Skip to content

ROP It Like It's Hot: A 101 on BOFs, ROPs, and Shellcode Development on Linux

Photo of Sherif Koussa
Hosted By
Sherif K.
ROP It Like It's Hot: A 101 on BOFs, ROPs, and Shellcode Development on Linux

Details

Speaker: Nadeem Douba

Abstract: To a normal human, hacking things like browsers and software seems like black voodoo magic. Even people in IT security struggle with the basic understanding of how a buffer overflow works. This workshop aims to demystify the art of exploiting vulnerabilities in binary software and equips you with the tools to pwn software on your own! We'll cover the following topics:

  1. A brief introduction to Assembly

  2. A brief overview of the Linux Stack

  3. Our Toolkit for Exploit Development

  4. Controlling the Instruction Pointer

a. Classic BOF (no strings attached)

b. ROP till' you drop (Defeating NX)

c. Where am I? (Defeating ASLR)

d. Silence the Canary (Defeating Stack Canaries)

  1. Advanced Topics to Research

Students are expected to bring a laptop as this workshop is hands-on. The following tools/software is required:

Students are encouraged to work in groups so encourage your friends to come along!

WARNING: We are in no way responsible for any hair loss during the course of this workshop. Successfully exploiting software may result in unusual happy dance behaviour.

Photo of OWASP Ottawa Chapter group
OWASP Ottawa Chapter
See more events