{
 "id": 36997,
 "slug": "2019-09-27_visiting-an-international-hackers-conference",
 "url": "https://agents.willem.com/en/posts/2019-09-27_visiting-an-international-hackers-conference/",
 "source_url": "https://willem.com/en/2019-09-27_visiting-an-international-hackers-conference/",
 "language": "en",
 "date": "2019-09-27",
 "published": "2019-09-27T00:00:00+02:00",
 "created": "2025-06-26T22:10:09.537000+02:00",
 "updated": "2025-07-22T16:42:47.911000+02:00",
 "title": "Visiting an international hackers conference",
 "subtitle": "OWASP Global AppSec Amsterdam",
 "summary": "This month I was lucky enough to attend Global AppSec Amsterdam, an international conference for hackers and security specialists. There were presentations from former intelligence agents, bounty hunters, academics and software vendors. I learned about some of the newest hacking techniques, met with interesting people and played some cool retro games. Read along for more.",
 "topics": [
  "Amsterdam",
  "Nintendo",
  "cyber-security",
  "data",
  "hacking",
  "people",
  "work"
 ],
 "author": {
  "name": "Willem L. Middelkoop",
  "url": "https://willem.com"
 },
 "translation": {
  "language": "nl",
  "url": "https://agents.willem.com/nl/posts/2019-09-27_het-bezoeken-van-een-internationale-hackersconferentie/",
  "source_url": "https://willem.com/nl/2019-09-27_het-bezoeken-van-een-internationale-hackersconferentie/"
 },
 "image": "https://willem.com/global/images/cb5ea75db8ba.webp",
 "image_width": 2560,
 "images": [
  {
   "url": "https://willem.com/global/images/403811a3464b.webp",
   "description": "Global AppSec-Amsterdam",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-1.jpg"
  },
  {
   "url": "https://willem.com/global/images/8d317a6e37bb.webp",
   "description": "Keynote presentation by cyberwarfare specialist, Chris Kubecka",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-2.jpg"
  },
  {
   "url": "https://willem.com/global/images/ad3f0bba8321.webp",
   "description": "Lessons learned from dealing with terrorists",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-3.jpg"
  },
  {
   "url": "https://willem.com/global/images/86cc76d31a28.webp",
   "description": "Coffee and PONG on the video-sports console with CRT monitor",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-4.jpg"
  },
  {
   "url": "https://willem.com/global/images/3ebd793dd0c1.webp",
   "description": "DuckHunt with an original Nintendo zapper",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-5.jpg"
  },
  {
   "url": "https://willem.com/global/images/5ac85970a721.webp",
   "description": "Remember the days that this was your average computer - note: the IBM model M keyboard... oh boy!",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-6.jpg"
  },
  {
   "url": "https://willem.com/global/images/f7a3c90be9d0.webp",
   "description": "Persistent Client-Side XSS is a real threat - by Marius Steffens and Ben Stock",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-7.jpg"
  },
  {
   "url": "https://willem.com/global/images/aa04e0114bcd.webp",
   "description": "James Kettle on hacking PayPal - gaining $38,900 in bounties",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-8.jpg"
  },
  {
   "url": "https://willem.com/global/images/3c11c554de6f.webp",
   "description": "Hacking return rates on investment between 100% on the low end and 150,000% on the high end! (By Jarrod Overson)",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-9.jpg"
  },
  {
   "url": "https://willem.com/global/images/d039827bdd65.webp",
   "description": "Hacking Google - How I could have stolen your photos from Google (Gergö Turcsányi)",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-10.jpg"
  },
  {
   "url": "https://willem.com/global/images/1053cb217048.webp",
   "description": "Global AppSec Amsterdam",
   "manager_file": "148-bf2d6faf6057f115dc72e82d984e71359f16b48d8c42b4b41c2ee918cf46b556_ContentAsPost_36997_images-11.jpg"
  }
 ],
