Index of works
Works
Public research from the region: conference talks, released tools, assigned CVEs, papers, and write-ups. Works are indexed by default — they are public record.
- 7 Vulns in 7 Days: Breaking Bloatware Faster Than It's Built Bloatware. We all hate it, and most of us are good at avoiding it. But some vendor tools – especially those managing critical drivers – can be useful when the Windows Update versions aren't good enough for performance-critical computing. What started as a routine driver update took a sharp turn when I confirmed a reboot modal… from my browser. Wait, my browser shouldn't be able to do that!? To my disappointment (and maybe some surprise), it turned out to be arbitrary code execution – right from the browser. This kicked off a week-long deep dive, uncovering seven CVEs in seven days across several prominent vendors, all exploiting a common pattern: privileged services managing software on Windows with little regard for security. recording youtube.com 2025 Talk
- Adversarial Explainability: Breaking explainable machine learning-based intrusion detection source blackhatmea.com 2025 Talk
- Blasting Through Defenses: The Rise of SMS Blasters Beyond Stingrays in the Middle East source blackhatmea.com 2025 Talk
- DNS Under the Lens: A Longitudinal Assessment of Resilience and Robustness in Saudi Arabia source blackhatmea.com 2025 Talk
- Moving Target Defence: Playing Around with Attackers source blackhatmea.com 2025 Talk
- Operationalizing Threat Informed Defense: A Security Architect's Perspective source blackhatmea.com 2025 Talk
- Overlooked & Overridden: Mitigating Risks from Unlocked Sessions to Unmanaged Local Assets source blackhatmea.com 2025 Talk
- The Imposter Factory: When Your Digital Identity Stops Being Yours - Deepfakes, Session Hijack Kits, and Fraud at Scale source blackhatmea.com 2025 Talk
- AI in OSINT – Zero snake oil In this blink-and-you'll-miss-it talk we cut all the introductions and waffle and, just like this abstract, get straight to the point :) Can we use AI in OSINT? Spoiler - yes and its pretty magical. We'll show, on screen, how AI helped solved real(ish) world cases. That's it. In the talk, I'll demo how we've build software that uses RAG AI to create an assistant that you can query about (deep, eg post authentication) web pages. I will show how the software works and then I will show results that were interesting. I'll end the talk with my predictions on how AI will impact OSINT in the near future. recording youtube.com 2024 Talk
- Attacking GraphQL: A guide for penetration testers Whats GraphQL? How do pwn it? And what do I write in my pentest report if I get this in a test? If these questions get your heart racing, fret not, this stalk is for you! GraphQL is at minimum, yet another API technology your company can get horribly wrong. The technology has grown considerably has an API interface technology in the last few years. With the growing interest, security engineering has been a keen focus for deployments because the technology is new, promises a lot (i.e. strict data typing, query batching and nesting, rapid adaptability etc.) and may not deliver the same impact in all environments or use cases. recording youtube.com 2024 Talk
- Attacking Pipelines: Large Scale Exploitation of Workflow Files In this talk, we present a tool designed to perform large-scale scanning of GitHub repositories to identify potential expression injection vulnerabilities within their workflow files. Our system efficiently scrapes repositories, concurrently pulling and analysing workflow configurations for insecure patterns. Through this mining process, we have discovered that expression injection vulnerabilities are surprisingly prevalent, even among popular projects, and often go unnoticed. We have reached out to affected vendors for remediation and hypothesis this prevalence attributed to a lack of in detection mechanisms and key documentation on GitHub's end. Additionally, we found that even when vulnerabilities are patched, they can be easily reintroduced by interpolating sanitised values. recording youtube.com 2024 Talk
- Ignorantia Juris Non Excusat – Understanding the Impact of the Law on the SA Hacker Community Many cybersecurity researchers and ethical hackers are becoming the target of criminal prosecutions and litigation, essentially for trying to do the right thing, and acting in an ethical manner. The reality is that cybersecurity researchers, practitioners and ethical hackers do run the risk of running afoul of both criminal and civil law in South Africa. This talk will explore the various laws and legal actions that could impact on them, and how to work within the framework of the law in South Africa, and essentially keep them safe from legal harm. The talk will cover the various activities that cybersecurity researchers, practitioners and ethical hackers undertake, and explore the various legal issues that may impact on these activities. recording youtube.com 2024 Talk
