{"id":226561,"date":"2023-07-03T15:39:09","date_gmt":"2023-07-03T13:39:09","guid":{"rendered":"https:\/\/www.intrinsec.com\/?p=226561"},"modified":"2023-07-03T15:39:09","modified_gmt":"2023-07-03T13:39:09","slug":"pov-un-pentester-au-sstic-2023-partie-2","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/","title":{"rendered":"POV: A pentester at SSTIC 2023 \u2013 Part 2"},"content":{"rendered":"<p>[et_pb_section fb_built= \u00bb1\u2033 _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb global_colors_info= \u00bb{} \u00bb theme_builder_area= \u00bbpost_content \u00bb][et_pb_row _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb global_colors_info= \u00bb{} \u00bb theme_builder_area= \u00bbpost_content \u00bb custom_padding= \u00bb12px|0px||0px|| \u00bb custom_margin= \u00bb-2px|-108px||1px|| \u00bb min_height= \u00bb3262.1px \u00bb hover_enabled= \u00bb0\u2033 sticky_enabled= \u00bb0\u2033 width= \u00bb85.7% \u00bb][et_pb_column type= \u00bb4_4\u2033 _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb global_colors_info= \u00bb{} \u00bb theme_builder_area= \u00bbpost_content \u00bb][et_pb_text content_last_edited= \u00bboff|desktop \u00bb _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb header_2_font_size= \u00bb16px \u00bb header_3_font_size= \u00bb18px \u00bb header_4_font= \u00bb|||||||| \u00bb custom_margin= \u00bb|||7px|| \u00bb global_colors_info= \u00bb{} \u00bb content__hover_enabled= \u00bboff|desktop \u00bb theme_builder_area= \u00bbpost_content \u00bb hover_enabled= \u00bb0\u2033 sticky_enabled= \u00bb0\u2033 custom_padding= \u00bb|0px|||| \u00bb width= \u00bb99.9% \u00bb]<\/p>\n<p style=\"text-align: justify\">\n<p style=\"text-align: justify\">This article constitutes the second part of <a href=\"https:\/\/www.intrinsec.com\/en\/?p=226543\">POV: A pentester at SSTIC 2023<\/a>, and follows the feedback from SSTIC presentations related to the pentester profession.<\/p>\n<p style=\"text-align: justify\">\n<p style=\"text-align: justify\">\n<p style=\"text-align: justify\">\n<h1 style=\"text-align: justify\"><em><strong>Top 3 \u2013 Favorites<br \/><\/strong><\/em><\/h1>\n<p style=\"text-align: justify\">Among the high-quality programming at this year&#039;s event, three presentations particularly caught my attention, both for the topics covered and the delivery. This is a subjective opinion, and I encourage you to watch them now. <em>replay<\/em> of these presentations.<\/p>\n<p style=\"text-align: justify\">\n<h3 style=\"text-align: justify\"><em><strong>Deep Attack Surfaces, Shallow Bugs<\/strong><\/em><em><strong><a href=\"https:\/\/www.sstic.org\/2023\/presentation\/deep_attack_surfaces_shallow_bugs\/\"><\/a><\/strong><\/em><\/h3>\n<h3 style=\"text-align: justify\"><\/h3>\n<p style=\"text-align: justify\">Presented by Valentina Palmiotti <em>@Chompie1337<\/em>, <a href=\"https:\/\/www.sstic.org\/2023\/presentation\/deep_attack_surfaces_shallow_bugs\/\">this conference<\/a> echoes a tweet published last December about a critical vulnerability found in a Windows authentication protocol (<a href=\"https:\/\/twitter.com\/chompie1337\/status\/1602757336908660736\">https:\/\/twitter.com\/chompie1337\/status\/1602757336908660736<\/a>).<\/p>\n<p style=\"text-align: center\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png\" alt=\"\" class=\"wp-image-226576 alignnone size-full\" width=\"433\" height=\"460\" \/><\/p>\n<p style=\"text-align: justify\">The first part is dedicated to the path of discovering a vulnerability. Several steps are systematically included:<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li>Target selection<\/li>\n<li>The discovery of the bug<\/li>\n<li>Its exploitation<\/li>\n<li>Success or failure<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p style=\"text-align: justify\">The author highlights the rarity of publications by researchers who recount their failures, even though this is the most common outcome. She describes these failures as inherent to the profession and also essential. It is by following a methodical approach that researchers find vulnerabilities, and the complexity lies primarily in identifying where a flaw is located rather than in identifying the vulnerability itself. She also points out that most of the flaws found are often the same, which can become tedious.<\/p>\n<p style=\"text-align: justify\">She thus distinguishes between two research approaches. One is for a &quot;monogamous&quot; researcher profile: the researcher focuses on a single project to master its code as much as possible, which avoids wasting time switching topics. The other is for a researcher less loyal to their targets, who tires more quickly and therefore regularly changes their scope. This is the case for the author, who has already obtained results for different operating systems or kernel components, for example. The choice of targets is based on various criteria such as their development history, source code accessibility, architecture, etc.