Uploaded August 2025 | Updated September 2026, 1 week ago
ROP (return-oriented programming) is today the de facto standard technique for performing arbitrary code execution attacks. Ulf describes the development and use of a tool that will tell you which components of your code base are most at risk of ROP attacks.
The goal is a vulnerability-independent analysis of risk-of-exploitability for memory based vulnerabilities in embedded systems.
The session describes the how and why this tool differs from other ROP generators. It ends by presenting comprehensive exploitation risk analyses of real, deployed software images from ICS vendors.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com
ROP (return-oriented programming) is today the de facto standard technique for performing arbitrary code execution attacks. Ulf describes the development and use of a tool that will tell you which components of your code base are most at risk of ROP attacks.
The goal is a vulnerability-independent analysis of risk-of-exploitability for memory based vulnerabilities in embedded systems.
The session describes the how and why this tool differs from other ROP generators. It ends by presenting comprehensive exploitation risk analyses of real, deployed software images from ICS vendors.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com










