Katherine Leese
Katherine is a tech professional with 4 years of experience, having retrained in her 40s to become a Computer Expert, specialising in System Integration. Originally from New Zealand, she is currently based in Germany. During her training, she undertook a practicum at SevenShift, a boutique IoT cybersecurity company in Cologne that recognised her talent and dedication, ultimately hiring her. She is now employed there, where she is honing her skills and contributing to the company's security initiatives. Outside of her professional life, Katherine is a dedicated single mother to a teenager. She is a member of the Haecksen, the FINTA branch of the CCC, and a Chapter Leader of OWASP Cologne.
Sessions
Modern web infrastructure doesn't route on IP addresses. Load balancers, proxies, and CDNs all make routing decisions based on application-layer content like Host headers, forwarding headers and request paths. This is how the web works at scale. But it creates a gap: the transport layer tells you exactly where a connection went, and above it, the web layer tells servers things the transport layer has no way to verify. I have been spending a lot of time in this territory while studying for my Burp Suite Certified Practitioner exam. The disagreement between what the IP layer says and what the web layer does is right there in a packet capture. This talk covers the main classes where the layers stop agreeing, and what each one looks like in Wireshark.
A packet-level tour of the TLS family. What stays visible when everything's encrypted? TLS is everywhere, and most people assume that means "encrypted, end of story." But TLS is a family of protocols, and each member leaves a different footprint on the wire. This talk is a tour of that family through Wireshark, built around a single idea: encryption hides content, not behaviour.