Please do not close or refresh this window...
Monday, 5 December 2022 9:00 AM - Wednesday, 7 December 2022 5:00 PM AEDT
Unit 2, 9 Beaconsfield Street, Fyshwick, ACT, 2906, Australia
Access code applied successfully. Remove
Invalid access code. Try again
Sales end on 03/12/2022
InfoSect, Unit 2, 9 Beaconsfield Street, Fyshwick, ACT, 2906, Australia.
You will be registering your interest in a online, live offering of Browser (JS Engine) Exploitation. Dates TBA, we will notify you when the course has dates available.
This 3-day course will give students a zero to hero in-depth examination of techniques to exploit JavaScript engine memory corruption bugs in the Firefox and Chrome web browsers. Spidermonkey and V8 will be the targets for exploitation. Spidermonkey is the JS engine in Firefox and V8 is the JS engine in Chrome. The OS environment for the course is Linux. However, the exploitation concepts and techniques presented will work on other platforms.
Course Objectives
To be able to gain code execution in Firefox (Spidermonkey) and Chrome (V8) given a JS engine memory corruption bug. Sandbox escapes will not be covered in this course.
Duration and Schedule
3 Days, 9am - 5pm
Training Outcomes
Who Should Attend?
What Will be Provided?
Participant Skillset
Students taking Browser (JS Engine) Exploitation should have an intermediate exploitation development background, an exposure in C++ development, and basic JavaScript development experience. Students who have completed the InfoSect courses Code Review and Linux Heap Exploitation will have the prerequisite knowledge. If these courses have not been attended, students should have hands on experience in:
CLASS SYLLABUS
Day 1
Lectures and Labs
Day 2
Day 3
Courses have no more than 10 people.
A minimum of 4 registrations are required for course to run. If less than 4 registrations are received, InfoSect will be in contact about refunding or rescheduling the course.
Dr Silvio Cesare is the Managing Director at InfoSect. He has worked in technical roles and been involved in computer security for over 20 years. This period includes time in Silicon Valley in the USA, France, and Australia. He has worked commercially in both defensive and offensive roles within engineering. He has reported hundreds of software bugs and vulnerabilities in Operating Systems kernels. He was previously the Director for Education and Training at UNSW Canberra Cyber, ensuring quality content and delivery. In his early career, he was the scanner architect and a C developer at Qualys. He is also the co-founder of BSides Canberra - Australia’s largest cyber security conference. He has a Ph.D. from Deakin University and has published within industry and academia, is a 4-time Black Hat speaker, gone through academic research commercialisation, and authored a book (Software Similarity and Classification, published by Springer).
Integer nulla lorem, pellentesque eget eros malesuada, semper bibendum felis. Proin quis est egestas, ultrices purus tempor, aliquet erat. Nullam molestie, neque at hendrerit semper, dui lacus eleifend arcu, quis mattis augue leo condimentum dui. Nunc vehicula eleifend risus vitae luctus. Sed sed sem nibh. Nam sit amet massa ullamcorper, iaculis felis id, ullamcorper libero. Aenean aliquet orci quis nisi interdum faucibus. Maecenas sollicitudin, nunc vitae tempus feugiat, arcu elit egestas diam, sit amet maximus neque turpis ac quam. Curabitur at ligula eget turpis pellentesque vestibulum eu id ante. Cras eget turpis mauris. Vestibulum vitae quam elit. Suspendisse bibendum at ipsum nec tempor. Ut in tristique nibh. Aliquam erat volutpat. In hac habitasse platea dictumst.
Vivamus tempor viverra enim, commodo faucibus quam porta sed. Sed et varius nunc. Fusce cursus sem nec tellus accumsan, sed laoreet nisi vulputate. Praesent varius quis turpis in aliquam. Phasellus nisl velit, porttitor eget risus sed, interdum elementum nibh. Praesent eget ante bibendum quam suscipit accumsan sit amet eu nisi. Ut eget facilisis risus. Proin molestie lorem ut interdum finibus. Sed pretium ut sapien at dictum. Sed sit amet dolor tincidunt turpis tincidunt ultricies et et neque.
Nam non augue a lorem tempor sodales. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia Curae; Quisque ullamcorper lobortis rhoncus. Morbi nec dui vitae odio ultricies posuere ac nec turpis. Vestibulum efficitur lectus sem, sed volutpat quam congue at. Nulla quis aliquam ex. Vestibulum eget felis consectetur, efficitur risus non, dapibus tellus. Aliquam ac gravida dui. Donec vel est a arcu tristique egestas id vitae neque. Nullam varius odio eget leo porttitor, pharetra rhoncus quam dignissim..
Please enter below, the secure invite code provided to you by the event organizer in order to proceed...
(Please use a genuine email address. It will be used to validate your request)