<\/p>\n<p style=\"text-align: justify\">Secondly, the application of this method was used to illustrate the search process. The objective was to find a critical vulnerability in a component for which few or no such vulnerabilities had been discovered in the past. The intended attack surface therefore had to meet the following criteria:<\/p>\n<ol style=\"text-align: justify\">\n<li>\u00ab&quot;High Severity&quot;: The bug found must have a major impact in a broad sense.<\/li>\n<li>\u00ab&quot;Ubiquitous&quot;: The attack surface must be present on many systems with a default configuration<\/li>\n<li>\u00ab&quot;Complex&quot;: The target must have complex features with unreliable user input, with components added over time.<\/li>\n<li>\u00ab&quot;Unpopular&quot; (optional): The project should not have been audited too extensively by researchers so that trivial vulnerabilities have not yet been discovered.<\/li>\n<\/ol>\n<p style=\"text-align: justify\">She therefore examined the Windows environment and, after listing the protocols and servers of major interest according to the stated criteria, selected SMB. Next, she listed and categorized the different components of SMB to distinguish the following: &quot;NetBIOS,&quot; &quot;Dialect\/Capability Negotiation,&quot; &quot;Session Setup\/User Authentication,&quot; &quot;Client File Ops &amp; other.&quot; After evaluating each, authentication was selected. Here is the chronology of the selection process:<\/p>\n<p style=\"text-align: center\"><img decoding=\"async\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/04.png\" alt=\"\" class=\"wp-image-226578 alignnone size-full\" width=\"760\" height=\"268\" \/><\/p>\n<p style=\"text-align: center\"><em>Figure 1 \u2013 Target selection process (Excerpt from the SSTIC presentation, slide 41)<\/em><\/p>\n<p style=\"text-align: justify\">Windows authentication relies on the Security Support Provider Interface (SSPI) and uses Security Support Providers (SSPs) in the form of DLLs. The main SSPs are Keberos, NTLM, PKU2U, CredSSP, SPNEGO, and NEGOEXTS. Since the latter two have very few known vulnerabilities (one for SPNEGO and none for NEGOEXTS), they were the natural choice.<\/p>\n<p style=\"text-align: justify\">Once the target was determined, the code analysis phase could begin, starting by finding the implementation of NEGOEXT (loaded at startup in LSA) and then reverse engineering this protocol. After reading the protocol documentation, the goal was then to find the function of <em>parsing<\/em> of messages. Once identified and after several analysis passes, a race condition can be exploited following the sending of multiple Negoex Session Setup requests. Its exploitation can allow an attacker to execute arbitrary code remotely.<\/p>\n<p style=\"text-align: justify\">Finally, to the problem of &quot;Finding a bug with a major impact in a widely used and complex technology,&quot; Chompie responds with CVE-2022-37958, a vulnerability in SPNego NegoEx leading to a critical failure escape (CFE). And to conclude, attack surface analysis is just as much an art as vulnerability research.<\/p>\n<p style=\"text-align: justify\">\n<h3 style=\"text-align: justify\"><em><strong>CERTA\/CERT-FR: A look back at 20+ years of CERTs at ANSSI<\/strong><\/em><\/h3>\n<p><em><strong><\/strong><\/em><\/p>\n<p style=\"text-align: justify\">The deputy director of operations at ANSSI, Mathieu Feuillet, intervened to <a href=\"https:\/\/www.sstic.org\/2023\/presentation\/cloture_2023\/\">the closing presentation<\/a> by reviewing the history of the ANSSI CERT and its main activities.<\/p>\n<p style=\"text-align: justify\">From CERT-A, created in anticipation of the Y2K bug, to the CERT-FR we know today, the organization has grown progressively in response to cyber threats, evolving both structurally and in terms of the resources deployed. In parallel, CERT-FR also contributes to the development of the CSIRT ecosystem by supporting the various stakeholders. Today, the operations conducted at the heart of the agency address espionage, destabilization, and cybercrime attacks.