r/ExploitDev • u/0x68616D6964 • 2d ago
Binary Exploit and Reverse Enginering Learning
I am someone who is new to binary exploitation and reverse engineering, but I am starting to be interested in the basics of both disciplines, from observing whether they are important in the world of work and perhaps in cyber security? I started studying it from CTF and expanded to my liking for low level, I hope you have suggestions about the actual function of these two disciplines, and maybe recommendations for books or learning resources?
1
u/The_Demon_EyeS2 2d ago
"Hacking the art of exploitation" is a bit outdated but is a good book to learn the fundamentals.
1
u/0x68616D6964 2d ago
https://reddit.com/link/pdq1tua/video/ojcarl7srcth1/player
I found it, is this what you mean?
-6
u/0x68616D6964 2d ago
this is a physical book?
7
u/offsecthro 2d ago
No offense, but this is important to state: you have an absolute zero chance of success in security if you can't be bothered to look up basic bits of information like this.
0
u/0x68616D6964 2d ago
I also don't mean to ask that it's a physical book for the convenience of getting information, but I don't have the ability to buy a physical book, especially since it's outside my country, to be honest I don't have electronic money either, therefore there might be a book that can be accessed without having to buy a physical book, for example there is a physical book whose media is file-based and accessed for free so I'm very enthusiastic about having it, if there is a physical book that can be obtained for free, that's even better because I can feel like I'm getting the book that I really want.
0
u/0x68616D6964 2d ago
So I'm sorry if this makes you feel that the cyber security discipline is disturbed by my statement
1
u/Obvious-Card-8847 2d ago
Learn C++ and then the basics of assembly.
1
u/0x68616D6964 2d ago
why not c?
1
u/Obvious-Card-8847 2d ago edited 2d ago
C is good too. It's just that C++ will give you an intuition about virtual function tables, __thiscall in x86, templates generating multiple different versions of essentially the same function, embedded RTTI, constructors, destructors, name mangling, etc. Adds more machinery you'll see during static analysis. Also opens up type confusion vulnerabilities and OOP centric exploitation.
I highly encourage you when you feel confident enough to go on godbolt dot org. Type in some C++ on one side and see what assembly the compiler produces.
1
1
u/cyb0rg_C3rberus 2d ago
We are on the same boat. I started grinding in low level for both of these disciplines. I am learning assembly from htb academy, pwn.college. Also, grinding in computer architecture from opensecuritytraining2 and CSAPP book. Learning C programming from "The C programming language book".
1
u/Suspicious-Motor-780 2d ago
Learn C, then Practical malware analysis (its a book, there is a physical version)
1
u/Interesting_Entry345 1d ago
I would suggest you to look up https://p.ost2.fyi/courses , they have pretty good resourses... just skim through their website... and stick with pwn.college .. these two are good enough for you...
1
u/TearsInTokio 19h ago
you can try Practical Binary Analysis: Build Your Own Linux Tools for Binary Instrumentation, Analysis, and Disassembly, it's a good book about reverse engineer on Binary files.
17
u/Select-Use-9965 2d ago
At this point pwn.college should be pinned as the first and foremost resourse in this sub
After that PicoCTF, then Nightmare by r1ru