pwn 36
- PTIT CTF 2023 Finals: writeups
- PTIT CTF 2023: writeups
- Lesson 10.3: Final project, build and exploit your own vulnerable binary
- Lesson 10.2: How to write a pwn writeup, with a full worked example
- Lesson 10.1: The approach workflow for an unknown pwn binary, from triage to exploit
- Lesson 9.4: Heap Note Lab, From UAF to Shell
- Lesson 9.3: Double Free and Tcache Poisoning
- Lesson 9.2: Use-After-Free and Type Confusion
- Lesson 9.1: How malloc and free Work, Chunks, Bins, Tcache
- Lesson 8.2: ret2plt and ret2dlresolve
- Lesson 8.1: GOT Overwrite to Hijack Function Calls
- Lesson 7.2: Arbitrary Memory Writes with %n
- Lesson 7.1: Format String Bugs, Leaking the Stack and Memory
- Lesson 6.4: Lab, Solving ROP Emporium
- Lesson 6.3: Chaining ROP Gadgets and ret2syscall
- Lesson 6.2: Leaking libc Through the GOT with puts or write
- Lesson 6.1: ret2libc, calling system when NX is on
- Lesson 5.3: ASLR and PIE, why you need an address leak
- Lesson 5.2: Stack canary mechanism, leak, and brute force
- Lesson 5.1: Overview of mitigations, NX, ASLR, PIE, canary, RELRO
- Lesson 4.2: Jumping into stack shellcode with jmp rsp
- Lesson 4.1: Writing execve Shellcode by Hand
- Lesson 3.4: A ret2win Lab, Three Challenges From Easy to Hard
- Lesson 3.3: Passing a Function Argument with pop rdi
- Lesson 3.2: Finding the Saved RIP Offset and ret2win
- Lesson 3.1: Overwriting a Local Variable to Bypass a Check
- Lesson 2.3: checksec, ROPgadget, ropper, and one_gadget
- Lesson 2.2: gdb and pwndbg, Looking Inside a Running Program
- Lesson 2.1: pwntools Basics, the Skeleton of Every Exploit
- Lesson 1.4: Dangerous C Functions and Buffer Overflows
- Lesson 1.3: ELF, GOT, PLT, and Lazy Binding
- Lesson 1.2: Stack Frames, call/ret, Saved RIP, and the System V AMD64 Calling Convention
- Lesson 1.1: x86-64 Assembly Review for Pwn, Registers, Instructions, Intel vs AT&T
- Lesson 0.3: Linux Process Memory Layout and Page Permissions
- Lesson 0.2: Setting Up a Pwn Lab with Ubuntu, pwntools, pwndbg and glibc
- Lesson 0.1: Binary Exploitation and the Life Cycle of a Bug