meetings

where & when

where
denhac, 700 Kalamath Street, Denver, CO 80204
when
typically 4th fridays (alternative dates can be arranged for speakers), 7-9 pm
discord
join the community on discord — decode: ZGlzY28gcmQge2RvdH0gZ2d7c2xhc2h9Q2FKV2pVZ3FFVg==
topics
we encourage members to be active and contribute to the group. if you have a meeting topic or idea, propose it in the discord channel or contact us directly.

upcoming meetings

next meeting

Post-Quantum Cybersecurity: Exploring the Quantum Threat Landscape

when
fri 7-9 pm
presenter
Saad Baig
where
denhac, 700 Kalamath Street, Denver, CO 80204
rsvp
meetup.com event page (optional)

Quantum computing is moving from a theoretical threat to a looming security crisis, and asymmetric cryptography is right in the crosshairs. This talk breaks down exactly how Shor’s algorithm dismantles the public-key foundations—like RSA and ECC—that secure everything from our web traffic to our identities.

We’ll cut through the hype to look at immediate, real-world risks—like “Harvest Now, Decrypt Later” and “Trust Now, Forge Later”—to help you pinpoint which of your systems and data are most vulnerable based on their lifespan and value. From there, we’ll dive into NIST’s new post-quantum standards and look at what they actually mean for your PKI, TLS, and enterprise architecture.

To bridge the gap between theory and execution, I’ll introduce pqcscan, an open source tool built to scan your infrastructure and hunt down vulnerable public-key implementations before adversaries can exploit them. We’ll wrap up by weighing the tradeoffs of post-quantum cryptography, hybrid rollouts, and quantum key distribution. You’ll walk away with a no-nonsense action plan for crypto agility, asset discovery, and the exact steps needed to build a quantum-resilient future.

also coming up

The Coroner's Report: A Guided Autopsy of msfvenom's Windows Shellcode

when
fri 7-10 pm
presenter
Nick Neal
where
denhac, 700 Kalamath Street, Denver, CO 80204
rsvp
meetup.com event page (optional)

This will be an interactive lab covering the reverse engineering of msfvenom’s stageless Windows x64 reverse TCP shellcode. We will cover the basics of Windows internals, x86_64 assembly code in Windows, as well as the obfuscation techniques used by the shellcode author in an attempt to hinder static analysis.

To participate in the lab, you will need a fresh Windows 11 VM with 2 cpu cores, 4GB of RAM, and 64GB of disk space allocated. A script will be provided to set up the VM with the necessary software and configurations before the talk (will post a github link in discord a week or 2 before the meetup).

past meetings

Android Malware Reverse Engineering Workshop

presenter: Emma

Fire up JADX-gui and poke around a real malware sample of the AndroRAT android malware family. Learn about how android apps are structured and explore malicious functionality.

WARNING THERE WILL BE LOTS OF JAVA

Prereqs:

  • Optional (recommended) download and setup an analysis linux vm like ubuntu.
    • Sample is primarily Dalvik bytecode / compiled Java and is relatively low risk for static analysis.
  • Install Java
  • Download Jadx https://github.com/skylot/jadx/releases/tag/v1.5.5
  • Acquire malware sample by going to https://vx-underground.org/Samples/Families/Android.AndroRAT and downloading version 7729b69281dd037739b6f2802e5b90636694e59482288438ad43b5dfb8d3ad15.7z

Reversing Bad Brew

presenter: Emma

Have you ever heard that Macs don’t get malware? Well that’s not true. Bad Brew was a click fix malware campaign that tricked users into downloading and running malware by imitating the homebrew package manager. I will compare an earlier and a more advanced malware sample that shows how the threat actors tactics changed over time

Intro to CDX: A cybersecurity training range built for real learning

presenter: Q

“What am I working on?”

Building a flexible cybersecurity training range — one that can simulate everything from simple flat networks to complex multi-site enterprises with legacy systems, modern infrastructure, and all the messy realism in between.

Why?

Because learning security requires a safe space to fail. Red teamers need targets they can attack without consequences. Blue teamers need environments where missed detections are lessons, not disasters. Students need room to break things and understand why. CDX provides that space — fully isolated, fully contained, and ready to reset as often as the learning demands.

What makes it different?

The range isn’t just isolated networks in a vacuum. There’s underlying infrastructure that makes it feel like operating within a larger ecosystem — realistic enough to be worth a longer conversation if you’re curious.

Where is this headed?

