By Bob Gourley | Article Rating: |
|
September 15, 2012 08:24 AM EDT | Reads: |
311 |

Friends and associates at Kyrus (Kyrus-Tech.com) recently announced they will be hosting Practical ARM Exploitation Course. This is the extremely popular course maintained by Stephen C. Lawler and Stephen A. Ridley.
Exploitation is harder and a bit more nuanced today than it was in the past with the advent of protection mechanisms like XN, ASLR, stack cookies, etc. As such we aim to teach exploitation on ARM under the real-world circumstances in which the exploit developer will encounter (and have to circumvent) these protection mechanisms. The course materials focus on advanced exploitation topics (circumventing protection mechanisms) using Linux as the platform as a basis to learn the ARM architecture but with the obvious applications being platforms running on mobile phones, tablets, embedded devices, etc.
Ideally, students with some previous exploitation experience will go from knowing nothing about ARM on the first day to exploiting custom heap implementation (bypassing ASLR, NX) using their hand-built ROP connect-back-shell payload at the end of the course.
Where: Sterling, VA, USA
When: October 9th – October 12th, 2012
Contact: michael.tanji @kyrus-tech.com
Syllabus:
• 650+ slides across 12 decks
• 17 lab exercises (ranging from code auditing and simple stack overflows to advanced heap exploitation and application specific exploitation)
• 3 CTF style exploitation challenges
• 80+ page printed/bound/laminated lab manual with comprehensive notes including: architecture quick reference, ARM GDB and IDA ‘gotchas’, et al
Prerequisites: Students taking the “Practical ARM Exploitation” course should have an intermediate software exploitation background on another architecture (such as x86). They should also have hands-on familiarity with the following concepts, tools and languages:
• Exploitation of stack and heap overflows
• Basic experience with IDA
• Basic experience with a debugger
• Cursory knowledge of Python or some equivalent language (Java, Ruby, etc.)
• C++ and C coding experience
Required Materials:
• A laptop (running any OS) capable of connecting to wired and wireless networks
• An installed valid VMWare
• An installed copy of IDA Standard or better
• An SSH/Telnet client to access the Gustix hardware images
Course Instructors
Stephen A. Ridley and Stephen Lawler were research partners at a major U.S Defense contractor that supported the U.S. defense and intelligence communities in areas of information security research and development. Since then they have worked for different companies but stay in contact to collaborate with each other “after hours” on interesting areas of research.
Together they maintain the blog: http://www.dontstuffbeansupyournose.com
Stephen A. Ridley
Stephen A. Ridley is a security researcher with more than 10 years of experience in software development, software security, and reverse engineering. Before becoming an independent researcher, Mr. Ridley served as the Chief Information Security Officer of a financial services firm. Prior to that: Senior Researcher at Matasano. He also was Senior Security Architect at McAfee, and a founding member of the Security and Mission Assurance (SMA) group at a major U.S defense contractor where he did vulnerability research and reverse engineering in support of the U.S. intelligence community. He has spoken about (and given trainings on) reverse engineering and software security at BlackHat, ReCon,EuSecWest, CanSecWest, Syscan and others. Mr. Ridley currently lives in Manhattan and frequently guest lectures at New York area universities such as NYU and Rensselaer Polytechnic Institute.
Stephen Lawler
Stephen Lawler is the Founder and President of a small computer software and security consulting firm. Mr. Lawler has been actively working in information security for over 7 years, primarily in reverse engineering, malware analysis, and exploit development. While working at Mandiant he was a principal malware analyst for high-profile computer intrusions affecting several Fortune 100 companies.
Prior to this, as a founding member of the Security and Mission Assurance (SMA) division of a major U.S. Defense contractor where he discovered numerous 0-day vulnerabilities in “Commercial-Off-The-Shelf” (or COTS) software and pioneered several exploitation techniques that have only been recently discovered and published publicly. Prior to his work at a the major defense contractor, Stephen Lawler was the lead developer for the AWESIM sonar simulator as part of the US Navy SMMTT program. He has spoken at (and given trainings) at BlackHat and other security conferences and is the technical editor of “Practical Malware Analysis” published by No Starch Press.
Kyrus is the world famous contributor of security expertise and innovation. Find more on Kyrus at: http://www.kyrus-tech.com/

This post by BobGourley was first published at CTOvision.com.
Read the original blog entry...
Published September 15, 2012 Reads 311
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Bob Gourley
Bob Gourley, former CTO of the Defense Intelligence Agency (DIA), is Founder and CTO of Crucial Point LLC, a technology research and advisory firm providing fact based technology reviews in support of venture capital, private equity and emerging technology firms. He has extensive industry experience in intelligence and security and was awarded an intelligence community meritorious achievement award by AFCEA in 2008, and has also been recognized as an Infoworld Top 25 CTO and as one of the most fascinating communicators in Government IT by GovFresh.
- Cloud People: A Who's Who of Cloud Computing
- Twelve New Programming Languages: Is Cloud Responsible?
- Agile Adoption – Crossing the Chasm
- What Makes Agile Agile?
- Monotype Imaging Appoints Timothy B. Yeaton to its Board of Directors
- Examining the True Cost of Big Data
- Understanding Business Intelligence and Your Bottom Line
- Thanks to Big Data, Analytics Will Be a $51B Business by 2016: IDC
- Cloud-Based Super Computing at Cloud Expo Silicon Valley
- Network Add-Ons for Web Traffic and Cloud Technology
- Cloud Expo Silicon Valley | Cloud Computing Adoption: Where Are We Really?
- Hybrid Elastic Computing for Digital Commerce at Cloud Expo Silicon Valley
- Cloud People: A Who's Who of Cloud Computing
- Twelve New Programming Languages: Is Cloud Responsible?
- Agile Adoption – Crossing the Chasm
- TOGAF Foundation Level Certification – Another Practice Test
- TOGAF Foundation Level Certification – Practice Test
- What Makes Agile Agile?
- Big Data: Information Spawns Innovation
- Why Infrastructure Technology Is Challenging
- Monotype Imaging Appoints Timothy B. Yeaton to its Board of Directors
- The Cloud Is the Future and Big Data Enables New Products
- Examining the True Cost of Big Data
- 10th International Cloud Expo | Cloud Expo New York – Photo Album
- A Cup of AJAX? Nay, Just Regular Java Please
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- JavaServer Faces (JSF) vs Struts
- The i-Technology Right Stuff
- Rich Internet Applications with Adobe Flex 2 and Java
- Java vs C++ "Shootout" Revisited
- Bean-Managed Persistence Using a Proxy List
- Reporting Made Easy with JasperReports and Hibernate
- Creating a Pet Store Application with JavaServer Faces, Spring, and Hibernate
- Why Do 'Cool Kids' Choose Ruby or PHP to Build Websites Instead of Java?
- What's New in Eclipse?
- i-Technology Predictions for 2007: Where's It All Headed?
- ');
for(i = 0; i < google_ads.length; ++i)
{
document.write('
- ');
document.write('' + google_ads[i].line1 + '
'); document.write('' + google_ads[i].visible_url + '
'); document.write(google_ads[i].line2 + ' ' + google_ads[i].line3); document.write(' ');
}
document.write('