Offensive Security Exploit
Development - Windows
Joas Antonio
Details
• This ebook is just a content guide for OSED certification. It's just an
overview of the certification.
• My LinkedIn: [Link]
OSED - About
• WinDbg tutorial
• Stack buffer overflows
• Exploiting SEH overflows
• Intro to IDA Pro
• Overcoming space restrictions: Egghunters
• Shellcode from scratch
• Reverse-engineering bugs
• Stack overflows and DEP/ASLR bypass
• Format string specifier attacks
• Custom ROP chains and ROP payload decoders
Windbg
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Stack Buffer Overflow
• [Link]
• [Link]
• [Link]
need-to-know/
• [Link]
• [Link]
• [Link]
acf9b8659cba
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
8d2be7321af5
Stack Buffer Overflow
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
0_%20TCC_BufferOverflow_Mecan_Defesa.pdf
• [Link]
overflows_part2.pdf
• [Link]
[Link]
• [Link]
• [Link]
[Link]
Exploiting SEH overflows
• [Link]
overflows#:~:text=In%20order%20to%20exploit%20an,current%20SEH%20records%20exception%20handler
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
part-3-seh/
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Exploiting SEH overflows
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
corruption-exploits-part-i-stack-overflows
• [Link]
• [Link]
• [Link]
82f815bc809b
• [Link]
• [Link]
overwrites-with-sehop/
• [Link]
• [Link]
Intro to IDA Pro
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Intro%20to%20IDA%[Link]
• [Link]
malware-part-3-ida-pro-introduction
• [Link]
• [Link]
• [Link]
• [Link]
Overcoming space restrictions: Egghunters
• [Link]
• [Link]
• [Link]
egghunting/
• [Link]
modeexploit-development-exp-301-90-days-qaosed90/
• [Link]
• [Link]
3-egg-hunters
• [Link]
• [Link]
egghunter
• [Link]
bison-ftp-server/
• [Link]
b12383f7a449
• [Link]
Egghunters
• [Link]
[Link]
• [Link]
[Link]
• [Link]
• [Link]
[Link]/Techniques%[Link]%20%20.%20%20Failles/Exploit%20writing
%20tutorial%20part%208-Win32%20Egg%[Link]
• [Link]
• [Link]
%20presentations/DEF%20CON%20China%201.0%20-
%20Workshops/DEF%20CON%20China%201.0%20-%20Dino-Covostos-Hack-to-
[Link]
• [Link]
• [Link]
techniques/Exploit%20writing%20tutorial%20part%208-
Win32%20Egg%[Link]
Egghunters
• [Link]
305b947f792e
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
exploits-parte-3-estudo-de-caso-vulnserver-kstet-com-egghunter/
• [Link]
8-win32-egg-hunting/
Egghunters
• [Link]
[Link]
• [Link]
• [Link]
3/
• [Link]
winamp-5-12-buffer-overflow-in-python-with-egghunters/
• [Link]
server-egg-hunter-example-1-5e435aa84879
• [Link]
• [Link]
• [Link]
method-1/
Egghunters
• [Link]
• [Link]
egghunting-to-exploit-cve-2012-0124/
• [Link]
egghunter/
• [Link]
x86
• [Link]
hunting/
• [Link]
• [Link]
Windows-Exploit-Development-Practice
Shellcode from scratch
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Shellcode from scratch
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
development-part1/
• [Link]
files/publications/2016/05/[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
Reverse Engineering
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
aslr-at-the-same-time
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
bypass-2bbf9736fe46
• [Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
[Link]
• [Link]
• [Link]
with-pwntool
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
06-rockandropeando/[Link]
• [Link]
• [Link]
• [Link]
Stack overflows and DEP/ASLR bypass
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
Understanding-The-Attack-Surface-And-Attack-Resilience-Of-Project-
[Link]
• [Link]
[Link]
ROP and ROP Decoders
• [Link]
programming-(rop-ftw).pdf
• [Link]
f11/slides/BH_US_08_Shacham_Return_Oriented_Programming.pdf
• [Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
08/Shacham/BH_US_08_Shacham_Return_Oriented_Programming.pdf
ROP and ROP Decoders
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
[Link]
• [Link]
• [Link]
• [Link]
• [Link]
decoding/
• [Link]
• [Link]
• [Link]
• [Link]
OSED
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
OSED
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
OSED - Labs
• [Link]
• [Link]
• [Link]
• [Link]
labs/[Link]
• [Link]
• [Link]
• [Link]
OSED - Reviews
• [Link]
• [Link]
• [Link]
• [Link]
review-etizaz-mohsin-/
• [Link]
[Link]
• [Link]
exploitation-awe-osee-review/
• [Link]
• [Link]