NetSPI   »   Presentations

Hunting for Crits on Adventure Mode | BSidesYXE

Conference:

In this presentation from BSides Saskatoon 2024, security consultant Michelle Eggers explores the practical application of ethical hacking through the lens of “Adventure Mode”, a mindset emphasizing curiosity and structured exploration within clearly defined Rules of Engagement.

Drawing on her experience at NetSPI, Eggers demystifies the path to uncovering high-impact vulnerabilities. Rather than relying solely on complex exploit chains, she demonstrates how foundational testing techniques can expose critical security gaps. The session provides a technical walkthrough of three real-world findings: an S3 bucket misconfiguration, unauthorized data access within a Mainframe environment, and a classic Insecure Direct Object Reference (IDOR) flaw.

Throughout the talk, Eggers emphasizes the importance of restraint, proper scoping, and the “principle of least privilege” in maintaining the integrity of client environments during testing. By analyzing these critical vulnerabilities, the session offers actionable insights for security professionals on improving defensive configurations, segmenting production environments, and implementing robust server-side authentication. This talk serves as a compelling reminder that effective security auditing remains accessible through consistent, methodical, and responsible inquiry.