Part 1: Shellcode Execution with Python | Joff Thyer

Описание к видео Part 1: Shellcode Execution with Python | Joff Thyer

Join us in the Black Hills InfoSec Discord server here:   / discord   to keep the security conversation going!

🏫 Learn Introduction to Python with Joff Thyer from Antisyphon
https://www.antisyphontraining.com/on...

00:00 - FEATURE PRESENTATION: Part 1
00:28 - About Joff
01:44 - Scenario
03:46 - What is shellcode
05:44 - Python3 – ctypes module
06:59 - Python3 – ctypes windll object
08:37 - Windows Architecture
10:50 - Passing Arguments to WinAPI Functions
12:11 - Some types from ctypes module
12:39 - Specifying Required Argument Types
14:08 - WinAPI data types and constants
15:06 - the ctypes module also has wintypes
15:51 - Example function prototype
17:54 - Shellcode Execution using Windows API
20:05 - The Myriad of Ways you get BUSTED
23:23 - Machine Architecture Matters

Description: Imagine you are pen testing a company and gain access to a Windows application server. You discover the server has application allow listing deployed, and strong EDR/XDR defensive solutions. To your excitement, you find there is a Python interpreter installed. It would be really great if you could use that Python interpreter to execute your favorite C2 framework shellcode and use all of your normal hacking toolsets to continue your work. With a little bit of coding work, you can! In this Black Hills Information Security (BHIS) webcast, you will learn exactly how to achieve your goal of shellcode execution with Python.

Tiny repo with demo code:
https://github.com/RiverGumSecurity/P...

Slides
https://www.blackhillsinfosec.com/wp-...

Part 2
   • Part 2: Shellcode Execution with Pyth...  
Part 3
   • Part 3: Shellcode Execution with Pyth...  

Black Hills Infosec Socials
Twitter:   / bhinfosecurity  
Mastodon: https://infosec.exchange/@blackhillsi...
LinkedIn:   / antisyphon-training  
Discord:   / discord  

Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.mysh...

Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/ser...
Penetration Testing: https://www.blackhillsinfosec.com/ser...
Incident Response: https://www.blackhillsinfosec.com/ser...

Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/

Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pa...
Live Training: https://www.antisyphontraining.com/co...
On Demand Training: https://www.antisyphontraining.com/on...

Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin' Fest YouTube:    / wildwesthackinfest  
Active Countermeasures YouTube:    / activecountermeasures  
Antisyphon Training YouTube:    / antisyphontraining  

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/

#redteaming #cybersecurity #python #redteam

Комментарии

Информация по комментариям в разработке