ISAC Cambodia (InfoSec)
Video

EXPLOIT RESEARCH MEGAPRIMER PART 5 FREESSHD BUFFER OVERFLOW

Description:

Welcome to Part 5 of the Exploit Research Megaprimer. Please begin this series by watching Part 1, if you have not already done so!

In this video, we will look at how to exploit a buffer overflow which was disclosed on Exploit-Db – FreeSSHD 1.0.9 Buffer Overflow. You can download the FreeSSHD Program and follow this video.

We will first start by understanding the vulnerability from it’s description on Exploit-Db and then reproduce the same in our lab setup. After this, we will use the Immunity Debugger to examine the exploit conditions, find the offsets for RET and ESP overwrite, find the bad characters which are 0x00, create shellcode for the payload encoding for these bad characters, create the exploit program and finally exploit the program! One of the interesting things you will find in this program is that the RET address and ESP are not adjacent to each other like in the previous examples.

Show More
Apsara Media Services (AMS)

Phannarith

Mr. OU Phannarith is one of the well-known cybersecurity experts in Cambodia and the region. He is the founder of the first leading information security website (www.secudemy.com) in Cambodia. He has been invited to present in global conferences, forums, and seminars and he was awarded in Information Security Leadership Achievements (ISLA) in 2016 by (ISC)2 and in December 2012 as one of the top 10 Chief Information Security Officers (CISO) in ASEAN by the International Data Group (IDG). Mr. OU has been the Professor specializing in Cybersecurity.

Related Articles

Back to top button