
Set up the lab environment for hands-on linux security basics using free labs. The lecture gives an overview of the labs, notes optional textbooks, and a brief linux primer.
Set up the lab environment with free open source tools and personal computers, enabling hands-on cybersecurity labs via virtual machines for software and system security labs.
Explore how linux assigns user ids and groups, enforces root privileges, and manages access with /etc/passwd, /etc/group, and shadow files, using commands like id, su, and adduser.
Explore how access control and permissions regulate resource access, focusing on access control lists, owner/group/others permissions, and commands like chmod, umask, chown, and getfacl/setfacl.
Learn to run commands with superuser privileges using sudo, including using -u to run as another user, and how the /etc/sudoer configuration and the sudo group enable access.
Explore lab setup and an overview of Linux security basics, including users, groups, password and shadow files, and file permissions, plus practical use of sudo and related commands.
Explore how setuid programs operate in operating systems and why privileged programs attract attackers. Analyze the setuid mechanism, its vulnerabilities, breaches, and lessons for examining other privileged programs.
Explore why operating systems use privileged programs to safely modify protected files like /etc/shadow, and how the setuid mechanism lets users perform privileged actions with secure, direct execution.
Explain the setuid mechanism, including real and effective user ids, and how root-owned programs with the setuid bit grant privileges, and the associated security risks.
Explore how setuid programs can be attacked, examine attack surfaces and vulnerabilities, and how attackers exploit them to gain privileges.
Learn how explicit user inputs in a setuid program can merge data and code via the system function, risking a root shell; use execve with separate command and data channels.
Explore the bash shellshock vulnerability in CGI by injecting data into environment variables with curl's user agent to trigger remote code execution, illustrating execution as www_data and limited privileges.
Explore how to establish a reverse shell during a shellshock attack by redirecting bash input and output to a tcp connection using netcat, enabling remote control.
Demonstrates a reverse shell attack by exploiting the Shellshock vulnerability to inject code into a server and gain a remote shell on the victim machine.
explore buffer overflow attacks, their memory and stack layout, and practical countermeasures through hands-on labs that demonstrate exploiting vulnerabilities and gaining root privileges in a linux environment.
Explore stack layout, frame pointers, and how function calls place arguments, locals, and return addresses. Understand how ebp coordinates access to variables and preserves return flow.
Explains buffer overflow vulnerabilities, how strcpy can overflow a 40-byte buffer, corrupt the stack, and overwrite the return address to execute attacker code.
Explore how to construct a payload to overflow a return address in a vulnerable function, using a badfile, nop sleds, and shellcode, with gdb debugging.
Practice buffer overflow exploitation by constructing a zero-free payload, calculating the 64-byte offset, and using return-address spraying across a range when sizes are unknown.
Learn to craft linux shellcode in assembly to spawn a shell via execve, including setting ebx, ecx, edx with stack-based strings, handling zeros, and building argument arrays.
Examine three countermeasure categories for buffer overflow defense: developer-led resilience, operating system protections, and compiler-based defenses. Learn how address randomization and stack memory protection reduce risk and harden programs.
Validate data length against the buffer before copying, use safe functions like strncpy and snprintf, and consider safer languages such as Java to prevent Heartbleed attacks.
Explore how operating systems use address space layout randomization to hinder buffer overflow attacks by randomizing stack and heap locations, and examine effectiveness across architectures.
Demonstrates how the compiler inserts the StackGuard canary between the buffer and the return address to detect buffer overflows and validate it against a random secret on the heap.
Explore heap-based buffer overflow vulnerabilities using malloc-allocated memory. Learn how overflowing a heap buffer can alter the linked list of heap blocks to hijack a return address or trigger return-to-libc.
Explain buffer overflow attacks by examining memory layout and stack frames, showing how overwriting the return address enables code execution or return-to-libc, with lab exercises and countermeasures including StackGuard.
Lab description
Learn how return-to-libc exploits leverage stack frame changes to redirect execution from a vulnerable function to system, passing arguments via ebp-based offsets, and preparing a crafted payload.
