Skip to content

Guides tagged: #ret2win

0x8000 · ARM64 Exploitation

ARM64 Exploitation: the Link Register and ret2win

On AArch64 the return address lives in a register, not on the stack — until a non-leaf function saves it. Build the ARM ret2win in a lab and see where the saved link register sits.

0x7000 · Exploitation Techniques

Hijacking Control Flow: the ret2win Technique

A complete lab walkthrough: build a vulnerable C program, find the offset to the saved return address, redirect execution with pwntools, then watch each mitigation break the exploit.