| 2025-08-07 | Tool demo | Blackhat |
Frogy 2.0 - Automated external attack surface analysis toolkit
| Chintan Gurjar | #attack-surface#vulnerability-assessment#asset-management+2 |
| 2025-08-07 | Tool demo | Blackhat |
Q-TIP (QR Code Threat Inspection Platform)
| Rushikesh D Nandedkar | #incident-management#web-security#architecture+1 |
| 2025-08-06 | Tool demo | Blackhat |
Damn Vulnerable Browser Extension (DVBE): Unmask the risks of your Browser Supplements
| Abhinav Khanna, Krishna Chaganti | #web-security#secure-coding#security-assessment+2 |
| 2025-08-06 | Tool demo | Blackhat |
Open-Source API Firewall by Wallarm - Advanced Protection for REST and GraphQL APIs
| Satinder Khasriya | #api-security#web-security#owasp+1 |
| 2025-08-06 | Tool demo | Blackhat |
SmuggleShield - Protection Against HTML Smuggling
| Dhiraj Mishra | #web-security#malware-detection#browser-security+2 |
| 2025-06-27 | Talk | Lehack |
From HTML Injection to Full AWS Account Takeover: Discovering Critical Risks in PDF Generation
| Raunak Parmar | #ssrf#aws#web-security+2 |
| 2024-12-12 | Tool demo | Blackhat |
Damn Vulnerable Browser Extension (DVBE) - Knowing the risks of your Browser Supplements
| Abhinav Khanna, Krishna Chaganti | #browser-security#web-security#web-pentesting |
| 2024-11-21 | Talk | Securityfest |
UnRegister Me - Advanced Techniques for hunting and securing user registration vulnerabilities
| Priyank Nigam | #web-security#appsec#iam |
| 2024-11-15 | Talk | C0c0n |
PCI 4.0, Javascript Security for product security teams
| Anand Kumar Ganesan, Mohammad Arif | #web-security#secure-coding#application-pentesting+2 |
| 2024-08-30 | Talk | Hitbsecconf |
Exploiting the In-Vehicle Browser: A Novel Attack Vector in Autonomous Vehicles
| Ravi Rajput | #web-security#security-assessment#exploitation+2 |
| 2024-08-10 | Talk | Defcon |
Sneaky Extensions: The MV3 Escape Artists
| Vivek Ramachandran, Shourya Pratap Singh | #web-security#security-assessment#application-pentesting+4 |
| 2024-04-18 | Tool demo | Blackhat |
Damn Vulnerable Browser Extension (DVBE) - Unfold the risks for your Browser Supplements
| Abhinav Khanna | #browser-security#web-security#vulnerability-assessment |
| 2023-08-11 | Talk | Defcon |
Generative Adversarial Network (GAN) based autonomous penetration testing for Web Applications
| Ankur Chowdhary | #web-security#xss#application-pentesting+3 |
| 2023-08-06 | Talk | C0c0n |
Mitigating SSRF at scale the right way with IMDSv2!
| Ayush Priya | #web-security#api-security#aws+2 |
| 2022-09-24 | Talk | C0c0n |
Raining CVEs on Wordpress plugins with Semgrep
| Shreya Pohekar, Syed Sheeraz Ali | #web-security#static-analysis#sast+1 |
| 2022-09-24 | Talk | C0c0n |
Web3 Security - Security in MetaVerse, and the new world of web3
| Rohit Srivastwa | #web3#decentralized-systems#smart-contracts+2 |
| 2022-03-25 | Talk | Insomnihack |
Hook, Line and Sinker - Pillaging API Webhooks
| Abhay Bhargav | #web-security#api-security#ssrf+1 |
| 2021-11-13 | Talk | C0c0n |
Exploiting 2A(Authentication and Authorization) Vulnerabilities of Web Application
| Gayatri Nayak | #web-security#authentication#authorization+2 |
| 2021-11-13 | Talk | C0c0n |
Server-side javascript Injection
| Kavisha Sheth | #web-security#secure-coding#web-pentesting |
| 2020-11-21 | Talk | Appsecindonesia |
Learn how to find and exploit race conditions in web apps with OWASP TimeGap Theory
| Abhi M Balakrishnan | #web-security#owasp#application-pentesting+1 |
| 2020-11-11 | Talk | Powerofcommunity |
My Hacking Adventures With Safari Reader Mode
| Nikhil Mittal 1 | #browser-security#ios-security#vulnerability-assessment+1 |
| 2020-10-01 | Tool demo | Blackhat |
OWASP Python Honeypot
| Sri Harsha Gajavalli, Ali Razmjoo | #web-security#owasp#security-assessment+1 |
| 2020-09-18 | Talk | C0c0n |
Web Application hacking with WebZGround
| Parveen Yadav, Narendra Kumar | #web-security#web-pentesting#security-assessment+3 |
| 2020-08-09 | Talk | Defcon |
Running an appsec program with open source projects
| Vandana Verma Sehgal | #owasp#secure-development#devsecops+3 |
| 2020-03-06 | Tool demo | Nullcon |
Wolverine
| Furqan Khan, Siddharth Anbalahan | #linux#secure-coding#web-security+3 |
| 2019-10-11 | Talk | Texascybersummit |
Exploit The State of Embedded Web Security in IoT Devices !
