Index of works

Works

Public research from the region: conference talks, released tools, assigned CVEs, papers, and write-ups. Works are indexed by default — they are public record.

  1. 7 Vulns in 7 Days: Breaking Bloatware Faster Than It's Built Leon Jacobs · Unattributed Bloatware. We all hate it, and most of us are good at avoiding it. But some vendor tools – especially those managing critical drivers – can be useful when the Windows Update versions aren't good enough for performance-critical computing. What started as a routine driver update took a sharp turn when I confirmed a reboot modal… from my browser. Wait, my browser shouldn't be able to do that!? To my disappointment (and maybe some surprise), it turned out to be arbitrary code execution – right from the browser. This kicked off a week-long deep dive, uncovering seven CVEs in seven days across several prominent vendors, all exploiting a common pattern: privileged services managing software on Windows with little regard for security. recording youtube.com 2025 Talk
  2. Adversarial Explainability: Breaking explainable machine learning-based intrusion detection Mohammed M. Alani · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  3. Blasting Through Defenses: The Rise of SMS Blasters Beyond Stingrays in the Middle East Nauman Khan · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  4. DNS Under the Lens: A Longitudinal Assessment of Resilience and Robustness in Saudi Arabia Fatemah Alharbi · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  5. Moving Target Defence: Playing Around with Attackers Bushra Alhetelah · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  6. Operationalizing Threat Informed Defense: A Security Architect's Perspective Sivaraman Girisan · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  7. Overlooked & Overridden: Mitigating Risks from Unlocked Sessions to Unmanaged Local Assets Adel Alzubeir · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  8. The Imposter Factory: When Your Digital Identity Stops Being Yours - Deepfakes, Session Hijack Kits, and Fraud at Scale Laith Samara · Black Hat MEA · Saudi Arabia source blackhatmea.com 2025 Talk
  9. AI in OSINT – Zero snake oil Roelof Temmingh · BSides Cape Town · South Africa In this blink-and-you'll-miss-it talk we cut all the introductions and waffle and, just like this abstract, get straight to the point :) Can we use AI in OSINT? Spoiler - yes and its pretty magical. We'll show, on screen, how AI helped solved real(ish) world cases. That's it. In the talk, I'll demo how we've build software that uses RAG AI to create an assistant that you can query about (deep, eg post authentication) web pages. I will show how the software works and then I will show results that were interesting. I'll end the talk with my predictions on how AI will impact OSINT in the near future. recording youtube.com 2024 Talk
  10. Attacking GraphQL: A guide for penetration testers Keith Makan · BSides Cape Town · South Africa Whats GraphQL? How do pwn it? And what do I write in my pentest report if I get this in a test? If these questions get your heart racing, fret not, this stalk is for you! GraphQL is at minimum, yet another API technology your company can get horribly wrong. The technology has grown considerably has an API interface technology in the last few years. With the growing interest, security engineering has been a keen focus for deployments because the technology is new, promises a lot (i.e. strict data typing, query batching and nesting, rapid adaptability etc.) and may not deliver the same impact in all environments or use cases. recording youtube.com 2024 Talk
  11. Attacking Pipelines: Large Scale Exploitation of Workflow Files David Baker Effendi, Rohan Dayaram · BSides Cape Town · South Africa In this talk, we present a tool designed to perform large-scale scanning of GitHub repositories to identify potential expression injection vulnerabilities within their workflow files. Our system efficiently scrapes repositories, concurrently pulling and analysing workflow configurations for insecure patterns. Through this mining process, we have discovered that expression injection vulnerabilities are surprisingly prevalent, even among popular projects, and often go unnoticed. We have reached out to affected vendors for remediation and hypothesis this prevalence attributed to a lack of in detection mechanisms and key documentation on GitHub's end. Additionally, we found that even when vulnerabilities are patched, they can be easily reintroduced by interpolating sanitised values. recording youtube.com 2024 Talk
