OSED Certification Guide: Exploit Development

0% found this document useful (0 votes)
301 views26 pages
This document provides an overview of topics covered in the Offensive Security Exploit Development certification for Windows, including tutorials on WinDbg, stack buffer overflows, SEH overf…

Uploaded by

Luccas Souza

Offensive Security Exploit

Development - Windows
Joas Antonio
Details
• This ebook is just a content guide for OSED certification. It's just an
overview of the certification.
• My LinkedIn: [Link]
OSED - About
• WinDbg tutorial
• Stack buffer overflows
• Exploiting SEH overflows
• Intro to IDA Pro
• Overcoming space restrictions: Egghunters
• Shellcode from scratch
• Reverse-engineering bugs
• Stack overflows and DEP/ASLR bypass
• Format string specifier attacks
• Custom ROP chains and ROP payload decoders
Windbg
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Stack Buffer Overflow
• [Link]
• [Link]
• [Link]
need-to-know/
• [Link]
• [Link]
• [Link]
acf9b8659cba
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
8d2be7321af5
Stack Buffer Overflow
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
0_%20TCC_BufferOverflow_Mecan_Defesa.pdf
• [Link]
overflows_part2.pdf
• [Link]
[Link]
• [Link]
• [Link]
[Link]
Exploiting SEH overflows
• [Link]
overflows#:~:text=In%20order%20to%20exploit%20an,current%20SEH%20records%20exception%20handler
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
part-3-seh/
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Exploiting SEH overflows
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
corruption-exploits-part-i-stack-overflows
• [Link]
• [Link]
• [Link]
82f815bc809b
• [Link]
• [Link]
overwrites-with-sehop/
• [Link]
• [Link]
Intro to IDA Pro
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Intro%20to%20IDA%[Link]
• [Link]
malware-part-3-ida-pro-introduction
• [Link]
• [Link]
• [Link]
• [Link]
Overcoming space restrictions: Egghunters
• [Link]
• [Link]
• [Link]
egghunting/
• [Link]
modeexploit-development-exp-301-90-days-qaosed90/
• [Link]
• [Link]
3-egg-hunters
• [Link]
• [Link]
egghunter
• [Link]
bison-ftp-server/
• [Link]
b12383f7a449
• [Link]
Egghunters
• [Link]
[Link]
• [Link]
[Link]
• [Link]
• [Link]
[Link]/Techniques%[Link]%20%20.%20%20Failles/Exploit%20writing
%20tutorial%20part%208-Win32%20Egg%[Link]
• [Link]
• [Link]
%20presentations/DEF%20CON%20China%201.0%20-
%20Workshops/DEF%20CON%20China%201.0%20-%20Dino-Covostos-Hack-to-
[Link]
• [Link]
• [Link]
techniques/Exploit%20writing%20tutorial%20part%208-
Win32%20Egg%[Link]
Egghunters
• [Link]
305b947f792e
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
exploits-parte-3-estudo-de-caso-vulnserver-kstet-com-egghunter/
• [Link]
8-win32-egg-hunting/
Egghunters
• [Link]
[Link]
• [Link]
• [Link]
3/
• [Link]
winamp-5-12-buffer-overflow-in-python-with-egghunters/
• [Link]
server-egg-hunter-example-1-5e435aa84879
• [Link]
• [Link]
• [Link]
method-1/
Egghunters
• [Link]
• [Link]
egghunting-to-exploit-cve-2012-0124/
• [Link]
egghunter/
• [Link]
x86
• [Link]
hunting/
• [Link]
• [Link]
Windows-Exploit-Development-Practice
Shellcode from scratch
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Shellcode from scratch
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
development-part1/
• [Link]
files/publications/2016/05/[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
Reverse Engineering
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
aslr-at-the-same-time
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
bypass-2bbf9736fe46
• [Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
[Link]
• [Link]
• [Link]
with-pwntool
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
06-rockandropeando/[Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
Understanding-The-Attack-Surface-And-Attack-Resilience-Of-Project-
[Link]
• [Link]
[Link]
ROP and ROP Decoders
• [Link]
programming-(rop-ftw).pdf
• [Link]
f11/slides/BH_US_08_Shacham_Return_Oriented_Programming.pdf
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
08/Shacham/BH_US_08_Shacham_Return_Oriented_Programming.pdf
ROP and ROP Decoders
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
decoding/
• [Link]
• [Link]
• [Link]
• [Link]
OSED
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
OSED
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
OSED - Labs
• [Link]
• [Link]
• [Link]
• [Link]
labs/[Link]
• [Link]
• [Link]
• [Link]
OSED - Reviews
• [Link]
• [Link]
• [Link]
• [Link]
review-etizaz-mohsin-/
• [Link]
[Link]
• [Link]
exploitation-awe-osee-review/
• [Link]
• [Link]

You might also like