Good news:

- THCon prechal (teaser) is out: https://thcon.party/prechallenge/
- FCSC registration is out: https://fcsc.fr/

#thcon #fcsc #ctf #france

Pre-challenge – Toulouse Hacking Convention

Pre-challenge

The #THcon organizers suggested that I take a hotel in the city center and commute to the conference. In spite of bad past experiences in every major city in France, I took their advice and learned why Toulouse does not have a problem with transport strikes: they got rid of the conductors!
Will give a keynote at the Toulouse Hacking Convention today 2pm CEST. You can watch a livestream here: https://www.youtube.com/live/pDwSHoT2g2I #THCon
THCon 2024, day 1/2

YouTube

On présente toujours le scoreboard des CTFs avec les premiers. Allez savoir pourquoi, je le préfère comme ça ;-) Et devinez dans quelle équipe j'étais :D

Mes writeups : https://cryptax.github.io

Merci aux organisateurs du CTF (très présents + super architecture blockchain), bravo aux premiers... et à tous !

#Thcon #CTF #scoreboard

cryptax.github.io

Interesting talk on cheating on online games: intended lags from the attacker, DoS on the victim...
And defenses (sync, predicted and rollbacks...).
#thcon #mmorpg #fortnite #conference

The slides of my keynote for #THCon are online: https://github.com/cryptax/talks/tree/master/THCon-2023

I forgot/didn't have time:
1. To cite Spiderman: "with great power comes great responsabilities" :D
2. To emphasize why you can't conclude anything from a study on 5000 IoT malware. Why? Because it's no more than 10 days of IoT malware! Do you draw any conclusion on your life out of only 10 days?! + some studies rely on malware from 2017 (or worse). That's too old because cybercriminality evolves quickly.

talks/THCon-2023 at master · cryptax/talks

My talks and papers. Contribute to cryptax/talks development by creating an account on GitHub.

GitHub

Later today at THcon, Florent Moriconi, Axel Neergaard, Lucas Georget, Samuel Aubertin and @aurelsec presented what started as an interesting fun student project: modifying a docker client to inject a payload while building a docker container, and then self replicating through CI.

Very interesting. but I have _concerns_ as it creates a *virus*, and is difficult to mitigate.

Maybe publish only when there's a fix? Detection methods?
#malware #ethics #research #thcon #conference

. @yarienkiva et @dascritch auraient-ils le même t shirt @masterbootrec à la #thcon @ToulouseHacking
This morning, @travisgoodspeed walked us through mask ROMs. After some info on how to risk dissolve your bones with some acid substance;-), he focused on the toolchain and how to automate getting bits from microscope images of the #ROM.
#thcon #conference
Pas d'émission aujourd'hui pour cause de .... #thcon ! Si vous êtes à Rangueil pour la @ToulouseHacking , choppez nous : y'a rien à gagner !