HackTheBay 3.0

Rotem Bar

Hacker | Security Researcher | AppSec Innovation at Palo Alto Networks

Rotem Bar is a veteran hacker and security researcher with over 20 years of experience breaking—and then fixing—complex systems. Currently serving as a Hacker within the InfoSec organization at Palo Alto Networks,

Rotem focuses on offensive security, identifying novel attack vectors in modern cloud infrastructures, and securing the software supply chain. Rotem's career spans the full spectrum of the industry, from early days in the IDF’s elite technology units to securing critical infrastructure in the automotive and SaaS sectors. Before joining Palo Alto Networks (via the acquisition of Cider Security), he led security initiatives at AppsFlyer and Cymotive, where he specialized in penetration testing and automotive security concept design.

As a bug bounty hunter, Rotem has uncovered critical vulnerabilities in major global platforms, including TikTok, Aws, General Motors, AT&T, and many more. His research has led to significant industry disclosures, for example the discovery of a vulnerability in Elementor that exposed over 6 million websites (CVE-2022-29455) and groundbreaking research on hacking automotive clouds presented at DEF CON.

He is a frequent speaker at top-tier conferences like DEF CON (Cloud & AppSec Villages), BSidesTLV, and Security Fest, where he often shares new novel reaearch," CI/CD security, and the intricacies of the hacker mindset.


Session

03-23
16:00
75min
Let’s hack from the beginning
Rotem Bar

There are so many techniques, methods, focus areas in the hacking world which makes it overwhelming to begin. I would want to pause with all my research, pentesting, hacking, exploiting, writing ai to replace me.. and take an hour or two and guide you from the beginning.

tackling 10 different areas I played with over the years, how to start, how to dive deep and how to think like a hacker. This presentation will be technical but built for anyone who wants to join this amazing world. We will learn web, mobile, iot, browsers, and more.. how to leverage code analysis and anything that can help you cheat your way into the exploit
Following the talk we will have a collaborative workshop practicing these methods

Let’s have fun!!

WORKSHOP
WORKSHOPS