home.social

#sstic — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sstic, aggregated by home.social.

fetched live
  1. La lutte contre la Cybercriminalité - Keynote lors de la conférence #SSTIC 2025 par Johanna Brousse, vice-procureur, chef de la section J3 Cybercriminalité du Tribunal de Justice de Paris #Infosec #Video sstic.org/2025/presentation/cl

  2. La lutte contre la Cybercriminalité - Keynote lors de la conférence #SSTIC 2025 par Johanna Brousse, vice-procureur, chef de la section J3 Cybercriminalité du Tribunal de Justice de Paris #Infosec #Video sstic.org/2025/presentation/cl

  3. CLIP : développement d'un OS (basé sur Linux) sécurisé et « souverain » ; projet de l'ANSSI - Vieux Talk de Vincent Strubel (maintenant DG de l'agence) lors de la conférence #SSTIC 2015 #Video sstic.org/2015/presentation/cl

  4. CLIP : développement d'un OS (basé sur Linux) sécurisé et « souverain » ; projet de l'ANSSI - Vieux Talk de Vincent Strubel (maintenant DG de l'agence) lors de la conférence #SSTIC 2015 #Video sstic.org/2015/presentation/cl

  5. Et n'oubliez pas. Le SSTIC 2027 aura vraisemblablement lieu du 2 au 4 juin 2027 et l'appel à soumissions ouvrira à l'automne.

    D'ici là vous pouvez toujours réviser blog.sstic.org/2017/01/06/comm !

    #sstic #sstic2027

  6. Et n'oubliez pas. Le SSTIC 2027 aura vraisemblablement lieu du 2 au 4 juin 2027 et l'appel à soumissions ouvrira à l'automne.

    D'ici là vous pouvez toujours réviser blog.sstic.org/2017/01/06/comm !

    #sstic #sstic2027

  7. Le #SSTIC 2026 c'est fini. Encore merci pour votre participation et à l'année prochaine !

    #sstic #sstic2026

  8. Le #SSTIC 2026 c'est fini. Encore merci pour votre participation et à l'année prochaine !

    #sstic #sstic2026

  9. Première fois au #SSTIC (Symposium sur la sécurité des technologies de l'information et des communications) cette année.

    Des gens sont dans le coin ?

  10. Je vais être au SSTIC du mercredi au vendredi prochain ! Faites moi signe si vous venez :)

    #sstic

  11. 🏃🏃🏃🏃🏃🏃
    Avis à tous les sportifs du #SSTIC !
    J'organise un petit jogging les matins avant les conférences. N'hésitez pas à me rejoindre et à faire circuler l'information à ceux qui pourraient être intéressés. Il suffit de remplir ce petit formulaire (environ 2 minutes)

    framaforms.org/jogging-avant-l

    Merci à vous ! N'hésitez pas à faire circuler sur les autres réseaux auxquels je ne suis pas présent.
    @sstic

  12. Je recherche un billet pour le #SSTIC 2026
    Si quelqu'un d'inscrit ne peux plus y aller 😉🙏🏻

  13. Je recherche un billet pour le #SSTIC 2026
    Si quelqu'un d'inscrit ne peux plus y aller 😉🙏🏻

  14. Suite à la réunion du comité de programme, les notifications aux auteurs et autrices sont parties ce jour et les commentaires leur sont accessible sur le site

    Encore merci à toutes les personnes qui ont fait l'effort de soumettre leur travail, accepté ou non.

    #sstic #sstic2026

  15. Suite à la réunion du comité de programme, les notifications aux auteurs et autrices sont parties ce jour et les commentaires leur sont accessible sur le site

    Encore merci à toutes les personnes qui ont fait l'effort de soumettre leur travail, accepté ou non.

