Max van der Horst
CSIRT member and CNA administrator at the Dutch Institute for Vulnerability Disclosure.
DIVD investigations:
Co-speaker Ralph Horn: https://www.divd.nl/people/Ralph%20Horn/
Max: https://www.divd.nl/people/Max%20van%20der%20Horst/
Sessions
DIVD is known for notifying parties running vulnerable software on the IPv4-space. Members of DIVD have given many presentations on this process, but never on the practical approach to ethically confirming the vulnerability in hosts on this scale. During this workshop, the audience is taken along DIVD's fingerprinting process including the practical and ethical considerations of accurate identification. By leveraging Open-Source Intelligence (OSINT), the participants are guided through practical examples of fingerprinting and deweaponizing exploitation of vulnerable software with the goal of finding vulnerable instances at scale.