WeAreDevelopers LIVE • Apr 20, 2022

The attacker's footprint

Antonio De Mello , Amine Abed

Could you trace an attacker's exact steps after a breach? Watch a live attack simulation and learn to reconstruct the timeline using manual log analysis.

Pause
Mute Enter Fullscreen
#1 about 7 min

Common information security tools and terminologies

An overview of essential offensive and defensive security concepts used in application assessments.

#2 about 3 min

Structure and mindset of an attacker

How attackers understand scope, run initial scans, and form exploitation hypotheses.

#3 about 8 min

Initial reconnaissance and port scanning execution

Using nmap to identify open network ports and running web services.

#4 about 6 min

Investigating exposed web services and company products

Exploring hosted frontend applications for specific product hints or exposed directories.

#5 about 7 min

Exploring internal endpoints and proxy traffic interception

Intercepting HTTP requests with a proxy tool to analyze application backend communication.

#6 about 3 min

Breaking application logic with malformed JSON payloads

Injecting syntax errors into JSON requests to trigger debugging outputs and leak file paths.

#7 about 3 min

Gaining basic access through weak default credentials

Using common default username and password combinations to establish an initial application foothold.

#8 about 7 min

Identifying authorization flaws through cookie tampering

Modifying base64 encoded cookies to bypass organization boundaries and access restricted data.

#9 about 6 min

Fuzzing query parameters for vertical privilege escalation

Automating API request variations to uncover hidden administrator data fields.

#10 about 8 min

Exploiting path traversal vulnerabilities in outdated servers

Leveraging known CVEs in web servers to read internal configuration files.

#11 about 5 min

Achieving server access via predictable password variations

Connecting through SSH using leaked credentials incremented to match the current year.

#12 about 20 min

Analyzing API logs for suspicious attacker behavior

Identifying failed authentication attempts, abnormal payload sizes, and path disclosure leaks to reconstruct the attack.

#13 about 10 min

Tracing reconnaissance footprints and path traversal execution

Detecting nmap scans and malicious URL patterns that indicate successful directory traversal attacks.

#14 about 6 min

Confirming unauthorized access through host authentication logs

Reviewing Linux auth logs to verify successful SSH logins after multiple failed attempts.

#15 about 10 min

Incident response reporting and log quality assessment

Documenting weaknesses in password policies while identifying essential log attributes for security analysis.

#16 about 4 min

Automating threat detection with SIEM solutions

Correlating specific user agents and malicious patterns rapidly using specialized security information tools.

#17 about 19 min

Attack and defense summary with learning resources

A recap of the discovered vulnerabilities with suggestions for further cybersecurity learning and patching practices.

Matching moments

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:15 min

Retaining the defender advantage in the cybersecurity race

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:05 min

Demonstrating automated defense strategies at prominent cybersecurity conferences

Ben Hopkins +1 · Coffee With Developers

2:41 min

Setting the stage for software security demos

Vandana Verma Sehgal · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE