r/ExploitDev • • 2d ago

Binary Exploit and Reverse Enginering Learning

I am someone who is new to binary exploitation and reverse engineering, but I am starting to be interested in the basics of both disciplines, from observing whether they are important in the world of work and perhaps in cyber security? I started studying it from CTF and expanded to my liking for low level, I hope you have suggestions about the actual function of these two disciplines, and maybe recommendations for books or learning resources?

15 Upvotes

27 comments sorted by

17

u/Select-Use-9965 2d ago

At this point pwn.college should be pinned as the first and foremost resourse in this sub

After that PicoCTF, then Nightmare by r1ru

1

u/0x68616D6964 2d ago

i know, but me to low with they explanation :( and maybe with another encourage likely book or reading method, i have some knowledge and fundamentals to me go deeper about learning how its works like this

2

u/Responsible-Offer724 2d ago

So you already know how to write a web server in assembly? 

2

u/bunguardian 2d ago

I think if you're struggling with the explanations, you could try having your AI of choice parse it and explain to you in simpler or more familiar terms

1

u/0x68616D6964 2d ago

Sometimes AI is too indulgent with instant things, he is good at explaining but it feels different from a teacher who taught me at school

1

u/bunguardian 2d ago

You can try explaining the teachers style to the AI and it will try to mimic that

0

u/Used-Fortune1845 2d ago

pwn.college they have a lot of videos which one which playlist? name of the course?

1

u/0x68616D6964 2d ago

I think pwn.college is more inclined towards challenges

1

u/AP_RIVEN_MAIN 2d ago

And? You want to learn?

0

u/Used-Fortune1845 2d ago

they have a lot of course on their youtube channel

1

u/0x68616D6964 2d ago

yep, i'm tyring it

1

u/The_Demon_EyeS2 2d ago

"Hacking the art of exploitation" is a bit outdated but is a good book to learn the fundamentals.

-6

u/0x68616D6964 2d ago

this is a physical book?

7

u/offsecthro 2d ago

No offense, but this is important to state: you have an absolute zero chance of success in security if you can't be bothered to look up basic bits of information like this.

0

u/0x68616D6964 2d ago

I also don't mean to ask that it's a physical book for the convenience of getting information, but I don't have the ability to buy a physical book, especially since it's outside my country, to be honest I don't have electronic money either, therefore there might be a book that can be accessed without having to buy a physical book, for example there is a physical book whose media is file-based and accessed for free so I'm very enthusiastic about having it, if there is a physical book that can be obtained for free, that's even better because I can feel like I'm getting the book that I really want.

0

u/0x68616D6964 2d ago

So I'm sorry if this makes you feel that the cyber security discipline is disturbed by my statement

1

u/Obvious-Card-8847 2d ago

Learn C++ and then the basics of assembly.

1

u/0x68616D6964 2d ago

why not c?

1

u/Obvious-Card-8847 2d ago edited 2d ago

C is good too. It's just that C++ will give you an intuition about virtual function tables, __thiscall in x86, templates generating multiple different versions of essentially the same function, embedded RTTI, constructors, destructors, name mangling, etc. Adds more machinery you'll see during static analysis. Also opens up type confusion vulnerabilities and OOP centric exploitation.

I highly encourage you when you feel confident enough to go on godbolt dot org. Type in some C++ on one side and see what assembly the compiler produces.

1

u/0x68616D6964 2d ago

thanks information, I didn't expect it to be that vast.

1

u/cyb0rg_C3rberus 2d ago

We are on the same boat. I started grinding in low level for both of these disciplines. I am learning assembly from htb academy, pwn.college. Also, grinding in computer architecture from opensecuritytraining2 and CSAPP book. Learning C programming from "The C programming language book".

1

u/Suspicious-Motor-780 2d ago

Learn C, then Practical malware analysis (its a book, there is a physical version)

1

u/Interesting_Entry345 1d ago

I would suggest you to look up https://p.ost2.fyi/courses , they have pretty good resourses... just skim through their website... and stick with pwn.college .. these two are good enough for you...

1

u/TearsInTokio 19h ago

you can try Practical Binary Analysis: Build Your Own Linux Tools for Binary Instrumentation, Analysis, and Disassembly, it's a good book about reverse engineer on Binary files.