DEF CON 27 - Omer Yair - Exploiting Windows Exploit Mitigation for ROP Exploits @HackersOnBoard
DEF CON 27 - Omer Yair - Exploiting Windows Exploit Mitigation for ROP Exploits  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 12 hours ago
"A concept is a brick. It can be used to build a courthouse of reason. Or it can be thrown through the window." ― Gilles Deleuze

Ever since Smashing the Stack For Fun And Profit was published by Aleph One almost a quarter century ago the security world has completely changed the way it defends exploitation. Canary stack, DEP, ASLR, CFI and various other mitigation techniques were developed to address various exploit techniques. Yet, ROP remains a prominent practice employed by many exploits even today.

ROP is the most common exploitation method for attackers to mutate memory bugs on target process into malicious executable code. "Next Gen" endpoint security products try to address ROP and other exploitation methods. Windows embraces many mitigation techniques as well. However, these mitigation features such as CFG can in fact be leveraged and increase ROP's attack surface and allow it to even bypass exploit protections!

If you are intrigued by ROP, want to learn about methods in Windows that protect against ROP and how to bypass them - this talk is for you! On top of that a novel method of bypassing ROP mitigation of most products will also be revealed.
DEF CON 27 - Omer Yair - Exploiting Windows Exploit Mitigation for ROP ExploitsDEF CON 27 - jiska - Vacuum Cleaning Security Pinky and the Brain EditionHacking the Samsung Galaxy S8 IrisscannerDEF CON 27 - Michael Leibowitz - EDR Is Coming Hide Yo Sh!tBlack Hat USA 2018 - Holding on for Tonight Addiction in InfoSecBlack Hat USA 2018 - Practical Web Cache Poisoning Redefining UnexploitableBlack Hat USA 2018 - Automated Discovery of Deserialization Gadget ChainsBlack Hat USA 2018 - Back to the Future A Radical Insecure Design of KVM on ARMBlack Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF BinariesBlack Hat USA 2018 - DeepLocker - Concealing Targeted Attacks with AI LocksmithingDEF CON 27 - Bill Swearingen - HAKC THE POLICEDEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad Design
HackersOnBoard |

DEF CON 27 - Omer Yair - Exploiting Windows Exploit Mitigation for ROP Exploits

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER