Dailydave mailing list archives

Re: Mentors


From: "Matt Hargett" <matt () use net>
Date: Wed, 24 Mar 2004 13:52:10 -0800


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


I am not looking for any 0-day stuff. I am just trying to learn. For some
reason I am just not understanding buffer
overflows. I have a general concept of how they work. I have a lot of
how-to's, IDA Pro, ollydbg, Visual Studio
6, but I just can't make it work. I am doing more application layer stuff
with LibWisker and would like to round
out my skill set. I was going to take Dave's class, but since it is not
offered at Blackhat anymore I am waiting to
see what other classes he is going to be offering. One of the authors of
the ShellCoder's Handbook is also going to
be offering a course on BO, SQL injection, etc.

Yea, it is very tough to find anyone who will teach you anything relevant.
One of the more annoying aspects of the scene is how secretive everyone is,
keeping good/new techniques hidden. Even with a good teacher, though, there
are so many aspects to comprehend before you can fully understand even a
simple stack buffer overflow. (what's a stack/register/instruction
pointer/block pointer/nop sled/compiler/static array/etc). Thankfully, there
are a couple of good books out there now with hands on things you can do to
cement the concepts in your mind. I haven't seen the one recently mentioned,
so I can't comment on it.

I have been to the local 2600 meetings and they were more than lame. If
anyone has any other suggestions on
learning please let me know. Thanks.

2600 meetings are a great way to find people with the right mindset,
intelligence, and enthusiasm who aren't so full of thsemselves that it makes
you want to vomit. If you give some of these younger (and older) people a
chance, they can be very useful and you can learn a lot from them (and them
from you), even if it is only their perspective.


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0.3

iQA/AwUBQGIDCDM37G8Cnu+zEQLjyQCgqMKietU64yXX1OeVK9nQ1TokX/0Anjwx
WYfOV9XIt6fWkZdGWCLTg9Sz
=v3Jl
-----END PGP SIGNATURE-----

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


Current thread: