Organisers:
- Kylie McDevitt
Silvio
Cesare
Future Dates:
-
12th April 2024
-
N-Day Exploitation by AA
-
10th May 2024
-
TBA
-
7th June 2024
-
TBA
Friday 15th March 2024
Talk 1: Breaking into Offensive Cyber
This talk discusses the challenges of starting and running a company that specialises in vulnerability research.
Dr Silvio Cesare
Dr Silvio Cesare is a founder and Director at InfoSect, a vulnerability research company. He has worked in technical roles and been involved in computer security for over 29 years. This period includes time in Silicon Valley in the USA, France, and Australia. He has worked commercially in both defensive and offensive roles within engineering. He was previously the Director for Education and Training at UNSW Canberra Cyber, ensuring quality content and delivery. In his early career, he was the lead architect and developer for the startup Qualys, now the industry standard in vulnerability management. He has a Ph.D. from Deakin University and has published in academia, having been cited over 800 times on google scholar. He is a 4-time speaker and also a trainer at the international industry leading Black Hat conference. He has taken his University research through commercialisation and authored a book (Software Similarity and Classification, published by Springer).
Past Talks:
Friday 9th February 2024
Talk 1: Moral combat and gamifying the real world
Controversy over the potential impact of video games on users has come and gone. For some, games enhance
problem-solving skills, increase attention to detail, and even improve hand-to-eye coordination, while for
others, gaming encourages anti-social activities and can lead to problem behaviours. One thing for sure, video
games are not neutral places where everyone simply interacts and plays nicely. They are social, vibrant,
contested, politically charged zones where people of different ideologies compete for the hearts and minds of
audiences.
Steven Coomber
Steven works with the University of Melbourne delivering disinformation and malign influence resilience
workshops and supports the University of Canberra’s information literacy and health educational program for
schools. Steven is intrigued by the video gaming community and its place as a major social, cultural, economic,
and political human interaction medium in the digital age.
Talk 2: I got 99 problems but a 0day aint one
This presentation dives into recent 0day vuln exploited ITW affecting F5's BIG-IP Traffic Management
User-Interface (CVE-2023-46747) during late 2023.. I'll take you into a particular campaign end-to-end, from the
initial access, post-compromise activity, artifact extraction, discovery of nasty go-lang backdoors, and gnarly
opsec fails..
Buckle your seatbelts Dorothy, cause Kansas. is going bye-bye.
Dan
A reformed counterstrike degenerate from the late 90's who irssi'd roflcopters and never slapped anyone with a
large trout. He once tried to install FreeBSD4.5 on his i386. But couldn't defeat the grub boss. Now he's just a
dude trying to be a security dude, and surface insights into bad dudes things.
Friday 10th November 2023
Talk 1: How to best fuzz network services in embedded devices?
This research question is something we've tackled under a research grant provided by Defence Science and
Technology Group (DSTG). Network services can be challenging. Traditional fuzzers deal well with testing file
parsers but struggle to fuzz network programs.
We've built 3 sets of harnesses to fuzz test a variety of services:
- when we have the network service source code
- when we have only the firmware and the service is dynamically linked
- when we have only the firmware and the service is statically linked
Come to this talk and see our unique approaches to fuzz test harnessing.
Dr Silvio Cesare
Dr Silvio Cesare is the CTO and a Managing Director at InfoSect. He has worked in technical roles and been
involved in computer security for over 20 years. This period includes time in Silicon Valley in the USA, France,
and Australia. He has worked commercially in both defensive and offensive roles within engineering. He has
reported hundreds of software bugs and vulnerabilities in Operating Systems kernels. He was previously the
Director for Education and Training at UNSW Canberra Cyber, ensuring quality content and delivery. In his early
career, he was the scanner architect and a C developer at Qualys. He is also the co-founder of BSides Canberra -
Australia’s largest hacker conference. He has a Ph.D. from Deakin University and has published within industry
and academia, is a 4-time Black Hat speaker, gone through academic research commercialisation, and authored a
book (Software Similarity and Classification, published by Springer).