CS356 Software Exploitation

Instructor information

Instructor:W. Michael Petullo
Office location:210 Wing Technology Center
Office hours:2:00 p.m–3:00 every weekday and by appointment
Telephone:(608) 785-6817

Catalog description

This course examines techniques for exploiting vulnerable software. Topics include binary reverse engineering, source code analysis, intrusion, and exploitation. The course will also discuss matters of reconnaissance, privilege escalation, lateral movement, obfuscation, and exfiltration. Students are expected to write low-level exploits using modern tools and deploy them against vulnerable services in a laboratory environment.


CS270 and CS340

Time and location

Tuesday and Thursday at 9:25–10:40 a.m. Class meets in Morris 370.

Student learning objectives

This course follows the Computer Science Department’s learning objectives for CS356, which are listed below. The course schedule indicates the objectives covered by each lesson.

  1. Understand the operational sequence employed by cyber attacks, including reconnaissance, intrusion, exploitation, privilege elevation, lateral movement, obfuscation, and exfiltration.

  2. Understand opportunities for reconnaissance and exploitation presented by network software.

  3. Overcome countermeasures to exploit buffer overflows and other memory errors.

  4. Understand how to write shellcode.

  5. Understand techniques to exploit web-based software.

  6. Apply program analysis tools to find programming errors in software.

  7. Understand how to perform binary reverse engineering of software.


(2008). Hacking: The Art of Exploitation. No Starch Press.

Classroom standards

Please be prepared to take notes using a pen and paper, or use discipline while taking digital notes. Do not use the Internet for personal reasons during class. Do bring a laptop or other device capable of running the compilers and other tools we use in class; any lecture might include hands-on exercises.

Perform your assigned reading and other preparation before arriving for class. I will expect you to participate in class discussions, and I might call on you to contribute.

You are reminded of Board of Regents' Student Academic Disciplinary Procedures concerning academic integrity. Cheating undermines the integrity of this university and shows disrespect towards the work of your classmates. Starting coursework early will help you to avoid the temptation of cheating. Plagiarism or cheating in any form may result in a failing grade, and might also warrant harsher disciplinary action. “Students are responsible for the honest completion and representation of their work, for the appropriate citation of sources, and for respect of others' academic endeavors.”

On perseverance and the scientific method

You will inevitably encounter problems while trying to complete your coursework. Sometimes you will be led astray by the confusing interfaces that our software applications present, and other times you will simply make an error. When something goes wrong, try to fix the problem! Make small, incremental changes, and observe their effects. Most importantly, think about how systems work, and then consider why the error you are observing might have arisen. Occasionally, you should stop what you are doing and start from scratch. Learning how to better troubleshoot should be a beneficial side effect of this course.

Graded events

Homework will be submitted through Aquinas, a grading system that provides immediate feedback. Refer to the course schedule for the sequence of homework assignments, exams, and the final exam. Your running grade will be available through Aquinas.

EventPortion of grade
Homework33% (3% per assignment)
Exams37% (18½% per exam)
Instructor points5%
Final exam25%

Grade scale

Grades are assigned based on the following scale.


Late policy

Assignments are due the moment class starts. Late assignments will lose points according to the table below.

Up to 24 hours late15% reduction
24–48 hours late30% reduction
More than 48 hours lateNo credit

If some external circumstance might cause you to be late, then you must notify your instructor in writing and before the assignment deadline in order to be considered for an exception. The act of notification does not automatically grant you an exception.

COVID-19 health statement

Students with COVID-19 symptoms or reason to believe they were in contact with COVID-19 should consult with a health professional, such as the Student Health Center. Students who are ill or engaging in self-quarantine at the direction of a health professional must not attend class. Students in this situation will not be required to provide formal documentation and will not be penalized for absences. However, students should: 

  • notify the instructor in advance of the absence, and provide him with an estimate of how long the absence might last;
  • keep up with classwork, if able;
  • submit assignments electronically;
  • work with the instructor to either reschedule or remotely complete exams, labs, and other academic activities; and
  • consistently communicate their status to the instructor during the absence. 

Instructors have an obligation to provide reasonable accommodation for completing course requirements to students adversely effected by COVID-19. This policy relies on honor, honesty, and mutual respect between instructors and students. Students are expected to report the reason for absence truthfully and instructors are expected to trust the word of their students. University codes of conduct and rules for academic integrity apply to COVID-19 situations. Students may be advised by their instructor or academic advisor to consider a medical withdrawal depending on the course as well as the timing and severity of the illness. Students should work with the Office of Student Life if pursuing a medical withdrawal.