SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The poster emphasizes that string null termination, signed/unsigned type safety, proper use of strlen() vs sizeof(), and understanding pointer mechanics are not academic details but practical requirements that directly impact code security and stability when developing Windows implants and offensive tools. Methodology: This is a course-affiliated reference poster rather than a research survey; it distills core C programming concepts and Windows-specific patterns taught in SANS SEC670.
The entry point must be a function named main with the signature INT main(VOID). It does not require an explicit return statement; 0 is returned by default.
Many string functions (strlen, strcpy, gets) depend on the null byte (\0) to mark the end of a string. Without it, these functions produce undefined behavior and buffer overflow vulnerabilities.
strlen() returns the character count (excluding the null byte) and depends on null termination; sizeof() returns total bytes and is safe on uninitialized memory. When copying strings with null termination, use strlen() + 1 to include the terminating byte.
Assigning a negative value to an unsigned type causes the value to roll over to a large positive number. A negative value in an unsigned ULONG becomes 4,294,966,631 or similar astronomically large values, creating silent bugs.
When a pointer is incremented, it advances by the byte size of the type it points to. A PCHAR increments by 1, PULONG by 4, and PWORD by 2, allowing navigation through arrays or sequential memory structures.


Jonathan Reiter teaches advanced red team operations and Windows implant development through hands-on labs grounded in real-world experience.
Read more about Jonathan Reiter



















