video thumbnail 7:07
RTMP Heap Overflow CVE-2016-10191 - Exploiting FFmpeg ft. Paul Cher

2017-11-10

[public] 6.91K views, 274 likes, 5.00 dislikes audio only

Paul shows us another exploit for FFmpeg. The vulnerability is located in the RTMP protocol. While working with the binary format of the protocol requires a lot of work, the exploit itself is very easy.

Vulnerable Version: https://github.com/FFmpeg/FFmpeg/tree/d903b4e3ad4a81b3dd79f12c2f3b9cb16e511173

Paul on Twitter: https://twitter.com/__paulch

LiveOverflow Podcast: http://liveoverflow.libsyn.com/

Original Email: http://www.openwall.com/lists/oss-security/2017/02/02/1

-=[ šŸ”“ Stuff I use ]=-

ā†’ Microphone:* https://geni.us/ntg3b

ā†’ Graphics tablet:* https://geni.us/wacom-intuos

ā†’ Camera#1 for streaming:* https://geni.us/sony-camera

ā†’ Lens for streaming:* https://geni.us/sony-lense

ā†’ Connect Camera#1 to PC:* https://geni.us/cam-link

ā†’ Keyboard:* https://geni.us/mech-keyboard

ā†’ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ ā¤ļø Support ]=-

ā†’ per Video: https://www.patreon.com/join/liveoverflow

ā†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

ā†’ Twitter: https://twitter.com/LiveOverflow/

ā†’ Website: https://liveoverflow.com/

ā†’ Subreddit: https://www.reddit.com/r/LiveOverflow/

ā†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ šŸ“„ P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#SecurityResearch #BinaryExploitation #HeapOverflow #CVE


LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
Iā€™m moving, no videos sorry 17,542 views
/youtube/video/9CS3q0uG1LI
What do Nintendo Switch and iOS 9.3 have in common? CVE-2016-4657 walk-through 310,303 views
/youtube/video/xkdPjbaLngE