    #sstic #sstic2026

  16. L’appel à soumission est maintenant refermé. C’est maintenant aux membres du comité de programme de relire toutes les soumissions pour les évaluer, en discuter et construire le programme de l’édition 2026.
    Les résultats seront connus normalement à la mi-mars.
    #sstic #sstic2026

  17. L’appel à soumission est maintenant refermé. C’est maintenant aux membres du comité de programme de relire toutes les soumissions pour les évaluer, en discuter et construire le programme de l’édition 2026.
    Les résultats seront connus normalement à la mi-mars.
    #sstic #sstic2026

  18. L’appel à soumission pour le #sstic2026 est étendu jusqu’à vendredi 23 janvier, 23h59.

    sstic.org/2026/news/cfp_2026_p

    #sstic #sstic2026

  19. L’appel à soumission pour le #sstic2026 est étendu jusqu’à vendredi 23 janvier, 23h59.

    sstic.org/2026/news/cfp_2026_p

    #sstic #sstic2026

  20. Bonne année 2026 à tout le monde !

    N'oubliez pas que l'appel à soumission est en ligne et que la date limite pour envoyer vos articles est le 18 janvier.

    sstic.org/2026/cfp/

    #sstic #sstic2026

  21. Bonne année 2026 à tout le monde !

    N'oubliez pas que l'appel à soumission est en ligne et que la date limite pour envoyer vos articles est le 18 janvier.

    sstic.org/2026/cfp/

    #sstic #sstic2026

  22. L'appel à contributions pour SSTIC 2026 est en ligne : sstic.org/2026/cfp/.

    Date limite de soumission : 18 janvier 2026

    La conférence aura lieu du 3 au 5 juin 2026.

    Vous hésitez ? Relisez nos conseils:
    blog.sstic.org/2017/01/06/comm

    #sstic #sstic2026

  23. So, a bit late, but a TL;DR of the #sstic2025 :D

    #sstic

    Kube scale me one more time – TL;DR:

    (The demo is made on GCP, but it can affect other cloud providers such as AWS' EKS.)

    The issue comes from:
    - the creds of a deleted Node are still valid
    - a node, when created, can provide its own providerID.

    Thus, by using the autoscaling functions, it’s possible to priv esc from a machine (actually just having kubelet creds) to the admin of the K8S cluster.

    sstic.org/2025/presentation/ku

    github.com/padok-team/kne

    ——

    Argo CD secret - TL;DR

    Using misconfiguration of secrets, you can become an admin of the ArgoCD cluster.

    Please review who can view the argocd-secret. Make sure only the Argo CD UI can access them. Disable the local admin if not needed.

    ledger.com/argo-cd-security-mi

    sstic.org/media/SSTIC2025/SSTI

    ——

    All the ways are going to DROP; TL;DR:

    About BT Mesh 1.1, a really recent protocol. Any attacker in the mesh can create a fake route rule (in the forward table). This could remove some nodes from the network or intercept the communications between two nodes.

    [FR] sstic.org/2025/presentation/to

    ———

    We Have A Deal: we provide the lego bricks, you build cool wireless attacks; TL;DR:

    This talk is about why and how WHAD (a toolkit to implement radio attacks; whad.io) is made in a modular way, where each action is a brick, you linked to the others.

    whad.io

    github.com/whad-team

    ———

    Key recovery in ; TL;DR:

    This famous MCU is composed of 2 cores: one for the user mode, the other for the radio. The radio firmware is encrypted and signed with an internal PKI. This core is also responsible for ingesting some AES keys for encryption (as a security computation unit, as a TPM or an HSM).

    By using a race condition, we can dump and even rewrite the radio firmware from the user core.

    Some days before the talk, they pushed a new firmware with a new update mechanism. It’s easier to bypass the update verification.

    blog.xilokar.info/stm32wb55-fu

    ———

    afl-cov-fast; TL;DR:

    It’s a tool to create coverage information from AFL++ when we don’t have sources. It works for every runner (qemu, Frida, etc.) and covering data is able to be loaded in any reverse tool (via plugins).

    github.com/airbus-seclab/afl-c

    ———

    Pyrrha & friends; TL;DR:

    Tool to increase the productivity in the reconnaissance phase of a file-based firmware (currently only executables). It gives usage data of the binaries and functions across the system.

    github.com/quarkslab/pyrrha

    ———

    Pwn a car entertainment system in 5 mins ; TL;DR:

    Pentest of an entertainment system embedded in a used car that can be found in the wild. These cars are the FR state cars. The pentest is performed by an attacker being outside the car and without user interaction.
    The rooting of the system has been realized by exploiting an old vulnerability in a totally different way than provided in the small disclosed details of the CVE.
    The rooting of this system can result in the sending of CAN commands.

    [FR] sstic.org/media/SSTIC2025/SSTI

    ———

    ID of MCU firmware; TL;DR:

    How the file/libmagic db has been improved to identify the firmware of an MCU. Pushed in the upstream db of the file/libmagic.
    Also, to know the exact chip targeted by the firmware, the chiprec.py script has been created.

    github.com/erdnaxe/chiprec

    —————————

    Eurydice; TL;DR:

    Web UI, solving a lot of issues regarding the file transfers to a classified environment via a network diode.

