Vulnerability Research: how to get started hacking anything

by Jim Rush | - 12:15pm

What if I told you that the starting points for finding bugs in basically anything are the same, regardless of the target or tech. Sometimes, if you read some documentation, understand some existing research, you can understand how to bubble up an attack surface and start poking at it. Once you know where the attack surface is, you now know where to start! And starting’s the hard part!

While it may be tempting to put your brain in a jar and shake the latest magical vulnerability tree, what happens if we build and execute a robust vulnerability discovery methodology with our existing grey matter?

This talk will look at what it takes to develop your own research methodology, and we will be looking at some cursed windows internals as our case study.

Let’s do some archeology and deep dive into Windows internals, expose attack surfaces, blue screen a few things and maybe, just maybe, come out with some bugs on the other side.

About Jim Rush

Jim is a former developer who specialises in deep dives into web application attacks as well as research into the Microsoft ecosystem. This has resulted in CVEs, disclosures to the MSRC (Microsoft Security Reporting Centre) and patched bugs in Visual Studio, MS Word and MS Outlook. He is an active and successful bug bounty hunter, who combines creative techniques from bug bounty, security research and pentesting to find fun and interesting novel attacks. Jim has presented original research and vulnerabilities at several international conferences including Defcon, Off-By-One (Singapore), CHCon and OWASP.

Other talks