<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Talks and presentations at conferences on Martin Gallo</title><link>https://martingallo.ar/publications/talks/</link><description>Recent content in Talks and presentations at conferences on Martin Gallo</description><generator>Hugo</generator><language>en-us</language><copyright>CC BY-SA 4.0 - Martin Gallo</copyright><lastBuildDate>Thu, 24 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://martingallo.ar/publications/talks/index.xml" rel="self" type="application/rss+xml"/><item><title>pysap: protocols, tools and offensive capabilities for SAP security - YOLO edition</title><link>https://martingallo.ar/publications/talks/2026-09-24-pysap-protocols-tools-and-capabilities-for-sap-security-research/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2026-09-24-pysap-protocols-tools-and-capabilities-for-sap-security-research/</guid><description>&lt;h2 id="abstract-english"&gt;Abstract (English)&lt;/h2&gt;&#10;&lt;p&gt;pysap is an open-source offensive security framework for understanding, crafting, and interacting with proprietary SAP network protocols.&lt;/p&gt;&#10;&lt;p&gt;This talk looks at why the project was created, how it evolved from protocol research into a reusable offensive capability, and what that enables in practice. Through technical demos, we’ll explore how pysap can be used to inspect, manipulate, and experiment with SAP protocols.&lt;/p&gt;&#10;&lt;p&gt;We’ll also look at how AI changes the research workflow. By combining AI-assisted research with reusable offensive tooling, researchers can move faster from hypothesis to experimentation and validation.&lt;/p&gt;</description></item><item><title>The Enterprise Passkey: Security You Control, Simplicity Users Love</title><link>https://martingallo.ar/publications/talks/2025-10-13-the-enteprise-passkey-security-you-control-simplicity-users-love/</link><pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2025-10-13-the-enteprise-passkey-security-you-control-simplicity-users-love/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;Passwordless is here, but not all passkeys are created equal,&#10;especially within the enterprise. This presentation bridges the gap&#10;between consumer trends and corporate security needs, unveiling the&#10;Enterprise Passkey: your blueprint for deploying a truly secure,&#10;user-friendly, and scalable authentication future. See how&#10;phishing-resistant, non-syncable passkeys, when anchored by strong&#10;identity verification, become the cornerstone of trust for the entire&#10;employee lifecycle. We’ll show you how this powerful combination&#10;redefines critical processes like Day One onboarding, instant account&#10;recovery, and secure help desk access — enabling you to build lasting&#10;resilience, slash support costs, and finally eliminate user friction.&lt;/p&gt;</description></item><item><title>Recent Identity Threats and Trends: Lessons to Improve Identity Security</title><link>https://martingallo.ar/publications/talks/2021-06-25-recent-identity-threats-and-trends/</link><pubDate>Fri, 25 Jun 2021 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2021-06-25-recent-identity-threats-and-trends/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;As organizations modernize access architectures, attackers continue evolving&#10;their tactics to target identity infrastructure, session tokens, and&#10;authentication pipelines. This presentation examines recent real-world identity&#10;attack vectors mapped across modern threat frameworks (including MITRE ATT&amp;amp;CK&#10;techniques such as credential forging, token manipulation, input prompt capture,&#10;and session hijacking). The talk explores lessons learned from observed&#10;compromises and outlines actionable engineering strategies to strengthen&#10;enterprise identity posture and authentication resilience.&lt;/p&gt;</description></item><item><title>BIZEC Discussion Panel: Past, Present and Future of SAP Security</title><link>https://martingallo.ar/publications/talks/2019-03-20-discussion-panel-past-present-and-future-of-sap-security/</link><pubDate>Wed, 20 Mar 2019 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2019-03-20-discussion-panel-past-present-and-future-of-sap-security/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;Join us on this expert discussion panel where SAP Security experts from BIZEC&#10;organization will analyze how SAP Security has evolved over the last ten years,&#10;including not also the product security, but also the adoption and best&#10;practices of the companies side.&lt;/p&gt;&#10;&lt;p&gt;What are the biggest bugs in SAP? It is getting more difficult to find bugs in&#10;SAP products? How companies have adopted (or not) SAP Security measures? What’s&#10;the future of SAP and ERP Security? Those are some of the questions that would&#10;drive this discussion panel about past, present and future of SAP Security.&lt;/p&gt;</description></item><item><title>Hunting crypto secrets in SAP systems</title><link>https://martingallo.ar/publications/talks/2018-03-14-hunting-crypto-secrets-in-sap-systems/</link><pubDate>Wed, 14 Mar 2018 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2018-03-14-hunting-crypto-secrets-in-sap-systems/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;If you’re securing things in a proper way, cryptographic material should be all&#10;around your SAP systems: for protecting communications with HTTPS, TLS and SNC,&#10;Single-Sign-On, digital signatures and so on. Ever wondered how SAP systems&#10;stores that credentials and cryptographic keys in your system? Do you know if&#10;your private keys are properly protected? Succeed at a pentest and want to know&#10;how to extract and what to do with crypto secrets from a compromised host?