  12. Ignorantia Juris Non Excusat – Understanding the Impact of the Law on the SA Hacker Community Jason Jordaan · BSides Cape Town · South Africa Many cybersecurity researchers and ethical hackers are becoming the target of criminal prosecutions and litigation, essentially for trying to do the right thing, and acting in an ethical manner. The reality is that cybersecurity researchers, practitioners and ethical hackers do run the risk of running afoul of both criminal and civil law in South Africa. This talk will explore the various laws and legal actions that could impact on them, and how to work within the framework of the law in South Africa, and essentially keep them safe from legal harm. The talk will cover the various activities that cybersecurity researchers, practitioners and ethical hackers undertake, and explore the various legal issues that may impact on these activities. recording youtube.com 2024 Talk
  13. Rite of Passage: My Journey from BSides Volunteer to Black Hat Asia Attendee Blessing Mufaro Kashava · BSides Cape Town · South Africa From volunteering at BSides Cape Town to being sponsored to attend Black Hat Asia, I'll share my unexpected journey and the power of community involvement in shaping my career in cybersecurity. Through this talk, I aim to inspire students to take that first step into getting involved with the cybersecurity community. In 2023, I volunteered at BSides Cape Town as a way to immerse myself in the cybersecurity community. What I didn't anticipate was that my involvement would lead to an incredible opportunity: being selected for the Rite of Passage Initiative and getting sponsored to attend Black Hat Asia 2024. recording youtube.com 2024 Talk
  14. SpeedRunners: The Hackers of the Gaming World Nunudzai Mrewa · BSides Cape Town · South Africa Speedrunning, the art of completing games with incredible speed, has evolved into more than a gaming feat - it's a showcase of ingenuity, creativity, and technical prowess. This talk delves into the fascinating world of speedrunners, drawing parallels between their methodologies and those of cybersecurity professionals, while highlighting the significant impact on game development and software security. We'll explore how speedrunners discover and exploit glitches in games through a combination of accident, experimentation, and deep code analysis - skills that mirror the vulnerability hunting process in software security. recording youtube.com 2024 Talk
  15. Forging Chains: The Java Blacksmith Fabian Yamaguchi, David Baker Effendi · BSides Cape Town · South Africa We present a tool to automatically extract gadget chains from arbitrary combinations of classes on the Java class path - outside the lab environment. The aim is to demonstrate that patching chains makes no sense: deserializing arbitrary attacker-controlled objects is the vulnerability, not the chain. When a program is found to write past the bounds of its buffer, developers will eagerly fix the buffer overflow, whether proven to be exploitable or not. In contrast, when it is found to deserialize arbitrary attacker-controlled objects, you will find that developers would like to hold on to this particularly flexible way of passing objects between processes because it is a feature they love and cherish. recording youtube.com 2023 Talk
  16. Fun with GPON Denver Abrey · BSides Cape Town · South Africa source bsidescapetown.co.za 2023 Talk
  17. Hack South: Home of the ubiquitous South Charles "AngusRed" Wroth · BSides Cape Town · South Africa Hack South has become a staple of the ZA Hacker community. Hack South has come a long way since lockdown, but what does the future hold, and where can you get involved? recording youtube.com 2023 Talk
  18. How to sink a UBoot: Understanding bootloader attack surface Keith Makan · BSides Cape Town · South Africa Uboot is arguably the defacto standard for providing adaptable bootloader environments for a plethora of infrastructures. Unfortunately some of the configuration options may expose vulnerabilities which compromise environments and may allow attackers to take control during privileged contexts. The talk included here will cover some of the Uboot basics, detail some architectural aspects of modern bootloaders as well as ways an eager hacker can exploit Uboot in order to drop a shell and take control. Bootloaders are an obscure part of the operating system, they load the operating system, setup up the hardware and present us with a working, running machine all out of sight and out of mind. recording youtube.com 2023 Talk
