IERG 4851

Cyber Security Laboratory

2026-27 Term 1 · The Chinese University of Hong Kong
Instructor: Yajin Zhou Friday 09:30-11:15 Lady Shaw Building LT4
View weekly schedule ↓

Course overview

A hands-on introduction to cyber security through authorized Capture The Flag challenges and laboratory exercises.

How we learn

Observe the supplied artefact, form a hypothesis, test it in the authorized environment, and explain the result.

In-class practice

Short practical exercises build confidence with tools, program behaviour, and security reasoning.

Course rule

Work only on files, binaries, and systems explicitly provided for this course or a CTF event.

Teaching Assistant

Weekly outline

Tentative. Topics and materials may be adjusted as the course progresses. New slides will appear in the lecture materials list.
WeekDateTopicSlides
1Sep 11Course Introduction & In-class Quiz; lab environment setup00 · Course Overview
01 · Introduction to CTF
01-06 · Exercise Readmes
Ungraded report: Blackboard, 17 Sep 23:59
2Sep 18Pwn 1 — Memory, the Stack & Buffer OverflowTo be posted
3Sep 25Pwn 2 — Shellcode & Control-flow Hijack (ret2win / ret2shellcode)To be posted
4Oct 2Pwn 3 — Mitigations & ROP (NX/Canary/ASLR, ret2libc)To be posted
5Oct 9Pwn 4 — Format String & Heap (+ integer overflow)To be posted
6Oct 16Pwn 5 — Kernel Exploitation (Linux kernel, Kernel ROP)To be posted
7Oct 23Web 1 — Client-side Attacks (XSS, CSRF)To be posted
8Oct 30Web 2 — Backend Vulnerabilities (SQLi, SSRF, upload, cmd injection)To be posted
9Nov 6Reverse 1 — RE Basics (Ghidra, static/dynamic)To be posted
10Nov 13Reverse 2 — Advanced RE (VM reversing, anti-debug, obfuscation)To be posted
11Nov 20Crypto — Classical, Symmetric & RSA/AsymmetricTo be posted
12Nov 27Misc — Forensics + AI/Web3 tasterTo be posted
13Dec 4Misc 2 — Forensics + AI/Web3 taster (continued)To be posted