Reverse Engineering and Exploiting Font Rasterizers - The OpenType Saga
Offered By: 44CON Information Security Conference via YouTube
Course Description
Overview
Explore the intricacies of font rasterization security in this 57-minute conference talk presented by Mateusz Jurczy at the 44CON Information Security Conference. Delve into the world of font file formats, with a focus on OpenType, and discover why they are prime targets for attackers. Learn about the complexities of font processing software, its implementation in C/C++, and the challenges posed by aging codebases. Examine the widespread impact of font-related vulnerabilities across browsers, document viewers, and operating systems. Follow the speaker's journey through a detailed security audit of OpenType font handling in popular libraries, applications, and operating systems. Uncover critical vulnerabilities that enable reliable arbitrary code execution, bypassing modern exploit mitigations. Gain insights into the evolution of typography and font security research, including historical context from the 80s and 90s. Understand the process of reverse-engineering proprietary OpenType/CFF implementations, such as Windows kernel ATMFD.DLL module. Analyze root causes and exploitation techniques for vulnerabilities found in Microsoft Windows, Adobe Reader, DirectWrite, FreeType, and other products. Enhance your knowledge of font security and its implications for modern software ecosystems.
Syllabus
Reverse engineering and exploiting font rasterizers the OpenType saga Presented By Mateusz Jurczy
Taught by
44CON Information Security Conference
Related Courses
Supply Chain Unchained - How To Be A Bad SaaS44CON Information Security Conference via YouTube Aviation Security 101
44CON Information Security Conference via YouTube The Anti-Checklist Manifesto
44CON Information Security Conference via YouTube Why Are We Still Doing Authentication Wrong?
44CON Information Security Conference via YouTube What Do Hackers See When They Look at the Clouds
44CON Information Security Conference via YouTube