π‘οΈ Now Announcing: A New Cybersecurity Session at BSides Luxembourg
π§ͺπ πͺπππ‘ πππππ‘ππ ππ¦ ππππ’π π ππ§π§πππ π¦π¨π₯πππππ¦: πͺπππ£π’π‘ππππ‘π π‘ππ¦πβπ¦ ππππ§π¦ππ’ ππ«π§ππ‘πππ πππππ‘ππ π π¦π¬π‘π§ππ« β Adrian Denkiewicz ( @Adenkiewicz )
𧨠Turn filenames into attack vectors in this Talk (40 min) by uncovering how hidden parsing features can enable SSRF, file access, and data exposure.
What looks like a simple filename can actually be a powerful mini-language. This talk dives into CFITSIOβs Extended Filename Syntax (EFS), a feature widely embedded in scientific and imaging software, and shows how it silently expands the attack surface through built-in capabilities like virtual file handling, filtering, and network access.
Through original research, discover how these legitimate features can be abused to perform arbitrary file operations, trigger SSRF, and expose sensitive dataβall without exploiting traditional memory corruption bugs. This session highlights how overlooked functionality in widely used libraries can introduce systemic risks across the software supply chain.
Adrian Denkiewicz ( @Adenkiewicz ) is an Offensive Security Expert and security consultant with experience spanning financial, e-commerce, and semiconductor industries. Currently a Staff Application Engineer at Doyensec, he specializes in application security, red teaming, and uncovering complex vulnerabilities in real-world systems.
π
Conference Dates: 6β8 May 2026 | 09:00β18:00
π 14, Porte de France, Esch-sur-Alzette, Luxembourg
ποΈ Tickets: https://2026.bsides.lu/tickets/
π
Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
π² View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AppSec #SecureDevelopment #SSRF #SoftwareSecurity #CyberSecurity
BSidesLuxembourg
@BSidesLuxembourg@infosec.exchange
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
infosec.exchange
BSidesLuxembourg
@BSidesLuxembourg@infosec.exchange
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
infosec.exchange
@BSidesLuxembourg@infosec.exchange
Β·
5d ago
3
0
2
Loading comments...