System Hacking
10.0
(8)
Tier 2 Easy Skill Path System Hacking
Learn fundamental memory corruption vulnerabilities in system hacking. Completing this Path will give you the foundational skills for understanding vulnerabilities, as well as analyzing and exploiting vulnerabilites targeting binaries.
System Hacking
10.0
(8)
Tier 2 Easy Skill Path System Hacking
Learn fundamental memory corruption vulnerabilities in system hacking. Completing this Path will give you the foundational skills for understanding vulnerabilities, as well as analyzing and exploiting vulnerabilites targeting binaries.
0% Completed Total 0 completed
Lecture 0 /33
Excluded
33
Wargame 0 /21
21
Quiz 0 /8
8
You can access locked objectives by upgrading your plan or purchasing the units separately.
The Lab is a practice and is not included in the overall progress.

Why It's Worth Your Time

System security can feel overwhelming at first, but with a step-by-step approach, it becomes a highly rewarding field to explore. This Path is designed to help learners interested in
system hacking build their skills gradually, starting from fundamental vulnerabilities like stack buffer overflows. By practicing, thinking critically, and solving problems along the
way, you'll naturally develop a strong understanding of core system security concepts and principles. Through this Path, you'll build both a solid foundation and practical skills in
system hacking. This Path is based on the x86-64 architecture running Ubuntu 22.04 and Ubuntu 18.04 Linux operating systems.

Topics Covered

  • Vulnerability analysis and exploitation using pwntools
  • Hands-on exercises with key memory vulnerabilities such as Stack Buffer Overflow
  • Analysis of security mitigations (NX, ASLR, PIE, RELRO) and practical techniques to bypass them
  • Logical vulnerabilities including Command Injection, Path Traversal, and Type Errors

Recommended For

  • Those who want a clear understanding of system hacking and security principles
  • Aspiring white-hat hackers, security engineers, and vulnerability analysts

Prerequisite Knowledge

  • Basic computer skills
  • Basic understanding of computer components and how computers work
  • Programming experience with C or C++
Unit Composition
Total 12 units
  1. 1
    9.9
    (173)
    9.9
    (173)
    Learn how to use pwntools, a versatile tool widely used across various security fields.
    pwntools Basics
    Pwntools Basics
    Quiz: pwntools
    [Exercise] pwntools 1
    Exercise: Pwntools 1
    addition-quiz
    [Exercise] pwntools 2
    Exercise: Pwntools 2
    flag-shop
  2. 2
    9.8
    (130)
    9.8
    (130)
    Learn about shellcode used in system hacking and how to write your own.
    Shellcode
    Exploit Tech: Shellcode
    Quiz: Shellcode
    [Exercise] shell_basic
    Exercise: shell_basic
    shell_basic
  3. 3
    9.8
    (53)
    50 Coin
    9.8
    (53)
    50 Coin
    Understand Out-of-Bounds (OOB) vulnerabilities caused by out-of-range array access and learn how they can be exploited.
    Out of bounds
    Memory Corruption: Out of Bounds
    Quiz: Out of Bounds
    [Exercise] Out of Bounds
    Exploit Tech: Out of bounds
    out_of_bound
  4. 4
    9.8
    (77)
    50 Coin
    9.8
    (77)
    50 Coin
    Explore Linux file system path concepts and path traversal vulnerabilities.
    Path Traversal - C Language
    Logical Bug: Path Traversal
  5. 5
    9.8
    (60)
    50 Coin
    9.8
    (60)
    50 Coin
    Explore command injection vulnerabilities and how to prevent them.
    Command Injection - C Langauge
    Logical Bug: Command Injection
    [Exercise] Command Injection
    Exploit Tech: Command Injection
    cmd_center
  6. 6
    9.9
    (104)
    9.9
    (104)
    Explore stack buffer overflow vulnerabilities.
    Stack Buffer Overflow
    Memory Corruption: Stack Buffer Overflow
    Lab: Stack Buffer Overflow - Auth Overwrite
    Pro
    Lab: Stack Buffer Overflow - Memory Leak
    Pro
    Lab: Stack Buffer Overflow - Change Control Flow
    Pro
    [Exercise] Stack Buffer Overflow
    Exploit Tech: Return Address Overwrite
    Return Address Overwrite
    [Exercise] Stack Buffer Overflow - 2
    Exercise: basic_exploitation_001
    Exercise: basic_exploitation_000
    basic_exploitation_000
    basic_exploitation_001
  7. 7
    9.9
    (43)
    50 Coin
    9.9
    (43)
    50 Coin
    Learn the importance of data types in C and how improper usage can lead to security vulnerabilities.
    Type Error
    Logical Bug: Type Error
    [Exercise] Type Error
    Exploit Tech: Type Error
    sint
  8. 8
    9.9
    (74)
    100 Coin
    9.9
    (74)
    100 Coin
    Explore stack buffer overflow attacks, stack canaries, and techniques to bypass them.
    Stack Canary
    Mitigation: Stack Canary
    Lab: Stack Canary
    Pro
    Quiz: Stack Canary
    [Exercise] Stack Canary
    Exploit Tech: Return to Shellcode
    Exercise: ssp_001
    Return to Shellcode
    ssp_001
  9. 9
    9.9
    (58)
    200 Coin
    9.9
    (58)
    200 Coin
    Understand how NX and ASLR work as mitigation techniques, and explore ROP (Return-Oriented Programming) as a method to bypass them.
    NX & ASLR
    Mitigation: NX & ASLR
    Static Link vs. Dynamic Link
    Background: Library - Static Link vs. Dynamic Link
    Quiz: Static Link vs. Dynamic Link
    [Exercise] Return to Library
    Exploit Tech: Return to Library
    Return to Library
    [Exercise] Return Oriented Programming
    Exploit Tech: Return Oriented Programming
    rop
    [Exercise] Return Oriented Programming - 2
    Exploit Tech: ROP x86
    Exploit Tech: ROP x64
    basic_rop_x64
    basic_rop_x86
  10. 10
    200 Coin
    9.5
    (8)
    200 Coin
    Learn about the SROP attack technique and how to use it to bypass binary mitigations.
    Sigreturn-Oriented Programming (SROP)
    Background: SigReturn-Oriented Programming
    Quiz: SigReturn-Oriented Programming
    [Exercise] SigReturn-Oriented Programming
    Exploit Tech: SigReturn-Oriented Programming
    SigReturn-Oriented Programming
    [Self-practice] send_sig
    send_sig
  11. 11
    9.9
    (48)
    150 Coin
    9.9
    (48)
    150 Coin
    Learn how PIE and RELRO function as mitigation mechanisms, and explore bypass techniques using hook overwriting and One Gadget exploitation.
    PIE
    Background: PIE
    Quiz: PIE
    RELRO
    Background: RELRO
    Quiz: RELRO
    [Exercise] Hook Overwrite
    Exploit Tech: Hook Overwrite
    fho
    [Exercise] Hook Overwrite - 2
    Exercise: hook
    Exercise: oneshot
    oneshot
    hook
  12. 12
    10.0
    (16)
    150 Coin
    10.0
    (16)
    150 Coin
    Learn how to exploit the `__environ` variable in libc, which points to the environment variable area, for attack techniques.
    [Exercise] __environ
    Exploit Tech: __about
    __environ
Reviews
10.0 (8)