&lt;/p&gt;</description></item><item><title>Intercepting SAP SNC-protected traffic</title><link>https://martingallo.ar/publications/talks/2017-03-22-intercepting-sap-snc-protected-traffic/</link><pubDate>Wed, 22 Mar 2017 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2017-03-22-intercepting-sap-snc-protected-traffic/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;SNC (Secure Network Connections) is SAP’s standard security mechanism for&#10;protecting communications from clients to servers and between SAP servers. This&#10;security layer works with SAP protocols like RFC or DIAG, and strengthen the&#10;security of them by using additional security functions. While not enabled by&#10;default, its use rate has increased since SAP started shipping it in all kernel&#10;versions. Now it can be observed implemented on large and small organizations&#10;for preventing active attackers or eavesdroppers.&lt;/p&gt;</description></item><item><title>Deep-dive into SAP archive file formats</title><link>https://martingallo.ar/publications/talks/2016-03-16-deep-dive-into-sap-archive-file-formats/</link><pubDate>Wed, 16 Mar 2016 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2016-03-16-deep-dive-into-sap-archive-file-formats/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;SAP systems make use of custom archive file formats in several different places,&#10;such as for distributing software components and in the code transport&#10;mechanism. While the compression algorithms used by SAP have been known for a&#10;few years, they were only targets of security analysis recently. Additionally,&#10;the file formats are proprietary and there is not much public information about&#10;how to properly interpret such files.&lt;/p&gt;&#10;&lt;p&gt;This talk will shed some light over the compression algorithms and the CAR and&#10;SAR file formats, while demonstrating some potential attack vectors involving&#10;this type of files. Moreover, we&amp;rsquo;ll discuss how to dissect and examine these&#10;files for both offensive and defensive purposes, using an open source Python&#10;library.&lt;/p&gt;</description></item><item><title>HoneySAP: Who really wants your money?</title><link>https://martingallo.ar/publications/talks/2015-03-18-honeysap-who-really-wants-your-money/</link><pubDate>Wed, 18 Mar 2015 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2015-03-18-honeysap-who-really-wants-your-money/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;Targeted attacks against ERP systems and enterprise software are not something&#10;new, however they only started appearing in the media in recent years. On the&#10;other hand, we also have new kinds of attacks by means of malware and malicious&#10;programs. Understanding the motivations and techniques adversaries use to target&#10;systems where company&amp;rsquo;s most valuable assets reside is crucial to understand the&#10;nature of the attacks and the defense strategies.&lt;/p&gt;</description></item><item><title>SAP’s Network Protocols Revisited</title><link>https://martingallo.ar/publications/talks/2014-03-19-saps-network-protocols-revisited/</link><pubDate>Wed, 19 Mar 2014 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2014-03-19-saps-network-protocols-revisited/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;What network protocols does my SAP system use? Are those services secure from a&#10;network perspective? Are old and well-known attacks still relevant? What’s the&#10;remote attack surface of my SAP environment? Do I really know my level of&#10;exposure? Are there tools available to assess the security of the services?&lt;/p&gt;&#10;&lt;p&gt;This talk is the result of my journey trying to answer these questions and&#10;understanding how the different SAP network protocols work, after spending some&#10;of my spare time during the last months working on expanding my knowledge about&#10;the network attack surface of SAP systems, reversing some of the protocols and&#10;implementing tools and libraries to work with them.&lt;/p&gt;</description></item><item><title>Uncovering SAP vulnerabilities - Reversing and breaking the Diag protocol</title><link>https://martingallo.ar/publications/talks/2012-09-26-uncovering-sap-vulnerabilities-brucon/</link><pubDate>Wed, 26 Sep 2012 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2012-09-26-uncovering-sap-vulnerabilities-brucon/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;Nowadays, SAP Netweaver has become the most extensive platform for building&#10;enterprise applications and running critical business processes. In recent years&#10;it has become a hot topic in information security, at a time when headlines&#10;about hacks against SAP systems increase every day. Although fixes and&#10;countermeasures are released monthly by SAP at an incredible rate, the available&#10;security knowledge is limited and some components are still not well covered.&lt;/p&gt;</description></item><item><title>Uncovering SAP vulnerabilities - Reversing and breaking the Diag protocol</title><link>https://martingallo.ar/publications/talks/2012-07-26-uncovering-sap-vulnerabilities-defcon/</link><pubDate>Thu, 26 Jul 2012 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/talks/2012-07-26-uncovering-sap-vulnerabilities-defcon/</guid><description>&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;&#10;&lt;p&gt;Nowadays, SAP Netweaver has become the most extensive platform for building&#10;enterprise applications and running critical business processes. In recent years&#10;it has become a hot topic in information security, at a time when headlines&#10;about hacks against SAP systems increase every day. Although fixes and&#10;countermeasures are released monthly by SAP at an incredible rate, the available&#10;security knowledge is limited and some components are still not well covered.&lt;/p&gt;</description></item></channel></rss>