A webinar covering how to determine the exploitability of a software crash. In the previous episode we showed how to find crashes using AFL. This episode qualifies what type of crash has occurred and how it can be exploited.
Tools
AFL: https://lcamtuf.coredump.cx/afl/
Valgrind: https://www.valgrind.org
Crashwalk: https://github.com/bnagy/crashwalk
Peda GDB: https://github.com/longld/peda
Exploitable: https://github.com/jfoote/exploitable
AFL-utils (didn't get it to work): https://github.com/rc0r/afl-utils
Address sanitiser: https://github.com/google/sanitizers/...
Afl-plot: http://www.tin.org/bin/man.cgi?sectio...
Pwntools (checksec): https://github.com/Gallopsled/pwntools
Targets:
http://manpages.ubuntu.com/manpages/b...
https://www.xpdfreader.com/pdfinfo-ma...
Watch video F-Secure Labs Investigate The Crash online without registration, duration hours minute second in high quality. This video was added by user F-Secure Labs 01 January 1970, don't forget to share it with your friends and acquaintances, it has been viewed on our site 823 once and liked it 28 people.