BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//talk//UEYM89
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-UEYM89@cfp.balccon.org
DTSTART;TZID=CET:20260918T173000
DTEND;TZID=CET:20260918T183000
DESCRIPTION:Security issues are becoming harder to detect or exploit\, espe
 cially in well audited targets. Instead of subverting the code flow\, an a
 ttacker might try to subvert the application logic. This class of vulnerab
 ilities is commonly referred to as business logic vulnerabilities. In this
  session\, we will present the result of a research study where the author
  manually reviewed about 300 publicly disclosed vulnerability reports and 
 tried to classify and cluster discovered vulnerabilities into a few catego
 ries that can be used to secure business logic issues in applications. So 
 let's take a ride through some real life cases and examples on how to mani
 pulate calculation\, assumptions\, processes\, branching\, logical and tim
 e based TOCTOU and other fun cases on how to break an modern application.
DTSTAMP:20260901T071817Z
LOCATION:Tesla
SUMMARY:Hunting for business logic vulnerabilities - Tonimir Kisasondi
URL:https://cfp.balccon.org/balccon2k26-2026/talk/UEYM89/
END:VEVENT
END:VCALENDAR
