BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidesvienna.at//
BEGIN:VTIMEZONE
TZID:Europe/Vienna
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-A7M3LP@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T093000
DTEND;TZID=Europe/Vienna:20231118T100000
DESCRIPTION:This talk investigates security vulnerabilities of the wireless
  communication protocol Bluetooth Low Energy. The discovered vulnerabiliti
 es are united into a threat model using the STRIDE threat modeling approac
 h. The vulnerabilities examined in this thesis range from packet sniffing 
 on the physical layer to sophisticated Machine-in-the-Middle attacks that 
 are built upon address spoofing and jamming attacks. The proposed threat m
 odel also identifies the optional and mandatory dependencies between the a
 ttack vectors.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Bluetooth LE Security  & Threat Modeling - Christopher Skallak
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/A7M3LP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-PWDFZA@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T100500
DTEND;TZID=Europe/Vienna:20231118T110000
DESCRIPTION:If you own a Tesla\, you might be familiar with the PhoneKey fe
 ature that lets you unlock and start your car with your smartphone. But di
 d you know that this feature has some serious security flaws? In this talk
 \, we will show you some of the ways hackers can exploit these vulnerabili
 ties to steal or TEMPA with your Tesla. We will also discuss how Tesla has
  responded to these issues and whether they have fixed them or not.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Project TEMPA - Hacking Teslas for Fun and NO Profit - Martin Herfu
 rt
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/PWDFZA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-F77CXK@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T110500
DTEND;TZID=Europe/Vienna:20231118T115500
DESCRIPTION:Security researchers often have more questions than answers in 
 this domain. The aim of this talk is to give some insights from the suppli
 er's view. So get in and let me take you on a short road-trip through the 
 current threat landscape. Let me show you how the industry picks up speed 
 on vulnerability and incident management\, puts the brakes on emerging thr
 eats and put the pedal to the metal on new security features and solutions
 . New standards and regulations are popping up as traffic signs to lead th
 e way\, but there are many other challenges suppliers have to navigate thr
 ough with car manufacturers\, such as holistic vehicle system security.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Automotive Security Challenges: Supplier's View - Davor Frkat
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/F77CXK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-8HYV9D@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T120000
DTEND;TZID=Europe/Vienna:20231118T123000
DESCRIPTION:The 2022 Verizon Data Breach Investigations Report showed that 
 62% of system intrusion incidents came through a partner. To address this 
 challenge\, organisations across the industry have come together to design
  Minimum Viable Secure Product (MVSP) – a vendor-neutral security baseli
 ne that is designed to eliminate overhead\, complexity and confusion durin
 g the procurement\, RFP and vendor security assessment process by establis
 hing minimum acceptable security baselines for enterprise B2B solutions. \
 nIn this presentation\, we will talk about how Google uses MVSP\, and the 
 goals of the MVSP program to raise the minimum bar for enterprise software
  and services at scale.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Taking third-party risk in stride - Chris John Riley
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/8HYV9D/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-3QCXRM@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T132000
DTEND;TZID=Europe/Vienna:20231118T135000
DESCRIPTION:This talk introduces a new and open platform to track and compa
 re cloud vendors and their broken promises about secure cloud operations. 
 CVEs are not working for cloud vendors and we need a better way than triba
 l knowledge and smoke signals to communicate these issues. The platform pr
 ovides a structured way to search and evaluate past security incidents at 
 cloud vendors.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Tracking Broken Cloud Security Promises - Markus
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/3QCXRM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-H9JFKZ@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T135500
DTEND;TZID=Europe/Vienna:20231118T142500
DESCRIPTION:Tabletops are not a new thing in Incident Response training. Bu
 t oftentimes they’re pretty dull. But wait! What if we made this into a 
 game much like D&D. But instead of fighting orcs with magic you are fighti
 ng a realistic ransomware scenario armed with your D20 playing as the dext
 erous apprentice (who’s always the scapegoat\, right?) along with the re
 st of your team.\n\nThat sounds awesome\, right? You know what? It is!\n\n
 Come to my talk and I’ll tell you about my path to IR role playing\, my 
 experiences and how you can get started doing your own IR role playing gam
 es right away!
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Gamified Incident Response training: The whys\, whats and hows to g
 et you started right away - Klaus Agnoletti
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/H9JFKZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-J9PVUT@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T143000
DTEND;TZID=Europe/Vienna:20231118T150000
DESCRIPTION:Physiotherapy mobile health (mhealth) applications facilitate t
 he remote communication between practitioners and their patients. They pro
 cess and keep track of sensitive health data such as pain levels and train
 ing exercises\, which reveal health issues or physical impairment. In this
  presentation we give an introduction into the methodologies of our securi
 ty and privacy evaluation of four selected physiotherapy mhealth apps comm
 only used in Austria. The static and dynamic analysis of the apps and web 
 interfaces showed alarming results with plenty of room for improvement.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:What is Your Painlevel? - Testing Security and Privacy of Physiothe
 rapy Mhealth Apps - Ines
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/J9PVUT/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-Z7YPBD@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T150500
DTEND;TZID=Europe/Vienna:20231118T160500
DESCRIPTION:Staying under the radar and remaining undetected is one of our 
 priorities during Red Teaming assessments. After all\, we’re simulating 
 real threat actors and want to reach our objectives without raising any su
 spicion. This becomes a more and more challenging task as new defences are
  implemented\, requiring us to add new tools and techniques to our tool be
 lt. Occasionally\, though\, there is a new technique that brings a broad s
 et of features and doesn’t leave countless traces. This talk is about on
 e such technique: beacon object files (BOFs)!\n\nBOFs aren’t exactly the
  new hot stuff\, as a matter of fact\, they’ve been around for more than
  two years now. In those two years\, a de-facto BOF standard has been adap
 ted by many C2 frameworks out there. But what happens when your C2 doesn
 ’t support it? Will you need to fall back to other\, potentially less sa
 fe\, alternative techniques?\n\nThat’s a problem we faced and decided to
  solve when we worked with Brute Ratel C4\, which doesn’t support Cobalt
  Strike’s de-facto BOF standard API. In this talk\, we’ll dig deep int
 o the COFF format\, show how the Cobalt-Strike de-facto standard is incomp
 atible with Brute Ratel’s and how we established full compatibility betw
 een the two. A tool that automates this task and a blog post series about 
 it will be released\, accompanying the talk.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:Introducing CS2BR - Teaching Badgers new Tricks - Patrick Eisenschm
 idt
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/Z7YPBD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7e7-GHURTB@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20231118T161000
DTEND;TZID=Europe/Vienna:20231118T164000
DESCRIPTION:Multiple Zyxel devices are prone to critical vulnerabilities re
 sulting from insecure coding practices and insecure configuration. One of 
 the worst vulnerabilities is an unauthenticated buffer overflow in the cus
 tom "zhttpd" webserver. By bypassing ASLR\, the buffer overflow can be tur
 ned into an unauthenticated remote code execution (RCE). Besides that\, mu
 ltiple other vulnerabilities including unauthenticated file disclosure\, a
 uthenticated command injection and processing of symbolic links on storage
  media were found in the firmware.  \n\n This talk will detail the steps w
 e took to analyze the embedded device and how we reverse engineered the we
 bserver. Furthermore\, we will showcase our Metasploit module that is able
  to gain a root shell on 50+ devices without authentication.
DTSTAMP:20260722T005328Z
LOCATION:Badeschiff
SUMMARY:How to Hack Routers Like it's 1996: Adventures with Zyxel Routers -
  Steffen Robertz\, Gerhard Hechenberger
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7e7/talk/GHURTB/
END:VEVENT
END:VCALENDAR
