Главная
Study mode:
on
1
Intro
2
The origin of this talk
3
Motivations
4
Process
5
Post research
6
Bugs Buffer overflow
7
Program analysis tools
8
Improved security strategies
9
Develop advanced fuzzing
10
Case study - CVE-2021-30737
11
Execute arbitrary code
12
Exploit mitigations
13
Secure architectures
14
1-click attack steps
15
Case study - KPP
16
Case study - PAC in kernel
17
Case study-PAC in userland
18
Case study - PPL
19
Conclusions
20
Offensive and defensive game
21
What about the future?
22
Quick review of Blackbird
23
Exploits of Blackbird
24
Exploit from Checkrain
25
Loading SEPOS
26
Simple solution
27
Takeaways
Description:
Explore the evolving landscape of vulnerability research in this keynote address from OffensiveCon23. Delve into the origins and motivations behind vulnerability research, examining both changing and unchanged aspects of the field. Learn about buffer overflow bugs, program analysis tools, and improved security strategies. Discover advanced fuzzing techniques and analyze real-world case studies, including CVE-2021-30737. Examine exploit mitigations, secure architectures, and 1-click attack steps. Investigate specific cases involving KPP, PAC in kernel and userland, and PPL. Gain insights into the offensive and defensive game of cybersecurity and ponder the future of vulnerability research. Review the Blackbird exploit, including its exploitation techniques and loading of SEPOS. Conclude with key takeaways to enhance your understanding of modern vulnerability research and exploitation techniques.

Changing and Unchanged Things in Vulnerability Research

OffensiveCon
Add to list
0:00 / 0:00