The project is open source and actively evolving. I’m building exercises, refining automation, and exploring opportunities to support hands-on training for security professionals, students, and teams who want something more than a typical lab experience. Interested in training, contributing, or learning more? I’d welcome the conversation.

Car Hacking

presenter: Specters

Finding vulnerabilities in automobiles… Some old ones and some ??

Crash Course into the OWASP API Top 10

presenter: Alan Shen

At this month’s meeting, Alan will preview his upcoming SnowFROC talk, Crash Course into the OWASP API Top 10. As a DC303 exclusive complimenting the talk, we will practice on the vulnerable applications Completely Ridiculous API (crAPI) and VAPI.

To participate in the interactive part of the event, bring your own laptop with an intercepting proxy (Burp, ZAP, etc.) as well as an API testing tool like Postman. There will be several options for accessing the labs, including using API Sec University’s hosted environment, a local Proxmox lab network we will host in the space for the event, or setting up your own VMs on your laptop.

Recommended Tools:

https://portswigger.net/burp/communitydownload
https://www.zaproxy.org/
https://www.postman.com/
https://github.com/OWASP/crApi (or alternative to deploying a VM: http://crapi.apisec.ai/)
https://github.com/roottusk/vapi (or alternative to deploying a VM: http://vapi.apisec.ai/)

Talk Abstract:

Application Programming Interfaces (APIs) are the glue that allows independently evolving systems to communicate with each other, and are an important focus for security investment due to their privileged access to sensitive data and functionality. Recently, the OWASP API Top 10 has been updated for 2023, so join us as we introduce the OWASP API Security Project. We’ll cover what’s new in the 2023 API Top 10, as well as compare the differences with the previous 2019 version. For those interested in hands-on practice, we’ll also briefly introduce the OWASP crAPI (completely ridiculous API) Project which demonstrates common API vulnerabilities.

A Web CTF For Everyone

presenter: Mark Hoopes

At this month’s meeting we’ll spend some quality time with a truly insecure CRM application that has something for every level of web hacker. Entry level participants can explore a poorly designed authentication system, mid-level hackers will have plenty of opportunities to run SQL and JavaScript Injection attacks, and there is even a pathway to shell, but it will take some real dedication to get there. A walkthrough is available for those who need it so everyone should come away knowing a little more about how to attack (and defend) web applications. Bring your own laptop with an intercepting proxy (Burp, ZAP, etc.) installed to participate.

COME LEARN ABOUT WIFI HACKING!

presenter: Neko

COME LEARN ABOUT WIFI HACKING! We’ll be going over wifi’s evolution over the years, learning about vulnerabilities, mitigations, the tooling available, what’s under the hood of most wifi routers, and how you can run your own audits and even defend wifi in an enterprise or home environment.

INCLUDING PRACTICAL LABS! We’ll be putting out a bunch of wifi access points, maybe even some vulnerable clients, and you’re going to be hacking them.

HACK THE PLANET!

AI, cybersecurity, and privacy

presenter: Cameron Hopkin

Examining the complex relationship between AI and Cybersecurity and Privacy. May do some exploration of the Claude family of AI models. Be ready for good discussion.

Programmable Cryptography: Actualizing Academic Innovation for Novel Technology

presenter: Nuke

Seemly all of a sudden many theorized cryptographic systems are becoming practically usable. Programmable Cryptography is an exciting vision for novel applications using these new tools to empower privacy, verifiability, and much more. This talk will highlight some of these new tools and cover a few key use cases. We will invite discussions from the audience about how we might use these, helping drive adoption and innovation here in our local community and beyond! With any luck, we will come away with a few groups to kick-off a series of talks and workshops around this theme. Speaker bio: Nuke 🌄 is a developer relations advocate at https://risczero.com/ working to evangelize Verifiable Computation and is a huge fan of all things Programmable Cryptography Application. He is a community Steward for https://cryptorado.org that in home for web3 innovators and open source tools to empower people to be self sovereign, focused on engineering coworking and community hackin’. Connect with him on Cryptorado’s Zulip (join at https://Cryptorado.org, or directly on signal

Hacker Summer Camp Recap and Highlights

presenter: Mark Hoopes

Couldn’t make it to Hacker Summer Camp? Made it, but didn’t see every talk available? Join us for a group brain dump on the most interesting talks, research, and tools released at Blackhat, BSides Las Vegas, or DEF CON. Really anything recent and interesting is fair game. Please come with at least one item to share, even if it was just something you saw referenced and would like to know more about.

talk ideas looking for a presenter