Buffer Overflows? In my Mainframe?

Presented at CackalackyCon 2 (2023), May 5, 2023, 9 p.m. (60 minutes)

Once thought impossible is now possible! In the early 2020s an enterprising young mainframe hacker figured out how to do mainframe buffer overflows. For decades we've heard that the mainframe are safer because buffer overflows aren't possible. Turns out that was wrong. This talk will walk you through the history of mainframe hacking, mainframe buffer overflows in C and HLASM, find them, digging in the memory (no ASLR here) and how to do RCE against a mainframe target, its harder than you think thanks to EBCDIC. We'll be using a public domain mainframe operating system to show how this is possible and giving out a docker container which trains you how to find buffer overflows and exploit them. After this talk attendees will have an understanding of mainframe hacking, MVS registers and buffer overflows.


Presenters:

Similar Presentations: