SecTalks Perth 0x74
Details
SecTalks Perth 0x73
We were able to keep the same venue, so make sure to come by.
Please make sure to reach out if you want to Submit a talk, you can either;
Reach out to a Sectalks Organiser directly
-----------------------
# 0 - I Just Wanted the Leaderboard (Reverse engineering a mobile app, cloud API and BLE hardware trust model one WTF at a time) - Chloe Fletcher
It started with what should have been a simple question: how do I get live GPS data out of this device? The answer led to a rabbit hole through BLE, a mobile app, backend APIs, native code and cryptography — with each layer revealing something slightly more questionable than the last. This is the story of pulling the system apart, figuring out what it actually trusted, and discovering just how far that trust could be pushed (or if it even needed to be).
Chloe is the CIO for a mid sized charity, they do GRC for a living but play with electronics, software and breaking things for fun.
# 1 - Pwning TACACS+ on a Plane - Matt Jones
On a short flight with no internet, I found a 25-year-old pre-auth format string bug in tac_plus. tac_plus is the daemon that decides who can log in to a lot of the world's network gear. I'll cover the bug, the shared secret oracle that turns it into a practical RCE, and the painful disclosure that followed.
Matt Jones is a director at elttam and has been reading other people's code for a couple of decades. He still does it on planes.
# 2 - Bar?
After some chit chat from the talk, let's head to the bar downstairs, mingle, and chat (we still don't have a better idea for a bar)
