<?xml version="1.0"?>
<rss version="2.0"><channel><title>RSTCon Latest Topics</title><link>https://rstforums.com/forum/forum/69-rstcon/</link><description>RSTCon Latest Topics</description><language>en</language><item><title>RSTCon #3 - CTF</title><link>https://rstforums.com/forum/topic/116414-rstcon-3-ctf/</link><description><![CDATA[<p>
	Platforma pentru CTF este disponibilă. Înregistrările sunt deschise:
</p>

<p>
	 
</p>

<p>
	<a href="https://ctf.rstcon.com/" rel="external nofollow">https://ctf.rstcon.com/</a>
</p>

<p>
	 
</p>

<p>
	Premiile pentru concurs:
</p>

<table>
	<tbody>
		<tr>
			<td>
				Locul I
			</td>
			<td>
				4000 RON
			</td>
		</tr>
		<tr>
			<td>
				Locul II
			</td>
			<td>
				2000 RON
			</td>
		</tr>
		<tr>
			<td>
				Locul III
			</td>
			<td>
				1000 RON
			</td>
		</tr>
		<tr>
			<td>
				Cel mai bun write-up
			</td>
			<td>
				500 RON
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	Premiile sunt oferite din donații de la membrii comunității. Cei care ne pot ajuta cu o donație sunt rugați să ne contacteze la <a href="mailto:contact@rstcon.com" rel="">contact@rstcon.com</a>. Astfel există posibilitatea ca valoarea premiilor să fie mai mare.
</p>

<p>
	 
</p>

<p>
	De asemenea, dacă doriți să ne sprijiniți prin crearea unor exerciții CTF, indiferent de gradul de dificultate sau de tematica abordată, așteptăm un email la <a href="mailto:contact@rstcon.com" rel="">contact@rstcon.com</a>.
</p>

<p>
	 
</p>

<p>
	Pentru discuții referitoare la CTF vom folosi canalul #ctf de pe Discord.
</p>

<p>
	Prezentarea rezultatelor concursului va avea loc la ora 16:00 pe Discord.
</p>

<p>
	 
</p>

<p>
	Informatii complete: <a href="https://rstcon.com/ctf/" rel="external nofollow">https://rstcon.com/ctf/</a>
</p>

<p>
	 
</p>

<p>
	Revin cu detalii. 
</p>
]]></description><guid isPermaLink="false">116414</guid><pubDate>Sat, 25 Feb 2023 21:52:16 +0000</pubDate></item><item><title>RSTCon #3 - Prezentari video</title><link>https://rstforums.com/forum/topic/116561-rstcon-3-prezentari-video/</link><description><![CDATA[<p>
	Playlist: <a href="https://www.youtube.com/playlist?list=PLTaLvwriPW8xBEH3mFrF7d4EB3IB7M8x1" rel="external nofollow">https://www.youtube.com/playlist?list=PLTaLvwriPW8xBEH3mFrF7d4EB3IB7M8x1</a>
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/41f32Nxvtno?feature=oembed" title="RSTCon #3 – Ionut Popescu - Bun venit" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/-mRikgaqjy4?feature=oembed" title="RSTCon #3 - Cristina Florescu - OAuth2.0 si OpenID Connect: o scurta introducere" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/x6Xdi93WmcY?feature=oembed" title="RSTCon #3 - Ionut Cernica - Deanonymization of TOR HTTP hidden services" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/cuBm7cWcpw8?feature=oembed" title="RSTCon #3 - Alexandru Ariciu - Automation for security in high pace environments" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/UCuYb1D5pB8?feature=oembed" title="RSTCon #3 - Jan Rynes - How threat actors abuse DNS" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" src="https://www.youtube-nocookie.com/embed/Av34yoDOCqA?feature=oembed" title="RSTCon #3 - Sebastian Pitei - Hacker’s HomeLab, new and improved." width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/XESz6x1fhFY?feature=oembed" title="RSTCon #3 - Daniel Tomescu - LOTL: Ethical hacking in an adversary environment" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/6Wymc9US4Ik?feature=oembed" title="RSTCon #3 - Eduard Agavriloae - The C2 tool no one talks about: AWS SSM – Run command" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/_0TzNK3rT50?feature=oembed" title="RSTCon #3 - Sorin Baiuta - SOC2 From zero to compliant in 3 months" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/XfxLDR3kB34?feature=oembed" title="RSTCon #3 - Anamaria Ovejan - Vulnerability Management" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/EQNBmDS1jNs?feature=oembed" title="RSTCon #3 - Cosmin Radu - CVE Contextual Analysis Methodology" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/LCmCJuvqszk?feature=oembed" title="RSTCon #3 - Ionut Popescu - Windows Security features" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">116561</guid><pubDate>Sat, 29 Apr 2023 16:16:53 +0000</pubDate></item><item><title>RSTCon #3 - Informatii generale</title><link>https://rstforums.com/forum/topic/116413-rstcon-3-informatii-generale/</link><description><![CDATA[<p>
	RST Con este o conferință online, gratuită, în limba română, adusă la viață de către comunitatea RST. Conferința va avea loc pe 27-28 aprilie 2023 de la 10:00 la 17:00 iar concursul CTF va avea loc de pe 29 aprilie 2023 ora 10:00 până pe 30 aprilie 2023 la ora 17:00. 
</p>

