Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Bytecode Jiu-Jitsu - Forcing Execution of Malicious Bytecode Through Interpreter Manipulation

Black Hat via YouTube

Overview

Udemy Special: Ends May 28!
Learn Data Science. Courses starting at $12.99.
Get Deal
Learn about a groundbreaking conference talk from Black Hat that introduces Bytecode Jiu-Jitsu, a novel code injection attack technique targeting interpreter processes. Discover how this covert method works by dynamically replacing benign bytecode in interpreter memory to execute malicious code without triggering suspicious API calls. Explore the automated analysis technique for revealing bytecode locations and structures in interpreter binaries, making the attack applicable to proprietary interpreters with minimal human effort. Examine demonstrations showing the technique's effectiveness across various real-world interpreters, its ability to evade detection by antivirus products and forensics tools, and its capacity to disrupt behavioral analysis by sandboxes, EDRs, and malware analysts. Gain insights from NTT Security Holdings Corporation researchers and University of Tokyo experts as they present their findings and release a tool for security research and evaluation purposes.

Syllabus

Bytecode Jiu-Jitsu: Choking Interpreters to Force Execution of Malicious Bytecode

Taught by

Black Hat

Reviews

Start your review of Bytecode Jiu-Jitsu - Forcing Execution of Malicious Bytecode Through Interpreter Manipulation

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.