Vanguard Security & Compliance conference brings together cybersecurity leaders and professionals to deliver knowledge-based training for securing and defending the IBM System z®. On September 16-19 at Sonesta Charlotte Executive Park in Charlotte, NC, NetSPI security experts will join the conference with three speaking sessions, including a Keynote speech.
When:
September 16-19, 2024
Where:
Sonesta Charlotte Executive Park
Charlotte, NC
Speakers
Philip Young
Director, Mainframe
As a Director, Philip is responsible for the Mainframe Pentesting service line and managing clients to help them understand their mainframe cybersecurity treat landscape. Philip has spent the past 15 years building mainframe penetration testing programs at Fortune 500 companies.
Certifications earned include Security+, CISSP and OSCP.
Philip has contributed to the security community through presenting at BlackHat, SEC-T, GSE, RSA, Hactivity, DEFCON and SHARE. Philip has also co-created and taught the world’s only mainframe penetration testing class. He has contributed to multiple opensource tools such as Nmap and Metasploit to add support for z/OS, and has developed many opensource mainframe penetration testing tools such as CAPMAP, APFCHECK, as well as brute force tools for TSO and CICS.
Michelle Eggers
Security Consultant
As a Security Consultant, Michelle Eggers executes penetration testing for a variety of client environments. After making a strong pivot from operations into proactive security, Michelle primarily focuses on web application, mainframe, and network pentesting.
Michelle has contributed to the security community by speaking about mainframe and web application security at various cybersecurity conferences, volunteering with Black Girls Hack during Hacker Summer Camp, and driving forward interest in securing mission critical systems and critical infrastructure through authoring blog posts and social media content on the subjects.
Credentials and certifications earned include CompTIA Security+ and ISC2 Certified in Cybersecurity. She also holds a Bachelor of Science degree in Accounting, a Project Management Certificate from Cornell University, and an Evolve Security Certified Professional credential.
Speaking Session
Keynote
10 Years of Mainframe Hacking: A history of mainframe hacking and penetration testing
When: Monday, September 16 | 3:45-4:30pm ET
Philip Young
Director, Mainframe
What a long and weird journey it has been. Come learn about the short history of the last 10 years of mainframe hacking pen testing, the advances in research and how a rag-tag group of like-minded individuals are working together to make mainframe security testing more open and available than ever before.
No Longer a Myth: A Guide to Mainframe Buffer Overflows
When: Tuesday, September 17 | 9:15-10:15am ET
Philip Young
Director, Mainframe
A brilliant mind recently discovered that what was once thought impossible is now possible. For decades the myth in this community was that they weren’t susceptible to buffer overflows, therefore making them safer than their Linux/Windows counterparts.
Well, it turns out that’s not true. This talk will walk through how this was discovered, how to hunt for overflows, especially in APF authorized libraries, and how to exploit them using HLASM and the IBM assembler to make the shellcode for us.
This is an exciting discovery in the mainframe hacker community and we can’t wait to share it with you. Attendees will also be given a docker container where they can learn how to write mainframe buffer overflows.
CICS Application Penetration Testing
When: Tuesday, September 17 | 1:00-2:00pm ET
Philip Young
Director, Mainframe
In early 2023 a new mainframe attack tool was discussed: hack3270. The creators of this tool spoke about it but did not release it. Then in mid 2023 it was released as an opensource tool. This tool was designed (with support from the speaker) to ease and accelerate the testing of CICS applications, specifically targeting TN 3270 weaknesses and common CICS application pitfalls.
Attendees will learn some of the common security weaknesses we find in CICS applications, how we can target those weaknesses and how to automate some of their testing. Specifically, this talk will walk through various transactions in the Damn Vulnerable CICS Application (freely available as an open-source CICS application) using the hack3270 tool, demonstrating the types of attacks used during penetration testing. The presentation will also go over some of the code that leads to these weaknesses and how they can be prevented.
Come witness the bleeding edge of application security research.
Web Based Penetration Testing
When: Tuesday, September 17 | 2:15-3:15pm ET
Michelle Eggers
Security Consultant
Over the years, mainframe developers have seen fit to make almost everything a web app. From Abend Aid to z/OSMF, there’s no avoiding web apps on your mainframe. Even internally as companies modernize their mainframe, they’re opening up web APIs and web pages for other systems to consume. With the growing presence of web applications on mainframes comes new risks. Unfortunately the threats that exist for these web-based environments may be lurking in the shadows of the unexamined mainframe.
The purpose of this talk is to walk through some examples of vulnerable web applications, exploring well-established approaches to web application penetration testing methodology, covering several of the most frequently seen vulnerabilities, and how these vulnerabilities can potentially lead to a compromise of your z/OS environment. Vulnerabilities covered in this talk will be based on OWASP top 10 vulnerabilities but with a z/OS twist.
Explore more events and webinars
Black Hat Europe
It's game on with NetSPI to level-up with our Proactive Security Solutions. Thanks for stopping by Stand 320; we'll see you next year!
Strategic Attack Surface Management: Piecing Together the Puzzle
Join NetSPI security experts as they discuss integrating External Attack Surface Management (EASM) & External Network Penetration Testing (ExPens) in a proactive security strategy.
Enterprise AI Security Transformation Assembly Europe
Meet NetSPI at the Enterprise AI Security Transformation Assembly Europe on 19-20 November at The Atzavara in Barcelona!