<p>
	 
</p>

<p>
	Conferința se va desfășura folosind platforma Zoom. Înregistrarea și accesarea evenimentului este disponibilă la următoarea adresă:
</p>

<ul>
	<li>
		RSTCon #3 – 27 aprilie – Ziua I: <a href="https://us02web.zoom.us/webinar/register/WN_xKDZ0iklTjWeWcaH34VNsQ" rel="external nofollow">https://us02web.zoom.us/webinar/register/WN_xKDZ0iklTjWeWcaH34VNsQ</a>
	</li>
	<li>
		RSTCon #3 – 28 aprilie – Ziua II: <a href="https://us02web.zoom.us/webinar/register/WN_0Y7IwXCjR4-U1Fcvyj4R9w" rel="external nofollow">https://us02web.zoom.us/webinar/register/WN_0Y7IwXCjR4-U1Fcvyj4R9w</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	Vă rugăm să rețineți că evenimentele Zoom sunt diferite în cele două zile.
</p>

<p>
	 
</p>

<p>
	Linkedin: <a href="https://www.linkedin.com/events/rstcon-37035364565479473152/about/" rel="external nofollow">https://www.linkedin.com/events/rstcon-37035364565479473152/about/</a>
</p>

<p>
	 
</p>

<p>
	Informatii complete pe <a href="https://rstcon.com/" rel="external nofollow">https://rstcon.com/</a>
</p>

<p>
	 
</p>

<p>
	Revin cu informatii.
</p>
]]></description><guid isPermaLink="false">116413</guid><pubDate>Sat, 25 Feb 2023 21:49:26 +0000</pubDate></item><item><title>RSTCon #2 - CTF files</title><link>https://rstforums.com/forum/topic/115469-rstcon-2-ctf-files/</link><description><![CDATA[<p>
	Am incarcat pe Github mare parte din challenge-uri. O sa updatam repository-ul in functie de cum primim sursele.
</p>

<p>
	 
</p>

<p>
	<strong>Crypto</strong>
</p>

<ul>
	<li>
		Coliziune <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/crypto/coliziune" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/crypto/coliziune</a>
	</li>
	<li>
		Hash-uri <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/crypto/hash-uri" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/crypto/hash-uri</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Forensics</strong>
</p>

<ul>
	<li>
		Forensics VM <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/forensics/forensics-vm" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/forensics/forensics-vm</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Miscellaneous</strong>
</p>

<ul>
	<li>
		Apelul interceptat <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/apelul-interceptat" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/apelul-interceptat</a>
	</li>
	<li>
		Discutii <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/discutii" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/discutii</a>
	</li>
	<li>
		Forum <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/forum" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/miscellaneous/forum</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Networking</strong>
</p>

<ul>
	<li>
		Bruteforce <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/networking/bruteforce" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/networking/bruteforce</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Pwn</strong>
</p>

<ul>
	<li>
		Boferk <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/pwn/boferk" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/pwn/boferk</a>
	</li>
	<li>
		PWN Windows <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/pwn/pwn-windows" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/pwn/pwn-windows</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Reversing</strong>
</p>

<ul>
	<li>
		Shellcode <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/shellcode" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/shellcode</a>
	</li>
	<li>
		Crack me <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/crack-me" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/crack-me</a>
	</li>
	<li>
		Pop-up <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/pop-up" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/reversing/pop-up</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Stegano</strong>
</p>

<ul>
	<li>
		Steago <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/stegano/steago" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/stegano/steago</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>Web</strong>
</p>

<ul>
	<li>
		RST Coin <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/rst-coin" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/rst-coin</a>
	</li>
	<li>
		API securizat <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/api-securizat" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/api-securizat</a>
	</li>
	<li>
		Simple Admin Panel <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/simple-admin-panel" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/simple-admin-panel</a>
	</li>
	<li>
		Turnament <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/turnament" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/turnament</a>
	</li>
	<li>
		DNS lookup <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/dns-lookup" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/dns-lookup</a>
	</li>
	<li>
		Eat safe <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/eat-safe" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/eat-safe</a>
	</li>
	<li>
		Inception <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/inception" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/inception</a>
	</li>
	<li>
		Pastebin <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/pastebin" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/pastebin</a>
	</li>
	<li>
		Link <a href="https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/link" rel="external nofollow">https://github.com/RSTCon/rstcon-ctf-II-challenges/tree/main/web/link</a>
	</li>
</ul>
]]></description><guid isPermaLink="false">115469</guid><pubDate>Sat, 26 Mar 2022 12:17:34 +0000</pubDate></item><item><title>RSTCon #2 - Ionut Popescu - Introducere in securitate IT</title><link>https://rstforums.com/forum/topic/115432-rstcon-2-ionut-popescu-introducere-in-securitate-it/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/vbNV-PPUWQs?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	De-a lungul timpului am observat foarte des intrebarea: “Cum sa incep cu domeniul security?”. Exista atat persoane la inceput de drum care isi doresc o cariera pe aceasta cale cat si persoane cu experienta in domeniul IT dornice sa inteleaga ce presupune acest domeniu. Voi incerca sa raspund acestei intrebari din perspectiva personala, oferind sugestii celor care nu stiu cu ce sa inceapa si cum sa porneasca pe acest drum.
</p>
]]></description><guid isPermaLink="false">115432</guid><pubDate>Sun, 20 Mar 2022 01:09:13 +0000</pubDate></item><item><title>RSTCon #2 - Rezultate CTF</title><link>https://rstforums.com/forum/topic/115416-rstcon-2-rezultate-ctf/</link><description><![CDATA[<p>
	Multumim tuturor care au participat la concursul CTF! De asemenea multumim tuturor celor care au creat exercitii!
</p>

