Overview
Explore the process of discovering and reporting critical security vulnerabilities in an RPC service widely used by large companies in this 28-minute conference talk from NorthSec. Learn about preparing applications for analysis, reverse engineering binary protocols, and understanding RPC service authentication and message processing. Discover techniques for bypassing user authentication, finding and exploiting various vulnerabilities, and creating Metasploit modules. Gain insights into the full vulnerability research lifecycle, from initial discovery to coordinated disclosure with vendors, in this comprehensive end-to-end exploration of security research practices.
Syllabus
NSEC2023 - the moon and back: How we found and exploited a series of critical vulns in an RPC srv
Taught by
NorthSec