Practical Course: Real-world Vulnerability Discovery and Exploits
In this practical course, you work on finding 0-day vulnerabilities in real-world software. You practically learn about exploitation techniques, bug-bounty programs, and vulnerability disclosure. Students will engage in collaborative vulnerability research investigating the security of pre-defined software targets. However, instead of working in a controlled/staged setup with toy vulnerabilities, you will analyze real-world software found in production with an undefined number of vulnerabilities. You will report your findings in the scope of the vendor's bug-bounty programs or similar disclosure procedures, striving to have a CVE number assigned to the found vulnerability. More information at https://intellisec.de/teaching/exploits