Skip to content

Preparation

New References

  • https://tulpa-security.com/2017/07/18/288/
  • https://m101.github.io/binholic/2018/04/28/yet-another-osce-review.html
  • https://github.com/FabioBaroni/awesome-exploit-development

Summarized References

  • https://aminbohio.com/study-guide-tips-offensive-security-certified-expert-osce-cracking-the-perimeter-ctp/

Tools

  • Olly Debugger
  • WinDBG
  • Immunity Debugger with Mona
  • CFF Explorer
  • LordPE
  • DevCPP
  • nasm
  • VulnServer

Training

Open Security Training

Exploit development

Egg hunting

Fuzzing

Practice

Bypassing exploit mitigation:

Shellcoding:

Web app security

AV evasion:

  • https://resources.infosecinstitute.com/bypassing-antivirus/
  • https://www.youtube.com/watch?v=tBY46vs0ptE
  • https://dl.packetstormsecurity.net/papers/bypass/bypassing-av.pdf
  • https://pentest.blog/art-of-anti-detection-1-introduction-to-av-detection-techniques/

Practice

VulnServer Walk-throughs

CTF

  • CTP Registration: http://fc4.me/