Exploit Development

Veröffentlicht am: 06 Februar 2015
auf dem Kanal: MPICTCenter
330
1

Presenter:
Sam Bowne, City College of San Francisco, San Francisco, CA

When a program crashes, that’s just a bug. But when a hacker takes remote control of your computer, that’s a disaster. This presentation shows how to weaponize a simple crash of a vulnerable application and turn it into a remote control exploit, using Kali Linux, Metasploit, the Immunity debugger, and some very simple Python code. The result is remote control of a Windows 7 computer. Nothing about it is difficult anymore–you don’t need to be an expert on machine language or Windows internals to do it.

First, I will explain how a stack buffer overflow exploit works. Then I will demonstrate the complete process of finding and weaponizing an overflow on Linux: fuzzing, debugging, identifying forbidden characters, creating shellcode, and injecting it to achieve remote control.

Students will repeat the process using their own computers and complete step-by-step instructions. We will then repeat the process for a Windows stack buffer overflow, so students perform that as well. Finally I will explain modern Windows defenses including DEP, ASLR, and EMET, and how attackers can defeat them.

CREDIT
-Music: www.bensound.com (Happy Rock)


Auf dieser Seite können Sie das Online-Video Exploit Development mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer MPICTCenter 06 Februar 2015 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 330 Mal angesehen und es wurde von 1 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!