Yesterday Adobe released a very serious advisory for Flash Player: http://blogs.adobe.com/psirt/2011/03/security-advisory-for-a... http://news.ycombinator.com/item?id=2328928
And I was thinking of the highest-profile hacking case I can remember, when Google was infiltrated primarily by vulnerabilities in Adobe software. If I recall correctly, maliciously crafted PDFs were e-mailed to staff with cleverly engineered "From" addresses and subjects. For example, an employee received an e-mail from their boss's e-mail address.
If you read the various news reports closely, you'll see one vector was the 0-day IE vulnerability, another was malicious payloads in PDFs.
The headlines haven't helped.
http://www.computerworld.com/s/article/9144844/Hackers_used_...
"Hackers exploited an unpatched vulnerability in Microsoft's Internet Explorer (IE) browser to break into some of the firms targeted in a widespread attack that compromised Google's and Adobe's corporate networks"
"Google and Adobe, the only two companies to have stepped forward thus far to acknowledge the attacks, were hacked using malicious PDF files that exploited a zero-day vulnerability in Adobe's popular Reader software"
for years now, whatever computer I have myself, or whenever I am setting a network policy (if the owner agrees), I always always disable flash and acrobat/pdf readr.
Once upon a time http://www.wslabi.com/ tried to create some kind of eBay for vulnerabilities too but it did not seem to go well.
This is a guide I found on /r/reverseengineering on reddit (which actually has a decent community, considering the fact that its on reddit)
http://www.amazon.com/Art-Software-Security-Assessment-Vulne...
Mark is one of the best vulnerability researchers in the world. We used to hang in the same groups, and I remember that there was a 2-3 month period where he found and wrote exploits for vulnerabilities in almost a dozen different operating systems on 5-6 different architectures. the guy is a god
Back then the only way to learn was to try it out yourself. there were no books, only phrack, IRC, and setting up boxes on your own network and having a go at them with a debugger running. you really have to be motivated, as the work is laborious, but worthwhile because there is nothing better than the rush you get from developing your own exploit. it is awesome that ppl like Mark are now writing books and dumping the knowledge they have gained through decades of real experience
there are different types and categories of exploit. local apps and targeting privilege escalation, kernel exploits, server daemons (ie. anything that has a port opening and waiting for a connection), crypto implementation exploits and then webapps and browsers (more popular today).
then there are different discovery methods: black box testing, where you throw data at an unknown system and through known inputs and outputs figure out what is in the box. white box testing, where it is still closed source, but you are able to attach a debugger, and then code auditing - which is simply going through the source code and attempting to find common errors that you can exploit.
you will find that you will levitate to one particular type as you learn. for eg. for me personally it was IIS server (found and developed 6 diff vulnerabilities for IIS 4.0 and 5.0), NT kernel and web apps. good luck with it - if you find something, send it to me :)