Chain no-argument function calls by manipulating the stack return addresses, track ebp values to call bar ten times, and verify the rop chain using gdb with a setuid program.
Explore how to chain function calls from dynamic libraries by manipulating stack frames and ebp with empty functions and leaveret, demonstrated using a libc printf example.
Define race condition vulnerabilities, examine exploits, and outline countermeasures to defend against these attacks. Focus on application-layer risks and CPU vulnerabilities such as Dirty COW, meltdown, and spectre.
Examine a race condition in a setuid program that creates a root-owned /tmp/x file, and learn how atomic symbolic link renaming with rename closes the exploit window.
Apply the principle of least privilege by dropping privileges with setuid to the real user, avoiding writes to protected files. Relying on checks alone can incur race conditions.
Explore the Dirty COW vulnerability in the OS kernel, including memory mapping, virtual memory, and copy on write, then examine the race condition attack and a hands-on Ubuntu 12.04 lab.
Explore how memory mapping and copy-on-write drive the dirty cow vulnerability, comparing map_shared and map_private, and how madvice discards private copies to restore the master file.
Explore the dirty cow vulnerability, exploiting a race condition to write to a read-only file via copy-on-write memory. Learn the three steps—copy, change page table, write—and the two-thread timing attack.
Explore the dirty cow race condition and how a read-only file, like /etc/passwd, can be exploited via memory mapping and copy-on-write to elevate a normal user to root.
Explore the meltdown and spectre attacks, understand how cpu caches serve as side channels, and analyze hardware race conditions that enable secret data access.
Explore side channels and how cpu caches enable the meltdown and spectral attack, illustrating cache timing and memory access.
Contrast meltdown and spectre attacks by comparing hardware protection of the kernel space with software sandbox protections and the restricted access control API governing memory.
Explain how out-of-order execution in meltdown attacks lets code access kernel space, using cpu caches to prove executed instructions despite exceptions and denial of access.
Reveals how the Spectre attack exploits out-of-order execution and a cache side channel to reveal a secret, using training, flush-and-reload, and timing to exploit race conditions.
Explore how side channels use cpu caches, learn flush and reload, and reveal cache residues from out-of-order execution to understand Spectre and Meltdown attacks and cpu race conditions.
Explore format string vulnerabilities in printf and related functions, and learn how attackers exploit them to inject code into setuid or server programs with root privileges.
Explore how format strings govern printf and related functions through va_list, va_start, and va_arg, enabling optional arguments and specifiers like %d, %s, and %x to print formatted output.
Explore what happens when printf encounters more format specifiers than arguments, and how mismatches can cause memory reads, writes, and format string attacks from user input.
Learn how a format string vulnerability lets you read secret data from memory by manipulating printf arguments and ap pointer, using %x and %s to reveal stack and heap secrets.
Learn how format string vulnerabilities allow writing to memory using the %n specifier, and see how attackers manipulate addresses, offsets, and width modifiers to modify target memory values.
Demonstrates fast memory writes by using a two-address format string with %n and length modifiers. Shows splitting four-byte values into two-byte chunks using %hn and %hhn in little-endian memory.
Demonstrates exploiting a format string vulnerability to inject code by identifying the target address and value, then using printf memory writes to overwrite the return address and execute shellcode.
Avoid letting user input become part of the format string; derive all format strings from trusted sources or constants. Illustrate compiler warnings and how fixed strings prevent format string attacks.
Explain how variadic functions and printf format strings can mismatch arguments, enabling format string attacks that overwrite return addresses and inject code in privileged programs such as setuid or servers.
This course focuses on a variety of attacks on computer systems. Some of them are classical attacks, and some are quite new, such as the recently discovered Dirty COW, Meltdown, and Spectre attacks. The course emphasizes hands-on learning. For each attack covered, students not only learn how the attack work in theory, they also learn how to actually conduct the attack, in a contained virtual machine environment. The hands-on exercises developed by the instructor are called SEED labs, and they are being used by over 1000 institutes worldwide. The course is based on the textbook written by the instructor. The book, titled "Computer & Internet Security: A Hands-on Approach, 2nd Edition", has been adopted by over 120 universities and colleges worldwide.