Null offensive hacking hands-on training.
Proposed sessions for this event:
- Advanced Exploit Development by Mihir Shah
- Advanced Exploit Development by Mihir Shah
This is an advanced exploit development session to understand exploiting SEH based attacks on the applications. The participants will be understanding the concept of exception handling and gaining a shell by attacking the mechanism.
What would be covered in the session:
1. Methodology to testing thick clients
2. Fuzzing apps and checking for vulnerability
3. Exposure to using system level debuggers and making life easier by employing plugins
4. Understanding the infamous 'pop-pop-ret' to try having RCE
5. Basics of assembly coding
6. Understanding the mitigation techniques - etc and foundation to ROP
7. Primer to windows shell coding for the next part of the series
Pre-requisites:
1. Windows XP VM
2. Vulnerable apps from exploit db
- DVD X player : https://www.exploit-db.com/exploits/46962
- EFS Easy chat server: https://www.exploit-db.com/exploits/42155
- All media server: https://www.exploit-db.com/exploits/19625
3. To install IDA on windows XP
4. Download mona.py : https://github.com/corelan/mona/blob/master/mona.py
5. Attacking machine which is able to communicate to the windows VM
RSVP & Questionnaire are mandatory for everyone registering for this event (BOTH ARE COMPULSORY)
- https://null.co.in/events/633-bangalore-advanced-exploit-development
- https://forms.gle/ueUy9R2Tp8YDfTDE9
Failing to the above will automatically disqualify your nomination for this event.
Last date of registration: 07-AUG-2019 23:59.
Note:
* This is an invite-only event and the workshop champions & chapter leads reserve the rights to shortlist the participant.
* If shortlisted, you would receive email from Organizers and you should confirm your attendance.
* If you are shortlisted and don't turn up for the workshop, you will automatically not be eligible to attend next 2-3 future workshops.
* Not-shortlisted folks, please don't turn up for event.
* If you cannot make it to the event, due to unforeseen circumstances, please unregister yourself by replying to confirmation mail with the subject "PLEASE UNREGISTER". Please give your seat to the many others who are waiting to attend this session.
Date | Saturday August 10 2019 |
---|---|
Chapter | Bangalore |
Registrations | 33 |
Max Registrations | Unlimited |
Event Type | Invite Only |
Start Time | 09:30 AM |
End Time | 04:30 PM |
Session Schedule
Name | Speaker | Start Time | End Time | Resources |
---|---|---|---|---|
Advanced Exploit Development | Mihir Shah | 09:30 AM | 01:00 PM | |
Lunch | 01:00 PM | 02:00 PM | ||
Advanced Exploit Development | Mihir Shah | 02:00 PM | 04:30 PM |