CSides Monthly Security Meetups

CSides Monthly Security Meetups provide an opportunity to listen to and share security research within the Canberra region. The meeting occurs normally on the 2nd Friday of every month. Each meetup consists of 1-2 talks of around 30 mins each. Talks start at 6pm and are followed by some socialising at a local pub.

New attendees are welcome, just come along! (There are no entry fees, and no tickets to book)

The talks at CSides are technical. CSides welcomes new and interesting speakers to present - the topic will be on a technical or security issue. As a speaker you can be an expert, a student, someone learning a new area or maybe a regular speaker on the conference circuit, but we also love to have new and occasional speakers. Please contact one of the organisers below if you are interested in speaking.

You are very welcome to propose running activites other than talks, such as hands-on workshops, an infosec quiz or something else relevant to our techie audience!

Location:
Canberra Rex Hotel
150 Northbourne Ave

Braddon ACT 2612

Time:

6.00pm

Afterwards:
Swan & King Bar
Canberra Rex Hotel
Organisers:
Kylie McDevitt
Silvio Cesare

Future Dates:

12th April 2024

N-Day Exploitation by AA

10th May 2024

TBA

7th June 2024

TBA

Friday 15th March 2024

Talk 1: Breaking into Offensive Cyber

This talk discusses the challenges of starting and running a company that specialises in vulnerability research.
Dr Silvio Cesare
Dr Silvio Cesare is a founder and Director at InfoSect, a vulnerability research company. He has worked in technical roles and been involved in computer security for over 29 years. This period includes time in Silicon Valley in the USA, France, and Australia. He has worked commercially in both defensive and offensive roles within engineering. He was previously the Director for Education and Training at UNSW Canberra Cyber, ensuring quality content and delivery. In his early career, he was the lead architect and developer for the startup Qualys, now the industry standard in vulnerability management. He has a Ph.D. from Deakin University and has published in academia, having been cited over 800 times on google scholar. He is a 4-time speaker and also a trainer at the international industry leading Black Hat conference. He has taken his University research through commercialisation and authored a book (Software Similarity and Classification, published by Springer).

To be updated when talks are announced, subscribe to our mailing list

* indicates required

Past Talks:

Friday 9th February 2024

Talk 1: Moral combat and gamifying the real world
Controversy over the potential impact of video games on users has come and gone. For some, games enhance problem-solving skills, increase attention to detail, and even improve hand-to-eye coordination, while for others, gaming encourages anti-social activities and can lead to problem behaviours. One thing for sure, video games are not neutral places where everyone simply interacts and plays nicely. They are social, vibrant, contested, politically charged zones where people of different ideologies compete for the hearts and minds of audiences.
Steven Coomber
Steven works with the University of Melbourne delivering disinformation and malign influence resilience workshops and supports the University of Canberra’s information literacy and health educational program for schools. Steven is intrigued by the video gaming community and its place as a major social, cultural, economic, and political human interaction medium in the digital age.
Talk 2: I got 99 problems but a 0day aint one 
This presentation dives into recent 0day vuln exploited ITW affecting F5's BIG-IP Traffic Management User-Interface (CVE-2023-46747) during late 2023.. I'll take you into a particular campaign end-to-end, from the initial access, post-compromise activity, artifact extraction, discovery of nasty go-lang backdoors, and gnarly opsec fails..

Buckle your seatbelts Dorothy, cause Kansas. is going bye-bye.
Dan
A reformed counterstrike degenerate from the late 90's who irssi'd roflcopters and never slapped anyone with a large trout. He once tried to install FreeBSD4.5 on his i386. But couldn't defeat the grub boss. Now he's just a dude trying to be a security dude, and surface insights into bad dudes things.

Friday 10th November 2023

Talk 1: How to best fuzz network services in embedded devices?
This research question is something we've tackled under a research grant provided by Defence Science and Technology Group (DSTG). Network services can be challenging. Traditional fuzzers deal well with testing file parsers but struggle to fuzz network programs.

We've built 3 sets of harnesses to fuzz test a variety of services:

  1. when we have the network service source code
  2. when we have only the firmware and the service is dynamically linked
  3. when we have only the firmware and the service is statically linked

Come to this talk and see our unique approaches to fuzz test harnessing.

Dr Silvio Cesare
Dr Silvio Cesare is the CTO and a Managing Director at InfoSect. He has worked in technical roles and been involved in computer security for over 20 years. This period includes time in Silicon Valley in the USA, France, and Australia. He has worked commercially in both defensive and offensive roles within engineering. He has reported hundreds of software bugs and vulnerabilities in Operating Systems kernels. He was previously the Director for Education and Training at UNSW Canberra Cyber, ensuring quality content and delivery. In his early career, he was the scanner architect and a C developer at Qualys. He is also the co-founder of BSides Canberra - Australia’s largest hacker conference. He has a Ph.D. from Deakin University and has published within industry and academia, is a 4-time Black Hat speaker, gone through academic research commercialisation, and authored a book (Software Similarity and Classification, published by Springer).