    Only useful when you got a network diode :D

    github.com/ANSSI-FR/eurydice

    ——————

    WireGo; TL;DR:

    A flexible plugin development framework for Wireshark. It has been created to develop a Wireshark dissector plugin faster when reversing a protocol.

    github.com/quarkslab/wirego

    ———

    APKPatcher; TL;DR:

    Tool to quickly and reliably patch APK, add proxies and certificates, libraries, and much more.

    NB: not apk-patcher, but apkpatcher (no dash)

    apkpatcher.ci-yow.com/

    gitlab.com/MadSquirrels/mobile

    ———

    hrtng; TL;DR:

    Plugin IDA Pro to automate some recurring tasks when reversing (incl. vtables!)

    github.com/KasperskyLab/hrtng

    ———

    Windows Kernel Shadow Stack; TL;DR:

    Analyze the implementation of the shadow stack in the Windows kernel.

    It uses HVCI-like protection to render the shadow stack really read-only for the kernel and read-write in the secure kernel. It is well effective. This protects against the ROP, but, of course, not this JOP.

    sstic.org/media/SSTIC2025/SSTI

    github.com/synacktiv/windows_k

    synacktiv.com/sites/default/fi

    ———

    Windows network tooling; TL;DR:

    Tool with Scapy to implement a secure and modern implementation of LDAP, DCE/RPC, and SMB. In a nutshell, like impacket, but with the modern Windows security, every SSP everywhere. So it does not fail each time we meet a secure configuration of a Windows env.
    Merge in Scapy, except the DEC/RPC compiler, which is in another project : github.com/gpotter2/scapy-rpc

    github.com/secdev/scapy

    github.com/gpotter2/scapy-rpc

    ———

    Mofos; TL;DR:

    VM management, as Qubes OS, but with KVM/LibVirt

    github.com/Synacktiv/mofos

    ———

    Analysis of MS365 auth; TL;DR:

    Deep analysis of the MS365 OAuth to try to LPE without the user noticing.

    sstic.org/media/SSTIC2025/SSTI

    ———

    Feedback of PQC pentest; TL;DR:

    Small feedback on how works some part of the PQC and how to pentest it.

    To learn more, check the blog post of SynAcktiv

    [FR] sstic.org/2025/presentation/re

    ———

    Quic; TL;DR:

    There are some default implementations of the QUIC protocol, e.g., some values that should be truly random but are not random.

    [FR] sstic.org/media/SSTIC2025/SSTI

    ———

    Soxy; TL;DR:

    A reliable solution to forward network, files, copy-paste, etc. for RDP, Citrix, VMware Horizon, and XRDP. To transfer the soxy client, a solution has also been created.

    github.com/airbus-seclab/soxy

    ———

    UDP in proxychains and bbs; TL;DR:

    How they implemented UDP in proxychains and some of its limitations. (A lot of error management is not implemented (yet))
    BBS is like proxychains, but with routing, logging, and filtering. No UDP yet.

    github.com/hc-syn/proxychains-

    github.com/synacktiv/bbs

    ———

    SCCMSecret.py; TL;DR:

    Test the SCCM access (including anonymous access) and extract files and configurations.

    github.com/synacktiv/SCCMSecre

    ———

    What happens if I press here; TL;DR:

    Feedback of pentesting industrial things

    [FR] sstic.org/2025/presentation/re

    ———

    Random Factory reset; TL;DR:

    There is a low (11 ppm here) but real risk of a conflict in the ACPI access in read only. Take care when dumping the configuration (including sysctl -a)!

    [FR] sstic.org/2025/presentation/in

    ———

    Explainable AI in malware analysis; TL;DR:

    Use the MalConv2 model to determine which function is malevolent or not, tracking off the biases. Dataset to complete.

