{"id":3196,"date":"2017-07-06T19:07:27","date_gmt":"2017-07-06T17:07:27","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=3196"},"modified":"2017-07-06T19:07:27","modified_gmt":"2017-07-06T17:07:27","slug":"hack-in-paris-2017","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/","title":{"rendered":"Hack In Paris 2017"},"content":{"rendered":"<p>Intrinsec attended the 7th edition of the Hack In Paris conference, preceding the Nuit du Hack, at the conference center of the Newport Bay Club hotel in Disneyland Paris.<\/p>\n<p>All conference materials should soon be available on the conference website:\u00a0<a href=\"https:\/\/hackinparis.com\/archives\/2017\/\">https:\/\/hackinparis.com\/archives\/2017\/<\/a><\/p>\n<p>The presentation videos are available on YouTube:\u00a0<a href=\"https:\/\/www.youtube.com\/playlist?list=PLaS1tu_LcHA8yOrGuyvBIJjEO87-vXQG2\">https:\/\/www.youtube.com\/playlist?list=PLaS1tu_LcHA8yOrGuyvBIJjEO87-vXQG2<\/a><\/p>\n<h2>Strategies on Securing banks &amp; enterprises \u2013 Jayson E. Street<\/h2>\n<p>Jayson E. Street is a security expert at Pwnie Express who gives numerous talks around the world.<\/p>\n<p>During his presentation, he demonstrated how easy it was to conduct reconnaissance (both passive and active) to develop social engineering attacks on employees of large companies.<\/p>\n<p>Throughout his presentation, he detailed how to obtain highly specific information by navigating various external databases (DNS, whois, shodan, etc.) and social networks (professional or otherwise). With just a few searches, Jayson developed a very plausible targeted phishing scenario.<\/p>\n<p>His presentation also provided an opportunity to revisit the challenges of risk management within companies. Most executives believe they are immune to all risks: &quot;It&#039;s never going to happen to me [when it comes to security],&quot; which gives pause for thought.<\/p>\n<h2>Ventrilock exploring: voice-based authentication systems \u2013 Chaouki Kasmi &amp; Jos\u00e9 Lopes Esteves<\/h2>\n<p>Chaouki Kasmi and Jos\u00e9 Lopes Esteves are two agents from ANSSI. They presented their work on voice-based authentication methods (with a focus on Siri, Google Now and S-Voice).<\/p>\n<p>After introducing us to the risks and impacts that the misuse of such systems could have, the two researchers detailed the physical and mathematical analysis methods they used to perform speech recognition (voice modeling, parameter extraction, voice non-linearity, frequency analysis method, etc.).<\/p>\n<p>They then presented 3 black-box attack scenarios on these systems:<\/p>\n<ol>\n<li>\u00ab&quot;Speaker impersonation&quot;: the attacker hears their target&#039;s voice, records it, and then submits it multiple times to the phone&#039;s authentication service to refine the model to their advantage. They made the strange observation that Siri&#039;s model evolved before authentication, thus allowing the model to be refined until the phone authenticated the recording by submitting it a large number of times.<\/li>\n<li>\u00ab&quot;Reconstruction&quot;: The attacker knows the keyword (e.g., &quot;OK Google&quot;) and has a snippet of the victim&#039;s voice. They are thus able to reconstruct the keyword from the phonemes in the victim&#039;s voice. The demonstration shows the phone being unlocked despite a sound inaudible to a human.<\/li>\n<li>\u00ab&quot;Keyword composition&quot;: The attacker possesses snippets of voices from people saying the keyword. They are able to mix these snippets to authenticate themselves on the phone. The most interesting aspect of this is that the legitimate voice doesn&#039;t have to be in this mix. However, they were unable to explain this observation.<\/li>\n<\/ol>\n<p>Finally, they pointed out that these results should be taken with a grain of salt and that they cannot be generalized given the black-box analysis method.<\/p>\n<p>After presenting several countermeasures (preventing brute-force attacks, adding entropy with a challenge\/response mechanism, strengthening the model, etc.), they concluded that advancements in voice recognition are not yet mature enough. Therefore, using voice as the sole authentication method on your phones is not recommended!<\/p>\n<h2>Internet of compromised things: methodology and tools \u2013 Damien Cauquil<\/h2>\n<p>Damien Cauquil is a security researcher at Econocom \u2013 Digital Security. His research often involves investigating proprietary IoT devices whose protocols are little known or unknown, and whose documentation is often very limited or even nonexistent. Reverse engineering these devices is time-consuming and expensive, especially if they employ complex protection mechanisms (military-grade encryption, etc.). Therefore, he presented a collaborative platform dedicated to sharing and gathering information and techniques (TTP) on these devices. <a href=\"http:\/\/hfdb.io\">Hardware Forensic Database (HFDB)<\/a>.<\/p>\n<p>Sharing and collaboration are welcome!<\/p>\n<h2>The forgotten interface: Windows named pipes \u2013 Gil Cohen<\/h2>\n<p>Gil Cohen, CTO of Comsec Global, presented Windows Named Pipes and their characteristics. He introduced the IONinja tool, which allows users to read data transmitted through these named pipes. Because this information is accessible by default to any anonymous user on the network (it&#039;s not just accessible locally!) and is unencrypted, it can be exploited by an attacker.