<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Conferences on Willis Vandevanter</title><link>https://silentrobots.com/tags/conferences/</link><description>Recent content in Conferences on Willis Vandevanter</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 01 May 2016 00:00:00 +0000</lastBuildDate><atom:link href="https://silentrobots.com/tags/conferences/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploiting XXE In File Upload Functionality</title><link>https://silentrobots.com/exploiting-xxe-in-file-upload-functionality/</link><pubDate>Sun, 01 May 2016 00:00:00 +0000</pubDate><guid>https://silentrobots.com/exploiting-xxe-in-file-upload-functionality/</guid><description>&lt;img src="https://silentrobots.com/" alt="Featured image of post Exploiting XXE In File Upload Functionality" /&gt;&lt;p&gt;Just wanted to post some details from my BH USA 2015 briefing “Exploiting XXE In File Upload Functionality”.&lt;/p&gt;
&lt;p&gt;&lt;a class="link" href="https://www.youtube.com/watch?v=LZUlw8hHp44" target="_blank" rel="noopener"
 &gt;https://www.youtube.com/watch?v=LZUlw8hHp44&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I also gave an updated version of the presentation in November for the Blackhat Webcast Series. It included more file types; PDF, JPG, and GIF. The link is here: &lt;a class="link" href="https://www.blackhat.com/html/webcast/11192015-exploiting-xml-entity-vulnerabilities-in-file-parsing-functionality.html" target="_blank" rel="noopener"
 &gt;https://www.blackhat.com/html/webcast/11192015-exploiting-xml-entity-vulnerabilities-in-file-parsing-functionality.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Blackhat 2015 Arsenal</title><link>https://silentrobots.com/blackhat-2015-arsenal/</link><pubDate>Thu, 10 Sep 2015 00:00:00 +0000</pubDate><guid>https://silentrobots.com/blackhat-2015-arsenal/</guid><description>&lt;img src="https://silentrobots.com/" alt="Featured image of post Blackhat 2015 Arsenal" /&gt;&lt;p&gt;Last month at Blackhat Arsenal 2015, &lt;a class="link" href="https://github.com/parzamendi-r7" target="_blank" rel="noopener"
 &gt;Pete&lt;/a&gt; and I presented on Serpico. This was our second time at Arsenal. Yet again, awesome people, great venue, and overall a highlight for me of BH/DC/LV. We got some excellent feedback on the project, so thank you to anyone who stopped by.&lt;/p&gt;
&lt;p&gt;Last year I posted the top 3 feature requests and we squashed them (woot!). These are requested features/bugs this year and their associated issue on github:&lt;/p&gt;
&lt;h1 id="fix-image-breakage-in-presentations"&gt;Fix Image Breakage in Presentations
&lt;/h1&gt;&lt;p&gt;Automated Presentation creation was added the week before and had a rather embarassing stack trace in certain combinations; this was fixed in &lt;a class="link" href="https://github.com/MooseDojo/Serpico/commit/61fe996af37a79c94b34eea6fb5cf0a208fb87b5" target="_blank" rel="noopener"
 &gt;this commit&lt;/a&gt;&lt;/p&gt;
&lt;h1 id="statistics"&gt;Statistics
&lt;/h1&gt;&lt;p&gt;More than a few people asked for more correlation; “Support Findings Trending” (&lt;a class="link" href="https://github.com/MooseDojo/Serpico/issues/25" target="_blank" rel="noopener"
 &gt;Issue 25&lt;/a&gt;).&lt;/p&gt;
&lt;h1 id="wiki-additions"&gt;Wiki Additions
&lt;/h1&gt;&lt;p&gt;Add the following information to the wiki:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Report Creation Example&lt;/li&gt;
&lt;li&gt;Presentation Creation&lt;/li&gt;
&lt;li&gt;Export/Import Examples&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id="submit-to-kali"&gt;Submit To Kali
&lt;/h1&gt;&lt;p&gt;Here is the submission: &lt;a class="link" href="https://bugs.kali.org/view.php?id=2615" target="_blank" rel="noopener"
 &gt;New Tool Request: SERPICO&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Blackhat 2014 Arsenal Experience</title><link>https://silentrobots.com/untitled/</link><pubDate>Mon, 11 Aug 2014 00:00:00 +0000</pubDate><guid>https://silentrobots.com/untitled/</guid><description>&lt;img src="https://silentrobots.com/" alt="Featured image of post Blackhat 2014 Arsenal Experience" /&gt;&lt;p&gt;Last week at Blackhat Arsenal 2014, &lt;a class="link" href="https://github.com/parzamendi-r7" target="_blank" rel="noopener"
 &gt;Pete&lt;/a&gt; and I (&lt;a class="link" href="https://www.twitter.com/_will_is_" target="_blank" rel="noopener"
 &gt;@&lt;em&gt;will_is&lt;/em&gt;&lt;/a&gt;) presented on Serpico. Arsenal was a great experience and I would highly recommend to anyone as an attendee or presenter. We got some great feedback on the project, so thank you to anyone who stopped by.&lt;/p&gt;
&lt;p&gt;Here were the top 3 feature requests and their associated issue on github:&lt;/p&gt;
&lt;h1 id="global-variables"&gt;Global Variables
&lt;/h1&gt;&lt;p&gt;This feature would allow a user to add their own variable in the UI that would render in the template. A classic use case would be to edit the Executive Summary through the UI rather than inside of a template.&lt;/p&gt;
&lt;p&gt;Github Issue: &lt;a class="link" href="https://github.com/MooseDojo/Serpico/issues/19" target="_blank" rel="noopener"
 &gt;Support “Global Variables” for reports&lt;/a&gt; Released 08/22&lt;/p&gt;
&lt;h1 id="more-findings"&gt;More Findings
&lt;/h1&gt;&lt;p&gt;As of the most recent build Serpico comes with 8 findings; this is an area of active development. More than one person asked for findings from open sources such as CWE.&lt;/p&gt;
&lt;p&gt;Github Issue: &lt;a class="link" href="https://github.com/MooseDojo/Serpico/issues/20" target="_blank" rel="noopener"
 &gt;Include 40 Findings with the default installation&lt;/a&gt;&lt;/p&gt;
&lt;h1 id="plugin-to-3rd-parties"&gt;Plugin to 3rd Parties
&lt;/h1&gt;&lt;p&gt;This feature would allow a user to parse findings from different vulnerability scanners and import the results.&lt;/p&gt;
&lt;p&gt;Github Issue: &lt;a class="link" href="https://github.com/MooseDojo/Serpico/issues/21" target="_blank" rel="noopener"
 &gt;Support a connector to Nessus&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>