GISEC (Gulf Information Security Expo & Conference) Dubai - 2014
I was pleased to be selected as part of a team to demonstrate BT's capability in GISEC conference recently which was held at the Dubai World Trade Center. I contributed to the idea of having a 'Cyber Challenge' to the BT booth inspired by the exposure i have from attending to hackers conferences. I was also given an area to showcase the Ethical Hacking capability providing demonstration and presentation to passerby.
It was a very tiring and satisfying experience! Given the fact that i was able to come up with an end to end demo by myself without any critics from management gave me a sense of confidence they have on me to deliver.
First, it was the Cyber Challenge stand. This challenge is about the ability for a pentester to be able to find a XSS vulnerability and exploit it. Day 1 challenge was to inject a script inside the affected parameter and provide an alert pop up. Day 2 challenge was to 'deface' a website by embedding an image on it and Day 3 challenge was to inject a script that will come out with an output in the result section and upon clicking on it, will be redirected to another page.
Sound simple right? But during the 3 days, only 3-4 people managed to complete the challenge.
On the ethical hacking stand, my job was to perform demos on anyone who has the interest to see it. I was happy to know that some people came up to me and said that the booth managed to gather a huge number of people, mostly were curious to see the demo. I won't go into the details of my demo but all i can say is that the demo was similar to the demo i presented with a colleague at Defcon Kerala, India last year.
But one of the best and memorable moments was the fact that i got to meet many strangers in the professional world and exchanging contacts after that. Well, thats what we called 'Networking'. All in all, it was a great and superb experience and i am sure this will continue in the near future.
Below are some of the pictures taken:
a bookworm who loves cyber security. a sucker for hacker and security conferences. loves attending and promoting conferences and has spoken at multiple conferences globally (almost). interests include cyber threat intelligence, cyber 'warfare', cyber 'terrorism' and cyber conflict.
Showing posts with label british telecom. Show all posts
Showing posts with label british telecom. Show all posts
Thursday, 26 June 2014
Wednesday, 5 March 2014
Websense Security Seminar - A Presentation
So after our presentation at the ABS-FITA Cyber Security Seminar, we were invited to present our demo in another seminar organized by Websense.
It wasn't as big as the ABS-FITA seminar but it was still exciting nonetheless. The crowd was about 100-120 people from different backgrounds. It was great to see my brief bio on the speaker's website.
Felt more confident this time round especially after the stressful pressure on the previous demo. Good thing was, we nailed it smoothly. Everything went smooth and we managed to put the 'WOW' look on some of the audience. After the demo, we were greeted by some of the audience who asked more about the capabilities of our team and pretty much the sales representatives from BT took over the conversation.
Here are some of the photos taken by one of the attendees:
A Brief Bio
The Layout
The Finale
Bringing it all together
Notice the 'BT EHCOE' on Kali Wallpaper?
Command and Commands
NEXT STOP: Presenting in DEFCON KERALA!!!!
Sunday, 10 November 2013
Never Give Up
In life, not many are/were born with a silver spoon. Some have to work very very hard and some simply ask and they have it. People who came from difficult background or humble beginnings are often admired when they carved their way to success. This is an article that was published on the 8th of November 2013 about how he overcame rejections and still make his way up to achieve his dream career.
Front Page
Translation:
Ethical Hacker in Global Firm
ITE graduate works hard to become a Consultant in BT
Now, he may have reached his dream of becoming a consultant but not many know how much disappointments and rejections he faced. More than 10 years ago, with a Higher Nitec in Mechanical Electrical Engineering Design certificate, he tried to appeal to take a course in Infocomm Technology in Temasek Polytechnic but was not accepted due to unsatisfactory results. Nevertheless, in 2005 and completed his NS, Fadli went on a hunt for a private diploma in Infocomm Security from Raffles Education Corporation. With that diploma, he hoped he would be accepted for a specialist course in Polytechnic but sadly, he was unable to be accepted. His appeal to study in both TP and NYP was rejected. According to Fadli, he was told he was not accepted because he did not have any local polytechnic diploma as part of the requirement.
Disappointed but did not give up, he tried again in 2007 and this time with another diploma in Information Technology from SMF. Once again, he got rejected due to the same reason. "I was disappointed and worried at that time." said Mr Fadli, now 30 recalling it all back. "Disappointed as though i was ignored and worried about my loans," said Mr Fadli who loaned $16000 from a bank for his degree. He hoped he will be able to pay off all his loan of about $8000 by end of next year.
