35C3 - From Zero to Zero Day
- Title:
- 35C3 - From Zero to Zero Day
- Description:
-
more » « less
https://media.ccc.de/v/35c3-9657-from_zero_to_zero_day
In this talk I will share my story of how in a little over a year, a high school student with almost zero knowledge in security research found his first RCE in Edge.
After starting my BSc in CS and Math I picked up a new hobby: solving coding challenges. The next logical step was to try harder challenges, which lead me to participate in CTF competitions. During these CTFs I found that I’m fascinated by vulnerabilities: finding mistakes or things that developers failed to think through. This is how I started going down the rabbit hole.
Fast forward a year later, I found my first 0-day, a critical RCE in Edge. To understand it, we will review the recent trend of JIT Type Confusion vulnerabilities in ChakraCore. I will talk about the vulnerability I found, explain how I discovered it and show similar vulnerabilities recently found by other researchers. Finally, I will demo a working exploit of this vulnerability.
This session could be helpful both for people interested in getting into the security field, and for experienced security researchers who want to learn more about browser vulnerabilities and exploitation.
Jonathan Jacobi
https://fahrplan.events.ccc.de/congress/2018/Fahrplan/events/9657.html
- Video Language:
- English
- Duration:
- 48:29
![]() |
C3Subtitles edited English subtitles for 35C3 - From Zero to Zero Day | |
![]() |
C3Subtitles added new URL for 35C3 - From Zero to Zero Day | |
![]() |
C3Subtitles added a video: 35C3 - From Zero to Zero Day |