| Aditya K Sood | #iot-security-testing#web-security#embedded-security |
| 2019-09-23 | Talk | Rootcon |
Identity crisis: war stories from authentication failures
| Vishal Chauhan | #authentication#identity-management#vulnerability-assessment+3 |
| 2019-08-08 | Talk | Defcon |
Phishing in the cloud era
| Ashwin Vamshi, Abhinav Singh | #phishing#api-security#web-security+2 |
| 2019-05-28 | Talk | Securityfest |
Oh! Auth: Implementation pitfalls of OAuth 2.0 & the Auth Providers who have fell in it
| Samit Anwer | #web-security#iam#appsec |
| 2018-10-05 | Talk | C0c0n |
DomGoat - the DOM Security Playground
| Lavakumar Kuppan | #xss#web-security#input-validation+4 |
| 2018-10-04 | Talk | Confidence |
Hacking 50 Million users using 123456
| Aman Sachdev, Himanshu Sharma | #web-security#authentication#ethical-hacking+2 |
| 2018-09-27 | Talk | Rootcon |
Defending cloud Infrastructures with Cloud Security Suite
| Shivankar Madaan | #aws#secure-coding#web-security+2 |
| 2018-08-11 | Tool demo | Defcon |
Sh00t—An open platform for manual security testers & bug hunters
| Pavan Mohan | #security-assessment#bug-hunting#secure-coding+1 |
| 2018-06-04 | Talk | Confidence |
From 123456 on a staging to compromising a multi-million dollar VC - The journey of us Red Teamers of a hack spanning over 200 days
| Himanshu Sharma, Aman Sachdev | #red-teaming#ethical-hacking#security-assessment+2 |
| 2018-05-30 | Talk | Auscert |
How to Bypass Authentication & Authorization
| Sarwar Jahan | #authentication#authorization#web-security+1 |
| 2018-05-29 | Award | |
Data Exfiltration via Formula Injection #Part1
| Ajay Prashar, Balaji Gopal | #data-leak#exploitation#web-security+1 |
| 2017-06-26 | Tool demo | Blackhat |
DiffDroid
| Anto Joseph | #android#security-assessment#web-security |
| 2017-06-23 | Talk | Hackinparis |
Injecting Security into Web apps with Runtime Patching and Context Learning
| Ajin Abraham | #blueteam#secure-development#sqli+4 |
| 2017-05-23 | Talk | Phdays |
Injecting security into web apps in the runtime
| Ajin Abraham | #blueteam#secure-development#sqli+4 |
| 2017-03-03 | Talk | Nullcon |
Injecting Security into Web apps with Runtime Patching and Context Learning
| Ajin Abraham | #blueteam#secure-development#sqli+4 |
| 2017-01-25 | Talk | Owaspappseccalifornia |
DASTProxy: Don’t let your automated security testing program stall on crawlInstead focus on business context
| Kiran Shirali, Srinivasa Rao Chirathanagandla | #dynamic-analysis#dast#devsecops+2 |
| 2017-01-25 | Talk | Owaspappseccalifornia |
OCSP Stapling in the Wild
| Devdatta Akhawe, Emily Stark | #web-security#architecture#devsecops |
| 2016-10-07 | Talk | Deepsec |
Inside Stegosploit
| Saumil Shah | #web-security#exploitation#security-assessment |
| 2016-07-01 | Talk | Hackinparis |
DIFFDroid - Dynamic Analysis Made Easier for Android
| Anto Joseph | #android#security-assessment#web-security |
| 2016-03-15 | Talk | Groundzerosummit |
Web App Security
| Harpreet Singh, Himanshu Sharma, Nipun Jaswal | #web-security#api-security#secure-coding+3 |
| 2015-11-05 | Talk | Groundzerosummit |
Sanctioned to Hack: Your SCADA HMIs Belong to Us!
