SlideShare a Scribd company logo
1 of 123
Connect | Protect | Optimize
Irrational, But Effective
(Applying Parenthood Lessons to Cyber Security)
Rafal Los – VP, Chief Security Strategist
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
./whoami
Just in case you don’t know me
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
strategist, advisor
strategy executive
~25 years in ”the business”
writer
a guy who knows a few things
VP, Chief Security Strategist –
Lightstream Managed Services
professional smartass
Founder
Down the Security Rabbithole Podcast
father of twins
DO
NOT
BE
FOOLED
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 1:
Worry when everything is quiet
silence is terrifying to security people
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
when my kids are loud,
I don’t worry
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
when my kids are quiet,
I start to panic
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
3 types of baddies
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“those that set off alarms”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“those that leave a trail”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“ghosts”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
ghosts leave nothing*
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
but can be devastating
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
hunt threats in the quiet
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 2:
You can’t prevent every possible oops
bad things will happen, contain the disaster
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
you can teach them
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
you can warn them
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
but bad sh** will happen
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
sorry, it’s true
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
prepare them
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
design contingency plans
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
practice regularly
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
involve everyone
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
build containment in
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
practice reduces panic
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 3:
Creativity beats boundaries every time
always think about human creativity
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
kids and hackers
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
demonstrate amazing
creativity
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
often used phrase:
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“How the hell did they
manage to do that?!”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
both work ‘around’ controls
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
I put cookies on the top
shelf in pantry…
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
my daughter used my SON as a
ladder
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
hack outside the box
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 4:
Your reaction matters more than the
ouchie
never let them see you sweat or panic
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
the first time your child
falls
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
they look at your reaction
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
how you react influences
their next move
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
if you remain calm, steady
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
your customers will too
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
resist the urge to PANIC
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
appearances matter
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 5:
They know better, but will do it
anyway
two words: compensating controls
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“I know I’m not supposed to
do that, but…”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
don’t pretend you haven’t
done it
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
recognize this is human
nature
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
what’s the impact?
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
sometimes,
you get away with it
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
sometimes,
you don’t
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
we provide “training”…
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
training != behavior
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
assume they’ll break rules
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
implement compensating
controls
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
three strikes rule?
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
“training” no guarantee
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 6:
You, the expert, is never right
the frog won’t believe it’s being boiled
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
”dad, my friend said…”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
authority and expertise
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
are not absolute
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
perception matters
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
proximity matters
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
relationships matter
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be present
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be relatable
Complexity Averted.
Possibilities Realized.
© 2019 Lightstream
Communications. All rights reserved.
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be “human”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
aka: “don’t be a .. donkey”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
your authority only matters
if they accept it
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 7:
They love you until you tell them no
prepare to be the enemy, it’s OK
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
my kids love me,
unconditionally
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
until it’s time for bed
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
or I have to say no
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
what happens next is odd-
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
they can turn quickly
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
animosity is temporary
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
trust your policy
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
what you want is respect
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be fair
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
be respected always,
liked usually
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 8:
Sometimes you must meet them half-
way, or else
you can’t fight water, but you can direct it
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
sometimes policy needs
flexibility
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
homework is a priority
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
but it’s going to rain later
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
play now, promise homework
later
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
enforce the promise
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
works the same in business
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be appropriately flexible
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
absolutists always lose
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
nobody likes a dictator
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
flex, but don’t abandon
principles / policy
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
if you don’t strategically
bend
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
policy will be subverted
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
grant limited exceptions
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 9:
Be a friend, and an authority; but
know the difference
people will take advantage if you let them
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
children need balance
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be their friend
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
but know limitations
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
and sometimes you’ll have to
be “aww dad!”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
be your customer’s buddy
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
but have boundaries
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
our job is relationships
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
without them, we’re tyrants
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
coach, counsel
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
enforce limitations
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take-away:
master relationships
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Lesson 10:
Tomorrow won’t be better, or worse;
just different
maturity brings different types of disaster scenarios
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
parents-to-be ask:
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
“is year 8 easier than 2?”
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
nope, just different
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
challenges at 2
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
challenges at 8
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
challenges at 18
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
risk shifts, threats change
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
as your org matures, this
applies
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
bigger companies,
smaller companies
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
different problems
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
different threats
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
different scope
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
security challenges change
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
security teams adapt
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
threats, challenges change
as org matures
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
take—way:
a rock that won’t move, is
worn away slowly
Complexity Averted. Possibilities Realized. © 2021 Lightstream Communications. All rights reserved.
Thank you!
• Where to find me
- Twitter
• @Wh1t3Rabbit and @DtSR_Podcast
- Down the Security Rabbithole Podcast
• iTunes, RSS (https://ftwr.libsyn.com), and almost literally anywhere else
- Lightstream – Consulting, Professional & Managed Services
• www.Lightstream.tech
- LinkedIn:
• https://www.linkedin.com/in/rmlos/
• https://www.linkedin.com/company/down-the-security-rabbithole-podcast
Complexity Averted.
Possibilities Realized.
www.lightstream.tech

