Channel: LiveOverflow
Category: Education
Tags: fuzzingafl++liveoverflowfuzzeraflplusplusaflargvhow to hackexploit tutoriallive overflowsudo baron samedithacking tutoriallinuxsecurity researchpwneditcve-2021-3156sudobinary exploitation
Description: Recently a serious vulnerability in sudo was announced. But how can people even find these kind of bugs? Let's talk about why we would want to look for vulnerabilities in sudo, and how we could do that. We then try to setup afl, but fail... well... this will take a while liveoverflow.com/support Text Version: liveoverflow.com/why-pick-sudo-research-target-part-1 GitHub: github.com/LiveOverflow/pwnedit/tree/main/episode01 Full Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx Episode 01: 00:00 - Intro 01:48 - Prepare the System 03:57 - How to Pick a Research Target? 05:57 - Choose the Strategy: Fuzzing 09:27 - Fuzzing argv[] With AFL 13:00 - Running Into the Next AFL Problem 14:51 - Outro -=[ ❤️ Support ]=- → per Video: patreon.com/join/liveoverflow → per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ 🐕 Social ]=- → Twitter: twitter.com/LiveOverflow → Website: liveoverflow.com → Subreddit: reddit.com/r/LiveOverflow → Facebook: facebook.com/LiveOverflow