- Rite of Passage: My Journey from BSides Volunteer to Black Hat Asia Attendee From volunteering at BSides Cape Town to being sponsored to attend Black Hat Asia, I'll share my unexpected journey and the power of community involvement in shaping my career in cybersecurity. Through this talk, I aim to inspire students to take that first step into getting involved with the cybersecurity community. In 2023, I volunteered at BSides Cape Town as a way to immerse myself in the cybersecurity community. What I didn't anticipate was that my involvement would lead to an incredible opportunity: being selected for the Rite of Passage Initiative and getting sponsored to attend Black Hat Asia 2024. recording youtube.com 2024 Talk
- SpeedRunners: The Hackers of the Gaming World Speedrunning, the art of completing games with incredible speed, has evolved into more than a gaming feat - it's a showcase of ingenuity, creativity, and technical prowess. This talk delves into the fascinating world of speedrunners, drawing parallels between their methodologies and those of cybersecurity professionals, while highlighting the significant impact on game development and software security. We'll explore how speedrunners discover and exploit glitches in games through a combination of accident, experimentation, and deep code analysis - skills that mirror the vulnerability hunting process in software security. recording youtube.com 2024 Talk
- Forging Chains: The Java Blacksmith We present a tool to automatically extract gadget chains from arbitrary combinations of classes on the Java class path - outside the lab environment. The aim is to demonstrate that patching chains makes no sense: deserializing arbitrary attacker-controlled objects is the vulnerability, not the chain. When a program is found to write past the bounds of its buffer, developers will eagerly fix the buffer overflow, whether proven to be exploitable or not. In contrast, when it is found to deserialize arbitrary attacker-controlled objects, you will find that developers would like to hold on to this particularly flexible way of passing objects between processes because it is a feature they love and cherish. recording youtube.com 2023 Talk
- Fun with GPON source bsidescapetown.co.za 2023 Talk
- Hack South: Home of the ubiquitous South Hack South has become a staple of the ZA Hacker community. Hack South has come a long way since lockdown, but what does the future hold, and where can you get involved? recording youtube.com 2023 Talk
- How to sink a UBoot: Understanding bootloader attack surface Uboot is arguably the defacto standard for providing adaptable bootloader environments for a plethora of infrastructures. Unfortunately some of the configuration options may expose vulnerabilities which compromise environments and may allow attackers to take control during privileged contexts. The talk included here will cover some of the Uboot basics, detail some architectural aspects of modern bootloaders as well as ways an eager hacker can exploit Uboot in order to drop a shell and take control. Bootloaders are an obscure part of the operating system, they load the operating system, setup up the hardware and present us with a working, running machine all out of sight and out of mind. recording youtube.com 2023 Talk
- Impose Cost The best defence is a good offence - except in cybersecurity where we send people to the battlefield with armour and radios. The most active defence gets is evicting attackers from their network. We've leaned in so hard into defence as an industry we're lying on the floor, and it's time to look up. But, how can we take the fight to the criminals, without crossing legal and ethical boundaries? recording youtube.com 2023 Talk
- Oops!!!…did I reveal something? Protect your Azure infrastructure from insecure secrets in deployment templates with deployment grazor - an Azure PowerShell script that detects potential misconfigurations and leaked secrets. Infrastructure as Code (IaC) has been a valuable tool in the arsenal of DevOps teams globally. IaC tools such as Bicep and Terraform promote speed and consistency of deployments. These tools and associated deployment templates are typically leveraged in environments requiring large scale infrastructure. In Microsoft Azure, deployment templates are static files written in JSON, and used to define the configuration of a deployed resource. recording youtube.com 2023 Talk
- Outsmarting cyber villains on a shoestring budget This presentation covers the most common cyber threats affecting South Africa and how to combat them by building your own cyber threat intelligence platform on a budget. This presentation focuses on practical steps to help you get started with building your own cyber threat intel programme for your organisation - importantly - on a budget! The start of the presentation looks at the cybercrime crisis we face in SA and includes stats and info about the most prevalent threats noted and the "why" behind why these malicious acts are carried out. The next slides discuss strategies to combat the threats mentioned. recording youtube.com 2023 Talk
- Securing a Derivatives Platform With Over $25b Volume How would you approach exploiting a derivatives market? We'll explore how we secured a perpetuals market averaging north of $100m in daily volume. It'll be a technical deep dive beyond traditional pentesting concerns, focusing on abusing game theory and economic models for profit. In the high-stakes world of smart contracts, a single overlooked flaw could result in an instantaneous multi-million dollar loss. The talk will be based on experience gained through security reviews iosiro has performed of Synthetix's Perpetual markets. The code, infrastructure, and assessment results are all public, so we can give deep insights into our learnings. recording youtube.com 2023 Talk
- ALL BARK, NO BYTE recording youtube.com 2022 Talk
- An IOT War Story recording youtube.com 2022 Talk
- Made in SA – For the World recording youtube.com 2022 Talk
- Permanently bricking smart contracts for fun and profit recording youtube.com 2022 Talk
- Securing a cloud native open source microservice based core banking system recording youtube.com 2022 Talk
- Smart Watch Lobotomy recording youtube.com 2022 Talk
- Authentication is Broken. Can We Try Fix It? This talk seeks to demonstrate how the hardened derivation of hierarchically deterministic asymmetric keys can be used as an authentication mechanism that sites could use to replace the passwords. As anyone who frequents haveibeenpwned would know, password reuse is a major problem that is worsened by inevitable data leakages. Without the use of a password manager a person is prone to reuse a password at least once (or risk forgetting their password if they try to be clever by coming up with a new password for every site). In this proposed authentication mechanism sites would store xpubs instead of passwords. The xpubs would be used to derive public keys when authenticating users. recording youtube.com 2019 Talk
- Hacking satellites with Software Defined Radio (SDR) In this no holds barred down introduction to Software Defined Radio (SDR) you'll learn how you can write software to hack remote control security gates, track ships at sea, code your own aircraft radar, and ultimately how to download data directly from various satellites in low earth orbit with nothing more than a cheap USB dongle and a makeshift antenna. recording youtube.com 2019 Talk
- Hashing the $#!+ out of firmware Everything is broken... But is it possible that more things are more broken than we though? Probably. But lets look at that. When it comes to embedded devices, we rely largely on the OEM manufacturer to provide firmware and firmware updates. These updates could be issued for a number of reasons: better performance, improved feature set, bug fixes, and security patches. But when you download a firmware update, you generally only have the manufacturer's word that it does what it says, with information sometime being provided in the change-log. But these change logs don't always tell all. This research looks at pulling firmware apart to see whats inside, and comparing firmwares to see what might have changed (between versions), and what might be getting reused (between different devices). recording youtube.com 2019 Talk
- How machine learning and AI can help reduce the cyber-attacks According to Global cyber security company Kaspersky Lab South Africans have once again been warned to be careful in cyberspace with a 22% increase in malware attacks in the country in the first quarter of this year. It seems that every presentation from every security vendor begins with an introductory slide explaining how the number and complexity of attacks an organization faces have continued to grow exponentially. Of course, everyone from security operations center (SOC) analysts, who are drowning in alerts, to chief information security officers (CISOs), who are desperately trying to make sense of the trends in security, is acutely aware of the situation. The question is how do we, collectively, solve the problem of overwhelmed security teams? recording youtube.com 2019 Talk
- Meticulously Modern Mobile Manipulations Mobile app hacking peaked in 2015 with tools like keychain-dumper & ssl- kill-switch released but requiring jailbroken/rooted devices. Back then, wresting the power to understand & modify apps on our devices from dystopian looking mega corps was our cause. As jailbreaks became infrequent, the hackers' arsenal was left behind. While this is progress against dark uses of hacking, done to protect our freedom fighters, how can hackers still hold power to account? Can we still find flaws in apps/devices & live up to the protections the technology promises? Enter runtime binary instrumentation with Frida. It's possible to analyze apps in their final state when executed on real hardware running the latest iOS/Android with no jailbreaks. This fills a gap between source analysis & debuggers. recording youtube.com 2019 Talk