According to him, he was stubborn, searching for a career in the field of IT Security and has a huge interest in Hacking. "Im not sure why but ever since i watched the show 'Operation Takedown' and 'Hackers' i fell in love with Hacking," said Mr Fadli. Ever since that, he never gave up to chase his dream career.
In 2008, he started his degree with Murdoch University and now he has armed himself with a Degree double majoring in Cyber Forensics, Information Security Management and Business Information Systems, He is also now building up his career as an IT security consultant with BT and part of the Ethical Hacking Center of Excellence. The company offers IT solutions and services globally.
Recently, hacking events has been the talk of the town in the media when the hacker known as 'The Messiah' and claimed to be from the group 'Anonymous' vowed to threated the IT infrastructure of the Singapore Government. PM Lee Hsien Loong told that this act is dangerous and true. Unsurprised, the services offered by the security consultants like Mr Fadli who declared himself as 'Hacker for Hire' is on demand.
He said that he never would have thought becoming a security consultant one day since owning his first computer at the age of 18. "Without hard work, all these will never be in fruition", said Mr Fadli.
Page 17
Translation:
Hard Work is the key to Success
Work and overcoming the trials of life is not an alien concept to Mr Fadli, 30 years old. Since his father died in an accident in 1988, Mr Fadli was only 5 years old at that time and his 2 other siblings had to shift house to house while his mother goes to work. His studies was more or less affected, said Mr Fadli who had to change from school to school to accomodate the shifting of houses.
In a pressed state, his mother had to send her children to Jamiyah, Darul Mawa, an orphanage while he was 11 years old. "The challenge living in the home was many..if you think the influence in the school was great, imagine the influence you get living all day and night in the home", said Mr Fadli. Finally, Mr Fadli stayed in the home until he completed his O Levels from Serangoon Garden Technical school.
To increase the family income, he had to work part time in a shop called Miz29 and selling satay while waiting for his O level results.
Upon completing his ITE education and National Service, he worked at HP as a media operator and then NCS. 3 years later, Mr Fadli went back to HP as a systems engineer. According to him, while getting different experiences in the field of IT, he often changed job in the hopes of getting a raise to pay off his education loans. In silence, he was still hoping to get a career in the field of IT Security.
The opportunity came when he was offered a position in BT Global Services in 2010. "Even though i had to stare at the computer for hours, i truly enjoyed my job. Not many have the interest in doing this kind of job but i loved it because of its challenging landscape and the need to have a strong sense of creativity and continuos learning," said Mr Fadli who has to always keep up with the knowledge of the neverending change of new threats in the cyber world.
"Most of the systems encountered are very vulnerable and able to be exploited and these vulnerabilities change in time," said Mr Fadli. As of now Mr Fadli has published at least 3 security articles at an international security magazine called PentestMag. Additionally, Mr Fadli was also a member of the BT team that won the hacking competition GWAPT, Catch the Flag in Bangkok, Thailand. He and his colleague also became the first runner up in the Cyber Readiness Challenge organized by Symantec last month. Next week, Mr Fadli and his colleague will be participating in another Catch the Flag hacking competition in the Cloud Expo Asia in Suntec.
Mr Fadli, who now married with Mrs Siti Mariam realized how things have changed. Mr Fadli hopes that he would continue his studies once he completed his loans. He also advised teenagers with similar beginnings and background to never give up. "Our future will not change without hard work", he said.
Labels:
8th november,
berita harian,
british telecom,
BT,
catch the flag,
darul mawa,
fadli bin sidek,
global services,
GWAPT,
hacker,
hard work,
humble beginnings,
jamiyah,
success,
symantec
Wednesday, 7 August 2013
Published Article: AV Evasion
Another article published by PenTest magazine!
In this article, i demonstrate an end to end process on how to create a malware using open source tools and used it to avoid being detected by Anti Virus applications. However, besides demonstrating on how to evade them, i also described on how to prevent against such things using additional features from AV vendors.
The Cover Page
The First Page
The Last Page
The full article/magazine can be downloaded for free at
Subscribe to:
Posts (Atom)