World Congress 2022 Jun 15, 2022

Capture the Flag 101

Micah Silverman

Is a widely used package secretly compromising your Node.js runtime? Adopt a "hack yourself" mindset with Capture the Flag exercises to proactively exploit and patch hidden architectural vulnerabilities.

Pause
Mute Enter Fullscreen
#1 about 5 min

Introduction to cloud-native application developer security

How shifting security to developers changes traditional approaches to application safety.

#2 about 3 min

Learning application security through capture the flag events

How complex cross-functional challenges encourage practical learning and out-of-the-box thinking.

#3 about 3 min

Understanding flags and collaborative rules of engagement

Finding alphanumeric solution codes while sharing progress without spoiling the challenge.

#4 about 3 min

Setting up the invisible ink web vulnerability challenge

Gathering provided files and interface hints to start solving the web application security puzzle.

#5 about 2 min

Utilizing basic HTTP verbs for security exploration

Reviewing get, post, and delete methods to understand how data interacts with the RESTful server.

#6 about 6 min

Interacting with payloads and content types using curl

Sending command line requests to test server responses and discover tainted data flows.

#7 about 2 min

Identifying prototype pollution vulnerabilities with scanning tools

Running a security scan against the package configuration to discover prototype pollution flaws.

#8 about 8 min

Exploiting lodash merge functions via prototype pollution

Using practical proof of concepts to inject arbitrary data into JavaScript object prototypes.

Matching moments

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:41 min

Setting the stage for software security demos

Vandana Verma Sehgal · LIVE

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · World Congress 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

How Docker caught a supply chain attack in 83 minutes

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 16:00–18:00

Stage 11

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 6

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg