Every lesson in the Computer Security slide course, in full text: 42 decks, 3326 slides.
L01 · Security Principles I (Threat Models, Human Factors, Economics)CS 161, Lesson 1. It covers threat models, attacker assumptions, human factors, security economics, and the principle of detecting what you cannot prevent, across 20 slides anchored to textbook sections 1.1 to 1.4 and to Saltzer & Schroeder (1975).
L02 · Security Principles II (the remaining nine: Defense in Depth → TOCTTOU)CS 161, Lesson 2, in 50 slides. It covers the nine remaining design principles: defense in depth, least privilege, separation of responsibility, complete mediation, Shannon's Maxim, fail-safe defaults, designing security in from the start, the Trusted Computing Base, and TOCTTOU races. It is anchored to textbook sections 1.5 to 1.13 and to Saltzer & Schroeder (1975).
L03 · Threat Modeling (STRIDE/DFD) + TCB & TOCTTOU LabsCS 161, Lesson 3 and Quiz 3, in 48 slides. It covers structured threat modeling with STRIDE and data-flow diagrams, marked as supplemental, then a TCB-identification exercise from section 1.12 and the classic access()/open() symlink TOCTTOU lab from section 1.13. It applies all 13 principles from Lessons 1 and 2.
L04 · Numbers, the Toolchain, and 32-bit C Memory LayoutCS 161, Lesson 4, in 50 slides and code mode. It covers binary, hexadecimal, and two's-complement representation, the toolchain that turns source into a running process, the ELF sections (supplemental), and the four-section 32-bit C memory layout - code, static, heap, and stack - with the direction each one grows. It is anchored to textbook sections 2.1 to 2.3, and all conversions were verified.
L05 · Little-Endian, the Registers eip/ebp/esp, and Push/PopCS 161, Lesson 5, in 50 slides and code mode. It covers little-endian byte order, the three special 32-bit registers eip, ebp, and esp, and push and pop as decrement-then-write and read-then-increment, with a full esp trace table. It is anchored to textbook sections 2.4 to 2.6.
L06 · The 11-Step Calling Convention & Stack-Frame AnatomyCS 161, Lesson 6 and Quiz 6, in 50 slides and code mode. It covers the full 11-step x86 cdecl call and return, the prologue and epilogue, ebp-relative addressing with arguments at ebp+8, and the assembly for foo(1,2) with leave and ret. It includes two full call-trace tables and is anchored to textbook sections 2.7 to 2.9.
L07 · Reading x86 Assembly + GDB (and the C→memory bridge)CS 161, Lesson 7, in 50 slides and code mode. You learn to read gcc -S -O0 output, recognize the prologue, body, and epilogue, and decode MOV, LEA, ADD, SUB, CMP, JE, JNE, and JMP along with the AT&T addressing modes. You then annotate assembly instruction by instruction and step through it in gdb using stepi, info registers, and x/8xw $esp, closing on the unbounded C strcpy copy loop that sets up the overflow in Lesson 8. It includes several full trace tables and is anchored to textbook section 2.9.
L08 · Buffer Overflows & Stack SmashingCS 161, Lesson 8, in 50 slides and code mode. It explains why C has no bounds checking, then works the vulnerable gets(buf) frame, the 8 + 4 = 12-byte offset to the saved rip, and how an address is typed in little-endian order. It covers three shellcode-placement strategies, NOP sleds, the history of the worm, and the fgets fix. The examples are toys running in a sandbox, and it is anchored to textbook sections 3.1 to 3.2.
L09 · Format Strings, Integer Conversion & Off-by-One BugsCS 161, Lesson 9, in 50 slides and code mode. It covers three classes of memory-safety vulnerability: format-string bugs, through printf's walk up the stack, the %x leak, and the %n write; integer conversion bugs, through signed against unsigned, overflow that under-allocates, and truncation; and off-by-one bugs, through the fence-post error, a single-null overwrite of the saved frame pointer, and strncpy leaving a string unterminated. It includes several full trace tables and is anchored to textbook sections 3.3 to 3.5.
