Exploit Development

Publicado em: 06 Fevereiro 2015
no canal de: MPICTCenter
330
1

Presenter:
Sam Bowne, City College of San Francisco, San Francisco, CA

When a program crashes, that’s just a bug. But when a hacker takes remote control of your computer, that’s a disaster. This presentation shows how to weaponize a simple crash of a vulnerable application and turn it into a remote control exploit, using Kali Linux, Metasploit, the Immunity debugger, and some very simple Python code. The result is remote control of a Windows 7 computer. Nothing about it is difficult anymore–you don’t need to be an expert on machine language or Windows internals to do it.

First, I will explain how a stack buffer overflow exploit works. Then I will demonstrate the complete process of finding and weaponizing an overflow on Linux: fuzzing, debugging, identifying forbidden characters, creating shellcode, and injecting it to achieve remote control.

Students will repeat the process using their own computers and complete step-by-step instructions. We will then repeat the process for a Windows stack buffer overflow, so students perform that as well. Finally I will explain modern Windows defenses including DEP, ASLR, and EMET, and how attackers can defeat them.

CREDIT
-Music: www.bensound.com (Happy Rock)


Nesta página do site você pode assistir ao vídeo on-line Exploit Development duração hora minuto segundo em boa qualidade , que foi baixado pelo usuário MPICTCenter 06 Fevereiro 2015, compartilhe o link com seus amigos e conhecidos, no youtube este vídeo já foi visto 330 vezes e gostou 1 espectadores. Boa visualização!