  19. Impose Cost Singe · BSides Cape Town · South Africa The best defence is a good offence - except in cybersecurity where we send people to the battlefield with armour and radios. The most active defence gets is evicting attackers from their network. We've leaned in so hard into defence as an industry we're lying on the floor, and it's time to look up. But, how can we take the fight to the criminals, without crossing legal and ethical boundaries? recording youtube.com 2023 Talk
  20. Oops!!!…did I reveal something? Javan Mnjama · BSides Cape Town · South Africa Protect your Azure infrastructure from insecure secrets in deployment templates with deployment grazor - an Azure PowerShell script that detects potential misconfigurations and leaked secrets. Infrastructure as Code (IaC) has been a valuable tool in the arsenal of DevOps teams globally. IaC tools such as Bicep and Terraform promote speed and consistency of deployments. These tools and associated deployment templates are typically leveraged in environments requiring large scale infrastructure. In Microsoft Azure, deployment templates are static files written in JSON, and used to define the configuration of a deployed resource. recording youtube.com 2023 Talk
  21. Outsmarting cyber villains on a shoestring budget Roshan Harneker · BSides Cape Town · South Africa This presentation covers the most common cyber threats affecting South Africa and how to combat them by building your own cyber threat intelligence platform on a budget. This presentation focuses on practical steps to help you get started with building your own cyber threat intel programme for your organisation - importantly - on a budget! The start of the presentation looks at the cybercrime crisis we face in SA and includes stats and info about the most prevalent threats noted and the "why" behind why these malicious acts are carried out. The next slides discuss strategies to combat the threats mentioned. recording youtube.com 2023 Talk
  22. Securing a Derivatives Platform With Over $25b Volume Kyle Riley · BSides Cape Town · South Africa How would you approach exploiting a derivatives market? We'll explore how we secured a perpetuals market averaging north of $100m in daily volume. It'll be a technical deep dive beyond traditional pentesting concerns, focusing on abusing game theory and economic models for profit. In the high-stakes world of smart contracts, a single overlooked flaw could result in an instantaneous multi-million dollar loss. The talk will be based on experience gained through security reviews iosiro has performed of Synthetix's Perpetual markets. The code, infrastructure, and assessment results are all public, so we can give deep insights into our learnings. recording youtube.com 2023 Talk
  23. ALL BARK, NO BYTE Amy Mania · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  24. An IOT War Story Jason Spencer · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  25. Made in SA – For the World Haroon Meer · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  26. Permanently bricking smart contracts for fun and profit Ashiq Amien · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  27. Securing a cloud native open source microservice based core banking system Ntando Mngomezulu · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  28. Smart Watch Lobotomy Dale Nunns · BSides Cape Town · South Africa recording youtube.com 2022 Talk
  29. Authentication is Broken. Can We Try Fix It? Kgothatso Ngako · BSides Cape Town · South Africa This talk seeks to demonstrate how the hardened derivation of hierarchically deterministic asymmetric keys can be used as an authentication mechanism that sites could use to replace the passwords. As anyone who frequents haveibeenpwned would know, password reuse is a major problem that is worsened by inevitable data leakages. Without the use of a password manager a person is prone to reuse a password at least once (or risk forgetting their password if they try to be clever by coming up with a new password for every site). In this proposed authentication mechanism sites would store xpubs instead of passwords. The xpubs would be used to derive public keys when authenticating users. recording youtube.com 2019 Talk
  30. Hacking satellites with Software Defined Radio (SDR) Gerard de Jong · BSides Cape Town · South Africa In this no holds barred down introduction to Software Defined Radio (SDR) you'll learn how you can write software to hack remote control security gates, track ships at sea, code your own aircraft radar, and ultimately how to download data directly from various satellites in low earth orbit with nothing more than a cheap USB dongle and a makeshift antenna. recording youtube.com 2019 Talk
