Black Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit Development @HackersOnBoard
Black Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit Development  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Speak with any Fortune 500 running mainframe and they'll tell you two things: (1) without their mainframes they'd be out of business (2) they do not conduct any security research on them, let alone vulnerability scans. The most infuriating part is that mainframes are simply computers, they're different from what you're used to, but that doesn't mean they can't be hacked. Previous talks about this topic have covered the platform from a high level, imploring you to do the basics. This talk continues this series of talks, given by others, around mainframe hacking. Previously covered topics included network penetration testing and privilege escalation. To complement those talks, this talk will expose attendees to the various tools that exist on the platform to help you do your own reverse engineering, followed by detailed steps on how to start your own exploit development. Attendees will learn what debuggers are available on the platform, such as dbx and ASMIDF, as well as the challenges you'll have using them. After learning how to RE, attendees will then learn how to develop their own exploits and buffer overflows on the platform using C, assembler and JCL. A demo program will be used to teach all these items so people can follow along. Topics included in this discussion are APF authorization, bypassing RACF/ACEE, TSO, Unix System Services.
Black Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit DevelopmentDetecting Malicious Cloud Account Behavior A Look at the New Native Platform CapabilitiesDEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRsDEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile ManipulationsDEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection AttacksBlack Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient Lives
HackersOnBoard |

Black Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit Development

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER