> Markdown version of [/videos/375-the-attacker-s-footprint?t=6369](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint?t=6369). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # The attacker's footprint Could you trace an attacker's exact steps after a breach? Watch a live attack simulation and learn to reconstruct the timeline using manual log analysis. - **Speakers:** Antonio De Mello, Amine Abed - **Event:** WeAreDevelopers LIVE - **Published:** April 20, 2022 - **Duration:** 2:08:06 - **URL:** https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint ## Summary Antonio and Amin present a dual-perspective cybersecurity workshop that bridges the gap between offensive application hacking and defensive log analysis. Through a simulated attack on a demo application, the session illustrates the complete lifecycle of a security breach—from an attacker mapping the external footprint to a security analyst tracing those exact steps in the aftermath. This hands-on narrative reinforces how understanding the offensive mindset directly empowers better incident response and system defense. The attack phase leverages tools like Nmap for reconnaissance and Burp Suite for request manipulation, uncovering an array of vulnerabilities including broken access control (IDOR), cookie tampering, and local file inclusion (LFI) via an outdated Apache server. By chaining these exploits, the attacker extracts sensitive configuration files and leverages weak authentication rules to gain SSH access. On the defensive side, the narrative shifts to meticulous manual log analysis, demonstrating how an analyst uses API, web server, and authentication logs to reconstruct the attack timeline. The session highlights the critical role of comprehensive log hygiene before showcasing how a SIEM platform automates the detection of suspicious anomalies. Several meaningful insights emerge from this dual walkthrough. First, attackers often rely on custom software implementations or outdated dependencies to find their initial foothold, emphasizing the importance of rigorous patch management. Second, seemingly insignificant behavioral details, such as uniform body sizes in HTTP responses, can serve as crucial indicators of automated fuzzing or brute-force attempts. Third, human elements—such as lazy password policies that simply increment years (e.g., "supersecret2019" to "supersecret2022")—remain a highly exploitable vulnerability that bypasses complex technical defenses. Additionally, dropping basic assumptions about system security allows attackers to find overlooked flaws, meaning defenders must adopt a similarly creative mindset when configuring applications. Ultimately, while automated tools and User and Entity Behavior Analytics (UEBA) offer powerful threat detection, foundational knowledge of manual log investigation remains an indispensable skill for validating automated alerts and maintaining a robust security posture. **Keywords:** cybersecurity workshop, offensive security tactics, defensive log analysis, burp suite request manipulation, nmap port scanning, broken access control idor, cookie tampering exploit, local file inclusion lfi, path traversal vulnerability, siem anomaly detection, incident response timeline, weak password policies, apache server exploits, api log monitoring, user entity behavior analytics, patch management strategy, manual log investigation, fuzzing techniques ## Chapters 1. **Common information security tools and terminologies** (04:04) — An overview of essential offensive and defensive security concepts used in application assessments. 1. **Structure and mindset of an attacker** (10:28) — How attackers understand scope, run initial scans, and form exploitation hypotheses. 1. **Initial reconnaissance and port scanning execution** (13:24) — Using nmap to identify open network ports and running web services. 1. **Investigating exposed web services and company products** (20:26) — Exploring hosted frontend applications for specific product hints or exposed directories. 1. **Exploring internal endpoints and proxy traffic interception** (25:47) — Intercepting HTTP requests with a proxy tool to analyze application backend communication. 1. **Breaking application logic with malformed JSON payloads** (32:38) — Injecting syntax errors into JSON requests to trigger debugging outputs and leak file paths. 1. **Gaining basic access through weak default credentials** (34:55) — Using common default username and password combinations to establish an initial application foothold. 1. **Identifying authorization flaws through cookie tampering** (37:40) — Modifying base64 encoded cookies to bypass organization boundaries and access restricted data. 1. **Fuzzing query parameters for vertical privilege escalation** (44:01) — Automating API request variations to uncover hidden administrator data fields. 1. **Exploiting path traversal vulnerabilities in outdated servers** (49:52) — Leveraging known CVEs in web servers to read internal configuration files. 1. **Achieving server access via predictable password variations** (57:16) — Connecting through SSH using leaked credentials incremented to match the current year. 1. **Analyzing API logs for suspicious attacker behavior** (61:18) — Identifying failed authentication attempts, abnormal payload sizes, and path disclosure leaks to reconstruct the attack. 1. **Tracing reconnaissance footprints and path traversal execution** (81:15) — Detecting nmap scans and malicious URL patterns that indicate successful directory traversal attacks. 1. **Confirming unauthorized access through host authentication logs** (90:49) — Reviewing Linux auth logs to verify successful SSH logins after multiple failed attempts. 1. **Incident response reporting and log quality assessment** (96:47) — Documenting weaknesses in password policies while identifying essential log attributes for security analysis. 1. **Automating threat detection with SIEM solutions** (106:09) — Correlating specific user agents and malicious patterns rapidly using specialized security information tools. 1. **Attack and defense summary with learning resources** (109:14) — A recap of the discovered vulnerabilities with suggestions for further cybersecurity learning and patching practices. ## Related Moments - [Exploring offensive security with red team tooling](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) (from " Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together") - [Retaining the defender advantage in the cybersecurity race](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) (from "Fighting the Next Wave of Cybercrime") - [Using intentionally vulnerable applications for practical security training](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Demonstrating automated defense strategies at prominent cybersecurity conferences](https://www.wearedevelopers.com/videos/1316-fighting-fraud-with-an-ai-grandma-ben-hopkins-and-morten-legarth-from-faith-vccp) (from "Fighting Fraud with an AI Grandma - Ben Hopkins and Morten Legarth from faith @ VCCP") - [Setting the stage for software security demos](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Exploring pathways to application security careers and research workflows](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) ## Related Jobs - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/3081075-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Staff Hardware Security Engineer](https://www.wearedevelopers.com/jobs/ext/1915092-staff-hardware-security-engineer) at **Arm** - [Senior Threat Intelligence Analyst](https://www.wearedevelopers.com/jobs/ext/2000909-senior-threat-intelligence-analyst) at **ZEISS Group** - [Senior Cybersecurity Incident Responder](https://www.wearedevelopers.com/jobs/ext/2427081-senior-cybersecurity-incident-responder) at **ZEISS Group**