  31. Hashing the $#!+ out of firmware Brent Shaw · BSides Cape Town · South Africa Everything is broken... But is it possible that more things are more broken than we though? Probably. But lets look at that. When it comes to embedded devices, we rely largely on the OEM manufacturer to provide firmware and firmware updates. These updates could be issued for a number of reasons: better performance, improved feature set, bug fixes, and security patches. But when you download a firmware update, you generally only have the manufacturer's word that it does what it says, with information sometime being provided in the change-log. But these change logs don't always tell all. This research looks at pulling firmware apart to see whats inside, and comparing firmwares to see what might have changed (between versions), and what might be getting reused (between different devices). recording youtube.com 2019 Talk
  32. How machine learning and AI can help reduce the cyber-attacks Silent Dzikiti · BSides Cape Town · South Africa According to Global cyber security company Kaspersky Lab South Africans have once again been warned to be careful in cyberspace with a 22% increase in malware attacks in the country in the first quarter of this year. It seems that every presentation from every security vendor begins with an introductory slide explaining how the number and complexity of attacks an organization faces have continued to grow exponentially. Of course, everyone from security operations center (SOC) analysts, who are drowning in alerts, to chief information security officers (CISOs), who are desperately trying to make sense of the trends in security, is acutely aware of the situation. The question is how do we, collectively, solve the problem of overwhelmed security teams? recording youtube.com 2019 Talk
  33. Meticulously Modern Mobile Manipulations Leon Jacobs · BSides Cape Town · South Africa Mobile app hacking peaked in 2015 with tools like keychain-dumper & ssl- kill-switch released but requiring jailbroken/rooted devices. Back then, wresting the power to understand & modify apps on our devices from dystopian looking mega corps was our cause. As jailbreaks became infrequent, the hackers' arsenal was left behind. While this is progress against dark uses of hacking, done to protect our freedom fighters, how can hackers still hold power to account? Can we still find flaws in apps/devices & live up to the protections the technology promises? Enter runtime binary instrumentation with Frida. It's possible to analyze apps in their final state when executed on real hardware running the latest iOS/Android with no jailbreaks. This fills a gap between source analysis & debuggers. recording youtube.com 2019 Talk
  34. Natural Language Processing & Anomaly detection in Sys call logs Christo Goosen · BSides Cape Town · South Africa Containers (lightweight application virtualization) provide further isolation for application's, but the container daemon and management systems, ads more attack surface. The research problem is that despite segmentation and system call hardening, containers are still vulnerable and the host and other containers can be affected. In this paper, the use of syscall (system calls, calls to kernel) logging in Linux x86_64 systems is investigated with Natural Language Processing. Logs are tokenized and hashed, then transformed into a sparse matrix encoding. The purpose of the method is to classify the documents and test the different accuracies of different classifiers, such as Random Forest, K Nearest Neighbor, etc. recording youtube.com 2019 Talk
  35. Put Words In My Mouth Amy Mania · BSides Cape Town · South Africa Money has been withdrawn from your account. You don't remember making, or authorising that transaction. When you follow up with the bank, they say you called earlier and requested the transfer - it was, after-all, you speaking - right? Unbeknownst to you, your voice was stolen, and so was your money. With the rise of voice authentication biometrics, so will the opportunities to spoof it. Text-to-Speech API's are constantly improving, with Google's technology now being indistinguishable from the real human speaker. Threat actors have access to a target's YouTube videos, social media posts. recording youtube.com 2019 Talk
  36. WhatsApp Digger Deemah A. Alotaibi, Lamyaa S. Alsaleem, Malak F. Aldakheel, Sarah A. Alqhtani · OPCDE · Saudi Arabia slides github.com 2019 Tool
