YoVDO

Cooper Knows the Shortest Stave - Finding 134 Bugs in the Binding Code of Scripting Languages

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Software Development Courses Bug Hunting Courses

Course Description

Overview

Explore a groundbreaking approach to bug detection in scripting language binding code through this 30-minute Black Hat conference talk. Dive into the concept of cooperative mutation, which simultaneously modifies script code and program native input to uncover elusive bugs. Learn about three innovative solutions developed for popular scripting languages: object clustering for search space reduction, statistical inference of script-object relationships, and targeted mutation based on inferred connections. Gain insights from the speakers' successful identification of 134 bugs using this method, and understand how the interplay between initial program state and dynamic operations can reveal previously undetected vulnerabilities.

Syllabus

Cooper Knows the Shortest Stave: Finding 134 Bugs in the Binding Code of Scripting Languages


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube