Recon 2024

.NET Exploitation WorkShop
06-29, 13:00–15:00 (US/Eastern), Soprano B

.NET Reverse engineering for vulnerability researchers, how to map the attack surface, interesting areas of focus, tools of the trade for .NET Exploitation.

Prerequisites:

A windows 10 VM Visual studio 2022 installed .NET Framework 4.0 to 4.8
A copy of https://github.com/pwntester/ysoserial.net.


During the workshop, participants will delve into the intricacies of .NET reverse engineering and gain a comprehensive understanding of the techniques involved. Starting with an overview of the .NET framework, the workshop will gradually progress towards advanced topics such as deserializations, bypassing mitigations, and a lot more, empowering attendees with the necessary skills to identify and exploit vulnerabilities.

Students will be provided with lab files before the workshop which contain tools and exercises for the workshop.

See also: flight invoice (60.2 KB)

@SinSinology is a full time vulnerability researcher, pwn2own 202{2,3,4} contestant, Microsoft MVR 2022/2023