 "text": "OWASP Foundation and Global AppSec Amsterdam\nThe OWASP Foundation is a not-for-profit organisation dedicated to create tools, documentation, forums and conferences around software security. OWASP is special because it's free from commercial pressure, it is not affiliated with any technology company. They advocate approaching application security as a people, process and technology problem because the most effective approaches to application security include improvements in all of these areas. More about OWASP can be found on https://www.owasp.org.\nThe Global AppSec events are organised all over the world. This September there was such an event in my hometown Amsterdam. Check their_schedule (https://www.owasp.org/index.php/OWASP_Events/upcoming_events) to find out if OWASP is coming to your town.\nWhen cyber security gets real: Squashing Terrorists\nOne of the most impressive stories was told by Chris_Kubecka (https://en.wikipedia.org/wiki/Chris_Kubecka), a woman wo has worked for the US Air Force and United States Space Command. She is a computer security researcher, and cyberwarfare specialist.\nShe talks about her work at the Royal Saudi Arabian Embassy in The Hague. It's very interesting to learn about how the local police, the Diplomatic Corps and special agents were involved to ultimately prevent a bomb attack on the Kurhaus_in_Scheveningen (https://en.wikipedia.org/wiki/Kurhaus_(Scheveningen). It's when you hear these stories that you realise that not everything that happens gets featured on the news!\nCoffee and games\nAfter the keynote about terrorists, cyberwarfare and bomb attacks it was time for some coffee and games. Playing retro games is a fun way to meet other hackers on the conference as you'll have an obvious shared thing to talk about. That's useful as most IT-experts need a little help breaking the ice when it comes to socialising...\nHacking techniques\nAfter coffee there were several sessions that you could attend. I selected a few based on my personal interests and my work.\nPersistent Client-Side XSS\nOne of the talks I attended involved attacking websites using Local Storage or cookies. Aptly named \"Don't trust the locals\", the presentation from Marius_Steffens (https://cispa.saarland/people/marius.steffens/) and Ben_Stock (https://cispa.saarland/people/ben.stock/) was very interesting. Their academic research revealed that many websites are vulnerable for threats gaining a permanent foothold!\nHacking PayPal using HTTP desync attack\nIn his brilliant talk James_Kettle (https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn) describes his research on possibly one of the most dangerous hacking techniques on the modern web: HTTP_Request_Smuggling_by_desyncing_HTTP_requests (https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn). This technique uses vulnerabilities when a website uses a content delivery network (CDN), a web cache or a web application firewall (WAF). It's amazing to learn about this, to understand the underlying principle and to learn how to defend against this kind of attack.\nHacking economics: what's an hacked account worth?\nIn another interesting talk Jarrod_Overson (https://jarrodoverson.com) explains the state of credential_stuffing_attacks (https://jarrodoverson.com/post/no-2fa-does-not-stop-credential-stuffing-attacks-79de7476a80a/). This type of attack involves using leaked account names and passwords on different websites, which is surprisingly successful as a lot of people use the same password on different sites. He explains how_to_bypass_CAPTCHAS (https://jarrodoverson.com/post/bypassing-captchas-with-headless-chrome-93f294518337/) and how hackers make their malware mimic human behaviour for fraud. He concludes that fraud is a human problem, not a technical one - driven by simple economics: it's worth hacking!\nHacker's mindset\nIn his talk, Gergö_Turcsányi (https://twitter.com/gergoturcsanyi?lang=en) talks about how he became a bounty hunter. He explains that you don't need to be an incredibly skilled mathematician to do this, all you need is a little creativity and some time to time to poke around. Eventually, this led him to successfully hack Google!\nConclusion\nVisiting Global AppSec was fantastic! It's a privilege to meet other hackers, learn from them and hear about the things you normally won't see on the news.\nWhatever you take away from a conference, there will always be something that you didn't expect to learn. It's this unexpected learning that makes visiting conferences very much worth the effort!",
 "word_count": 617,
 "markdown_url": "https://agents.willem.com/en/posts/2019-09-27_visiting-an-international-hackers-conference/post.md"
}