<\/p>\n<p>By performing <em>fuzzing<\/em> On certain named channels, Gil Cohen has shown that he can cause a <em>crash<\/em> within two applications using named pipes: qBitTorrent and SugarSync. Unfortunately, the demonstration did not show whether it was possible to perform remote code execution through this mechanism.<\/p>\n<h2>Beyond OWASP Top 10 \u2013 Aaron Hnatiw<\/h2>\n<p>Aaron Hnatiw is a security researcher at Security Compass.<\/p>\n<p>In his presentation, he discussed the need to go beyond the OWASP Top 10 when assessing the security of web applications. To illustrate this, he presented three other types of vulnerabilities with concrete examples of exploitation:<\/p>\n<ul>\n<li>HTTP Parameter Pollution (CWE 235)<\/li>\n<li>Overly Permissive Regex (CWE 625)<\/li>\n<li>Server-Side Request Forgery (CWE 918)<\/li>\n<\/ul>\n<p>To conclude his presentation, Aaron discussed the future developments of the OWASP Top 10 (with the 2017 version currently in release candidate). He reiterated that it was a good starting point for assessing the security of a web application, but that further investigation was needed to achieve a truly satisfactory level of security.<\/p>\n<h2>Dissecting a ransomware-infected MBR \u2013 Raul Alvarez<\/h2>\n<p>Raoul Alvarez, a security researcher at Fortinet, analyzed the workings of the Petya malware.<\/p>\n<p>Find our detailed report in a separate article:\u00a0<a href=\"https:\/\/www.intrinsec.com\/en\/2017\/07\/06\/hip2017-dissecting-a-ransomware-infected-mbr-petya\/\">[HIP2017] \u2013 Dissecting A Ransomware-infected MBR \u2013 PETYA<\/a><\/p>\n<h2>Are you watching TV now? Is it real? Hacking of smart TV with 0-day \u2013 Lee Jong Ho &amp; Kim MinGeun<\/h2>\n<p>Lee Jong Ho and Kim MinGeun are two Master&#039;s students in security in South Korea. They presented their work on smart TVs and more specifically on the WebOS operating system found on most connected televisions to date.<\/p>\n<p>After detailing the internal mechanisms of WebOS, they performed a demonstration where they remotely took control of a connected television by:<\/p>\n<ol>\n<li>Forcing the installation of development mode<\/li>\n<li>Restarting the television<\/li>\n<li>Installing a malicious application<\/li>\n<li>Restarting the television a second time<\/li>\n<li>Exploiting a vulnerability that allows them to escalate their privileges on the system<\/li>\n<\/ol>\n<h2>802.1X Network Access Control and Bypass Techniques \u2013 Val\u00e9rian Legrand<\/h2>\n<p>This conference is described in detail in a dedicated article: <a href=\"https:\/\/www.intrinsec.com\/en\/2017\/07\/06\/hip2017-bypass-802-1x-fenrir\/\">[HIP2017] Bypass 802.1x \u2013 FENRIR<\/a><\/p>\n<h1>Hackers! Do we shoot or do we hug? \u2013Edwin Van Andel<\/h1>\n<p>Edwin Van Andel discussed the complex relationship between hackers and companies in the context of vulnerability reporting processes. By default, those who report vulnerabilities are viewed negatively and considered malicious by companies. Despite responsible disclosure practices, hackers are still too often prosecuted.<\/p>\n<p>By describing their methods and ways of thinking, he tried to show that hackers were benevolent and that they needed to be treated properly to encourage these approaches.<\/p>\n<p>To conclude his presentation, the speaker clearly stated: &quot;We hug!&quot;\u00ab<\/p>\n<h2>Popping a shell on a mainframe, is that even possible? \u2013 Ayoub Elaassal<\/h2>\n<p>Ayoub Elaassal, a security consultant at Wavestone, addressed the topic of mainframe security. These machines, with their high processing power, are widely used in large companies, such as banks and insurance companies. Having encountered this issue during certain projects, Ayoub continued his research, and his presentation described various mechanisms for bypassing the security of these machines.<\/p>\n<p>The applications available on the mainframes are accessed via a Telnet connection and rely on the CICS (Customer Information Control System). The first step proposed by Ayoub is to escape the application environment displayed upon system access. This can be done by pressing a specific key combination, which may vary depending on the application or system. It is then possible to execute arbitrary transactions. Some of these transactions can have a significant impact on the confidentiality of the data stored on the mainframe. This is the case with the CECI (Live Interpreter Debugger) transaction, which allows the execution of CICS API commands. Through this transaction, it is possible to read the contents of files stored on the mainframe, and thus access potentially sensitive customer data.<\/p>\n<p>The next step described by Ayoub is obtaining a <em>reverse shell<\/em> on the mainframe. It achieves this through a CICS feature called &quot;Spool functions&quot;. Using this function, it is able to write a program to the task scheduler (JES) queue, which will then execute it.