COMpromise: remote code execution in Windows development environments | Stan Hegt | NULLCON Goa 2020
About this talk
This talk demonstrates how compiling, reverse engineering, or even simply viewing source code can compromise a developer's workstation. With the rise of code sharing platforms like GitHub, downloading and scrutinizing potentially untrusted code has become common, but this practice can be exploited by attackers due to the interactions between integrated development environments for Windows and the Component Object Model (COM). The speaker presents comprehensive and practical exploit chains for Visual Studio, illustrating that merely opening code can pose significant risks. The session delves into COM, type libraries, and the intricate inner workings of Visual Studio, revealing critical insights for developers.
More from this event
See all 39 talks →
ML for security and security for ML | Training Tidbits | Nikhil Joshi | NULLCON Goa | March 2020
0:30
Practical IoT Hacking | Training Tidbits | Aseem Jakhar | NULLCON Goa | March 2020
0:54
Hacking iOS Applications, Like A Pro | Training Tidbits | Abhinav Mishra | NULLCON Goa | March 2020
1:14
Windows Kernel Exploitation - Foundation & Advanced | Training Tidbits | Ashfaq Ansari #NULLCON2020
0:36