35C3 - The Layman's Guide to Zero-Day Engineering

Title:
35C3 - The Layman's Guide to Zero-Day Engineering
Description:

https://media.ccc.de/v/35c3-9979-the_layman_s_guide_to_zero-day_engineering

A demystification of the exploit development lifecycle

There's a certain allure to zero-day exploits. At the apex of the security industry, these elusive technologies are engineered by a persistent few to open doors of software systems that were never meant to exist. We go behind-the-scenes to provide an inside look at the zero-day development lifecycle, breaking common misconceptions regarding this increasingly difficult tradecraft.

In this talk, we will discuss the engineering process behind a zero-day that was used to exploit Apple Safari at PWN2OWN 2018. Rather than placing an intense focus on the technical challenges required to weaponize this particular chain of vulnerabilities, we reflect on this experience as a case-study of the analytical approach we employ to attack unfamiliar software targets. In addition to these methods, we will contrast how this process differs from CTF/Wargame challenges, highlighting the path one can take to graduate from casual enthusiast to security professional.

Markus Gaasedelen Amy (itszn)

https://fahrplan.events.ccc.de/congress/2018/Fahrplan/events/9979.html

more » « less
Video Language:
English
Duration:
57:04
http://www.youtube.com/watch?v=WbuGMs2OcbE
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=25xNKHoLCSs
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=is5WSIRH52U
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Completed subtitles (1)