3 ms·
if you are comfortable with gdb go with it or else i generally prefer hexdump, objdump and radare2 over gdb (for linux pwnables). i really like radare2, and ctf
by ismailamca 11y ago
if you are comfortable with gdb go with it or else i generally prefer hexdump, objdump and radare2 over gdb (for linux pwnables). i really like radare2, and ctfs generally come with radare nowadays.
however, i think, the most important thing about cracking challenges is your knowledge, you need to learn the paltforms, the architecture, possible vulnerabilities and exploitation of all. so you may benefit reading some vulnzines like phrack and valhalla, some vxforums or papers from exploit-db. also there are very nice books where you can learn basic exploitation techniques(shellcoders handbook, hacking the art of exploitation, etc...). these may be useful if you really have the basic aspects, if you aren't comfortable with shell(bash, sh, zsh, etc..) you should get comfortable with them at the begining.
also you need to learn some c and another scripting language(like python, perl, ruby, lua etc...) for effective cracking (in *nixes).
and don't use windows, it makes you lazy.
also you can take these courses, that would be a marvelous start http://www.opensecuritytraining.info/ http://www.opensecuritytraining.info/
<IMPORTANT!> before starting these please ask yourself, why do you do this to yourself? go and get a (girl|boy)friend instead of this. the security field is such a §H!™ hole and endless.
TL;DR: go with radare, and crack this challenges first >> https://exploit-exercises.com/ https://exploit-exercises.com/