L10 · Heap Bugs: Use-After-Free, Double-Free, vtable & Type ConfusionCS 161, Lesson 10, in 50 slides and code mode. It covers dangling pointers and use-after-free, the exploitation primitive in which two objects share one block, double-free corrupting the allocator's free list, and the C++ vtable-pointer overwrite, which hijacks a pointer to a pointer. It adds type confusion as supplemental material and explains why stack canaries do nothing for the heap. The examples are toys running in a sandbox, and it is anchored to textbook section 3.6.
L11 · Memory-Safe Languages, Safer C, and the Secure Software ProcessCS 161, Lesson 11, in 50 slides and code mode. It lays out the spectrum of memory-safety fixes: memory-safe languages, which are the only 100% guarantee; Rust's ownership and borrow model, which achieves that without a garbage collector; safer C through pre- and post-conditions and bounds-checked library calls, replacing gets with fgets, strcpy with strncpy or strlcpy, and sprintf with snprintf; and the secure-development process, covering controlled crashes, code review, fuzzing, Valgrind, sanitizers, static analyzers, and the SDL. It is anchored to textbook sections 4.1 to 4.3.
L12 · Exploit Mitigations Overview: NX, Stack Canaries, ASLRCS 161, Lesson 12, in 50 slides and code mode. It explains why mitigations exist at all when you are stuck writing C, then covers non-executable pages - NX, W^X, and DEP - which stop injected shellcode; stack canaries, which detect a contiguous overwrite of the saved rip; and ASLR, which randomizes absolute addresses but not relative offsets. It gives the consolidated table mapping each mitigation to its attack and its bypass, and explains why combining all three is synergistic. This is an overview only, since the deep bypasses come in Week 5. The examples are toys running in a sandbox, and it is anchored to textbook sections 4.4, 4.5, 4.8, and 4.11.
L13 · Non-Executable Pages & Return-to-libcCS 161, Lesson 13, in 54 slides and code mode. It covers W^X and NX pages and the NX bit in the page table, why the buffer-injection attack from Lesson 8 now faults, and the code-reuse insight that defeats NX. It then builds the 32-bit ret2libc stack layout, with its fake return address and argument pointer, shows how to find the libc base with ASLR off and why you need a leak with ASLR on, and chains libc calls toward ROP. The examples are toys running in a sandbox and the addresses are kept symbolic. It is anchored to textbook sections 4.5 to 4.6.
L14 · Return-Oriented Programming & Stack CanariesCS 161, Lesson 14, in 50 slides and code mode. It generalizes ret2libc into ROP gadget chains, works the book's two-gadget example that adds 4 to edx, and covers finding gadgets and chaining them across rets. It then covers stack canaries from section 4.8 - a random word containing a NULL, placed between the locals and the saved registers and checked on return - and the limits of the canary that lead into Lesson 15. The examples are toys running in a sandbox, and it is anchored to textbook sections 4.7 to 4.8.
L15 · Subverting Canaries, Pointer Authentication, ASLR & Combining MitigationsCS 161, Lesson 15, in 50 slides and code mode. It covers the three things canaries do not stop, guessing a canary against leaking one - 24 bits of entropy against 56 - and pointer authentication, which stuffs a PAC into unused address bits. It then subverts ASLR by guessing or leaking a single absolute address, since rip = sfp + 4, and explains why combining ASLR, NX, and canaries forces an attacker to find both a leak AND a write. The examples are toys running in a sandbox, and it is anchored to textbook sections 4.9 to 4.13.
L16 · Cryptography Intro: History, Definitions, KeysCS 161, Lesson 16, in 50 slides, opening the cryptography unit. It gives a brief history - the Caesar cipher, Enigma, and Shannon and DES - then explains why we need formal definitions, introduces the cast of Alice, Bob, Eve, and Mallory, and distinguishes symmetric from asymmetric keys. It is anchored to textbook sections 5.2 to 5.5.
L17 · Confidentiality, Integrity, Authenticity & the Scheme FamiliesCS 161, Lesson 17, in 51 slides. It covers the three core goals of cryptography - confidentiality, integrity, and authenticity - plus deniability, and lays out the two-by-two grid of scheme families, crossing symmetric against asymmetric with confidentiality against integrity. It is anchored to textbook sections 5.6 to 5.7.
