Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Best of securitytube for RE and security

txttxt

A collection of tutorials, videos and fun

I think it's an amazing site. There're many video tutorial sites these days. However the quality differs a lot. In the following I listed stuff I like so far. Feel invited to watch everything:

Programming

Python programming course from MIT - the advanced stuff may be of some interest, however it starts of with fairly trivial and introductorily mentioned stuff.

Automating Windows GUI programs. I never tried that. Could be worth a look for post-exploitation to gain some more interactivity.

Some ASM - and no... you don't need to write asm programs in order to understand all the nifty hacks. But it might come in handy to debug shellcode with relative jmps e. g..

Reversing

IDA vs. passwords - if you never used IDA you'll like this. If you used it before you won't.

Reversing Malware - this stuff is almost too basic, but in any case you can find interesting related videos currently:
1. monitoring API calls
2. constructing Linux Malware with some C in Debian.

There's definitely a need for more of these videos.

Inline function hooking - some stuff with rootkits. Hooking is modern again.

Finding security vulnerabilities through RE by Alex. It's from 2007 - anyhow. That was a good one.

Applied RE on MacOS - features some Ruby stuff. RE:trace, Dtrace and stuff. It's fun. But older, too. The real-time code-coverage stuff with IDA is worth it.

Exploitation

Stack-smashing and more. It's a five part series that may help you decide whether you want to dive into it. Or not.

Programming Windows-Exploits - by Dino. However he featured Win2k if I remember correctly. Well... that's not too kewl. He taught some students to exploit vulnerabilities. ;) Who wouldn't like that.

Return to libc heap-overflow attack. That's kind of interesting.

How to overcome ASLR on a Linux stack. Hmmh... worth a look.

w32 fuzzing and exploit development stuff. It's on my playlist.

Basic exploit dev-stuff.

I pretty much guess that's enough fun for this day. However the material seem to be promising. Back in the days people really had to search for information and just got some txts. It turns out information sharing matured, doesn't it? - For educational purposes only: believe it!
And if that stuff doesn't teach you all you seek to learn: here's my personal collection of conference videos. And if that isn't enough you need to search.

Have fun,
wishi

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.