1 of 26

Skeleton’s in the closet and other tales from beyond the grave

Katie Paxton-Fear / @insiderPhD

2 of 26

About Me

  • PhD in ML + security
  • Lecturer at Manchester Metropolitan University
  • Occasional bug bounty hunter
  • Educational YouTuber
  • Former Developer
    • Got into security by accident, not sure how to leave

3 of 26

About this talk

  • All about weird vulnerabilities in forgotten pieces of code
  • Fun stories of security/bug bounty archaeology
    • Based on my own experiences
  • So gather round the campfire as we tell spooky stories of long forgotten code
  • And secrets best kept in the dark

4 of 26

API Versioning

A story of backwards compatibility

5 of 26

Quick Intro to Developer APIs

6 of 26

API Depreciation

7 of 26

V1.1 -> V2

8 of 26

A long-forgotten blog

Wordpress is cursed when you forget to update your plugins

9 of 26

Wordpress

10 of 26

Blogs vs Social Media

11 of 26

Plugins

12 of 26

CVEs for just Wordpress

13 of 26

Evaluation

An oops I made as a developer

14 of 26

Conferences and Tech FOMO

15 of 26

Free trial

16 of 26

It’s still running

17 of 26

CVEs are easy fixes, if you well update

18 of 26

Test code please ignore

Using GitHub to find interesting vulnerabilities

19 of 26

Version Control

20 of 26

GitHub Issues

21 of 26

Developer discussion

22 of 26

Searching for secrets

23 of 26

Changing attitudes

Punishment to engagement

24 of 26

Vulnerabilities

25 of 26

Taking inventory

26 of 26

Thanks for Listening