L18 · Kerckhoff's Principle, Attacker Models & IND-CPACS 161, Lesson 18, in 50 slides. It covers Kerckhoff's Principle, which holds that the key is the only secret, then the hierarchy of attacker models running from COA through KPA, replay, CPA, and CCA to CCA2, and an informal IND-CPA security game. Together these set the rules of the game for the whole cryptography unit. It is anchored to textbook sections 5.8 to 5.9 and to section 6.1.
L19 · One-Time Pad, XOR & the IND-CPA GameCS 161, Lesson 19, in 50 slides. It covers XOR and its algebra in section 6.2, the one-time pad and its perfect secrecy in section 6.3, and the fatal two-time-pad break that key reuse allows, as seen in VENONA. It then gives the formal IND-CPA game from section 6.1 and uses it to prove that a one-time pad with a reused key is not IND-CPA. It is anchored to textbook sections 6.1 to 6.3.
L20 · Block Ciphers, PRPs & Modes of Operation (ECB/CBC/CTR)CS 161, Lesson 20, in 52 slides. It explains what a block cipher is - a keyed permutation - why AES on its own is not IND-CPA even though it is a strong PRP, and how the modes of operation ECB, CBC, and CTR, together with parallelization, turn the primitive into a usable scheme. It is anchored to textbook sections 6.4 to 6.7.
L21 · Padding (PKCS#7), Parallelization Trade-offs & IV ReuseCS 161, Lesson 21, in 56 slides. It explains why CBC needs PKCS#7 padding while CTR does not, works the parallelization trade-offs between CBC and CTR, and shows why reusing an IV is catastrophic for CTR but merely contained for CBC. This is where IND-CPA is won or lost in practice. It is anchored to textbook sections 6.7 to 6.9.
L22 · Cryptographic Hash FunctionsCS 161, Lesson 22, in 51 slides. It explains what a cryptographic hash is and why it is avalanche-prone, deterministic, and unkeyed, in section 7.1, then gives the three security properties in section 7.2: preimage resistance, second-preimage resistance, and collision resistance. It covers using hashes for integrity and the trusted-channel limit, also in section 7.2, then real algorithms, including SHA-2's length-extension flaw and the birthday bound, in section 7.3, and closes with the lowest-hash verification scheme in section 7.4. It is anchored to textbook sections 7.1 to 7.4.
L23 · Message Authentication Codes: EUF-CMA, AES-EMAC, HMACCS 161, Lesson 23, in 51 slides. It explains what a MAC is and what it guarantees, in sections 8.1 and 8.2, then defines unforgeability through the EUF-CMA forgery game in section 8.3. It covers the AES-EMAC CBC-MAC construction and its two-key final step in section 8.4, and HMAC, built from NMAC with the ipad and opad key transform, in section 8.5 - including why the naive Hash(K||M) is forgeable. It is anchored to textbook sections 8.1 to 8.5.
L24 · Authenticated Encryption & AEADCS 161, Lesson 24, in 50 slides. It explains why a MAC gives no confidentiality, in section 8.6, then combines encryption with a MAC and compares the two orders in section 8.7: encrypt-then-MAC against MAC-then-encrypt, with the padding-oracle break that the latter allows. It covers authenticated encryption with associated data in section 8.8, and AES-GCM together with its catastrophic failure under nonce reuse. It is anchored to textbook sections 8.6 to 8.8.
L25 · Randomness, Entropy, pRNGs & Rollback ResistanceCS 161, Lesson 25, in 50 slides. It explains what randomness and entropy mean for cryptography, in section 9.1, then covers the pseudorandom generator with its Seed, Reseed, and Generate interface and the computational indistinguishability it aims at, in sections 9.1 and 9.2, and rollback resistance against state compromise in section 9.3. It adds real-world entropy failures - VM snapshots, the Debian OpenSSL bug, and weak entropy at boot - flagged as enrichment. It is anchored to textbook sections 9.1 to 9.3.
L26 · HMAC-DRBG & Stream CiphersCS 161, Lesson 26, in 51 slides. It covers HMAC-DRBG, a secure pseudorandom generator built from HMAC, along with its Seed and Generate algorithms, its absorption of low-entropy input, and its rollback resistance, in section 9.4, then the Dual_EC_DRBG backdoor as enrichment. It closes with stream ciphers in section 9.5: the keystream used as a one-time pad, the formal Enc and Dec scheme, the roughly 2^64-bit limit on AES-CTR, and ChaCha20's counter-driven random access. It is anchored to textbook sections 9.4 to 9.5.
L27 · Diffie-Hellman Key Exchange, ECDH & MITMCS 161, Lesson 27, in 54 slides. It states the key-exchange problem and gives the paint intuition, in sections 10 and 10.1, then covers one-way functions and the discrete-log problem in section 10.2 and the Diffie-Hellman protocol with a worked toy example in section 10.3. It goes on to elliptic-curve Diffie-Hellman and the equivalences in bit strength, in sections 10.4 and 10.5, and ends with the man-in-the-middle attack that forces authentication, in section 10.6. It is anchored to textbook sections 10.1 to 10.6.
L28 · Public-Key Encryption: Trapdoor Functions, RSA & El GamalCS 161, Lesson 28, in 50 slides. It explains why asymmetric cryptography solves the pre-shared-key problem, in section 11.1, then covers trapdoor one-way functions and the hard problems behind RSA and discrete log, in section 11.2. It covers RSA encryption and why textbook RSA is deterministic and therefore not IND-CPA without OAEP padding, in section 11.3, and El Gamal encryption built on Diffie-Hellman, with a fully worked toy example, in section 11.4. It is anchored to textbook sections 11.1 to 11.4.
L29 · Public-Key Distribution, Hybrid Encryption & Session KeysCS 161, Lesson 29, in 51 slides. It covers the public-key distribution problem and the Attila key-substitution attack, in section 11.5, then why public-key cryptography is too slow to encrypt data directly and how hybrid encryption with session keys and its four-key setup solves that, in section 11.6. Supplemental material covers KEM and DEM, post-quantum cryptography, and Shor's and Grover's algorithms. It is anchored to textbook sections 11.5 to 11.6.
L30 · Digital Signatures: RSA Signatures, Number Theory & EUF-CMACS 161, Lesson 30, in 56 slides. It presents digital signatures as public-key MACs with the roles reversed, in section 12.1, then the hash-then-sign RSA idea in section 12.2, the number theory that builds the trapdoor in section 12.3, the RSA signature scheme in section 12.4, and EUF-CMA security and its dependence on the hash in section 12.5. It is anchored to textbook sections 12.1 to 12.5.
L31 · Certificates, PKI, Chains, Revocation & Web of TrustCS 161, Lesson 31, in 53 slides. It covers the public-key authenticity problem and the trusted directory, in sections 13.1 and 13.2, then self-validating digital certificates in section 13.3, and PKI and certificate authorities with the HTTPS trust model in section 13.4. It goes on to certificate chains and hierarchical PKI in section 13.5, revocation through validity periods and CRLs in section 13.6, and the web of trust together with leap-of-faith, or TOFU, in sections 13.7 and 13.8. It is anchored to textbook sections 13.1 to 13.8.
L32 · Password Risks & MitigationsCS 161, Lesson 32, in 54 slides. It covers the five password risk vectors in section 14.1, eavesdropping and SSL/TLS in section 14.2, client-side malware and two-factor authentication in section 14.3, and the statistics of online guessing in section 14.4. It then covers the mitigations - rate limiting, CAPTCHAs, and password requirements - in section 14.5, and server compromise and why you must never store cleartext, in section 14.6. It is anchored to textbook sections 14.1 to 14.6.
L33 · Password Hashing: Salt, Slow Hashes & Key DerivationCS 161, Lesson 33, in 51 slides. It explains why storing H(w) is not enough, in section 14.7, then covers the offline guessing attack and the amortized precomputation attack, and the two defenses given in section 14.8: a per-user salt, and slow iterated hashing. It closes with what this implies for key derivation, in section 14.9. It is anchored to textbook sections 14.7 to 14.9.
L34 · Bitcoin: Identities, Transactions, Hash Chains & Proof of WorkCS 161, Lesson 34, in 51 slides. It presents Bitcoin as a digital currency that has the properties of physical money but NO trusted bank, in section 16.1, then public keys as identities in sections 16.2 and 16.3, and the signed transaction ledger with balances computed by replay, in sections 16.4 and 16.5. It covers the append-only hash chain and tamper detection in sections 16.6 and 16.7, and consensus by proof of work under the longest-chain rule, in sections 16.8 and 16.9. It is anchored to textbook sections 16.1 to 16.9.
