Premium Only Content

10: Bypassing Stack Canaries (leak + write) - Buffer Overflows - Intro to Binary Exploitation (Pwn)
10th video from the "Practical Buffer Overflow Exploitation" course covering the basics of Binary Exploitation. NX and stack canaries are enabled this time, so we'll use a printf() format string vulnerability leak the stack canary, allowing us to overwrite it with the expected value. We'll use checksec, ghidra, pwndbg and pwntools! Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #BinaryExploitation #BufferOverflow #BinExp #RE #Pwn #PwnTools
Find the binary files, source code and scripts to go with the series @ https://github.com/Crypto-Cat/CTF/tree/main/pwn/binary_exploitation_101
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Binary Exploitation / Reverse Engineering↣
Pwn.College: https://pwn.college
How2Heap: https://github.com/shellphish/how2heap
NightMare: https://guyinatuxedo.github.io
Ir0nstone: https://ir0nstone.gitbook.io/notes/types/stack
PinkDraconian: https://www.youtube.com/playlist?list=PLeSXUd883dhjmKkVXSRgI1nJEZUDzgLf_
More: https://github.com/Crypto-Cat/CTF#readme
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
HackTricks: https://book.hacktricks.xyz/exploiting/linux-exploiting-basic-esp
GTFOBins: https://gtfobins.github.io
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Basic File Checks: 0:25
Review Source Code: 2:06
Disassemble with Ghidra: 3:05
Outline Attack (Canary Leak + Write): 3:56
Fuzz Printf Format Vuln for Canary: 5:23
Locating Canaries with GDB-PwnDbg: 6:42
PwnTools Exploit Script: 10:37
Additional Pwn/CTF Resources: 12:57
End: 14:38
-
12:05
Vania Fernandes
4 days agoMy empty Dubai apartment tour
33.3K15 -
46:03
SouthernbelleReacts
3 days ago $2.07 earnedShutter Island Reaction | I Did NOT See That Ending Coming! | SouthernBelle Reacts
7.88K2 -
6:39
nospeedlimitgermany
1 day ago $0.54 earnedBMW M3 E46 | 343 PS | Top Speed Drive German Autobahn No Speed Limit POV
4.08K3 -
11:41
Sideserf Cake Studio
19 hours ago $2.03 earnedI Made A Disco Ball Cake!
15.9K5 -
4:58:51
Steven Crowder
13 hours agoLIVE: No Kings Day - Following The Money w/ Guest: Data Republican | Louder with Crowder
790K416 -
1:11:45
Man in America
11 hours ago🚨 America Descends Into CHAOS—Are You Prepared?
65.1K56 -
2:23:54
Badlands Media
1 day agoDevolution Power Hour Ep. 363: Lawfare, Psyops, and the Great Narrative Reversal
83.8K20 -
2:32:48
Tundra Tactical
6 hours ago $8.08 earnedSilencers, Senators, and Survival: Roasting Lies and a Security Breakdown of The MN Shooting
49.8K6 -
LIVE
Spartan
10 hours agoPro Halo Player | !politics Halo Infinite Ranked Arena into SWTOR and/or Gears Beta
296 watching -
40:25
The Connect: With Johnny Mitchell
1 day ago $8.78 earnedBlackwater CEO Erik Prince Gets HONEST About The Israeli Invasion Of Lebanon
42.9K46