<p>
	Clasamentul final poate fi vazut aici: <a href="https://ctf.rstcon.com/scoreboard" rel="external nofollow">https://ctf.rstcon.com/scoreboard</a> 
</p>

<p>
	 
</p>

<p>
	- Locul I - adragos (3000 RON)
</p>

<p>
	- Locul II - Kayn (2000 RON)
</p>

<p>
	- Locul III - edmund (1000 RON)
</p>

<p>
	 
</p>

<p>
	Castigatorii au fost contactati pentru oferirea premiilor.
</p>

<p>
	Exercitiile CTF vor mai ramane online o perioada (1-2 saptamani): <a href="https://ctf.rstcon.com/" rel="external nofollow">https://ctf.rstcon.com/</a> Mentionez ca exercitiul Windows PWN nu a fost rezolvat, prima persoana care o va rezolva va primi un premiu bonus de 1000 RON.
</p>

<p>
	 
</p>

<p>
	Statistici:
</p>

<p>
	- 78 de persoane inregistrate
</p>

<p>
	- 32 au rezolvat cel putin un exercitiu
</p>

<p>
	- 25 au rezolvat probabil cel mai usor exercitiu (Steago)
</p>

<p>
	 
</p>

<p>
	Asteptam parerile voastre referitoare la CTF dar si la exercitii.
</p>

<p>
	De asemenea sper ca la anul sa avem mai multi participanti si mai multe exercitii. 
</p>
]]></description><guid isPermaLink="false">115416</guid><pubDate>Sat, 19 Mar 2022 17:07:49 +0000</pubDate></item><item><title>RSTCon #2 - Ionut Cernica - Hack the hackers: Leaking data over SSL/TLS</title><link>https://rstforums.com/forum/topic/115431-rstcon-2-ionut-cernica-hack-the-hackers-leaking-data-over-ssltls/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/jonFhR5amCE?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Have you considered that in certain situations the way hackers exploit vulnerabilities over the network can be predictable? Anyone with access to encrypted traffic can reverse the logic behind the exploit and thus obtain the same data as the exploit.<br />
	Various automated tools have been analyzed and it has been found that these tools operate in an unsafe way. Various exploit databases were analyzed and we learned that some of these are written in an insecure (predictable) way.<br />
	This presentation will showcase the results of the research, including examples of exploits that once executed can be harmful. The data we obtain after exploitation can be accessible to other entities without the need of decrypting the traffic. The SSL/TLS specs will not change. There is a clear reason for that and in this presentation I will argue this, but what will change for sure is the way hackers will write some of the exploits.
</p>
]]></description><guid isPermaLink="false">115431</guid><pubDate>Sun, 20 Mar 2022 01:08:50 +0000</pubDate></item><item><title>RSTCon #2 - Ovejan Anamaria-Margaret - Security &#x2013; a whac-a-mole game</title><link>https://rstforums.com/forum/topic/115430-rstcon-2-ovejan-anamaria-margaret-security-%E2%80%93-a-whac-a-mole-game/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/tNqmB7mAn84?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	O sa exploram impreuna viata unui blue-teamer. O sa vedem exemple despre cum nimic nu e niciodata sigur, despre cursa de-a soarecele si pisica intre blue-team si atackatori dar si despre cum userii gasesc mereu cate ceva nou si interesant care strica planurile de securitate ale unei firme.
</p>
]]></description><guid isPermaLink="false">115430</guid><pubDate>Sun, 20 Mar 2022 01:08:28 +0000</pubDate></item><item><title>RSTCon #2 - Cristian Cornea - BadUSB 101</title><link>https://rstforums.com/forum/topic/115429-rstcon-2-cristian-cornea-badusb-101/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/Otvc_Xx4glY?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Pe parcursul prezentarii, vom aborda o tema ce se invarte mai mult in jurul Red Teaming-ului, ci anume – BadUSB. Ce este, cum il putem folosi, cateva real-life use case-uri, payload development, si bypass-uri cu acesta (UAC, CLM, AMSI, etc.).
</p>
]]></description><guid isPermaLink="false">115429</guid><pubDate>Sun, 20 Mar 2022 01:08:08 +0000</pubDate></item><item><title>RSTCon #2 - Stefan Nicula si Marian Gusatu - CVE-2022-21882 Windows LPE: tehnici de analiza/detectie</title><link>https://rstforums.com/forum/topic/115428-rstcon-2-stefan-nicula-si-marian-gusatu-cve-2022-21882-windows-lpe-tehnici-de-analizadetectie/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/FW0DFckepAA?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Acest studiu se concentreaza pe analizarea unui exploit recent publicat in luna Ianuarie 2022 ce afecteaza componenta de sistem win32k din Windows kernel si rezulta intr-o vulnerabilitate de tipul elevare de privilegii. Analiza exploiturilor de tipul 1day ne poate ajuta atat pe plan defensiv, prin crearea de detectii relevante asupra celor mai noi tehnicilor de exploatare, cat si in identificare si prevenirea unor noi vulnerabilitati similare in aceleasi componente. Totodata, cercetarea acestui CVE reprezinta un bun exemplu in care patch-urile aplicate initial nu mitigheaza in profunzime problema. In cadrul prezentarii, vom discuta despre notiuni de Windows internals, atacuri de tip data-only, WinDbg kernel debugging si indicatori de detectie, cu un focus principal pe analiza defensiva si intelegerea procesului de exploatare.
</p>
]]></description><guid isPermaLink="false">115428</guid><pubDate>Sun, 20 Mar 2022 01:07:48 +0000</pubDate></item><item><title>RSTCon #2 - Cosmin Radu - Evaluarea Sistemelor din Cloud</title><link>https://rstforums.com/forum/topic/115427-rstcon-2-cosmin-radu-evaluarea-sistemelor-din-cloud/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="150" width="200" data-embed-src="https://www.youtube.com/embed/Ap3kb6xwYcc?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	În ziua de azi, când tot mai multe firme aleg sa isi tina infrastructura în diversele clouduri publice, ar trebui sa putem arunca o privire asupra posibilelor probleme care pot apărea. Vom avea o privire de ansamblu a baseline-ului de securitate în clouduri, diverse tooluri de evaluare a securitatii, apoi vom continua cu o privire spre Lambda și Kubernetes.
</p>
