Michael Bargury: How to Take Over an Enterprise Through No-Code
A DEF CON 30 talk on how low-code and no-code platforms are becoming the perfect attack surface — especially within shadow IT environments, where applications are built outside formal IT oversight and often without proper security controls.
The speaker demonstrates real-world attack techniques: account takeover with a single link click, lateral movement without generating network traffic, privilege escalation, deployment of stealthy backdoors, and automated data exfiltration. Each scenario is backed by proof-of-concept demonstrations and shared source code.
The talk concludes with the introduction of an open-source reconnaissance tool designed to identify opportunities for lateral movement and privilege escalation within enterprise low-code platforms.
The speaker demonstrates real-world attack techniques: account takeover with a single link click, lateral movement without generating network traffic, privilege escalation, deployment of stealthy backdoors, and automated data exfiltration. Each scenario is backed by proof-of-concept demonstrations and shared source code.
The talk concludes with the introduction of an open-source reconnaissance tool designed to identify opportunities for lateral movement and privilege escalation within enterprise low-code platforms.