Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow From Advisory to Exploit
EH-Net
May 25, 2013, 01:15:54 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: From Advisory to Exploit  (Read 6182 times)
0 Members and 1 Guest are viewing this topic.
satyr
Newbie
*
Offline Offline

Posts: 41



View Profile
« on: August 11, 2010, 06:24:09 AM »

i recently read an article by the same name and in interested in knowing more about how exploits are created from advisories.

kindly suggest the skill set, resources, forums/websites, certifications which may help me in this endeavor.

any suggestion in this direction would he really helpful as im starting off with limited information i have been able to collect.

thanks
Logged
Knb15
Jr. Member
**
Offline Offline

Posts: 50


View Profile
« Reply #1 on: August 11, 2010, 05:19:00 PM »

i recently read an article by the same name and in interested in knowing more about how exploits are created from advisories.

kindly suggest the skill set, resources, forums/websites, certifications which may help me in this endeavor.

any suggestion in this direction would he really helpful as im starting off with limited information i have been able to collect.

thanks


Hi Satyr and welcome to the forums.

Personally i don't know the answer to your question. However, from being around for a few months i've noticed that you need to be a bit more descriptive in your request to get a better answer from the guys/gals that do know the answer.

It would be useful if you provided what your current skill level is, if you have completed any certifications in the past, if you have any programming knowledge (what languages you know or are familiar with) or experience in any computer related fields.
Logged
satyr
Newbie
*
Offline Offline

Posts: 41



View Profile
« Reply #2 on: August 11, 2010, 11:37:16 PM »

im currently working as a pentester... i have completed CEH

i have been following tutorials for exploit development and reverse engineering and i love the entire process of exploit development.

i want to become well versed with exploit development ... right now im following tutorials ... later i want to build my own exploits

from what i have read, following advisories is one of the most logical ways to create zero day exploits.

i want to know how people create zero day exploits by following advisories...is there some site or reference material i can follow for a start ?
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #3 on: August 12, 2010, 12:06:52 AM »

You're probably going to be best of learning assembly. After that, The Shellcoder's Handbook and Hacking: The Art of Exploitation (2nd) are good resources to take the next step.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
satyr
Newbie
*
Offline Offline

Posts: 41



View Profile
« Reply #4 on: August 12, 2010, 12:24:39 AM »

great Smiley

i am currently following Peter Van's tutorial on exploits and Lenas tutorials on reverse ingineering.

im thinking of doing a course for each one of them ...

any pointers about websites or forums to follow (along with this forum ofcourse Smiley )
Logged
mesho
Newbie
*
Offline Offline

Posts: 24


View Profile
« Reply #5 on: August 12, 2010, 05:58:50 AM »

check this out:

http://pentest.cryptocity.net/exploitation/
http://myne-us.blogspot.com/2010/08/from-0x90-to-0x4c454554-journey-into.html

Logged
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #6 on: August 12, 2010, 07:57:23 AM »

I'm going to put these links in order for the learning aspect of it:

http://www.amazon.com/A-Bug-Hunters-Reading-List/lm/R21POHD6Y2DOLQ
http://cansecwest.com/slides06/csw06-sotirov.pdf
http://www.slideshare.net/guest9f4856/returnoriented-programming-exploits-without-code-injection
http://www.cs.cmu.edu/~dbrumley/pubs/apeg.pdf
http://www.metasploit.com/redmine/projects/framework/wiki/AdvisoryToExploit

In order to understand how to create an exploit from a patch, you'd need to understand (drum roll) what was patched and why was it patched. To understand THAT you will need a hefty amount of experience in Assembly programming period. There is no shortcut around this. If you can get through Lena's tutorials, I'd suggest moving onto "Microsoft Patching Internals" (http://www.openrce.org/articles/full_view/22) After that soaks in, move over to "Binary Diffing Heuristics" (http://www.openrce.org/forums/posts/82) How about starting there then worrying about the tools.

I'm taking into account that we're talking MS based patches here as *nix based patches are visible and MS' aren't. As for blogs to follow, sites to view.

OpenRCE
http://www.openrce.org

Some good legacy articles
http://maliciousattacker.blogspot.com/

Excellent articles from Aaron
http://dvlabs.tippingpoint.com/blog/

Veracode
http://www.veracode.com/blog/category/binary-analysis/

Nico!
http://eticanicomana.blogspot.com/

Dino
http://trailofbits.com/

Halvar
http://addxorrol.blogspot.com/

MUST follow... Reversing on this level is a royal pain and not for the impatient. As mentioned already, Pentest.Cryptocity is another must. Beginning with "Reverse Engineering" (http://pentest.cryptocity.net/reverse-engineering/). I'd suggest you watch it over a few times paying exact attention to what he is saying with regards to structure and discipline prior to even opening a tool.

Lastly, a "stumbleupon" approach: http://www.reddit.com/r/ReverseEngineering/
Logged

satyr
Newbie
*
Offline Offline

Posts: 41



View Profile
« Reply #7 on: August 15, 2010, 10:51:03 PM »

whoa :O
thanks a ton mate for the wonderful reply... im sure this will keep me and anyone interested in the same , busy for quiet a while Smiley

cheers to you Cheesy
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.