<\/p>\n<p style=\"text-align: justify\">The 2011 Bercy breach was a pivotal moment in the agency&#039;s operational activity. Indeed, the detection of this incident, a campaign &quot;linked to China through open sources,&quot; represented the first large-scale operation that allowed for the establishment of principles subsequently applied numerous times. This event marked the beginning of the consistent targeting of France for political, diplomatic, economic, and industrial purposes. A timeline of attacks suffered by a key government sector was presented, highlighting the omnipresence of attacks that systematically involved at least four simultaneous malicious activities:<\/p>\n<p style=\"text-align: center\"><img decoding=\"async\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/05.png\" alt=\"\" class=\"wp-image-226580 alignnone size-full\" width=\"634\" height=\"448\" \/><\/p>\n<p style=\"text-align: center\"><em>Figure 2 \u2013 Periods of malicious activity for a sovereign sector X (Extract from the SSTIC presentation, slide 21)<\/em><\/p>\n<p style=\"text-align: justify\">For the next three years, the attacks were persistent, large-scale, and targeted both government agencies and critical infrastructure. The latter were then included in the scope of the operation. Starting in 2017, these attacks returned, more discreet than before, and increasingly targeted IT services companies and other downstream entities, before rebounding on the targets themselves. Finally, since 2021, and still with the same rebound strategy, the targeted organizations are increasingly smaller and generally lack adequate security measures. In addition to the aforementioned targeted entities, embedded equipment such as routers, firewalls, and Wi-Fi access points are also being targeted.<\/p>\n<p style=\"text-align: justify\">2021 has seen the most mass data breaches to date. New techniques have been deployed, including the publication of certain attacker indicators and methods to hinder attacks. 2021 was also the year of Pegasus, the spying on high-profile individuals through the compromise of their phones, as well as Solarwinds and Log4j, for which proactive measures were developed to better protect potential victims.<\/p>\n<p style=\"text-align: justify\">Furthermore, regarding destabilization, the agency has notably had to combat hacktivism, which emerged significantly following the 2015 attacks and the 2022 war in Ukraine. These malicious actions are politically motivated and primarily involve denial-of-service attacks and defacement (for example, the sabotage operation of <a href=\"https:\/\/www.sstic.org\/2017\/presentation\/2017_cloture\/%20\">TV5 Monde in 2015<\/a>, or Ka-Sat in 2022).<\/p>\n<p style=\"text-align: justify\">As for cybercrime, the emergence of ransomware began in 2018 with the targeting of large entities (&quot;big game hunting&quot;), less precise and more opportunistic than before. The victims are generally companies with the least security compared to the average (&quot;In cybercrime, it&#039;s like when you&#039;re being chased by a lion: you shouldn&#039;t outrun the lion, you should outrun someone else&quot;). The impacts of this type of attack vary and materialize in concrete ways. For example, for healthcare facilities, the consequences directly affect patients.<\/p>\n<p style=\"text-align: justify\">In conclusion, defensive actions are essential and effective in the face of an increasing threat.<\/p>\n<p style=\"text-align: justify\">\n<h3 style=\"text-align: justify\"><em><strong>Bug hunting in Steam: a journey into the Remote Play protocol<\/strong><\/em><\/h3>\n<p><em><strong><\/strong><\/em><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/www.sstic.org\/2023\/presentation\/bug_hunting_in_steam_remote_play\/\">Another presentation<\/a> A vulnerability search, this time with Valentino Ricotta (@face0xff), has been exposed, concerning a protocol on the Steam platform. The author targeted this Valve studio platform due to its popularity\u2014it&#039;s the most used by online gamers\u2014as well as the wide range of features it offers. The attack surface for targeting a player includes game components, the Source engine common to Valve games, the Steamworks API, and the Steam client. The latter has fewer known vulnerabilities and was therefore chosen by the author.<\/p>\n<p style=\"text-align: justify\">During his analysis of the client, Valentino encountered the undocumented &quot;Remote Play&quot; protocol, allowing a player who does not own the game to play through another player who does, combining streaming and remote control (which echoes <a href=\"https:\/\/www.sstic.org\/2022\/presentation\/fuzzing_microsofts_rdp_client_using_virtual_channels\/\">his presentation from last year on RDP<\/a>).