0x8000 · ARM64 Exploitation
ARM64 Exploitation: the Link Register and ret2win
On AArch64 the return address lives in a register, not on the stack — until a non-leaf function saves it. Build the ARM ret2win in a lab and see where the saved link register sits.