OffenSkill Trainings

Lvl 30 · Expert

Abstract

You are already an established hacker, proud of your work, yet willing to do more in less time? You want to approach new problems with more structure, tooling, and techniques in mind?

Join this training to improve your audit methodology & code-reading skills. It's focused on web 0-day research, giving you the adequate tools for fuzzing, introspection, and assisted code audits.

Key Takeaways

  • Narrow focus on code-reading methodology

  • Web app & server instrumentation for bug detection

  • Praticing web 0-day research, write detailed and clear bug reports

Requirements

  • You enjoy reading code, and are familiar with at least 2/3 languages

  • Be fluent with XSS, XXE, SSRF, SQLI, RCE, File read/write, unserialize

  • Scripting capabilities (python or equivalent)

  • This training requires a sharp mind, and coffee! ☕

Planning

  • Day 1

    • Deep Dive on Code Audit Techniques

    • Deep Dive on Code Audit Tooling

    • Deep Dive on Fuzzing & Introspection Tooling

    • Web-App labs setup & brainstorm on potential findings

  • Day 2

    • Practice: Let's find some real 0-days now! 💣

    • Exploit development for the bugs found during the training