<\/p>\n<p style=\"text-align: justify\">More specifically, he explains how this protocol works: to start a session, the host sends an invitation link to the guest, and then a direct connection is established between them (P2P \/ transparent relay). The client can then attack the host and vice versa. The most impactful scenario is an attack on the guest (the client): the only requirement for the guest is to have a Steam client. By exploiting the &quot;steam:\/\/&quot; wrapper, which can be hidden on a web page, an attacker (the host) could establish a connection with users.<\/p>\n<p style=\"text-align: justify\">Once the protocol&#039;s behavior was determined, its implementation was studied. A phase of <em>reverse<\/em> This made it possible to determine the logical path of network flows that pass successively through:<\/p>\n<ol style=\"text-align: justify\">\n<li>Network reception, the interface for exchanging data<\/li>\n<li>The processing of packet headers, which introduces the concept of <em>channel<\/em><\/li>\n<li>The distribution of packets according to their <em>channel<\/em>.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/06.png\" alt=\"\" class=\"wp-image-226582 alignnone size-full\" style=\"margin-left: auto;margin-right: auto\" width=\"760\" height=\"307\" \/><\/p>\n<p style=\"text-align: center\"><em>Figure 3 \u2013 Logical representation of network flows (Extract from the SSTIC presentation, slide 31)<\/em><\/p>\n<p style=\"text-align: center\">\n<p style=\"text-align: justify\">The author explains that channels are layers of abstraction used to parallelize data transmission depending on whether it involves audio, video, control streams, etc. He chose to focus on three of them (control, statistics, and data) and defined his target surface in this way:<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul style=\"text-align: justify\">\n<li>Control messages (about a hundred types of messages)<\/li>\n<li>The remote HID that adds control messages processed with higher priority<\/li>\n<li>Audio and video codecs<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p style=\"text-align: justify\">To find vulnerabilities, the first step in his approach was to reimplement Remote Play, including both the client and server, with the aim of efficiently performing proof-of-concept tests. This approach evolved into a fuzzer, rpfuzz, which offers the ability to interact directly with the client (guest) or server (host), maintain a history of packets, replay and modify them, and organize packets to play a specific scenario. Modifying packets is done using another tool developed by the author, pbfuzz. Here is the architecture of the test environment:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/07.png\" alt=\"\" class=\"wp-image-226584 alignnone size-full\" style=\"margin-left: auto;margin-right: auto\" width=\"760\" height=\"313\" \/><\/p>\n<p style=\"text-align: center\"><em>Figure 4 \u2013 Diagram of the test environment (Extract from the SSTIC presentation, slide 62)<\/em><\/p>\n<p style=\"text-align: center\">\n<p style=\"text-align: justify\">Ultimately, this led to the discovery of about ten vulnerabilities affecting all platforms. The two main ones that have been fixed and presented affect control messages and are of the following types:<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul style=\"text-align: justify\">\n<li>\u00ab&quot;String format&quot;: its exploitation allows for the leakage of client memory information: breaking the ASLR and scanning the memory, for example.<\/li>\n<li>\u00ab&quot;Request Forgery&quot;: the attack can lead to a leak of local resources or a scan of the internal network, for example.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>","protected":false},"excerpt":{"rendered":"<p>[et_pb_section fb_built= \u00bb1\u2033 _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb global_colors_info= \u00bb{} \u00bb theme_builder_area= \u00bbpost_content \u00bb][et_pb_row _builder_version= \u00bb4.21.0\u2033 _module_preset= \u00bbdefault \u00bb global_colors_info= \u00bb{} \u00bb theme_builder_area= \u00bbpost_content \u00bb custom_padding= \u00bb12px|0px||0px|| \u00bb custom_margin= \u00bb-2px|-108px||1px|| \u00bb min_height= \u00bb3262.1px \u00bb hover_enabled= \u00bb0\u2033 sticky_enabled= \u00bb0\u2033 [\u2026]<\/p>","protected":false},"author":38,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-226561","post","type-post","status-publish","format-standard","hentry","category-non-categorise"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>POV : un pentester au SSTIC 2023 - Partie 2 - INTRINSEC<\/title>\n<meta name=\"description\" content=\"Retour d&#039;exp\u00e9rience sur le SSTIC 2023 en 2 parties : Pr\u00e9sentation des conf\u00e9rences li\u00e9es aux pentests, puis de 3 conf\u00e9rences coups de coeur !