4 ms·
Are there any good online resources that someone experienced in this field would recommend that go through the basics of how to perform this type of bug hunting
by Hortinstein 12y ago
Are there any good online resources that someone experienced in this field would recommend that go through the basics of how to perform this type of bug hunting?
I have a background in computer science but was never given the opportunity to take any classes in reverse engineering and exploitation of software. Thanks!
- kyrre 12y agoTry these courses/exercises: http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/ http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/ https://pentesterlab.com/ https://pentesterlab.com/ http://exploit-exercises.com/ http://exploit-exercises.com/
- mikecb 12y agoDo 'tptacek's challenges? They seemed pretty popular at the time.
- Huppie 12y agoAside from the courses/exercises mentioned above you could also give Google Gruyere a go: http://google-gruyere.appspot.com/ http://google-gruyere.appspot.com/ If you want to go in-depth I learned a lot by just reading interviews (and following the links) from the 'How to Break Into Security' series of KrebsOnSecurity, here's the ones I had in my bookmarks (there are more if you use the search) Thomas Ptacek (tptacek) Edition: http://krebsonsecurity.com/2012/06/how-to-break-into-security-ptacek-edition/ http://krebsonsecurity.com/2012/06/how-to-break-into-securit... Charlie Miller Edition: http://krebsonsecurity.com/2012/08/how-to-break-into-security-miller-edition/ http://krebsonsecurity.com/2012/08/how-to-break-into-securit... Richard Bejtlich: http://krebsonsecurity.com/2012/07/how-to-break-into-security-bejtlich-edition/ http://krebsonsecurity.com/2012/07/how-to-break-into-securit...
- josu 12y agoThere is an amazing book about hacking the original xbox. I think it may be this one, but I'm behind a firewall that doesn't let me open it: http://bunniefoo.com/nostarch/HackingTheXbox_Free.pdf http://bunniefoo.com/nostarch/HackingTheXbox_Free.pdf
- amckenna 12y agoThere is a lot of more classroom style learning on: http://opensecuritytraining.info/Training.html http://opensecuritytraining.info/Training.html I also like: https://pentesterlab.com/exercises/ https://pentesterlab.com/exercises/ for web based attack walkthroughs and practice. http://vulnhub.com/ http://vulnhub.com/ is a great resource for vulnerable systems to practice on.
- schoen 12y agoI'm impressed by djb's MCS 494 ("UNIX Security Holes") course. This was kind of famous at the time because students were taught to find real security holes in software as homework (and they sure did). http://cr.yp.to/2004-494.html http://cr.yp.to/2004-494.html http://it-beta.slashdot.org/story/04/12/15/2113202/djb-announces-44-security-holes-in-nix-software http://it-beta.slashdot.org/story/04/12/15/2113202/djb-annou... I have meant to work through this. It is very focused on C on Unix.
- adricnet 12y agoYou might enjoy A Bug Hunter's Diary by Tobias Klein. It's a detailed series of technical essays about vulnerabilities the author discovered in real software, how he went about finding and reporting them, and what happened. The appendices are helpful for those without a background in some of the techniques he uses. http://www.nostarch.com/bughunter http://www.nostarch.com/bughunter