Loading…
This event has ended. Visit the official site or create your own event on Sched.
It is an annual, community-driven information security conference held in Prague. The event provides a platform for cybersecurity professionals, enthusiasts, and researchers to share knowledge, exchange ideas, and discuss the latest trends in the field. It’s a unique opportunity to connect with like-minded individuals, expand professional networks, and stay informed about the ever-evolving cybersecurity landscape.
More info at www.bsidesprg.cz

Wednesday April 22, 2026 13:00 - 17:00 CEST
Internet is big and scary. Let’s ignore all the remote web apps for a while and stay cozy and warm on our localhost. Attack surface of Windows apps is also interesting!


What we’ll look into?

  • OS Interaction Technologies: protocol handlers, COM/DCOM, named pipes, MSRPC, NTLM, handles, …
  • Userland OS Weaknesses: ACLs, MSI, filesystem, TOCTOU, junctions
  • 3 practical exercises on premade lab VMs: protocol handlers, COM and named pipes


After the workshop you should have basic idea of where to poke for cracks in attack surface of Windows apps and where to look for more information. We won’t have time to fully dive deep, but this approach lets us cover more ground and give you references to tear down the curtain hiding the details at your own pace. Who knows - maybe you’ll secure your code against attack surfaces you hadn’t considered or even get your own CVE-2026!


Requirements: laptop with RDP client, ability to write and understand code, basic knowledge of Windows OS (e.g., difference between EXE/DLL, the concept of a process)

Speakers
avatar for malacupa

malacupa

red teamer, former pentester, former web dev. 8 years in sec
i like cool vulnerabilities
Wednesday April 22, 2026 13:00 - 17:00 CEST
Novotel - WR1 Kateřinská 38, Nové Město, 120 00 Praha-Praha 2, Czechia

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link