Presenter:
Sam Bowne, City College of San Francisco, San Francisco, CA
When a program crashes, that’s just a bug. But when a hacker takes remote control of your computer, that’s a disaster. This presentation shows how to weaponize a simple crash of a vulnerable application and turn it into a remote control exploit, using Kali Linux, Metasploit, the Immunity debugger, and some very simple Python code. The result is remote control of a Windows 7 computer. Nothing about it is difficult anymore–you don’t need to be an expert on machine language or Windows internals to do it.
First, I will explain how a stack buffer overflow exploit works. Then I will demonstrate the complete process of finding and weaponizing an overflow on Linux: fuzzing, debugging, identifying forbidden characters, creating shellcode, and injecting it to achieve remote control.
Students will repeat the process using their own computers and complete step-by-step instructions. We will then repeat the process for a Windows stack buffer overflow, so students perform that as well. Finally I will explain modern Windows defenses including DEP, ASLR, and EMET, and how attackers can defeat them.
CREDIT
-Music: www.bensound.com (Happy Rock)
On this page of the site you can watch the video online Exploit Development with a duration of hours minute second in good quality, which was uploaded by the user MPICTCenter 06 February 2015, share the link with friends and acquaintances, this video has already been watched 330 times on youtube and it was liked by 1 viewers. Enjoy your viewing!