| Aditya K Sood | #ics-security#web-security#firmware-analysis+2 |
| 2015-10-25 | Talk | Toorcon |
PixelCAPTCHA – A Unicode Based CAPTCHA Scheme
| Gursev Singh Kalra | #web-security#authentication#bypassing |
| 2015-09-25 | Talk | Appsecusa |
The State of Web Application Security in SCADA Web Human Machine Interfaces (HMIs)!
| Aditya K Sood | #scada#hmi#web-security+1 |
| 2015-09-11 | Talk | 44con |
Stegosploit – Drive-by Browser Exploits using only Images
| Saumil Shah | #steganography#red-teaming#web-security+1 |
| 2015-08-07 | Talk | Defcon |
Hacker’s Practice Ground
| Lokesh Pidawekar | #security-assessment#ethical-hacking#vulnerability-assessment+2 |
| 2015-05-28 | Talk | Hitbsecconf |
Stegosploit: Hacking With Pictures
| Saumil Shah | #red-teaming#steganography#web-security |
| 2015-03-27 | Talk | Syscan |
Stegosploit - Hacking with Pictures
| Saumil Shah | #steganography#red-teaming#web-security+1 |
| 2015-02-06 | Talk | Nullcon |
Pentesting a website with million lines of Javascript
| Lavakumar Kuppan, Ahamed Nafeez | #web-security#security-assessment#application-pentesting+2 |
| 2015-01-27 | Talk | Owaspappseccalifornia |
The Emperor’s New Password Manager: Security Analysis of Web-based Password Managers
| Devdatta Akhawe | #web-security#xss#csrf+2 |
| 2014-09-25 | Talk | Virusbulletin |
Optimized mal-ops. Hack the ad network like a boss
| Rahul Kashyap, Vadim Kotov | #browser-security#web-security#malware-distribution+1 |
| 2014-08-21 | Talk | Usenix |
The Emperor’s New Password Manager: Security Analysis of Web-based Password Managers
| Devdatta Akhawe, Zhiwei Li, Warren He, Dawn Song | #web-security#xss#csrf+2 |
| 2014-03-27 | Talk | Blackhat |
JS Suicide: Using JavaScript Security Features to Kill JS Security
| Ahamed Nafeez | #web-security#red-teaming#csrfguard+1 |
| 2014-03-15 | Talk | Hitbsecconf |
JS Suicide: Using Javascript Security Features to Kill Itself
| Ahamed Nafeez | #web-security#application-pentesting#code-review+3 |
| 2014-02-14 | Talk | Nullcon |
A security analysis of Browser Extensions
| Abhay Rana | #browser-security#web-security#vulnerability-assessment |
| 2014-02-14 | Talk | Nullcon |
phoneypdf: A Virtual PDF Analysis Framework
| Kiran Bandla | #pdf#web-security#red-teaming+2 |
| 2013-08-15 | Talk | Usenix |
Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness
| Devdatta Akhawe, Adrienne Felt | #web-security#security-training#architecture+2 |
| 2013-07-31 | Talk | Blackhat |
Javascript static security analysis made easy with JSPrime
| Nishant Das Patnaik, Sarathi Sabyasachi Sahoo | #web-security#blueteam#application-hardening+4 |
| 2013-03-01 | Talk | Nullcon |
Automating JavaScript Static Analysis
| Lavakumar Kuppan | #web-security#security-assessment#blueteam |
| 2012-10-25 | Talk | Appsecusa |
Cross Site Port Scanning
| Riyaz Walikar | #web-security#owasp#api-security |
| 2012-09-28 | Talk | Nullcon |
Alert(/xss/) - How to catch an XSS before someone exploits / reports it?