<\/p>\n<p>Ayoub Elaassal concludes by demonstrating the possibility of privilege escalation to obtain administrator rights on the system, made possible by two characteristics: firstly, there is a category of library (APF) for which each program can request higher privileges. Secondly, access rights to these libraries are not restrictive enough, allowing arbitrary code to be written within them.<\/p>\n<p>The tools developed during this research are available on <a href=\"https:\/\/github.com\/ayoul3\">his Github<\/a>, and in particular <a href=\"https:\/\/github.com\/ayoul3\/cicspwn\">cicspwn<\/a>, which automates some of the tasks mentioned above.<\/p>\n<h2>25 Techniques to gather threat Intel and Track actors \u2013 Wayne Huang &amp; Sun Huang<\/h2>\n<p>Wayne Huang and Sun Huang presented 25 methods they used within Proofpoint to obtain information on various malicious actors in the market.<\/p>\n<p>Of the 25 methods presented, many are derived from standard penetration testing methodologies:<\/p>\n<ul>\n<li>Acknowledgement <em>(fuzzing<\/em> of known files, etc.)<\/li>\n<li>Exploiting misconfigurations (Apache Status, Directory Listing, etc.)<\/li>\n<li>Exploitation of known vulnerabilities (Shellshock, etc.)<\/li>\n<li>Etc.<\/li>\n<\/ul>\n<p>These methods nevertheless dispelled any doubt in the audience regarding the legitimacy of the actions taken.<\/p>","protected":false},"excerpt":{"rendered":"<p>Intrinsec attended the 7th edition of the Hack In Paris conference, preceding the [\u2026]<\/p>","protected":false},"author":12,"featured_media":3268,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[],"class_list":["post-3196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-veille-securite"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Hack In Paris 2017 - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hack In Paris 2017\" \/>\n<meta property=\"og:description\" content=\"Intrinsec s&rsquo;est rendu \u00e0 la 7\u00e8me \u00e9dition de la conf\u00e9rence Hack In Paris, pr\u00e9c\u00e9dant la [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2017-07-06T17:07:27+00:00\" \/>\n<meta name=\"author\" content=\"Quentin LEMAIRE\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Quentin LEMAIRE\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/\"},\"author\":{\"name\":\"Quentin LEMAIRE\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/6a3a288e6b8fdfa4f0cba274d8b2358f\"},\"headline\":\"Hack In Paris 2017\",\"datePublished\":\"2017-07-06T17:07:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/\"},\"wordCount\":1975,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"articleSection\":[\"Veille S\u00e9curit\u00e9\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/\",\"name\":\"Hack In Paris 2017 - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2017-07-06T17:07:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/hack-in-paris-2017\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hack In Paris 2017\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/6a3a288e6b8fdfa4f0cba274d8b2358f\",\"name\":\"Quentin LEMAIRE\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Quentin LEMAIRE\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/quentin-lemaire\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hack In Paris 2017 - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/","og_locale":"en_US","og_type":"article","og_title":"Hack In Paris 2017","og_description":"Intrinsec s&rsquo;est rendu \u00e0 la 7\u00e8me \u00e9dition de la conf\u00e9rence Hack In Paris, pr\u00e9c\u00e9dant la [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/","og_site_name":"INTRINSEC","article_published_time":"2017-07-06T17:07:27+00:00","author":"Quentin LEMAIRE","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Quentin LEMAIRE","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/"},"author":{"name":"Quentin LEMAIRE","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/6a3a288e6b8fdfa4f0cba274d8b2358f"},"headline":"Hack In Paris 2017","datePublished":"2017-07-06T17:07:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/"},"wordCount":1975,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#primaryimage"},"thumbnailUrl":"","articleSection":["Veille S\u00e9curit\u00e9"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/","url":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/","name":"Hack In Paris 2017 - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#primaryimage"},"thumbnailUrl":"","datePublished":"2017-07-06T17:07:27+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2017\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Hack In Paris 2017"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/6a3a288e6b8fdfa4f0cba274d8b2358f","name":"Quentin LEMAIRE","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Quentin LEMAIRE"},"url":"https:\/\/www.intrinsec.com\/en\/author\/quentin-lemaire\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/3196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=3196"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/3196\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=3196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=3196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=3196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}