Skip to content

Memory safety, from the defender's side

Understand the bug.Ship the mitigation.

A structured reference to memory-corruption vulnerabilities in C and C++: how stack and heap overflows, use-after-free and integer bugs happen, and how compilers, sanitizers, fuzzers and safer languages stop them.

areas
11
in-depth guides
35
glossary terms
28

Memory map

Seven areas, one bug lifecycle

Start with how memory is laid out, learn the classes of bugs that corrupt it, then the layers that prevent, detect, contain and triage them.

Defense in depth

No single control is enough

Every mitigation has gaps. Real resilience comes from stacking layers so a bug that slips past one is caught or contained by the next.

  1. Prevent

    Memory-safe languages, bounds-checked APIs, compiler warnings and code review stop bugs from being written.

    • Rust
    • std::span
    • -Wformat=2
    • ckd_add
  2. Detect

    ASan, UBSan and coverage-guided fuzzing surface the bugs that were written, before an attacker does.

    • ASan
    • UBSan
    • libFuzzer
    • AFL++
  3. Mitigate

    Canaries, NX, ASLR/PIE, RELRO, CFI and shadow stacks make the remaining bugs hard to exploit.

    • canary
    • NX
    • PIE
    • RELRO
    • CET
  4. Respond

    Crash triage, core dumps and deduplication turn field crashes into prioritised fixes.

    • gdb
    • coredumpctl
    • !analyze

Latest guides

Read the deep dives

All guides
0x9000 · Kernel Exploitation

KASLR, KPTI and Modern Kernel Defenses

Kernel address randomization, page-table isolation, and the config options that harden a Linux kernel against memory-corruption exploits — what each one stops and how to enable it.

0x9000 · Kernel Exploitation

Kernel Exploitation: From a Bug to root

A kernel memory-corruption bug is about privilege, not a shell. The credential model, the commit_creds(prepare_kernel_cred(0)) payload, and returning cleanly to userspace — in a lab VM.

0x9000 · Kernel Exploitation

ret2usr, SMEP and SMAP

The kernel once trusted userspace memory, so exploits just pointed kernel execution at a user payload. SMEP and SMAP ended that — and how kernel ROP works around them.

0x2000 · Exploit Mitigations

The Mitigation Stack: Which Defenses, In Order

Every exploit walks the same stages: bug, corruption, hijack, code execution, escalation. A defender's checklist of which mitigation stops each — across Linux, ARM, Windows and the kernel.

0xa000 · Windows Exploitation

Bypassing DEP on Windows with ROP

DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.

0xa000 · Windows Exploitation

Windows Flow-Integrity Mitigations: CFG and CET

How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.

Editorial line

Defensive by design

Understanding exploitation is what makes mitigations make sense. We teach the mechanics at the level a secure coder, reviewer or incident responder needs, and stop short of weaponisation.

What you will find

  • Vulnerable patterns next to their fixes
  • Compiler, linker and sanitizer flags you can ship
  • How to verify mitigations with checksec and readelf
  • How to read crash and sanitizer reports

What we never publish

  • Working exploit chains or shellcode
  • Step-by-step bypasses of mitigations
  • Payloads aimed at real software
  • Solutions to live CTF challenges