COMpromise: remote code execution in Windows development environments | Stan Hegt | NULLCON Goa 2020

45:29 · 06 Mar 2020 – 07 Mar 2020 · YouTube

About this talk

This talk demonstrates how compiling, reverse engineering, or even simply viewing source code can compromise a developer's workstation. With the rise of code sharing platforms like GitHub, downloading and scrutinizing potentially untrusted code has become common, but this practice can be exploited by attackers due to the interactions between integrated development environments for Windows and the Component Object Model (COM). The speaker presents comprehensive and practical exploit chains for Visual Studio, illustrating that merely opening code can pose significant risks. The session delves into COM, type libraries, and the intricate inner workings of Visual Studio, revealing critical insights for developers.

From event

NULLCON Goa 2020

06 Mar 2020 – 07 Mar 2020

All event videos
Back to Watch