  37. A Walk With Shannon: A walkthrough of a PWN2OWN Baseband exploit Amat Cama · OPCDE Kenya · Senegal slides github.com 2018 Talk
  38. Anomaly detection in container sandboxing Christo Goosen · BSides Cape Town · South Africa Anomaly detection through sand-boxing and network monitoring, for security incident detection of un-trusted code. Talk including google's gvisor and sandboxing kubernetes. recording youtube.com 2018 Talk
  39. Mallet – an intercepting proxy for arbitrary protocols Rogan Dawes · BSides Cape Town · South Africa In this talk, I will focus on a new open-source intercepting proxy named Mallet, based on the mature and high-performance Netty framework, that wraps it with a drag and drop graph-based graphical user interface and a datastore. In doing so, we gain access to an existing library of protocol implementations, including TLS (and SNI), various compression algorithms, HTTP, HTTP/2, MQTT, REDIS, and many others, and most important, an existing community of developers creating new protocol decoders and encoders, and the associated body of knowledge in this area. recording youtube.com 2018 Talk
  40. Program Analysis on Smart Contracts JP Smith · OPCDE Kenya · Kenya slides github.com 2018 Talk
  41. SDN Crash Course Keagan Jarvis · BSides Cape Town · South Africa recording youtube.com 2018 Talk
  42. The Baseband Basics: Understanding, Debugging and Pwning the Mediatek Communication Processor Nitay Artenstein, Charles Muiruri · OPCDE Kenya · Kenya slides github.com 2018 Talk
  43. You and your research Saif ElSherei · OPCDE Kenya · Kenya slides github.com 2018 Talk
  44. Docker for Hackers Ross Simpson · BSides Cape Town · South Africa recording youtube.com 2017 Talk
  45. Junk Hacking to skill up – Exploiting a Personal Cloud Storage and Media Streamer Masande Mtintsilana · BSides Cape Town · South Africa source bsidescapetown.co.za 2017 Talk
  46. Stranger Danger Mohamed Saher, Ahmed Garhy, Nikita Tarakanov · OPCDE · United Arab Emirates slides github.com 2017 Talk
  47. Using Electromagnetic Emissions to Intercept AES-128 Cryptographic Keys from a Raspberry Pi Ibraheem Frieslaar · BSides Cape Town · South Africa source bsidescapetown.co.za 2017 Talk
  48. SensePost XRDP Tool Thomas Underhay, Darryn Cull · BSides Cape Town · South Africa In this talk, we'll cover how an X server functions, how one becomes vulnerable, previous methods of exploitation, and finally the developed tool as well as how it works and what it provides. In 1997, a vulnerability in X11 was released that allowed unauthenticated access to the X server due to access controls being disabled [1]. This vulnerability gives an attacker full control of the target host using the default X toolset developed to work using the protocol. Given the age of this vulnerability, it is still being found while on internal penetration tests and even on the Internet. recording youtube.com 2016 Tool
  49. Mercury – Android exploitation framework Tyrone Erasmus · BSides Cape Town · South Africa source bsidescapetown.co.za 2013 Tool
  50. Offensive Software Defined Radio Jacques Louw · BSides Cape Town · South Africa source bsidescapetown.co.za 2013 Talk
  51. Using DNS as Anti-virus Etienne Staalmans · BSides Cape Town · South Africa source bsidescapetown.co.za 2012 Talk
  52. Cyber Warfare: The Amplified Great Hacker War Amr Ali · Cairo Security Camp · Egypt 2011 Talk
  53. Data Security Best Practices Bahaa Eldin M. Hasan · Cairo Security Camp · Egypt 2011 Talk
  54. Hacking The Economy Osama Kamal · Cairo Security Camp · Egypt 2011 Talk
  55. Handling Incidents Before They Handle You Michael Lewis · Cairo Security Camp · Egypt 2011 Talk
  56. How Did I Steal Your Database Mostafa Siraj · Cairo Security Camp · Egypt 2011 Talk
  57. New trends in Cybercrime and Digital Forensics Challenges Adel Abdel Moneim · Cairo Security Camp · Egypt 2011 Talk
  58. Owning the Command and Control: Reverse Engineering Malware Ehab Hussein · Cairo Security Camp · Egypt 2011 Talk
  59. SCADA Security, The Emerging Threat Omar Sherin · Cairo Security Camp · Egypt 2011 Talk
  60. The Role of Information Security in the Post-Revolution Economic & Political Development Osama Hijji, Ahmed El-Ezabi · Cairo Security Camp · Egypt 2011 Talk
  61. The Weakest Link Mustafa El-Masry · Cairo Security Camp · Egypt 2011 Talk
  62. Towards an Egyptian Framework for CyberSecurity Sherif Hashem · Cairo Security Camp · Egypt 2011 Talk
  63. Web Threats & Defense in Depth Strategy for Web Servers Mahmoud Tawfik, Mohamed Rabie · Cairo Security Camp · Egypt 2011 Talk