
Set up the lab environment by configuring a Windows host with a static IP, adjusting firewall rules, and enabling VirtualBox network features to ping and communicate between virtual machines.
Analyze a sample buffer overflow via static analysis on Windows using brainpan x, strings, and netcat to inspect the login input and reveal how the buffer can yield access granted.
Understand practical buffer overflow testing with Kali Linux’s Spike tool, observing memory and registers via Immunity Debugger to uncover potential vulnerabilities on a TCP server.
Perform step two fuzzing to locate program vulnerabilities via spike step, by building a Python payload, sending it through a socket to a VM, and refining the approximate localization.
Identify the exact buffer overflow offset by generating a unique pattern with metasploit, sending it via a python script over tcp, and testing to overwrite the instruction pointer.
Explore practical buffer overflow concepts and learn how control over the instruction pointer is achieved, using payloads to potentially gain shell access on a target system.
Identifica la memory address de la instrucción jmp esp y demuestra cómo el control del instruction pointer con un payload puede comprometer un sistema Windows.
Explain buffer overflow concepts, how to determine an offset to overwrite the instruction pointer, and how shellcode built with MSF venom and Python creates a reverse shell via netcat.
¿Quieres aprender a explotar Buffer Overflows como un profesional? Este curso práctico y directo al punto te enseñará desde cero cómo funcionan los desbordamientos de búfer, cómo manipular la pila, encontrar direcciones de salto (jmp esp), utilizar instrucciones NOP como padding y ejecutar tu propio shellcode.
Aprenderás cómo identificar y explotar vulnerabilidades reales, analizar la memoria y los registros en sistemas Linux, utilizar herramientas como GDB, pattern_offset y técnicas comunes en entornos de CTF (Capture The Flag). Además, conocerás prácticas seguras y metodologías profesionales utilizadas en auditorías de seguridad y pruebas de penetración.
El curso está diseñado para ser completamente práctico, guiándote paso a paso en la creación de un exploit funcional. Se incluye la preparación del entorno, análisis del binario vulnerable, detección del offset de control de flujo, construcción del payload y ejecución controlada del código. A lo largo del curso, también se explican conceptos clave de bajo nivel como la estructura del stack, segmentación de memoria, y cómo operan los registros de la CPU.
Está dirigido a estudiantes de ciberseguridad, pentesters junior, desarrolladores interesados en seguridad de software y entusiastas del hacking ético. No necesitas experiencia previa con exploits ni conocimientos avanzados de programación, aunque una base en Linux y C será de ayuda.