]]></description><guid isPermaLink="false">115427</guid><pubDate>Sun, 20 Mar 2022 01:07:25 +0000</pubDate></item><item><title>RSTCon #2 - Ionut Popescu - Windows Internals</title><link>https://rstforums.com/forum/topic/115426-rstcon-2-ionut-popescu-windows-internals/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/I73PyRDRKZA?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	O detaliere orientata catre incepatori referitoare la modul de functionare intern al sistemului de operare Windows. Vom trece prin arhitectura acestuia, vom vedea componentele, cum interactioneaza intre ele si care este rolul fiecareia.
</p>
]]></description><guid isPermaLink="false">115426</guid><pubDate>Sun, 20 Mar 2022 01:07:02 +0000</pubDate></item><item><title>RSTCon #2 - Ionut Morosan - Introducere in Android Pentesting (Hacking Android Applications)</title><link>https://rstforums.com/forum/topic/115425-rstcon-2-ionut-morosan-introducere-in-android-pentesting-hacking-android-applications/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/AS5Klk4x2h4?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Voi prezenta cate date introductive despre modelul de securitate al SO Android, cateva tipuri de framework-uri pentru dezvoltarea de aplicatii de Android. Voi prezenta cateva tool-uri care sa ajute: MobSF, Frida, Objection, RMS, ADB, Drozer. Dupa care voi prezenta diferite atacuri precum XSS, SQLI, Arbitrary URL Opening, Sensitive data stored Unencrypted, DeepLinking, Bypass Root &amp; SSL Pinning, Dynamic instrumentation to obtain precious data.
</p>
]]></description><guid isPermaLink="false">115425</guid><pubDate>Sun, 20 Mar 2022 01:06:35 +0000</pubDate></item><item><title>RSTCon #2 - Antonio-Dan Macovei si Rare&#x219; Br&#x103;tean - Automated Incident Response in the Cloud</title><link>https://rstforums.com/forum/topic/115424-rstcon-2-antonio-dan-macovei-si-rare%C8%99-br%C4%83tean-automated-incident-response-in-the-cloud/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/WkRZf6ak4kA?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Recently, Amazon Web Services (AWS) cloud environment has reached more than 200 services, which presents both possibilities of business expansion and new concerns, such as an uncontrolled cloud environment, known as cloud sprawl. The more difficult it is to defend a network, the more likely it is that security incidents will occur. Moreover, the current security tools are either expensive or require large amounts of configuration. This research aims to find an automated IR solution that requires minimal configuration and can be used in any AWS environment. The solution is mapped against the first two steps of the NIST IR Life Cycle, namely Preparation and Detection &amp; Analysis. It analyses the feasibility of two potential tools using Python, Lambda and AWS CLI, in a test environment with the ten most common services. Furthermore, AWS services for security logging and alerting are investigated, both premium and non-premium, with the goal to see what data can be extracted from them. The results indicate that the non-premium environment offers extensive data, while the premium ones provide alerts and additional logs that can easily pinpoint malicious activity. Based on the given performance, AWS CLI was considered to be the best alternative. Unlike AWS Lambda, it has no constraints (such as execution times and memory limits) and adds minimal overhead to the environment.
</p>
]]></description><guid isPermaLink="false">115424</guid><pubDate>Sun, 20 Mar 2022 01:06:14 +0000</pubDate></item><item><title>RSTCon #2 - Vrajitoru Vlad - Blockchain Security and Smart Contract Vulnerabilities (EN)</title><link>https://rstforums.com/forum/topic/115423-rstcon-2-vrajitoru-vlad-blockchain-security-and-smart-contract-vulnerabilities-en/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/6f0SyuIYyc8?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	1.Why Blockchain Security?<br />
	2.Blockchain Elements That Need Securing<br />
	3.What is a “Smart Contract”?<br />
	4.Understanding Smart Contracts and their Architecture<br />
	5.Smart Contract Platforms<br />
	6.Applications that integrate with blockchain<br />
	7.Smart Contract Code and vulnerabilities.<br />
	8.Demo: Live Exploit (Maybe).
</p>
]]></description><guid isPermaLink="false">115423</guid><pubDate>Sun, 20 Mar 2022 01:05:52 +0000</pubDate></item><item><title>RSTCon #2 - Daniel Tomescu - Let&#x2019;s build a ransomware!</title><link>https://rstforums.com/forum/topic/115422-rstcon-2-daniel-tomescu-let%E2%80%99s-build-a-ransomware/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/7lQqo2jF_5g?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Let me tell you a story about the time I’ve built a deadly ransomware virus in our secret hacking labs. Of course, the virus got lost into the wild and terrorized the world into a global ransomware epidemy, so that now every computer needs to stay at least 2 switches apart when communicating. Computers are now forced to wear a firewall each time a port is opened. Some say it’s all a conspiracy by Bill Gates to force us to install Windows Defender, others say the Internet will never be the same again…
</p>
]]></description><guid isPermaLink="false">115422</guid><pubDate>Sun, 20 Mar 2022 01:05:30 +0000</pubDate></item><item><title>RSTCon #2 - Ionut Popescu - Introducere</title><link>https://rstforums.com/forum/topic/115421-rstcon-2-ionut-popescu-introducere/</link><description><![CDATA[<div class="ipsEmbeddedVideo">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" width="200" data-embed-src="https://www.youtube.com/embed/MTYdX2hGVXY?feature=oembed"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Deschiderea conferintei ce va include detalii despre organizare, concursul CTF si desfasurarea evenimentului. De asemenea, veti afla mai multe despre comunitatea Romanian Security Team.
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">115421</guid><pubDate>Sun, 20 Mar 2022 01:04:57 +0000</pubDate></item><item><title>RST Con #2 - Informatii generale</title><link>https://rstforums.com/forum/topic/115290-rst-con-2-informatii-generale/</link><description><![CDATA[<p>
	Salut,
</p>

