WCU / Cybersecurity
~/CSC 472
CSC 472

Software Security & Exploitation

How memory-corruption vulnerabilities work, how they are exploited, and how modern defenses stop them.

pwntoolsGDB / pwndbgGhidraROPgadgetone_gadgetQEMU
01

Lectures

CLASS 01→

Introduction and the Memory-Corruption Landscape

18 knowledge points

CLASS 02→

Process Memory, x86-64 Assembly, and the Stack

23 knowledge points

CLASS 03→

Buffer Overflows and Return-Address Hijacking

17 knowledge points

CLASS 04→

Shellcode

18 knowledge points

CLASS 05→

Exploit Mitigations and Modern Defenses

19 knowledge points

CLASS 06→

Format String Vulnerabilities

18 knowledge points

CLASS 07→

Return-Oriented Programming and ret2libc

18 knowledge points

CLASS 08→

Multi-Stage Exploitation — Info Leaks and GOT Overwrite

20 knowledge points

CLASS 09→

Heap Exploitation

25 knowledge points

CLASS 10→

Kernel Exploitation and Wrap-Up

20 knowledge points

02

Labs

LAB 1→

Stack Frames, GDB, and pwntools

7 sections

LAB 2→

Stack Buffer Overflow

8 sections

LAB 3→

Format String Vulnerabilities

7 sections

LAB 4→

Return-Oriented Programming (ROP)

7 sections

LAB 5→

Multi-Stage Exploitation: Info Leak, GOT Overwrite, and ret2libc

7 sections

LAB 6→

Heap Exploitation: Use-After-Free and tcache

7 sections

LAB 7→

Kernel Exploitation: Use-After-Free

8 sections