\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"POV : un pentester au SSTIC 2023 - Partie 2\" \/>\n<meta property=\"og:description\" content=\"Retour d&#039;exp\u00e9rience sur le SSTIC 2023 en 2 parties : Pr\u00e9sentation des conf\u00e9rences li\u00e9es aux pentests, puis de 3 conf\u00e9rences coups de coeur !\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-03T13:39:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png\" \/>\n<meta name=\"author\" content=\"Margaux Dabert\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Margaux Dabert\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/\"},\"author\":{\"name\":\"Margaux Dabert\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/15304758ef548790a716c99505e6d056\"},\"headline\":\"POV : un pentester au SSTIC 2023 &#8211; Partie 2\",\"datePublished\":\"2023-07-03T13:39:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/\"},\"wordCount\":2397,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/03.png\",\"articleSection\":[\"Non cat\u00e9goris\u00e9\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/\",\"name\":\"POV : un pentester au SSTIC 2023 - Partie 2 - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/03.png\",\"datePublished\":\"2023-07-03T13:39:09+00:00\",\"description\":\"Retour d'exp\u00e9rience sur le SSTIC 2023 en 2 parties : Pr\u00e9sentation des conf\u00e9rences li\u00e9es aux pentests, puis de 3 conf\u00e9rences coups de coeur !\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/03.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/03.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/pov-un-pentester-au-sstic-2023-partie-2\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"POV : un pentester au SSTIC 2023 &#8211; Partie 2\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/15304758ef548790a716c99505e6d056\",\"name\":\"Margaux Dabert\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Margaux Dabert\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/margaux-dabert\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"POV: a pentester at SSTIC 2023 - Part 2 - INTRINSEC","description":"Feedback on SSTIC 2023 in 2 parts: Presentation of conferences related to pentesting, then 3 favorite conferences!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/","og_locale":"en_US","og_type":"article","og_title":"POV : un pentester au SSTIC 2023 - Partie 2","og_description":"Retour d'exp\u00e9rience sur le SSTIC 2023 en 2 parties : Pr\u00e9sentation des conf\u00e9rences li\u00e9es aux pentests, puis de 3 conf\u00e9rences coups de coeur !","og_url":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/","og_site_name":"INTRINSEC","article_published_time":"2023-07-03T13:39:09+00:00","og_image":[{"url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png","type":"","width":"","height":""}],"author":"Margaux Dabert","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Margaux Dabert","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/"},"author":{"name":"Margaux Dabert","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/15304758ef548790a716c99505e6d056"},"headline":"POV : un pentester au SSTIC 2023 &#8211; Partie 2","datePublished":"2023-07-03T13:39:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/"},"wordCount":2397,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png","articleSection":["Non cat\u00e9goris\u00e9"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/","url":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/","name":"POV: a pentester at SSTIC 2023 - Part 2 - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png","datePublished":"2023-07-03T13:39:09+00:00","description":"Feedback on SSTIC 2023 in 2 parts: Presentation of conferences related to pentesting, then 3 favorite conferences!","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#primaryimage","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2023\/06\/03.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/en\/pov-un-pentester-au-sstic-2023-partie-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"POV : un pentester au SSTIC 2023 &#8211; Partie 2"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/15304758ef548790a716c99505e6d056","name":"Margaux Dabert","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Margaux Dabert"},"url":"https:\/\/www.intrinsec.com\/en\/author\/margaux-dabert\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/226561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=226561"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/226561\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=226561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=226561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=226561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}