<p>
	 
</p>

<p>
	Din moment ce primavara nu sunt multe conferinte, am decis ca ar fi o perioada ideala pentru RST Con #2. Conferinta va fi online, gratuita si in limba romana.
</p>

<p>
	 
</p>

<p>
	Detalii: <a href="https://rstcon.com/" rel="external nofollow">https://rstcon.com/</a> 
</p>

<p>
	 
</p>

<p>
	<strong>Date conferinta: 17-18 martie 2022 (joi si vineri)</strong>
</p>

<p>
	 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	Events: 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	Linkedin: <a href="https://www.linkedin.com/events/rstcon-26894664423269556224/about/" rel="external nofollow" style="background-color:transparent;">https://www.linkedin.com/events/rstcon-26894664423269556224/about/</a>     
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	Facebook: <a href="https://www.facebook.com/events/312925840851762/" rel="external nofollow" style="background-color:transparent;">https://www.facebook.com/events/312925840851762/</a>  
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	Inregistrare (Zoom): 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	 
</p>

<p style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">
	<span style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">- Prima zi (17 martie):<span> </span></span><a href="https://us02web.zoom.us/webinar/register/7716432416217/WN_ihd6n-QbT9SmhUFEEiOouw" rel="external nofollow" style="background-color:#1c1c1c;font-size:14px;">https://us02web.zoom.us/webinar/register/7716432416217/WN_ihd6n-QbT9SmhUFEEiOouw</a><br style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;" />
	<span style="background-color:#1c1c1c;color:#bfbfbf;font-size:14px;">- A doua zi (18 martie):<span> </span></span><a href="https://us02web.zoom.us/webinar/register/8216433285169/WN_FvmdS_d2SJSo-OJpFaNRMA" rel="external nofollow" style="background-color:#1c1c1c;font-size:14px;">https://us02web.zoom.us/webinar/register/8216433285169/WN_FvmdS_d2SJSo-OJpFaNRMA</a>
</p>

<p>
	 
</p>

<p>
	<strong>Call for papers</strong>: <a href="https://rstcon.com/call-for-papers/" rel="external nofollow">https://rstcon.com/call-for-papers/</a>
</p>

<p>
	<strong>CTF</strong>: <a href="https://rstcon.com/ctf/" rel="external nofollow">https://rstcon.com/ctf/</a>
</p>

