Hands-On Advanced Ethical Hacking: Preventing and Writing
Exploits for Buffer Overflows with Ralph Durkee
Join the Rochester OWASP chapter for a fun evening of hands-on
advanced ethical hacking on July 23rd at 5:30pm at Nixon Peabody.
The buffer overflow remains one of the most prolific and exploited software vulnerabilities. Join us for a brief and intense hands-on course where you will discover a buffer overflow vulnerability and then develop a code execution exploit for a stack based buffer overflow! We'll also discuss and test preventive and mitigating techniques. Pizza and soft drinks will be provided.
A virtual Linux system will be provided with the required tools running on your own laptop. Students should be comfortable with the Linux command line, and be familiar with basic programming. The Gnu development tools such as g++. gcc, gdb, and make may be used. Vim, Emacs and Eclipse will all be installed for your editing and exploit writing pleasure. You must bring your own laptop The laptop can be MS Windows, Mac or Linux, with a recent version of VirtualBox installed and working.
Laptop Requirements: • At least 8Gb RAM, 16 Gb recommended
• Recent Virtual Box installed.
• Administrator or root privileges for the laptop.
RSVP: Space is very limited, respond soon via email to
jim.k...@owasp.org to reserve your seat.
Directions:Nixon Peabody (13th Floor), 1300 Clinton Square, Rochester, NY 14604
Parking Entrance:
https://goo.gl/maps/gdY46GLiR3C2
• Please bring your parking ticket with you for validation.
• Take the garage elevator to the lobby.
• Please sign in with the security guard.
• Then take lobby elevators to the 13th floor.
• Return your parking ticket to the security desk before leaving.
Our Speaker:
Ralph
Durkee is the principal security consultant and owner of Durkee
Consulting, Inc since 1996. Ralph started the OWASP Rochester,
NY
chapter in 2004 and served as founding officer and president for
the
Rochester ISSA chapter and the annual Rochester Security Summit.
He
routinely performs network and application penetration tests,
software security assessments and secure software development
consultations for clients. His expertise in advanced penetration
testing, incident handling, secure software development and
secure
Internet and web applications is based on over 30 years of
hands-on
technical experience. He has developed and taught a wide variety
of
professional security seminars including custom web application
security training, and SANS course since 2004. Ralph also
regularly
consults on the development and implementation of a variety of
security standards such as web application security, database
encryption, Windows, and Linux security. Ralph has been working
professionally with Unix and Linux non-stop since the 80’s,
including 4 years at Bell Labs. Ralph holds over a dozen
security
certifications including advance penetration testing.