Jump to content

Question For Find Zero Day

- - - - -

  • Please log in to reply
6 replies to this topic

#1
C0nn3ct0r

C0nn3ct0r

    Newbie

  • Members
  • Pip
  • 3 posts
Hi All Friends...:)

Im Sorry For Bad English Speak:D But...

Guys, I Want To The Software , Find Zero Day Or Vullnerabille And Exploting 0 Day...

What i This Should Do Professional Discourse ?!

Next Programing Language Should I Do?!

And What Books Do You Recommend For My Study?!

Im Sorry All Friend For Bad Typing:D Please Help Me:D

#2
Vaielab

Vaielab

    Programming God

  • Members
  • PipPipPipPipPipPipPip
  • 547 posts
You want to create a software that will find 0day vulnerability for you?

#3
C0nn3ct0r

C0nn3ct0r

    Newbie

  • Members
  • Pip
  • 3 posts
No Bro.

For example, I do examine corporate programs"Microsoft,Adobe,Autodesk.." and their bugs and security problems I find.

And Exploiting Bug..

I need to know what to do?

#4
Vaielab

Vaielab

    Programming God

  • Members
  • PipPipPipPipPipPipPip
  • 547 posts
Sorry I'm not sure what you are trying to do... try to translate your question with google translate

#5
C0nn3ct0r

C0nn3ct0r

    Newbie

  • Members
  • Pip
  • 3 posts
Language Easier . If I Want To Say....

How I Do Can Find These Type Of Security Problems?

Apple QuickTime PICT PnSize Buffer Overflow
Linux Kernel < 2.6.36.2 Econet Privilege Escalation Exploit
DVD X Player 5.5 Pro SEH Overwrite

#6
Alexander

Alexander

    It's Science!

  • Moderators
  • 4,118 posts
  • Location:Vancouver, Eh! Cleverness: 200
Understanding what types of attacks are possible (buffer overruns are a common) could help you apply similar methods to other programs, however much of this may be guessing with a debugger and seeing what the program does with malformed input. Instead of displaying an error it may do something that would allow arbitrary code injection (knowledge of assemblies could help)

There is also no one straightforward way to effectively find these things, a keen mind on how the program works without the source can help you spot where potential attacks or escalations could be applied.

If one person fails to do a check or opens a security risk, others likely may repeat the same mistake as well so you can build a framework to test multiple applications (metasploit has a great database of some of these tests)
Be sure to read the updated FAQ! || Health is achieved through the same 10,000 steps.
If a suggested code/method fails, informing us is less important than telling us why or what errors occurred.

#7
DarkLordofthePenguins

DarkLordofthePenguins

    Programming Expert

  • Members
  • PipPipPipPipPipPip
  • 409 posts
I think it's against forum rules to give instructions on cracking.
Programming is a journey, not a destination.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users