Good news:
- THCon prechal (teaser) is out: https://thcon.party/prechallenge/
- FCSC registration is out: https://fcsc.fr/
Good news:
- THCon prechal (teaser) is out: https://thcon.party/prechallenge/
- FCSC registration is out: https://fcsc.fr/
On présente toujours le scoreboard des CTFs avec les premiers. Allez savoir pourquoi, je le préfère comme ça ;-) Et devinez dans quelle équipe j'étais :D
Mes writeups : https://cryptax.github.io
Merci aux organisateurs du CTF (très présents + super architecture blockchain), bravo aux premiers... et à tous !
The slides of my keynote for #THCon are online: https://github.com/cryptax/talks/tree/master/THCon-2023
I forgot/didn't have time:
1. To cite Spiderman: "with great power comes great responsabilities" :D
2. To emphasize why you can't conclude anything from a study on 5000 IoT malware. Why? Because it's no more than 10 days of IoT malware! Do you draw any conclusion on your life out of only 10 days?! + some studies rely on malware from 2017 (or worse). That's too old because cybercriminality evolves quickly.
Later today at THcon, Florent Moriconi, Axel Neergaard, Lucas Georget, Samuel Aubertin and @aurelsec presented what started as an interesting fun student project: modifying a docker client to inject a payload while building a docker container, and then self replicating through CI.
Very interesting. but I have _concerns_ as it creates a *virus*, and is difficult to mitigate.
Maybe publish only when there's a fix? Detection methods?
#malware #ethics #research #thcon #conference