A Binary Exploitation Learning Path Through CTFs
A staged, legal path from C and assembly to CTF pwn challenges: what to learn in which order, practice platforms built for it, lab rules, and how it leads to defensive careers.
Memory safety, from the defender's side
A structured reference to memory-corruption vulnerabilities in C and C++: how stack and heap overflows, use-after-free and integer bugs happen, and how compilers, sanitizers, fuzzers and safer languages stop them.
Memory map
Start with how memory is laid out, learn the classes of bugs that corrupt it, then the layers that prevent, detect, contain and triage them.
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
AddressSanitizer, UBSan and coverage-guided fuzzing with libFuzzer and AFL++.
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Memory-safe languages, safer C++ and a realistic migration strategy.
A staged, legal path from C and assembly to CTF pwn challenges and security careers.
Defense in depth
Every mitigation has gaps. Real resilience comes from stacking layers so a bug that slips past one is caught or contained by the next.
Memory-safe languages, bounds-checked APIs, compiler warnings and code review stop bugs from being written.
ASan, UBSan and coverage-guided fuzzing surface the bugs that were written, before an attacker does.
Canaries, NX, ASLR/PIE, RELRO, CFI and shadow stacks make the remaining bugs hard to exploit.
Crash triage, core dumps and deduplication turn field crashes into prioritised fixes.
Latest guides
A staged, legal path from C and assembly to CTF pwn challenges: what to learn in which order, practice platforms built for it, lab rules, and how it leads to defensive careers.
Why memory-safe languages remove whole bug classes, what Rust's ownership model guarantees, where unsafe code and FFI remain risky, and how to harden the C++ you keep.
Write a fuzz harness, build it with sanitizers, run libFuzzer and AFL++, manage corpora and dictionaries, and run continuous fuzzing in CI with OSS-Fuzz or ClusterFuzzLite.
Triage native crashes like a defender: what SIGSEGV and SIGABRT mean, glibc abort messages, gdb and core dumps, ASan reports, WinDbg, and how to prioritise memory-safety crashes.
How ASan, UBSan, MSan, TSan and HWASan work, which flags and runtime options to use, how to read an ASan report line by line, and how to run sanitizers in CI.
How forward-edge and backward-edge control-flow integrity work, from Clang CFI and Microsoft CFG to Intel CET shadow stacks and Arm pointer authentication, and their limits.
Glossary
Short, precise definitions of the terms you will meet in advisories, crash reports and compiler docs.
Editorial line
Understanding exploitation is what makes mitigations make sense. We teach the mechanics at the level a secure coder, reviewer or incident responder needs, and stop short of weaponisation.
What you will find
What we never publish