Détails de la formation
The Corelan “ADVANCED” exploitL’exploit est un programme ou une technique démontrant l’existence d’une vulnérabilité au sein d’un logiciel informatique. Celui-ci peut se limiter à une démonstration de faisabilité d'exploitation de cette faille (preuve par l’exemple) ou être utilisé pour mener une action malveillante. development class is a fast-paced, mind-bending, hands-on course where you will learn advanced exploit development techniques from an experienced exploit developer. During this (typically 3 ‘long’ day) course, students will get the opportunity to learn how to write exploits that bypass modern memory protections for the Win32 platform, using Windows 7 and Windows 10 as the example platform, but using techniques that can be applied to other operating systems an applications. We will discuss differences between Windows 7 and Windows 10 and explore previously undocumented techniques to achieve important exploitation primitives in Windows 10. The trainer will share his “notes from the field” and various tips & tricks to become more effective at writing exploits.
This is most certainly not an entry level course. In fact, this is a one of the finest and most advanced courses you will find on Win32 exploit development.
This hardcore, practical, hands-on course will provide students with solid understanding of x86 Windows heap exploitation. We make sure the course material is kept updated with current evolutions, includes previously undocumented tricks and techniques, and details about research we performed ourselves, so you can apply the research techniques on other applications and operating system versions. Combined with the way the course is built up, this will turn this class into a truly unique learning experience.
During all of our courses, we don’t just focus on techniques and mechanics, we don’t focus on just using one vulnerability, but we mainly want to make sure you understand why a given technique is used, why something works and why something doesn’t work. In the advanced course, we provide you with generic insights on how to do your own research related with heap exploitation in general (not just Windows 7 or Windows 10), fully preparing you for the futurel.
The new 2020 edition of the course is based on Windows 7 and Windows 10. (As the Windows 10 Heap Manager contains additional mitigations, we use Windows 7 first to teach the basics, and then use Windows 10 later on). Furthermore, starting with the 2020 edition, the course contains an intro to x64 exploitation (stack & heap)
We believe those are just a few arguments that makes this training stand out between other exploit development training offerings. Feel free to check our testimonials page if you want to see real, voluntary, unmodified and uncensored reactions by some of our students.
Finally, we offer you post-training support as well. If you have taken the course and you still have questions afterwards, we will help.
WARNING: We do not provide solutions for any of the exercises in this course, but we will help you to find the solutions yourself, either during the course or after the course (via the student-only support system)
Lien vers la description de la formation : https://hackinparis.com/trainings/#training-2020-corelan-advanced-3-days
Niveau souhaité : Expert
Fonction souhaitée : Pentesters, auditors, network/system administrators, reverse engineers, malware analysts, developers, members of a security department, security enthusiasts, or anyone that has a solid and practical basic knowledge of exploit development for Windows already.
Conditions
Prix de la formation : 2500 HT
Informations complémentaires
Détail des supports remis au participant : https://hackinparis.com/trainings/#training-2020-corelan-advanced-3-days
En intra : oui En inter : oui
Conditions repas et hébergement : repas inclus
Organisé par
SYSDREAM
Audit, Conseil
Contact inscription
Nom : KOLTSIDIS
Prénom : Evangélia
Téléphone : 0178765800
Email : e.koltsidis@sysdream.com
Autres formations
- Les métiers du RSSI
- Hacking entreprises – 2020 Release
- DPO (Délégué à la Protection des Données) – Réf : DPO
- Tests d’intrusion – Réf : PENTEST1
- Offensive Industrial Control System Security
- ISO 27001 Lead Implementer – Réf : ISO27LI
- Parcours métier d’Analyste SOC (Security Operations Center)
- EBIOS – Gestion des risques
- ISO 27005 – Risk Manager
- Hands- on Malware Analysis Reverse Engineering