Reverse-Engineer and Patch an N-Day Vulnerability in a Vendor Binary
Overview
What this challenge is about.
Reverse-engineer a vulnerable banking binary, patch the TLS flaw, and validate the fix. Earn a verifiable certificate.
The scenario
The bank (regulated under BaFin + DORA, the middleware terminates TLS for an internal payment-routing API) cannot remove the binary in less than 18 months due to integration debt.
The Brief
What you'll do, and what you'll demonstrate.
Reverse-engineer a vendor binary, confirm a public N-day exploit, and produce a binary-level patch that mitigates the vulnerability without breaking legitimate traffic.
Earning criteria — what you'll demonstrate
- Reverse-engineer a stripped binary to locate a documented vulnerability
- Reproduce a public N-day exploit in a controlled environment
- Design and apply a binary-level mitigation safely
- Communicate residual risk to a CISO clearly
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Reverse Engineering
Apply reverse engineering to solve real industry problems and demonstrate production-level capability.
- Binary Exploitation
Apply binary exploitation to solve real industry problems and demonstrate production-level capability.
- Ghidra
Apply ghidra to solve real industry problems and demonstrate production-level capability.
- Frida
Apply frida to solve real industry problems and demonstrate production-level capability.
- Secure Design
Apply secure design to solve real industry problems and demonstrate production-level capability.
- Exploitation And Defense
Apply exploitation and defense to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles: