7 ms·
Black Hat Rust
- anonym29 2y agoIs there a preview of the content beyond a short synopsis of each chapter?
- queuebert 2y agoA sample chapter would be nice to see.
- omani 2y agoI found the whole book on github. https://github.com/rustaccato/road-to-being-master-rustacean/blob/main/Black%20Hat%20Rust.pdf https://github.com/rustaccato/road-to-being-master-rustacean...
- lsllc 2y agoThis appears to be a collection of for-pay Rust books no? Not sure the authors would be happy with this.
- tptacek 2y agoThere's a book like these for a bunch of modern languages; I think "Black Hat Python" started the trend, like 10-15 years ago.
- dijit 2y agoBlack Hat Python, along with RTFM: Red Team Field Manual; are excellent resources for binpacking your brain with some simple effective uses of tools to serve a need. I don't feel the same about this book. Python is pretty ubiquitous, and RTFM focuses on oneliners and easily composable programs with utilities that already exist on target systems. A lot of what makes Red Team work harder is the need for portability, which pushes people to need to learn lots of interpreted languages and OS internals. My memory of using Rust for interop with the OS, is syscalls in win32 api; which consumed the better part of a couple weeks to get right, and required the use of unsafe, a lot.
- daghamm 2y agoI recently read blackhat python. I feel it has not aged well as large parts are dedicated to issues that are no longer relevant. I don't see this book doing the same mistake. On the other hand, I dont know if I want to fight the borrow checker for weeks instead if throwing together a quick script in python...
- nicce 2y ago> I dont know if I want to fight the borrow checker for weeks instead if throwing together a quick script in python... To be fair, you only need to fight if you care about maximum performance.
- lord-squirrel 2y agoHave you read the 2nd Edition or the first one?
- red-iron-pine 2y agothe 2nd edition one is from 2021 and has some errors; there is errata for it it's alright, a lot of stuff I'd characterize as a 'good start'
- NewsaHackO 2y agoI feel as though buying a book like this is admission that you don't have what it takes to do black hat work. Good if it's just out of curiosity though.
- bikingbismuth 2y agoI will eventually read through this because I have a reasonably good handle on Python/Go, but don’t have any experience with Rust. This book will help me focus on the parts of Rust that I am most interested in given my current InfoSec work.
- TrackerFF 2y agoYou'd be surprised how many professional hackers - the ones that intelligence agencies hire/train/employ - start with close to zero prior knowledge on topics like cybersecurity, when they're going through selection. If you have solid knowledge in CS fundamentals and the right mindset/motivation, that tends to be enough.
- red-iron-pine 2y agobeing autodidactic matters a lot
- cpach 2y agoPlease, spare us the gatekeeping.
- chili6426 2y agoI feel as though buying a book like this is a great way to start learning about black hat work. Doing things out of curiosity is how everyone starts in a field like cybersecurity.
- jaylane 2y agoblack hat go was fun. deff needs a sample chapter.
- kurisufag 2y ago> Which programming language allows to craft shellcodes, build servers, create phishing pages? Before Rust, none! i'd ordinarily consider this too implausible a statement to be seriously believed, but rust people really do talk like this.
- dwattttt 2y agoIf I had to extract meaning from it, I'd say "Never before has there been one language that is at least ok at writing shellcode, a web server, and a phishing page in". Not sure I agree with the statement, but it's a pretty weird category to sit in. C would count as a possible member at least.
- PeterWhittaker 2y agoSure, we can do those things in C, but they are easier and faster to do in Rust, and safer, largely because of Rust's enums (algebraic data types, not as simplistic as C's) and traits, and because of crates: a lot can be done in Rust by gluing together a few well maintained crates. The only language that comes close, AFAICT, is python. Add the fact that Rust's memory safety brings thread safety for free (once you've grokked Rust's memory management model) and yiu get quickly written type safe memory safe thread safe high perfomance code.
- jerf 2y agoThere's aggressive language advocacy, and then there's passing into parody. I think you're getting perilously close to the latter here.
- anonym29 2y agoAnyone have any idea what makes Rust evangelists / apologists so religious about it? It's not like it's the only high-performance memory safe language. It wasn't the first. It's not the highest performance. What am I missing?
- yellow_lead 2y agoI thought this repo was something I could read on GitHub, but it seems like it just stores code associated with the book. So this is just an ad for the book. And all the chapter links 404.
- Xunjin 2y agoI've got to say, it's time for HN to add an obligatory tag for ads like that, I know it's not so much a loss of time, but it irritates me sometimes, just like now.
- cookiengineer 2y agoI think what the author hasn't realized yet is that for the most part - exploit development, fuzzing a binary, finding a logical problem and building a feasible exploit for it - you are fighting against the language that you chose. The reason Go got so popular is not because of its type system, but because it also has a mode of programming "good enough" prototypes. Python for exploit development is also great due to the gdb fork that can generate python payloads, offsets etc, but it sucks for deployment on targets. If I would compare the three language choices I don't see why anyone would choose Rust over the other two in terms of efficiency and not having to fight the language. I don't even know whether it would be possible to write an exploit that overflows something in an external ABI binary in Rust without sacrificing everything that Rust stands for. After all, the binary would have to be statically linked for deployment, have to support invalid types, have to support invalid control flows etc. On the other hand, in Go that's what CGo is made for. The VM and GC in Go doesn't care about what CGo does. Edit: nevermind, the only example that is using Rust for this type of exploits is a sudo cli argument exploit, lol. I would have expected a little more than a char array generator that's using the FFI package. [1] [1] https://github.com/skerkour/black-hat-rust/blob/main/ch_07/exploits/cve_2021_3156/exploit/src/main.rs https://github.com/skerkour/black-hat-rust/blob/main/ch_07/e...
- rollulus 2y agoExactly my thoughts reading the ToC. One exception would come to my mind though: Rust would seem a very reasonable language choice to me to write malware. E.g., the next Stuxnet. Low level enough, plus the language safety to help staying under the radar.
- Fnoord 2y agoThere are already terrible Rust projects out there where the mention of Rust is entirely marketing fluff, such as Rustdesk.
- Ygg2 2y ago> The reason Go got so popular is not because of its type system, but because it also has a mode of programming "good enough" prototypes. You can Grug program in any language. Including Rust. Just clone, Arc, and unwrap everything. The reason why Go got popular is: A) It's backed by Google (this is essential, there are many languages simpler/easier than it) B) It's easy to pickup
- statwin1159com 2y ago[dead]
- deleted 2y ago[deleted]
- lacoolj 2y agoJust a book selling ad Moving on
- red-iron-pine 2y agobro this is a "news" site run by a startup incubator. 80% of this site is about pushing and selling stuff. blatant out of the blue spam doesn't have a place here, but discussing (and hating on) Rust is a common topic.