More Related Content

More from Rafal Los

Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...
Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...
Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...Rafal Los
 
Cloud Security Alliance- Challanges of an elastic environment v8a [public]
Cloud Security Alliance- Challanges of an elastic environment v8a [public]Cloud Security Alliance- Challanges of an elastic environment v8a [public]
Cloud Security Alliance- Challanges of an elastic environment v8a [public]Rafal Los
 
Threat modeling the security of the enterprise
Threat modeling the security of the enterpriseThreat modeling the security of the enterprise
Threat modeling the security of the enterpriseRafal Los
 
Making Measurable Gains - Contextualizing 'Secure' in Business
Making Measurable Gains - Contextualizing 'Secure' in BusinessMaking Measurable Gains - Contextualizing 'Secure' in Business
Making Measurable Gains - Contextualizing 'Secure' in BusinessRafal Los
 
Security BSides Atlanta - "The Business Doesn't Care..."
Security BSides Atlanta - "The Business Doesn't Care..."Security BSides Atlanta - "The Business Doesn't Care..."
Security BSides Atlanta - "The Business Doesn't Care..."Rafal Los
 
Software Security Assurance - Program Building (You're going to need a bigger...
Software Security Assurance - Program Building (You're going to need a bigger...Software Security Assurance - Program Building (You're going to need a bigger...
Software Security Assurance - Program Building (You're going to need a bigger...Rafal Los
 
The Future of Software Security Assurance
The Future of Software Security AssuranceThe Future of Software Security Assurance
The Future of Software Security AssuranceRafal Los
 
Defying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with AutomationDefying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with AutomationRafal Los
 
Ultimate Hack! Layers 8 & 9 of the OSI Model
Ultimate Hack! Layers 8 & 9 of the OSI ModelUltimate Hack! Layers 8 & 9 of the OSI Model
Ultimate Hack! Layers 8 & 9 of the OSI ModelRafal Los
 
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)Rafal Los
 
Oh No They Didn't! 7 Web App Security Stories (v1.0)
Oh No They Didn't! 7 Web App Security Stories (v1.0)Oh No They Didn't! 7 Web App Security Stories (v1.0)
Oh No They Didn't! 7 Web App Security Stories (v1.0)Rafal Los
 
The QA Analyst's Hacker's Landmark Tour v3.0
The QA Analyst's Hacker's Landmark Tour v3.0The QA Analyst's Hacker's Landmark Tour v3.0
The QA Analyst's Hacker's Landmark Tour v3.0Rafal Los
 
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2Rafal Los
 
Sans Feb 2010 - When Web 2 0 Attacks v3.3
Sans Feb 2010 - When Web 2 0 Attacks v3.3Sans Feb 2010 - When Web 2 0 Attacks v3.3
Sans Feb 2010 - When Web 2 0 Attacks v3.3Rafal Los
 
StarWest 2009 - Detective Work For Testers: Finding Workflow Based Defects
StarWest 2009 - Detective Work For Testers: Finding Workflow Based DefectsStarWest 2009 - Detective Work For Testers: Finding Workflow Based Defects
StarWest 2009 - Detective Work For Testers: Finding Workflow Based DefectsRafal Los
 
SecTor '09 - When Web 2.0 Attacks!
SecTor '09 - When Web 2.0 Attacks!SecTor '09 - When Web 2.0 Attacks!
SecTor '09 - When Web 2.0 Attacks!Rafal Los
 
A Laugh RIAt -- OWASP 2009 Web 2.0 Talk
A Laugh RIAt -- OWASP 2009 Web 2.0 TalkA Laugh RIAt -- OWASP 2009 Web 2.0 Talk
A Laugh RIAt -- OWASP 2009 Web 2.0 TalkRafal Los
 
Creating Practical Security Test-Cases for Web Applications
Creating Practical Security Test-Cases for Web ApplicationsCreating Practical Security Test-Cases for Web Applications
Creating Practical Security Test-Cases for Web ApplicationsRafal Los
 
Total Browser Pwnag3 V1.0 Public
Total Browser Pwnag3   V1.0 PublicTotal Browser Pwnag3   V1.0 Public
Total Browser Pwnag3 V1.0 PublicRafal Los
 

More from Rafal Los (19)

Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...
Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...
Rebooting the Enterprise Security Program for Defensibility - ISSA Internatio...
 
