封闭的冲突与开放的和平 · 2016. 7. 27. · first, i'm sorry about reporting another...

23
封闭的冲突与开放的和平 SOBUG 冷焰

Upload: others

Post on 15-Sep-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

封闭的冲突与开放的和平

SOBUG 冷焰

Page 2: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

2000

白帽 甲方 创业者

2008 2013

创业者

2014

创业者

2015

Blackhat 腾讯 SOBUG

Page 3: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

“安全行业的陋习都有哪些?”-知乎问题

Page 4: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

娱乐圈

浮躁

自买自夸高调得没边

⋯ ⋯ Helen

Page 5: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

-知乎匿名网友

hacked by xxxxx

Page 6: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

“百度刘超事件”

Page 7: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info
Page 8: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

,

Page 9: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

“SOBUG加入阿里云生态”

Page 10: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

“真的感谢吗?”

Page 11: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info
Page 12: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

“开放的和平会怎么样?”

Page 13: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info
Page 14: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info
Page 15: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

Word Press

Hi @jouko 1 team.uberinternal.com JS

@jouko

WordPress Uber

Page 16: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

发现 “白帽子是流动的”

Page 17: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

解决

“处理更快”

“解决更彻底”

Page 18: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

复盘

“为什么会发生?”

“还有哪些有问题?”

Page 19: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

收敛 “数据驱动的SRC指标”

Page 20: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

沉淀

“案例”

“员工教育”

Page 21: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

发现 解决 复盘 收敛 沉淀

“红蓝对抗” “数据驱动”

Page 22: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

Wooyun is good But good is not enough

Page 23: 封闭的冲突与开放的和平 · 2016. 7. 27. · First, I'm sorry about reporting another WordPress bug (my intention was just to check if WP-OneLogin stores any sensitive info

谢谢