<p>
	 
</p>

<p>
	Lucrez in continuare la lucrurile necesare (e.g. platforma CTF).
</p>

<p>
	 
</p>

<p>
	Thanks! 
</p>
]]></description><guid isPermaLink="false">115290</guid><pubDate>Thu, 20 Jan 2022 13:55:22 +0000</pubDate></item><item><title>RST Con #2 - CTF</title><link>https://rstforums.com/forum/topic/115291-rst-con-2-ctf/</link><description><![CDATA[<p>
	Salut,
</p>

<p>
	 
</p>

<p>
	RST Con #2 va avea loc in zilele de 16-17 martie 2022. In aceeasi perioada va avea loc si RST Con CTF #2.
</p>

<p>
	 
</p>

<p>
	Astfel, persoanele interesate de createa unui exercitiu pentru CTF sunt rugate sa ma contacteze prin mesaj privat sau la contact@rstcon.com 
</p>

<p>
	Exercitiile pot fi de orice nivel si pot acoperi orice ramura a "security"-ului.
</p>

<p>
	Daca sunt necesare VPS-uri le veti primi cu ceva timp inainte de CTF. 
</p>

<p>
	Intre timp voi lucra la <a href="https://rstcon.com" rel="external nofollow">https://rstcon.com</a> , platforma CTF si alte lucruri necesare. 
</p>

<p>
	 
</p>

<p>
	De asemenea, vrem sa oferim ca si anul trecut premii castigatorilor. Daca exista persoane care pot dona pentru CTF, astept sa ma contactati. 
</p>

<p>
	 
</p>

<p>
	Daca aveti intrebari sau sugestii, le astept aici.
</p>

<p>
	 
</p>

<p>
	Thanks!
</p>
]]></description><guid isPermaLink="false">115291</guid><pubDate>Thu, 20 Jan 2022 14:00:19 +0000</pubDate></item><item><title>RSTCon #1 - CTF source codes</title><link>https://rstforums.com/forum/topic/114144-rstcon-1-ctf-source-codes/</link><description><![CDATA[<p>
	Mai jos vom posta sursele de la challenge-urile de la CTF-ul RSTCon #1.
</p>
]]></description><guid isPermaLink="false">114144</guid><pubDate>Sun, 13 Dec 2020 13:06:24 +0000</pubDate></item><item><title>RSTCon #1 - CTF write-ups</title><link>https://rstforums.com/forum/topic/114011-rstcon-1-ctf-write-ups/</link><description><![CDATA[<p>
	Premiul pentru cel mai bun write-up a fost castigat de catre 0x435446, felicitari!
</p>

<p>
	Mai jos vom posta write-up-uri.
</p>
]]></description><guid isPermaLink="false">114011</guid><pubDate>Mon, 23 Nov 2020 08:29:47 +0000</pubDate></item><item><title>RSTCon #1 - Rezultate CTF</title><link>https://rstforums.com/forum/topic/113994-rstcon-1-rezultate-ctf/</link><description><![CDATA[<p>
	Concursul CTF din cadrul RSTCon a avut loc pe perioada conferintei, 20 noiembrie 2020 intre orele 10:00 - 18:00.
</p>

<p>
	Multumim tuturor celor care au participat si sper ca le-au placut challenge-urile!
</p>

<p>
	 
</p>

<p>
	Felicitari castigatorilor: <a href="https://ctf.rstcon.com/scoreboard" rel="external nofollow">https://ctf.rstcon.com/scoreboard</a>
</p>

<ul>
	<li>
		Locul I - adragos - 3000 RON
	</li>
	<li>
		Locul II - 0x435446 - 2000 RON
	</li>
	<li>
		Locul III - baietzii_grei - 1000 RON
	</li>
</ul>

<p>
	 
</p>

<p>
	Pe Scoreboard veti vedea si echipa ByteForc3, insa nu sunt romani si nu le-am putut oferi unul dintre premii deoarece conferinta si concursul erau dedicate romanilor. Dar s-au descurcat bine si am decis sa le oferim un premiu onorific de 150 USD. 
</p>

<p>
	 
</p>

<p>
	Asteptam write-up-uri pentru challenge-uri pana duminica seara, mentionand ca avem de oferit un premiu de 500 RON pentru cel mai bun write-up.
</p>

<p>
	 
</p>

<p>
	Daca sunt intrebari, sugestii sau critici referitoare la CTF am vrea sa le stim. 
</p>

<p>
	 
</p>

<p>
	De asemenea, challenge-urile vor mai fi disponibile o perioada, probabil doua saptamani, pentru cei care vor sa le rezolve. Le vom publica si "international" in acest mod. Daca vor fi mai multe persoane interesate, putem extinde perioada in care vor fi disponibile.
</p>
]]></description><guid isPermaLink="false">113994</guid><pubDate>Sat, 21 Nov 2020 15:31:56 +0000</pubDate></item><item><title>RSTCon #1 - Informatii generale</title><link>https://rstforums.com/forum/topic/113993-rstcon-1-informatii-generale/</link><description><![CDATA[<p>
	RSTCon 1 a avut loc pe 20 noiembrie 2020, intre orele 10:00 - 18:30.
</p>

<p>
	As dori sa multumesc tuturor participantilor si suntem curiosi ce parere aveti despre conferinta. 
</p>