Cloud Security Alliance- Challanges of an elastic environment v8a [public]
Cloud Security Alliance- Challanges of an elastic environment v8a [public]Cloud Security Alliance- Challanges of an elastic environment v8a [public]
Cloud Security Alliance- Challanges of an elastic environment v8a [public]
 
Threat modeling the security of the enterprise
Threat modeling the security of the enterpriseThreat modeling the security of the enterprise
Threat modeling the security of the enterprise
 
Making Measurable Gains - Contextualizing 'Secure' in Business
Making Measurable Gains - Contextualizing 'Secure' in BusinessMaking Measurable Gains - Contextualizing 'Secure' in Business
Making Measurable Gains - Contextualizing 'Secure' in Business
 
Security BSides Atlanta - "The Business Doesn't Care..."
Security BSides Atlanta - "The Business Doesn't Care..."Security BSides Atlanta - "The Business Doesn't Care..."
Security BSides Atlanta - "The Business Doesn't Care..."
 
Software Security Assurance - Program Building (You're going to need a bigger...
Software Security Assurance - Program Building (You're going to need a bigger...Software Security Assurance - Program Building (You're going to need a bigger...
Software Security Assurance - Program Building (You're going to need a bigger...
 
The Future of Software Security Assurance
The Future of Software Security AssuranceThe Future of Software Security Assurance
The Future of Software Security Assurance
 
Defying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with AutomationDefying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with Automation
 
Ultimate Hack! Layers 8 & 9 of the OSI Model
Ultimate Hack! Layers 8 & 9 of the OSI ModelUltimate Hack! Layers 8 & 9 of the OSI Model
Ultimate Hack! Layers 8 & 9 of the OSI Model
 
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)
Into the Rabbithole - Evolved Web App Security Testing (OWASP AppSec DC)
 
Oh No They Didn't! 7 Web App Security Stories (v1.0)
Oh No They Didn't! 7 Web App Security Stories (v1.0)Oh No They Didn't! 7 Web App Security Stories (v1.0)
Oh No They Didn't! 7 Web App Security Stories (v1.0)
 
The QA Analyst's Hacker's Landmark Tour v3.0
The QA Analyst's Hacker's Landmark Tour v3.0The QA Analyst's Hacker's Landmark Tour v3.0
The QA Analyst's Hacker's Landmark Tour v3.0
 
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2
Magic Numbers - 5 KPIs for Measuring SSA Program Success v1.3.2
 
Sans Feb 2010 - When Web 2 0 Attacks v3.3
Sans Feb 2010 - When Web 2 0 Attacks v3.3Sans Feb 2010 - When Web 2 0 Attacks v3.3
Sans Feb 2010 - When Web 2 0 Attacks v3.3
 
StarWest 2009 - Detective Work For Testers: Finding Workflow Based Defects
StarWest 2009 - Detective Work For Testers: Finding Workflow Based DefectsStarWest 2009 - Detective Work For Testers: Finding Workflow Based Defects
StarWest 2009 - Detective Work For Testers: Finding Workflow Based Defects
 
SecTor '09 - When Web 2.0 Attacks!
SecTor '09 - When Web 2.0 Attacks!SecTor '09 - When Web 2.0 Attacks!
SecTor '09 - When Web 2.0 Attacks!
 
A Laugh RIAt -- OWASP 2009 Web 2.0 Talk
A Laugh RIAt -- OWASP 2009 Web 2.0 TalkA Laugh RIAt -- OWASP 2009 Web 2.0 Talk
A Laugh RIAt -- OWASP 2009 Web 2.0 Talk
 
Creating Practical Security Test-Cases for Web Applications
Creating Practical Security Test-Cases for Web ApplicationsCreating Practical Security Test-Cases for Web Applications
Creating Practical Security Test-Cases for Web Applications
 
Total Browser Pwnag3 V1.0 Public
Total Browser Pwnag3   V1.0 PublicTotal Browser Pwnag3   V1.0 Public
Total Browser Pwnag3 V1.0 Public
 

Recently uploaded

"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentationphoebematthew05
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 

Recently uploaded (20)

"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentation
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 

Irrational But Effective - Applying Parenthood Lessons to Cyber Security