Super Awesome Fuzzing, Part One
by Atte Kettunen and Eero Kurimo, 2017
đŠ A curated list of the awesome resources about the Vulnerability Research
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
by Atte Kettunen and Eero Kurimo, 2017
by Javier Jiménez, 2017
by Corelan Team, 2013
by Mark Dowd, John McDonald, Justin Schuh - published 2006, ISBN-13: 978-0321444424 / ISBN-10: 9780321444424
by Chris Anley, John Heasman, Felix Lindner, Gerardo Richarte - published 2007, 2nd Edition, ISBN-13: 978-0470080238 / ISBN-10: 047008023X
by Offensive Security with complementary OSEE (Offensive Security Exploitation Expert) Certification
by Offensive Security, with complementary OSCE (Offensive Security Certified Expert) Certification
by RPISEC at Rensselaer Polytechnic Institute in Spring 2015. This was a university course developed and run solely by students to teach skills in vulnerability research, reverse engineering, and binary exploitation.
by University of Maryland.
by W. Owen Redwood and Prof. Xiuwen Liu.
Las Vegas, NV, USA
Las Vegas, NV, USA
London, UK //đ„Join me this year on Dec, 7-10, 2020!
Worldwide
Brussels, Belgium
Hamburg, Germany
Tokyo, Japan
Goa, India
London, UK
Washington DC
Europewide
Moscow, Russia
Moscow, Russia
Warsaw, Poland
by Joshua Drake and Steve Christey Coley at DEFCON 24, 2016
by Kymberlee Price, originally presented at Nullcon, 2016
, by Atte Kettunen, presented at 44CON, 2013
HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
by Joshua Drake and Steve Christey Coley at DEFCON 24, 2016
by Mateusz âj00ruâ Jurczyk presented at BlackHat EU, 2016
or Speaker Deck - by Andrew M. Hay at SOURCE Boston, 2016
by Nick Jones, MWR Labs, 2016
Common Vulnerabilities and Exposures, maintained by the MITRE Corporation
Common Weakness Enumeration, maintained by the MITRE Corporation
Common Vulnerability Scoring System, maintained by FIRST (Forum of Incident Response and Security Teams)
Vulnerability Disclosure Standard
Full Disclosure Policy (RFPolicy) v2.0 by Packet Storm
Clément BERTHAUX, Synacktiv, CVE-2017-3143
Morten Schenk, originally presented at Black Hat 2017
The preferred debugger by exploit writers.
Intercepts library calls
An advanced cross platform fuzzing framework designed to find vulnerabilities in C/C++ code.
A framework which contains some fuzzing capabilities via Auxiliary modules.
A fuzzer development framework like sulley, a predecessor of sulley.
A repo with extended documentation, bugs and some helper code for the AddressSanitizer, MemorySanitizer, ThreadSanitizer, LeakSanitizer. The actual code resides in the LLVM repository.
FLARE (FireEye Labs Advanced Reverse Engineering) a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc.
The hackers-grep is a tool that enables you to search for strings in PE files. The tool is capable of searching strings, imports, exports, and public symbols (like woah) using regular expressions.
Grinder is a system to automate the fuzzing of web browsers and the management of a large number of crashes.
An evolutionary knowledge-based fuzzer
A fork and successor of Sulley framework
The Chromium Project. Google Account Required
by b33f
by fuzzing.info
Coding, reverse engineering, OS internals covered one more time
SSD provides the support you need to turn your experience uncovering security vulnerabilities into a highly paid career. SSD was designed by researchers, for researchers and will give you the fast response and great support you need to make top dollar for your discoveries.
ZDI is originally founded by TippingPoint, is a program for rewarding security researchers for responsibly disclosing vulnerabilities. Currently managed by Trend Micro.
Open source hacking tools for hackers and pentesters.
A list of movies every cyberpunk must watch.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
lissy93/awesome-privacy
đŠ A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
qazbnm456/awesome-web-security
đ¶ A curated list of Web Security materials and resources.