전반적인 시스템의 구조를 이해하지 못하고 있었는데 강의자료랑 웹 자료들을 보니 이해가 쉽고 빨라져서 좋았습니다

2 months ago

시스템의 기본 작동 원리를 해킹의 관점에서 체계적으로 뜯어보는 것뿐만 아니라, 학습 흐름에서 같이 디버깅해보고 관련된 문제로 연결해주는 지점이 이해에 큰 도움이 된다고 생각합니다

6 months ago

장점 1. 프로그램 작동방식을 직관적으로 배울 수 있음. 대학교에서 스택,힙,데이터,코드영역을 알려주긴 함. 근데 스택 영역이 자료구조 스택처럼 함수 호출 될 때 공간을 더 쓰고 리턴할 때 공간을 해제한다고만 배움. 드림핵에서 어셈블리, 취약점들을 배우면서 프로그램 작동방식을 직관적으로 알게 됨. 2. 컴구,운체 할 때 도움될거 같음. (글자수 부족으로 운체는 후기 X) 컴퓨터 구조를 혼자 독학해본 적이 있었음. 컴퓨터 구조 및 설계(RISC-V)이었는데 그때 배울 때는 책의 40~50퍼 정도만 이해한거 같은데 공부하고 다시 보니 파이프라이닝, 전방전달 같은 전에 추상적으로만 이해 했던게 이해 가서 재밌었음. (사실 회로 설계 공부도 해서 그렇긴 함) 단점 1. 오타 있음. 2. 설명이 가끔 생략됨.

7 months ago

기초를 다지는데 도움이 됐당께

8 months ago

처음엔 용어부터 낯설어서 많이 막막했지만 강의를 보고 하나씩 따라 치고 직접 익스플로잇에 성공하니깐 재밌었다. 이런 강의가 많이 없는데 드림핵에서 배울수 있어 정말 좋았다. 시스템해킹의 기본적인 공격 기법들을 배울수 있어서 정말 좋았다.

0% Completed Total 0 completed
Lecture 0 /33
Excluded
33
Wargame 0 /21
21
Quiz 0 /8
8
You can access locked objectives by upgrading your plan or purchasing the units separately.
The Lab is a practice and is not included in the overall progress.