When pentesting for a customer, we discovered that fast and deliberate swiping could give us access to very sensitive data through a mobile phone.
In this talk Bartek Pszczola will tell the tale of how he discovered a 0-day in a widely used VMware app, what it could lead to and how the process was when reporting the vulnerability to the vendor.
Bartek Pszczola
Bartek is a self-taught penetration tester with a master's degree in economics. He has 7 years of experience with penetration testing of applications and IT infrastructure, including for companies in the financial sector. Bartek has specialised in penetration testing of web applications and mobile phones. He also has experience with forensics and incident response. He has a background from SecuRing in Poland and from Deloitte in Norway, and he was employed by Defendable from April 2021.