iPad Air 2, Samsung Galaxy Tab A, or $350 Off with SANS Online Training Right Now!

Northern Virginia 2015

Reston, VA | Mon, Mar 9 - Sat, Mar 14, 2015
This event is over,
but there are more training opportunities.

Running Away from Security: Web App Vulnerabilities and OSINT Collide

  • Micah Hoffman
  • Thursday, March 12th, 8:15pm - 9:15pm

Lately it seems like more and more of our lives are being sucked into the computer world. There are wrist-sensors for tracking our steps, phone apps that plot our workouts on maps, and sites to share our healthy-eating and weight loss progress. When people sign up for these sites, they usually use pseudonyms or the sites give them a unique numbered ID to keep their information "private".

How hard would it be to connect a person's step-counting, diet history and other info on these health sites to their real lives? Are businesses using these sites for non-fitness purposes?

This talk will show weaknesses in several web applications used for health and exercise tracking and reveal [spoiler alert] how trivial it is to find the real people behind the "private" accounts.


Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
  • Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
Monday, March 9
Session Speaker Time Type
General Session- Welcome to SANS Josh Wright Monday, March 9th, 8:15am - 8:45am Special Events
Offensive Countermeasures, Active Defenses, and Internet Tough Guys John Strand Monday, March 9th, 7:15pm - 9:15pm Keynote
Tuesday, March 10
Session Speaker Time Type
Debunking the Complex Password Myth Keith Palmgren Tuesday, March 10th, 7:15pm - 8:15pm SANS@Night
Who's Watching the Watchers? Mike Poor Tuesday, March 10th, 8:15pm - 9:15pm SANS@Night
Wednesday, March 11
Session Speaker Time Type
Continuous Ownage: Why you Need Continuous Monitoring Eric Conrad Wednesday, March 11th, 7:15pm - 8:15pm SANS@Night
iOS Game Hacking: How I Ruled the World and Built Skills For AWESOME Mobile App Pen Tests Josh Wright Wednesday, March 11th, 8:15pm - 9:15pm SANS@Night
Thursday, March 12
Session Speaker Time Type
The 13 Absolute Truths of Security Keith Palmgren Thursday, March 12th, 7:15pm - 8:15pm SANS@Night
Running Away from Security: Web App Vulnerabilities and OSINT Collide Micah Hoffman Thursday, March 12th, 8:15pm - 9:15pm SANS@Night
Friday, March 13
Session Speaker Time Type
Bitcoin and Crypto and I-Pay, Oh My! G Mark Hardy Friday, March 13th, 7:15pm - 9:15pm SANS@Night