Presenter:
Sam Bowne, City College of San Francisco, San Francisco, CA
When a program crashes, that’s just a bug. But when a hacker takes remote control of your computer, that’s a disaster. This presentation shows how to weaponize a simple crash of a vulnerable application and turn it into a remote control exploit, using Kali Linux, Metasploit, the Immunity debugger, and some very simple Python code. The result is remote control of a Windows 7 computer. Nothing about it is difficult anymore–you don’t need to be an expert on machine language or Windows internals to do it.
First, I will explain how a stack buffer overflow exploit works. Then I will demonstrate the complete process of finding and weaponizing an overflow on Linux: fuzzing, debugging, identifying forbidden characters, creating shellcode, and injecting it to achieve remote control.
Students will repeat the process using their own computers and complete step-by-step instructions. We will then repeat the process for a Windows stack buffer overflow, so students perform that as well. Finally I will explain modern Windows defenses including DEP, ASLR, and EMET, and how attackers can defeat them.
CREDIT
-Music: www.bensound.com (Happy Rock)
Sur cette page du site, vous pouvez voir la vidéo en ligne Exploit Development durée heure minute seconde en bonne qualité , qui a été Téléchargé par l'utilisateur MPICTCenter 06 février 2015, Partagez le lien avec vos amis et connaissances, sur youtube cette vidéo a déjà été regardée 330 fois et il a aimé 1 téléspectateurs. Bon visionnage!