Wes McGrew - The Joy of Reverse Engineering: Learning With Ghidra and WinDb

Wes McGrew - The Joy of Reverse Engineering: Learning With Ghidra and WinDb

Saturday Afternoon DEF CON Workshop Starting at 1400 PDT

By DEF CON WORKSHOPS

Date and time

Saturday, August 12, 2023 · 2 - 6pm PDT

Location

Flamingo Las Vegas

3555 South Las Vegas Boulevard Las Vegas, NV 89109

About this event

Max Class Size: 80

Abstract:

While it can be intimidating to "get into" software reverse engineering (RE), it can be very rewarding. Reverse engineering skills will serve you well in malicious software analysis, vulnerability discovery, exploit development, bypassing host-based protection, and in approaching many other interesting and useful problems in hacking. Being able to study how software works, without source code or documentation, will give you the confidence that there is nothing about a computer system you can't understand, if you simply apply enough time and effort. Beyond all of this: it's fun. Every malicious program becomes a new and interesting puzzle to "solve".

The purpose of this workshop is to introduce software reverse engineering to the attendees, using static and dynamic techniques with the Ghidra disassembler and WinDbg debugger. No prior experience in reverse engineering is necessary. There will be few slides--concepts and techniques will be illustrated within the Ghidra and WinDbg environments, and attendees can follow along with their own laptops and virtual environments. We will cover the following topics:

- Software Reverse Engineering concepts and terminology

- Setting up WinDbg and Ghidra

- The execution environment (CPU, Virtual Memory, Linking and Loading)

- C constructs, as seen in disassembled code

- Combining static and dynamic analysis to understand and document compiled binary code

- Methodology and approaches for reverse engineering large programs

- Hands-on malware analysis

- How to approach a "new-to-you" architecture

Skill Level: Beginner

Prerequisites for students: No previous reverse engineering experience required. Basic familiarity with programming in a high-level language is necessary (C preferred, Scripting languages like Python would be okay).

Materials or Equipment students will need to bring to participate: A laptop with a fresh Windows 10 Virtual Machine.

- Being able to dedicate 8GB RAM to the VM (meaning, you probably have 16GB in your laptop) will make the experience smoother, but you can get by with 4GB

- 10 GB storage free in the VM (after installing Windows)

- Administrative privileges

- Ability to copy exercise files from USB

We will be working with live malware samples. Depending on your comfort level with this, bring a "burner" laptop, use a clean drive, or plan on doing a clean install before and after the workshop.

Bio:

Dr. Wesley McGrew directs research, development, and offensive cyber operations as Senior Cybersecurity Fellow for MartinFed. He has presented on topics of penetration testing and and malware analysis at DEF CON and Black Hat USA and taught a self-designed course on reverse engineering to students at Mississippi State University, using real-world, high-profile malware samples. Wesley has a Ph.D. in Computer Science from Mississippi State University for his research in vulnerability analysis of SCADA HMI systems.

Organized by

DEF CON Workshops are an opportunity to learn from others in our community in a four hour class. The workshops range in difficulty from n00b to hardcore hacker and on almost any topic that you can think of in the realm of hacking.

Now on to some things to keep in mind while you look at which workshop(s) to register for:

Workshop Registration will be handled online. Announcement will be made as we get ready to open reg the day before.

In order to decrease the number of no-shows, DEF CON Workshops will be instituting a $25 registration fee to attendees. Tickets are available on a first come, first served basis. Additional costs include possible low-fee for material costs, if applicable, and will be collected by the instructor at the time of the workshop.

There will be a limited number of students on standby lists for each class, should a registration cancel.

There will be NO onsite registration, period. Anyone on standby will be notified they are on standby before the conference. There will be NO onsite standby line or list to sign up for. Everything will be arranged pre-con.

Students will be limited to purchasing 2 tickets per class.

You can register for as many classes as you can attend in one day. ( No two classes at the same time. If you have mastered occupying two spaces at the same time, there are some physics academics who would be pleased to meet you among others)

Sales Ended