| Ahamed Nafeez | #web-security#xss#secure-coding+2 |
| 2012-09-26 | Talk | Nullcon |
How secure is internet banking in India
| Ajit Hatti | #web-security#authentication#financial-institutions+1 |
| 2012-08-03 | Talk | C0c0n |
Evil JavaScript
| Bishan Singh | #red-teaming#web-security#application-pentesting+4 |
| 2012-07-26 | Tool demo | Blackhat |
Bypassing Every CAPTCHA provider with clipcaptcha
| Gursev Singh Kalra | #web-security#bypassing#security-tools |
| 2012-07-14 | Talk | Hope |
Advancements in Botnet Attacks and Malware Distribution
| Aditya K Sood | #botnet#web-security#reverse-engineering+1 |
| 2012-05-13 | Talk | Carolinacon |
Attacking CAPTCHAs for Fun and Profit
| Gursev Singh Kalra | #web-security#bypassing#exploitation |
| 2012-03-15 | Talk | Nullcon |
An App(le) a day keeps the wallet away
| Antriksh Shah | #security-assessment#web-security#api-security+1 |
| 2012-03-02 | Award | |
CAPTCHA Re-Riding Attack
| Gursev Singh Kalra | #web-security#bypassing#authentication |
| 2012-02-15 | Talk | Nullcon |
Content sniffing Algorithm bypassing techniques and possible attack vectors
| Anil Aphale, Chaitany Kamble | #red-teaming#xss#web-security+2 |
| 2012-02-15 | Talk | Nullcon |
Javascript static analysis with IronWASP
| Lavakumar Kuppan | #web-security#security-assessment#blueteam |
| 2012-02-15 | Talk | Nullcon |
Node.js: The good, bad and ugly
| Bishan Singh | #web-security#red-teaming#blueteam+1 |
| 2011-11-17 | Award | |
CAPTCHA Hax With TesserCap
| Gursev Singh Kalra | #web-security#bypassing#authentication |
| 2011-09-06 | Talk | Securitybyte |
Application Security Strategies
| K K Mookhey | #secure-coding#secure-development#web-security+3 |
| 2011-09-06 | Talk | Securitybyte |
Enabling Un-trusted Mashups
| Bishan Singh | #web-security#xss#csrf+4 |
| 2011-09-06 | Talk | Securitybyte |
Security Threats on Social Networks
| Nithya Raman | #social-engineering#web-security#security-training+1 |
| 2011-08-03 | Talk | Blackhat |
Reverse Engineering Browser Components: Dissecting and Hacking Silverlight, HTML 5 and Flex
| Shreeraj Shah | #reverse-engineering#ajax#web-security+1 |
| 2010-11-11 | Talk | Blackhat |
Attacking with HTML5
| Lavakumar Kuppan | #web-security#xss#web-pentesting+1 |
| 2010-10-13 | Talk | Hitbsecconf |
Hacking a Browser’s DOM – Exploiting Ajax and RIA
| Shreeraj Shah | #red-teaming#web-security#ajax+3 |
| 2010-06-18 | Talk | Syscan |
REVERSE ENGINEERING WEB 2.0 APPLICATIONS
| Shreeraj Shah | #reverse-engineering#ajax#web-security+1 |
| 2010-03-15 | Talk | Blackhat |
400 Apps in 40 Days
| Nish Bhalla, Sahba Kazerooni | #risk-management#application-pentesting#attack-surface+1 |
| 2009-05-19 | Talk | Syscan |
Securing Enterprise Applications
| Shreeraj Shah | #web-security#ajax#xss+4 |
| 2008-10-29 | Talk | Hitbsecconf |
Top 10 Web 2.0 Attacks
| Shreeraj Shah | #web-security#ajax#xss+4 |
| 2008-04-16 | Talk | Hitbsecconf |
Securing Next Generation Applications – Scan, Detect and Mitigate
| Shreeraj Shah | #web-security#ajax#xss+4 |
| 2007-11-20 | Talk | Deepsec |
Web 2.0 Application Kung-Fu - Securing Ajax & Web Services
| Shreeraj Shah | #ajax#web-security#blueteam |
| 2007-09-06 | Talk | Hitbsecconf |
Hacking Ajax and Web Services – Next Generation Web Attacks on the Rise
| Shreeraj Shah | #red-teaming#ajax#web-security |
| 2007-04-05 | Talk | Hitbsecconf |
WEB 2.0 Hacking – Defending Ajax and Web Services
| Shreeraj Shah | #red-teaming#blueteam#purpleteam+2 |
| 2007-03-15 | Talk | Blackhat |
Exploit-Me Series – Free Firefox Application Penetration Testing Suite Launch
| Nish Bhalla, Rohit Sethi | #web-security#xss#sql-injection+4 |
| 2006-08-02 | Talk | Blackhat |
SQL Injections by Truncation
| Bala Neerumalla | #web-security#sql-injection#secure-coding |
| 2005-06-10 | Talk | Syscan |
.Net Web Security-Attack And Defense
| Shreeraj Shah | #.net#web-security#web-pentesting |