Learning Objectives
At the end of this course, students will be able to:
- classify and describe vulnerabilities and protection mechanisms of userspace applications for modern operating systems
- analyze and reason about protection mechanisms for userspace software
- identify vulnerabilities in software
- develop proofs of concept exploits/verifications to show the existence of a vulnerability in a software system understand how to write code defensively to reduce the risk of vulnerabilities
Content
The course covers the area of introductory software security, vulnerability discovery, and vulnerability verification, focusing on:
- Assembly and Disassembly, Shellcode
- Binary Reverse Engineering and Debugging
- Memory and Type Safety/Errors
- Stack-based Buffer Overflows
- Heap Attacks
- Information Leakage
- Format String Vulnerabilities
- Code Re-use Attacks
- Types and Type Safety
- Race Conditions
Requirements
The following courses (or equivalent) are required:
- System Security (211011)
- Operating Systems (211005)
Exam
Written exam (180 minutes)
Students must complete coursework in the form of assignments throughout the semester in order to be eligible to take the exam.
- Kursleiter/in: Kevin Borgolte
Semester: WiSe 2026/27