L35 · SQL Injection & Code InjectionCS 161, Lesson 35, in 50 slides. It presents code injection as the pattern in which data becomes code, in section 17.1, then SQL injection as its canonical instance in section 17.2, and the anatomy of an injection payload together with the OR 1=1 login bypass, in section 17.3. It covers escaping and why it is fragile in section 17.4, and parameterized queries as the real fix, since they separate code from data, in section 17.5. This is authorized security education using toy examples in a sandbox only, and it is anchored to textbook sections 17.1 to 17.5.
L36 · Web Basics: URLs, HTTP, HTML, the DOM & JavaScriptCS 161, Lesson 36, in 57 slides. It covers the browser and protocol model that sits behind every web attack: the parts of a URL in section 18.1, the HTTP request and response model with GET against POST in sections 18.2 to 18.5, the webpage as a distributed application together with HTML and frame isolation in sections 18.6 and 18.7, and CSS, JavaScript, the DOM, and the JavaScript sandbox in sections 18.8 and 18.9. It is anchored to textbook sections 18.1 to 18.9.
L37 · The Same-Origin PolicyCS 161, Lesson 37, in 50 slides. It covers the browser's core isolation boundary: why the same-origin policy exists, in section 19; what an origin is, namely the scheme, host, and port, in section 19.1; and what the policy restricts against what it allows, which is the difference between reading and embedding, in section 19.2. That same section also gives the exam-critical rules for assigning an origin to scripts, images, and frames, and covers controlled cross-origin communication through postMessage. It is anchored to textbook sections 19.1 to 19.2.
L38 · Cookies & Session ManagementCS 161, Lesson 38, in 53 slides. It explains why the statelessness of HTTP forces cookies, in section 20, then covers the cookie attributes in section 20.1, the send rule of domain-suffix plus path-prefix in section 20.2, and the set rule of suffix-of-server in section 20.3. It closes with session tokens and the gap between cookie policy and the same-origin policy that lets different origins share a cookie, in sections 20.4 and 20.5. It is anchored to textbook sections 20.1 to 20.5.
L39 · Cross-Site Request Forgery (CSRF)CS 161, Lesson 39, in 50 slides, on cross-site request forgery. It shows how an attacker rides the victim's automatically attached session cookie to forge state-changing requests, in section 21.1, covers CSRF based on GET and on POST, and explains why the same-origin policy does not stop it. It then gives the three defenses - CSRF tokens, Referer validation, and the SameSite cookie attribute - in sections 21.2 to 21.4. It is anchored to textbook sections 21.1 to 21.4.
L40 · Cross-Site Scripting (XSS)CS 161, Lesson 40, in 52 slides, on cross-site scripting. It shows how an attacker injects JavaScript that the victim's browser then RUNS with the target site's origin, defeating the same-origin policy, in section 22, and covers stored XSS and reflected XSS in sections 22.1 and 22.2. It then gives the defenses: sanitizing input by HTML-encoding it, in section 22.3, and Content Security Policy, in section 22.4. It is anchored to textbook sections 22.1 to 22.4.
L41 · Clickjacking, UI Attacks, Phishing & CAPTCHAsCS 161, Lesson 41, in 54 slides. It covers the UI attacks that "steal a click" - fake download buttons, mismatched form values, and fake cursors and browser chrome - in section 23.1, with the defenses in section 23.2. It then covers phishing with valid certificates, homograph URLs, and browser-in-browser attacks, in section 23.3. It ends with CAPTCHAs in sections 24.1 and 24.2: what they ask, why they lose the arms race, and the roughly ten-cents-per-solve farm economics that defeat them. It is anchored to textbook sections 23.1 to 24.2.
L42 · Introduction to Networking: Layers, Addressing & AdversariesCS 161, Lesson 42, in 54 slides, opening the network-security unit. It covers LANs, routers, and WANs through the postal model, in section 25.1, then layers of abstraction and the OSI model in section 25.2, protocols, headers, and encapsulation in section 25.3, and MAC, IP, and port addressing in section 25.4. It ends with packets against connections and the taxonomy of off-path, on-path, and in-path adversaries, in sections 25.5 and 25.6. It is anchored to textbook sections 25.1 to 25.6.
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.