- Natural Language Processing & Anomaly detection in Sys call logs Containers (lightweight application virtualization) provide further isolation for application's, but the container daemon and management systems, ads more attack surface. The research problem is that despite segmentation and system call hardening, containers are still vulnerable and the host and other containers can be affected. In this paper, the use of syscall (system calls, calls to kernel) logging in Linux x86_64 systems is investigated with Natural Language Processing. Logs are tokenized and hashed, then transformed into a sparse matrix encoding. The purpose of the method is to classify the documents and test the different accuracies of different classifiers, such as Random Forest, K Nearest Neighbor, etc. recording youtube.com 2019 Talk
- Put Words In My Mouth Money has been withdrawn from your account. You don't remember making, or authorising that transaction. When you follow up with the bank, they say you called earlier and requested the transfer - it was, after-all, you speaking - right? Unbeknownst to you, your voice was stolen, and so was your money. With the rise of voice authentication biometrics, so will the opportunities to spoof it. Text-to-Speech API's are constantly improving, with Google's technology now being indistinguishable from the real human speaker. Threat actors have access to a target's YouTube videos, social media posts. recording youtube.com 2019 Talk
- WhatsApp Digger slides github.com 2019 Tool
- A Walk With Shannon: A walkthrough of a PWN2OWN Baseband exploit slides github.com 2018 Talk
- Anomaly detection in container sandboxing Anomaly detection through sand-boxing and network monitoring, for security incident detection of un-trusted code. Talk including google's gvisor and sandboxing kubernetes. recording youtube.com 2018 Talk
- Mallet – an intercepting proxy for arbitrary protocols In this talk, I will focus on a new open-source intercepting proxy named Mallet, based on the mature and high-performance Netty framework, that wraps it with a drag and drop graph-based graphical user interface and a datastore. In doing so, we gain access to an existing library of protocol implementations, including TLS (and SNI), various compression algorithms, HTTP, HTTP/2, MQTT, REDIS, and many others, and most important, an existing community of developers creating new protocol decoders and encoders, and the associated body of knowledge in this area. recording youtube.com 2018 Talk
- Program Analysis on Smart Contracts slides github.com 2018 Talk
- SDN Crash Course recording youtube.com 2018 Talk
- The Baseband Basics: Understanding, Debugging and Pwning the Mediatek Communication Processor slides github.com 2018 Talk
- You and your research slides github.com 2018 Talk
- Docker for Hackers recording youtube.com 2017 Talk
- Junk Hacking to skill up – Exploiting a Personal Cloud Storage and Media Streamer source bsidescapetown.co.za 2017 Talk
- Stranger Danger slides github.com 2017 Talk
- Using Electromagnetic Emissions to Intercept AES-128 Cryptographic Keys from a Raspberry Pi source bsidescapetown.co.za 2017 Talk
- SensePost XRDP Tool In this talk, we'll cover how an X server functions, how one becomes vulnerable, previous methods of exploitation, and finally the developed tool as well as how it works and what it provides. In 1997, a vulnerability in X11 was released that allowed unauthenticated access to the X server due to access controls being disabled [1]. This vulnerability gives an attacker full control of the target host using the default X toolset developed to work using the protocol. Given the age of this vulnerability, it is still being found while on internal penetration tests and even on the Internet. recording youtube.com 2016 Tool
- Mercury – Android exploitation framework source bsidescapetown.co.za 2013 Tool
- Offensive Software Defined Radio source bsidescapetown.co.za 2013 Talk
- Using DNS as Anti-virus source bsidescapetown.co.za 2012 Talk
- Cyber Warfare: The Amplified Great Hacker War 2011 Talk
- Data Security Best Practices 2011 Talk
- Hacking The Economy 2011 Talk
- Handling Incidents Before They Handle You 2011 Talk
- How Did I Steal Your Database 2011 Talk
- New trends in Cybercrime and Digital Forensics Challenges 2011 Talk
- Owning the Command and Control: Reverse Engineering Malware 2011 Talk
- SCADA Security, The Emerging Threat 2011 Talk
- The Role of Information Security in the Post-Revolution Economic & Political Development 2011 Talk
- The Weakest Link 2011 Talk
- Towards an Egyptian Framework for CyberSecurity 2011 Talk
- Web Threats & Defense in Depth Strategy for Web Servers 2011 Talk