What you'll learn
Essential for OSCP Exam Prep (Offensive Security Certified Professional)
Try our course rather than paying $800 to $1,200 for the official Offensive Security Training. Two of our exploitable programs are featured in the Penetration Testing with Kali Linux Course.
See if aiming for a OSCP is right for you! Knock down the 25 point buffer overflow box in the OSCP exam in minutes, not hours!*
*In the official OSCP Exam you are given a pre-compiled app for the buffer overflow box that is worth 25 out of 100 points. The exam app expressedly emphasizes the bad character analysis section of the PwK course. There will be about twelve or so bad characters that must be eliminated, following the steps in our SLMail 5.5 exercise (which has far less bad characters).
Basic Introduction to Exploit Development
Students enrolling will learn how to discover and craft custom exploits against both Windows and Linux targets
The following techniques will be covered in detail
1. Stack smashing shellcode
2. Multi-stage shellcode
3. Post-exploitation
4. Pivoting on both Linux and Windows targets
5. Anonymity via Tor-over-VPN
6. Offensive shell passing between a underpowered Virtual Private Server back to a more capable Metasploit listener at home through reverse TCP and reverse SSH tunnels
7. A introduction to ROP-chaining, which is a teaser for my more advanced class (work-in-progress)
Debuggers and Tools
Students will learn how to debug flawed applications and craft exploits using
1. Immunity Debugger
2. GDB-PEDA (GNU Debugger)
3. EDB (Evan's Debugger)
Step-by-step guides on setting up your virtual penetration testing lab
1. How to install Kali Linux on Ubuntu 18.04 using KVM
2. How to install Kali Linux on Windows machines using VMWare Player 15
Chang
"Slayer-Ranger" Tan is a software-engineer that writes front-end web
applications as a primary trade of business with a emphasis of a
security-focused software development lifecycle (spiral methodology). He is currently a AWS Certified Cloud Practitioner and will be soon certified as AWS Certified Solutions Architect (Associate), AWS Certified DevOps Engineer, and Certified Kubernetes Administrator (CKA). He will eventually pursue the Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), and Offensive Security Exploitation Expert (OSEE) certifications.
He is a volunteer instructor at DEFCON 27 (2019) at the Red Team Village for Exploit-Development where he and his fellow volunteers and staff members oversaw the validation of approximately more than 90 newly-minted exploit developers over a course of 3-4 days.
He has also, through the negotiation of contracts and non-disclosure agreements (of parties involved and detailed source code), reverse-engineered multiple front-end web applications, primarily by relying on the inference attack on downloadable front-end code in order to infer the functionality and design of the back-end.