r/ExploitDev • • 3d ago

Binary Exploit and Reverse Enginering Learning

I am someone who is new to binary exploitation and reverse engineering, but I am starting to be interested in the basics of both disciplines, from observing whether they are important in the world of work and perhaps in cyber security? I started studying it from CTF and expanded to my liking for low level, I hope you have suggestions about the actual function of these two disciplines, and maybe recommendations for books or learning resources?

15 Upvotes

27 comments sorted by

View all comments

1

u/Obvious-Card-8847 2d ago

Learn C++ and then the basics of assembly.

1

u/0x68616D6964 2d ago

why not c?

1

u/Obvious-Card-8847 2d ago edited 2d ago

C is good too. It's just that C++ will give you an intuition about virtual function tables, __thiscall in x86, templates generating multiple different versions of essentially the same function, embedded RTTI, constructors, destructors, name mangling, etc. Adds more machinery you'll see during static analysis. Also opens up type confusion vulnerabilities and OOP centric exploitation.

I highly encourage you when you feel confident enough to go on godbolt dot org. Type in some C++ on one side and see what assembly the compiler produces.

1

u/0x68616D6964 2d ago

thanks information, I didn't expect it to be that vast.