Date | Day | Time | Duration |
20 Nov | Monday | 09:00 to 17:00 SGT/GMT +8 | 8 Hours |
21 Nov | Tuesday | 09:00 to 17:00 SGT/GMT +8 | 8 Hours |
22 Nov | Wednesday | 09:00 to 17:00 SGT/GMT +8 | 8 Hours |
A lot of exclusive lab environment and a lot of content and labs would be designed specifically for HITB. (first time).
The lab’s working code and applications will allow you to practice and experiment with the techniques and tools covered in the course. This access will help you build your skills and confidence in using these tools for security purposes. Course slides will provide you with an overview of the key concepts and topics covered in the course. These slides will help you review and understand the course material and provide you with a helpful reference tool for future work in this field. A ready-made, easy-to-install working setup that can be quickly spun up.
Introduction to mass scanning
o What is mass scanning
o Why Mass scanning is needed Using python to enhance your exploits
o Python Threading o Python Multithreading
o Python Asynchronous Computation
o Speed up your exploits o Writing an XSS finder Python Script
o Enhancing the python script o Make it faster than your thought
o Automate the hell out of XSS
Bash Programming
o Introduction to Bash scripting
o Automating your boring tasks using bash
o Enhancing your bash scripts
o Speed up your bash scripts
Yaml templating
o Understanding the working of nuclei
o Creating your first nuclei template
o Enhancing execution of nuclei
o Parallel execution of nuclei
o Distributed nuclei execution Axiom
o Introduction to Axiom
o Why is Axiom needed?
o Demo
Creating your first Automation BOT on a multi-cloud environment
o Introduction to Python Flask
o Introduction to Microservices
o Building microservices-based applications
o Creating APIs over your security tools
o Deploying Microservices
o Slack Integration
Scanning 2.3m of npm packages
o Creating a single-threaded python/bash POC script
o Distributing the workload
o Doing magic
o Collecting results in just 3 hours for 2.3m packages
Hassan Khan Yusufzai is a highly experienced Security Researcher with a proven track record of internet-wide scanning and penetration testing. A sought-after speaker, Hassan recently presented at the BlackHatMEA 2022 conference. His expertise extends to Ruby security, where he has conducted extensive research over the past few years. As a certified OSCP (Offensive Security Certified Professional), Hassan has also made a name for himself as a successful bug bounty hunter on both HackerOne and Bugcrowd.
Hassan’s achievements have earned him recognition in the industry, including inclusion in the Google Security Hall of Fame (2017), Twitter Security Hall of Fame (2017), and Microsoft Security Hall of Fame (2017). He has also conducted extensive research into WordPress security and won the HackFest CTF competition. In addition to his research, Hassan is also the developer of GemScanner.py and an npm scanner for account hijacking, further demonstrating his commitment to the security field and his skills as a developer.
Past speaking experience
– Presented twice at an Arsenal stage of BlackHat MEA and once at a Briefing stage at BlackHat MEA 2022.
– Hassan Khan has presented at local universities as well.
Danish Tariq is a Security Engineer by profession and a Security researcher by passion. He has been working in Cyber Security for over 8 years and it all started out of a curiosity to break things and look deep down into those things (physical or virtual) back in his teenage years. His major expertise is Penetration Testing and Vulnerability Assessments.
He was also involved in bug bounty programs as well, where he helped many companies by finding vulnerabilities at different levels. Companies include Microsoft, Apple, Nokia, Blackberry, Adobe, etc.
– Spoke @ BlackHat MEA 2022 (Briefing: Supply-Chain Attacks)
– Featured in “The Register” for an initial workaround for the NPM dependency attacks.
– Certified Ethical Hacker, Certified Vulnerability Assessor (CVA), Certified AppSec Practitioner, Certified Network Security Specialist (CNSS), IBM Cyber Security Analyst
– Ex-Chapter Leader @ OWASP
– Ex-Top Rated freelancer (Information security category) on Upwork
– Recent security research and CVEs include – CVE-2022-2848 & CVE-2022-25523
– Served as a Moderator @ OWASP 2022 Global AppSec APAC.