Diving Deeper into Subdomain Takeovers & Mitigations with Shubham Shah
▬▬▬▬▬▬ 📝 ABSTRACT & BIO ▬▬▬▬▬▬ In this episode of OWASP DevSlop we’ll be diving into different types of infrastructure takeovers, with a focus on subdomain takeovers, and how they can be leveraged by attackers and bounty hunters to create real security impact. Bug bounty hunters, defenders, and DevOps or DevSecOps practitioners should not miss this episode! We’ll be taking a look at different cloud infrastructure providers, cloud services, and how this often overlooked or misunderstood attack surface can translate into real security issues, as well as what defenders and developers can do about it. SHUBHAM SHAH Shubham Shah is the co-founder and CTO of Assetnote. Shubham is a prolific bug bounty hunter in the top 50 hackers on HackerOne and has presented at various industry events including QCon London, Kiwicon, AusCert, BSides Canberra and CrikeyCon. In his free time, Shubham enjoys performing high-impact application security research. ▬▬▬▬▬▬ 🔗 LINKS ▬▬▬▬▬▬ Ghostbuster Resources https://github.com/assetnote/ghostbuster https://blog.assetnote.io/2022/02/13/... Other Resources https://github.com/indianajson/can-i-... https://gist.github.com/fransr/a155e5... https://godiego.co/posts/STO-Azure/ ▬▬▬▬▬▬ 🎥 Producer ▬▬▬▬▬▬ Nancy Gariché ► / nancygariche ▬▬▬▬▬▬ 🎙️Hosts ▬▬▬▬▬▬ Bec ► / errbufferoverfl James ► / devec0 Lilly ► / attacus_au Mimi ► / p0kemina ▬▬▬▬▬▬ 👋 Connect with Us ▬▬▬▬▬▬ YOUTUBE ► / owaspdevslop INSTAGRAM ► / TWITTER ► / owasp_devslop ▬▬▬▬▬▬ SHOW SPONSOR ✨ ▬▬▬▬▬▬ https://www.appsecengineer.com/

Privilege Escalation in the Cloud with Carlos Polop

Demystifying the SBOM’s impact on Secure Software Deployment

Shubham Shah: From Burgers to Bounties (Ep. 30)

Let’s Write Security Unit Tests! with Eric Johnson

How to Crush Bug Bounties in the first 12 Months

Project “Make ISO Happen 2022” - The Octopus Deploy Adventure Towards 27001 Certification

Deep Dive into LLMs like ChatGPT

Attacking JSON Web Tokens with Louis Nyffenegger

Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview

China’s Secret | The Most Unbelievable Megaprojects in China | 4K Travel Documentary

Deep Techno 24/7 🔴 Live Stream

THE SINKING CITY 2 Feels Like Real Horror Now (Full Gameplay)

Account Security beyond 2FA with Neil Matatall

Time With God | Instrumental Worship Music for Prayer, Devotion, Meditation & Relax in His Presence

HackerOne Hacker Interviews: Shubham Shah (@notnaffy)

Ocean Waves for Deep Sleep LIVE 🌊 Rolling Waves & Dark Screen Reduce Anxiety, Stress & Sleep Aid

Building Modern Access-Control for Cloud Applications

AI Is Creating A Rare Opportunity For Investors. How Jim Roppel Is Playing It. | Investing With IBD

But what is quantum computing? (Grover's Algorithm)

