Bishop Fox to Speak at DragonJar Security Conference 2024

Date:
September 26-27, 2024
Time:
7 a.m. - 6:30 p.m. CT
Location:
Casa Dann Carlton Hotel & Spa in Bogotá, Colombia
DragonJar Security Conference 2024 logo

Bishop Fox is proud to present at DragonJar Security Conference 2024. Senior Security Consultant Berenice Flores will discuss insecure default configuration in cloud installations, while Managing Consultant III Hector Cruz will host a Lock Picking Village.

For more details, visit the official DragonJar Security Conference 2024 website.

The New "admin:admin"? - Insecure Default Configuration in Cloud Installations

Speaker: Berenice Flores   |    Date/Time: Friday, September 27 at 4:30-5:30 p.m. CT

A few years ago, it was quite common to find insecure admin:admin credentials as the default configuration after installing a web service or application. Very similar risks are now occurring on the cloud side in new components or frameworks that require high computing power to function. It is then that the user performs the cloud installation following the vendor's configuration and maintains this configuration that is insecure by default, either due to ignorance or omission, which can bring great risks to the user's cloud. In this talk I will show practical and real examples of default configurations established by vendors for AWS, where overly permissive policies or insecure EC2 configurations can be (ab)used to steal information or perform privilege escalation.

Lock Picking Village

Together with 7 young students (4 women, 3 men), Hector Cruz has prepared this village and will be teaching attendants how locks, handcuffs, safe-deposit box and suitcases works and how to bypass security mechanisms.


Berenice Flores

About the speaker, Berenice Flores Garcia

Senior Security Consultant

As a senior penetration tester at Bishop Fox, Berenice focuses on application security and cloud penetration testing (AWS). Berenice holds many cybersecurity certifications including Offensive Security Certified Professional (OSCP), Off-Sec Web Assessor (OSWA) and Offensive Security Wireless Professional (OSWP).
When she's not finding bugs, Berenice enjoys attending hacking conferences and collecting stickers, pins and token coins.

More by Berenice

Hector cuevas cruz

About the speaker, Hector Cuevas Cruz

Security Consultant

Hector Cuevas Cruz is a Bishop Fox security consultant. He has more than 11 years of experience in information security where he has worked as an Offensive Security Consultant, Forensic Analyst, and Threat Hunter at some of the most renowned security companies. Hector has been a regular presenter at national conferences in Mexico since age 17. He has specialized in Red teaming, Digital Forensics, Incident Response, and ATM security assessments.

More by Hector

Ready to get started? We can help.

Contact Us

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.