<p>
	 
</p>

<p>
	Multumiri speakerilor: Ionut Cernica, Cosmin Radu, Serban Bejan, Andrei Barbu. 
</p>

<p>
	Multumiri echipei care a create challenge-urile pentru concursul CTF: <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/21087-dragos/?do=hovercard" data-mentionid="21087" href="https://rstforums.com/forum/profile/21087-dragos/" rel="">@Dragos</a> , <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/6974-nytr0gen/?do=hovercard" data-mentionid="6974" href="https://rstforums.com/forum/profile/6974-nytr0gen/" rel="">@nytr0gen</a> si <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/99489-dancezar/?do=hovercard" data-mentionid="99489" href="https://rstforums.com/forum/profile/99489-dancezar/" rel="">@dancezar</a>
</p>

<p>
	Multumiri celor care au donat pentru premiile de la concursul CTF: <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/21313-malsploit/?do=hovercard" data-mentionid="21313" href="https://rstforums.com/forum/profile/21313-malsploit/" rel="">@malsploit</a> , <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/21087-dragos/?do=hovercard" data-mentionid="21087" href="https://rstforums.com/forum/profile/21087-dragos/" rel="">@Dragos</a> , <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/99489-dancezar/?do=hovercard" data-mentionid="99489" href="https://rstforums.com/forum/profile/99489-dancezar/" rel="">@dancezar</a> si <span><a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/85034-matasareanu/?do=hovercard" data-mentionid="85034" href="https://rstforums.com/forum/profile/85034-matasareanu/" rel="">@Matasareanu</a></span>
</p>

<p>
	 
</p>

<p>
	<span>Conferinta a fost inregistrata si prezentarile vor fi publicate zilele urmatoare.</span>
</p>
]]></description><guid isPermaLink="false">113993</guid><pubDate>Sat, 21 Nov 2020 15:22:09 +0000</pubDate></item><item><title>RSTCon #1 - Lista prezentari</title><link>https://rstforums.com/forum/topic/114013-rstcon-1-lista-prezentari/</link><description><![CDATA[<p>
	M-am gadit ca ar fi mai practic sa puteti gasi toate prezentarile intr-un singur loc.
</p>

<p>
	 
</p>

<p>
	Playlist Youtube: <a href="https://www.youtube.com/playlist?list=PLTaLvwriPW8y9lcJRXy1UdQLfGDbkkBjD" rel="external nofollow">https://www.youtube.com/playlist?list=PLTaLvwriPW8y9lcJRXy1UdQLfGDbkkBjD</a>
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	Lista prezentărilor RSTCon:
</p>

<p>
	 
</p>

<p>
	10:00 – 11:00 – RST – Trecut, prezent și viitor<br />
	Ionuț Popescu (Nytro) – UiPath<br />
	Romanian Security Team este o comunitate care a luat viață în 2006 și care azi ne aduce împreună. Ce este RST? Ce s-a întamplat în acești 14 ani? De ce merită mai multă atenție? Ce este în prezent această comunitate? Și mai ales, ce viitor are? În această prezentare voi răspunde acestor întrebări și vă voi explica punctul meu de vedere, atât ca persoană cât și ca administrator al comunității.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed300989789" scrolling="no" src="https://rstforums.com/forum/topic/114000-rstcon-1-ionu%C8%9B-popescu-rst-%E2%80%93-trecut-prezent-%C8%99i-viitor/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	11:00 – 12:00 – Real World Bitsquatting Attack<br />
	Ionuț Cernica – iccguard<br />
	Acest studiu practic se referă la exploatarea comportamentului browserelor moderne în legătură cu încărcarea URL-urilor externe. În research-ul meu studiez problema cu acest comportament al browserelor moderne în combinație cu problema “bit flipping” pentru a demonstra un nou tip de atac într-o manieră legală.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed6384234392" scrolling="no" src="https://rstforums.com/forum/topic/114001-rstcon-1-ionu%C8%9B-cernica-real-world-bitsquatting-attack/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	12:00 – 13:00 – Pauza
</p>

<p>
	 
</p>

<p>
	13:00 – 14:00 – Approaching OT Pentesting from an IT perspective<br />
	Cosmin Radu – Atos<br />
	O scurta incursiune în cum se desfășoară un pentest într-un mediu OT (Operational Technology – fabrici, nave maritime, sisteme SCADA, sisteme de control pentru furnizat utilități).<br />
	Care sunt riscurile și challenge-urile când testezi într-un mediu cu 0 downtime fizic, cu TCP/IP stacks proprietare și nu neaparat bine implementate.<br />
	Care sunt diferențele dintre recomandările de mitigare dintre mediul IT și OT?
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed3053823103" scrolling="no" src="https://rstforums.com/forum/topic/114002-rstcon-1-cosmin-radu-approaching-ot-pentesting-from-an-it-perspective/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	14:00 – 15:00 – How to find and exploit data conversion vulnerabilities in web apps<br />
	Șerban Bejan – SecureWorks<br />
	Exportarea datelor în diverse formate (PDF, documente OXML, imagini etc.) este omniprezentă pe web. Voi prezenta cum se poate injecta cod pentru a se ajunge la LFI, SSRF sau execuția de cod JavaScript arbitrar când există funcționalități de conversie. Veți vedea totul în legătură cu pașii necesari pentru a identifica și exploata injecțiile în exporturi și diverse trucuri și sfaturi practice.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed3060922609" scrolling="no" src="https://rstforums.com/forum/topic/114003-rstcon-1-%C8%99erban-bejan-how-to-find-and-exploit-data-conversion-vulnerabilities-in-web-apps/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	15:00 – 16:00 – Introducere în exploituri publice<br />
	Andrei Barbu – SecureWorks<br />
	În această prezentare voi acoperi pe scurt ce este o vulnerabilitate, ce este un exploit și voi vorbi despre exploituri publice.<br />
	Prezentarea va avea și live demo în care voi folosi o versiune outdated de Ubuntu pe care mă voi loga cu un guest account, voi descărca un local exploit pe care-l voi compila și apoi îl voi executa pentru a obține root.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed6041914928" scrolling="no" src="https://rstforums.com/forum/topic/114004-rstcon-1-andrei-barbu-introducere-%C3%AEn-exploituri-publice/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	16:00 – 17:00 – Security Evaluation of WordPress Backup Plugins<br />
	Ionuț Cernica – iccguard<br />
	Protejarea aplicațiilor web e o sarcină importantă pentru orice companie. WordPress este CMS-ul preferat de către companii. În această prezentare vom discuta de ce WordPress e o aplicație web importantă și necesitatea securizării acesteia. Un alt aspect analizat va fi în legătură cu securitatea plugin-urilor folosite pentru backup create pentru WordPress din punctul de vedere al leak-urilor de date sensibile, un număr de module vulnerabile, cauze ale vulnerabilităților, greșeli comune și impactul acestor vulnerabilități. Bazat pe un plan experimental vom observa potențialul distructiv al acestor plugin-uri de backup pe baza celor mai relevante website-uri din topul primelor 10 milioane de website-uri.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed9495469969" scrolling="no" src="https://rstforums.com/forum/topic/114005-rstcon-1-ionu%C8%9B-cernica-security-evaluation-of-wordpress-backup-plugins/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	17:00 – 18:00 – Web pentesting – Sfaturi utile<br />
	Ionuț Popescu – UiPath<br />
	Cu toții știm ce este un XSS și cum să îl găsim, cel puțin în cazurile mai simple. Dar un penetration test trebuie să acopere mult mai mult de atât. Atenția la detalii este cea care rezultă în “finding-uri”. În această prezentare nu voi veni cu lucruri ieșite din comun dar voi trece printr-o listă de sfaturi utile atunci când faceți un pentest. Lista nu este nici pe departe completă, dar sper să vă ajute.
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed1815531192" scrolling="no" src="https://rstforums.com/forum/topic/114006-rstcon-1-ionu%C8%9B-popescu-web-pentesting-%E2%80%93-sfaturi-utile/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	18:00 – 18:20 – Incheiere<br />
	Ionuț Popescu – UiPath<br />
	Ceremonia de încheiere a conferinței și prezentarea rezultatelor concursului CTF (Capture the Flag).
</p>
<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedauthorid="3859" data-embedcontent="" data-embedid="embed8079515270" scrolling="no" src="https://rstforums.com/forum/topic/114007-rstcon-1-ionu%C8%9B-popescu-incheiere-%C8%99i-prezentarea-rezultatelor-concursului-ctf/?do=embed" style="max-width:502px;"></iframe>

<p>
	 
</p>

<p>
	Alte informatii legate de conferinta: <a href="https://rstcon.com/" rel="external nofollow">https://rstcon.com/</a> 
</p>
]]></description><guid isPermaLink="false">114013</guid><pubDate>Mon, 23 Nov 2020 12:25:15 +0000</pubDate></item><item><title>RSTCon #1 - Statistici</title><link>https://rstforums.com/forum/topic/114009-rstcon-1-statistici/</link><description><![CDATA[<p>
	<strong>Conferinta: </strong>
</p>

<ul>
	<li>
		Eveniment Linkedin: 170 de participanti
	</li>
	<li>
		Eveniment Facebook: 68 de participanti
	</li>
	<li>
		Zoom participanti inregistrati: 204
	</li>
	<li>
		Zoom participanti unici: 186 (fara speakers)
	</li>
	<li>
		Zoom participanti maxim online: 95 (fara speakers)
	</li>
	<li>
		Zoom medie participanti: 70-75 (intre 90+ si 50+)
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong>CTF: </strong>
</p>

<ul>
	<li>
		15 challenges
	</li>
	<li>
		80 users registered
	</li>
	<li>
		45 teams registered
	</li>
	<li>
		32 right submissions
	</li>
	<li>
		137 wrong submissions
	</li>
</ul>

<p>
	 
</p>

<p>
	Multumim tuturor celor care au participat, au contribuit sau au transmis mai departe despre eveniment si ne revedem anul viitor!
</p>

<p>
	Mie mi se pare ca a iesit bine pentru o prima editie. 
</p>
]]></description><guid isPermaLink="false">114009</guid><pubDate>Sun, 22 Nov 2020 23:31:50 +0000</pubDate></item></channel></rss>
