Binary Exploitation
My notes on Linux x86-64 binary exploitation, from the process memory model and tooling through stack overflows, shellcode, mitigations, ROP, format strings, GOT/PLT and basic heap. Every exploit lesson is built against Ubuntu 24.04 with glibc 2.39 and the payloads are run for real.
The labs ship with source, a build script and an exploit. Everything is for learning, CTFs, and systems you are allowed to test.
Pwn · Getting Started
| # | Lesson |
|---|---|
| 0.1 | Binary Exploitation and the Life Cycle of a Bug |
| 0.2 | Setting Up a Pwn Lab with Ubuntu, pwntools, pwndbg and glibc |
| 0.3 | Linux Process Memory Layout and Page Permissions |
Pwn · Foundations
Pwn · Tooling
| # | Lesson |
|---|---|
| 2.1 | pwntools Basics, the Skeleton of Every Exploit |
| 2.2 | gdb and pwndbg, Looking Inside a Running Program |
| 2.3 | checksec, ROPgadget, ropper, and one_gadget |
Pwn · Buffer Overflow
| # | Lesson |
|---|---|
| 3.1 | Overwriting a Local Variable to Bypass a Check |
| 3.2 | Finding the Saved RIP Offset and ret2win |
| 3.3 | Passing a Function Argument with pop rdi |
| 3.4 | A ret2win Lab, Three Challenges From Easy to Hard |
Pwn · Shellcode
Pwn · Mitigations
| # | Lesson |
|---|---|
| 5.1 | Overview of mitigations, NX, ASLR, PIE, canary, RELRO |
| 5.2 | Stack canary mechanism, leak, and brute force |
| 5.3 | ASLR and PIE, why you need an address leak |
Pwn · ret2libc and ROP
| # | Lesson |
|---|---|
| 6.1 | ret2libc, calling system when NX is on |
| 6.2 | Leaking libc Through the GOT with puts or write |
| 6.3 | Chaining ROP Gadgets and ret2syscall |
| 6.4 | Lab, Solving ROP Emporium |
Pwn · Format String
Pwn · GOT and PLT
Pwn · Heap Basics
| # | Lesson |
|---|---|
| 9.1 | How malloc and free Work, Chunks, Bins, Tcache |
| 9.2 | Use-After-Free and Type Confusion |
| 9.3 | Double Free and Tcache Poisoning |
| 9.4 | Heap Note Lab, From UAF to Shell |