Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Fuzzing RDP Client and Server

Hack In The Box Security Conference via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains how WinAFL, DynamoRIO, and custom enhancements were used to apply coverage-guided fuzzing to the RDP protocol across Windows clients and servers. It covers protocol statefulness, target-function selection, crash reproduction, and automatic analysis of results.

Syllabus

Intro
Agenda
RDP Attack Vector #2
Examples
Attack Surface
Read Surface
Protocol Stack
General Info
Coverage-guided Fuzzing Setup
Fuzzing Options
DR Attach
Background Fuzzing
Statefulness
Code Patches
Grammar Enforcement
Multi-input
Multi-channel Input
Locating Target Functions
Reproduction Issues
Automatic Crash Analysis
AUDIO_PLAYBACK Channel
Crashing Input
Future Work

Taught by

Hack In The Box Security Conference

Reviews

Start your review of Fuzzing RDP Client and Server

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.