4 ms·
I think this is a good list on how to get good at learning to jump between layers of abstraction with gusto, but I think ultimately this all needs to be motivat
by yan 14y ago
I think this is a good list on how to get good at learning to jump between layers of abstraction with gusto, but I think ultimately this all needs to be motivated by a desire to actually exploit or reverse engineer something (as your latter bullets point out).
Learning C super well is important, so is assembly, so is other topics but I think fundamentally, step one needs to be: "I have product X. What is it trusting? What is it trying to protect? How do I get around it?" Then, find similar vulnerabilities and continue on stumbling to the ultimate goal.
- rockdon 14y agoI agree with both daeken and yan. Moving off that, I think a key to "thinking security" is understanding the threat model of a given thing. I believe this is partially what yan was alluding to as well. Understanding the function, and boundaries, and interactions of a system, application, protocol, device et al and being able to identify who are threat actors, what the assets to protect are, and what the real threats against the entity are will point you at the more valuable things to start. Far, far too many people gloss over threat modeling because they don't equate it with technical work.
- tptacek 14y agoBeing able to jump between layers of abstraction --- in both directions, so I'd add "learn the browser JS DOM model inside and out --- has to be in the top 5, probably top 3 all time most useful software security survival skills.
- sadpluto 14y agoWhat is the standard reference for DOM mastery?
- yan 14y agoThis is a very good starting document: http://code.google.com/p/browsersec/ http://code.google.com/p/browsersec/ (Also, anything icamtuf touches is probably going to be good.)
- tptacek 14y agoI'd start with _The Tangled Web_ by Zalewski.
- wglb 14y agoAnother document worthy of some study is http://lcamtuf.coredump.cx/postxss/ http://lcamtuf.coredump.cx/postxss/
- tptacek 14y agoYes! This is a great paper which made surprisingly little noise given how important it is. The idea is: stipulate that no attacker can ever inject Javascript into a browser. Assume we solve that problem completely. Now, how secure are DOM-based applications? Turns out: not that much more secure. Lots of very clever examples.
- wglb 14y agoRegarding abstractions, learn how to puncture them.
- emmelaich 14y agoI think it was Robert Morris (rtm's father) who said when asked how to break security: 1. Look in the manual for statements of the form "Don't do X" 2. Do X
- pierrebouchet 14y agoTo me "Pick a game, write a server emulator for it" is an excellent example of "What is it trusting? What is it trying to protect? How do I get around it?". But on top of being "a great way to use all your skills up to this point" I think it can also be a strong motivation for picking up new ones.