video thumbnail 15:18
Why Pick sudo as Research Target?

2021-04-29

[public] 32.0K views, 3.30K likes, 18.0 dislikes audio only

channel thumbLiveOverflow

Recently a serious vulnerability in sudo was announced. But how can people even find these kind of bugs? Let's talk about why we would want to look for vulnerabilities in sudo, and how we could do that. We then try to setup afl, but fail... well... this will take a while

https://liveoverflow.com/support

Text Version: https://liveoverflow.com/why-pick-sudo-research-target-part-1/

GitHub: https://github.com/LiveOverflow/pwnedit/tree/main/episode01

Full Playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx

Episode 01:

00:00 - Intro

01:48 - Prepare the System

03:57 - How to Pick a Research Target?

05:57 - Choose the Strategy: Fuzzing

09:27 - Fuzzing argv[] With AFL

13:00 - Running Into the Next AFL Problem

14:51 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Intro
/youtube/video/uj1FTiczJSE?t=0
Prepare the System
/youtube/video/uj1FTiczJSE?t=108
How to Pick a Research Target?
/youtube/video/uj1FTiczJSE?t=237
Choose the Strategy: Fuzzing
/youtube/video/uj1FTiczJSE?t=357
Fuzzing argv[] With AFL
/youtube/video/uj1FTiczJSE?t=567
Running Into the Next AFL Problem
/youtube/video/uj1FTiczJSE?t=780
Outro
/youtube/video/uj1FTiczJSE?t=891
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
How SUDO on Linux was HACKED! // CVE-2021-3156 178,954 views
/youtube/video/TLa2VqcGGEQ