    Currently improving this model based on the capabilities (using mandiant CAPA)

    github.com/glimps-re/xai-malco

    github.com/FutureComputing4AI/

    github.com/mandiant/capa

    sstic.org/media/SSTIC2025/SSTI

  24. Mofos, framework de manipulation de machines virtuelles « à la » QubesOS sur une distribution Linux classique, reposant sur Libvirt/QEMU/KVM
    - Repository GitHub github.com/synacktiv/mofos
    - Talk par Florian Guilbert à la conférence #SSTIC 2025 #Video sstic.org/2025/presentation/mo

  25. Mofos, framework de manipulation de machines virtuelles « à la » QubesOS sur une distribution Linux classique, reposant sur Libvirt/QEMU/KVM
    - Repository GitHub github.com/synacktiv/mofos
    - Talk par Florian Guilbert à la conférence #SSTIC 2025 #Video sstic.org/2025/presentation/mo

  26. Le SSTIC c'est fini ! Un énorme merci à toutes les oratrices et orateurs, la conférence c'est avant tout vous, on ne fait que faire un écrin autour de vous.

    Merci aussi à toutes les personnes qui ont osé soumettre leur travail, sans cela pas de sélection ni de conférence. Merci aussi aux conceptrices et concepteurs du challenge (et aux challengers !)

    Merci aux membres du comité de programme qui ont relu, commenté discuté les articles, fait des commentaires.

    Merci aux différents sites qui nous accueillent (Couvent des Jacobins, Halle Martenot, Halle de la Courrouze), aux personne qui les gèrent et les animent. Merci aussi aux gens qui nous nourrissent (et nous abreuvent) pendant ces trois jours.

    Enfin merci à tout l'auditoire qui se déplace en nombre pour venir voir et écouter la conférence (ainsi que les personnes qui suivent à distance). Votre présence et votre soutien année après année nous fait chaud au cœur.

    Merci à toute la communauté, bon retour et à l'année prochaine !

    #sstic #sstic2025

  27. Il est temps pour moi de quitter l'édition 2025 de #sstic.

    Encore une édition d'une homogénéité remarquable dans la qualité des présentations et un large panorama de sujets couverts 🔥

    On rajoute à cela une communauté de participant.e.s très ouverte aux échanges, communauté de plus en plus diverse de surcroît, ce qui fait chaud au cœur ❤️

    Et enfin, une équipe d'organisation qui bosse super bien et qui nous propose un super événement année après année 🙏

    Bref. Un énorme merci pour tout cela @sstic tant côté orga que communauté 🥰

    Finissez bien et à l'an prochain 👋🤞

  28. Les solution du challenge 2025 du SSTIC sont maintenant disponibles sur sstic.org/2025/challenge/

    Bravo à tous les challengers !

    #sstic #sstic2025

  29. It may sound silly, but, the fact that someone with a pride flag on a pin came to me just to tell me that he appreciates my Act-Up shirt, made me feel sooooooo much better.

    Yeah, signs counts, even small ones. It’s really a small thing I always neglected. But it really counts!

    So, to you, thank you ❤️

    #sstic2025 #sstic

  30. Pour ceux qui ne sont pas à Rennes, la conférence SSTIC est disponible en streaming ; discussions en live via IRC et Discord #Infosec #SSTIC
    - Programme édition 2025 sstic.org/2025/programme/
    - Streaming Live streaming.sstic.org/

  31. Le programme du #SSTIC devrait être disponible dans #Giggity pour #Android :

    f-droid.org/packages/net.gaast

    Quelqu'un peut me dire si ça fonctionne ?

    #SSTIC2025 cc @sstic

  32. Le programme du SSTIC 2025 est en ligne : sstic.org/2025/programme/

    N'oubliez pas les inscriptions demain vers 13h.

    #sstic #sstic2025

  33. L'appel à contributions pour SSTIC 2025 est en ligne : sstic.org/2025/cfp/.

    Date limite de soumission : 19 janvier 2025

    Vous hésitez ? Relisez nos conseils:
    blog.sstic.org/2017/01/06/comm

    #sstic #sstic2025

  34. @ericfreyss au passage... Une de mes utilisations principales de Twitter à la fin de sa vie était pour rechercher des infos sur un évènement en direct : les échanges entres les auditeurs du #SSTIC, lors d'un bouchon monstre dans une ville, une petite recherche me menait toujours vers quelque gazouilli évoquant tel incendie de véhicule sur une bretelle, etc... Une idée de plateforme qui ait pris ce relai ?
    La recherche globale sur le fediverse étant ce qu'elle est (=j'ai pas compris si c'est une chose...), il ne me reste plus que Google, très limité, parfois Reddit pour les gros événement, mais même là la structure des discussions rend la chose difficile...