☕ Social📍 MelbourneOpen to all

1. Footguns in Golang 2. Please stop exposing your LLM to the internet!

WhenFri, Oct 2, 6:30 PMStarts 3 hours ago📅 Add to calendarWhereRMIT Swanston Academic Building 80. level 2 room 2445 Swanston Street, Melbourne🗺 Apple Maps🗺 Google Maps🚕 UberHostRuxmon MelbourneCostNot stated — check with the hostOneJoy doesn't handle payments — settle directly with the host or venue.CapacityOpen — no spot limit

About this event

Talk Submissions: [email protected] (http://[email protected]%2A%2A/) Footguns in Golang - Zoltan (@loltan) Automated tooling and AI assistants have raised the floor for code review — the obvious Go bugs now get caught on the first pass by anyone. But that floor is also where most reviewers stop, because the tooling only flags what it already knows to look for. This talk goes past it, into Go's subtle and dangerous behaviours: silent integer overflows that smuggle SQL queries at the protocol level, null-byte auth bypasses at the CGO boundary, JSON marshallers that silently leak the very secrets they were written to redact, reverse-proxy hop-by-hop header abuse, and the JSON-parsing quirks that keep CSRF alive in modern REST APIs. These footguns and the Semgrep rules to catch them were the subject of a recent elttam blog post — but rules are only interesting once you point them at real code. So for Ruxmon, we've turned them loose on a swathe of large, widely-used open source Go projects to see what actually falls out 2\. Please stop exposing your LLM inference to the internet\! \- Griffyn Hancock LLM backend and frontend vendor docs make configuration recommendations that are vulnerable in non secure networks. Those same backends often have no auth out of the box, or no native option for auth at all. This becomes a problem when non technical people ask chatgpt to set up "local ai" for them and end up exposing their inference endpoint to the internet en masse. This is likely a contributing factor to the hundreds of thousands (and counting) hosts that are exposed with no authentication, which at best can result in inference compute hijacking, and at worst result in for RCE with extra steps. We will also look at some of the whacky poisoned system prompts that I have found while scanning for this. Griffyn Hancock is a cybersecurity student who has had a hobbyist interest in machine learning for 10 years. He is always tinkering and learning, and loves to share what he's found. Location Room 080.02.002 at RMIT (Building 80) - 445 Swanston St, Melbourne Discord Discord Invite (https://discord.gg/2qcaxce8Mw)

Join this event

Before you join

OneJoy is where people find each other — the host organises the event, not us. Check who is hosting, judge whether it suits you, and take the same care you would meeting anyone new. Under-18s should come with a parent or guardian. Any money changes hands directly with the host; OneJoy never handles payments.

Sign in — Have an account? Sign in and we'll fill this in for you.

Only shared with the host.

More options

Questions & comments

Ask the host anything — replies are visible to everyone.

—

⚑ Report

Report this to the OneJoy team

Tell us what is wrong. We read every report.