Skip to content

Guides tagged: #rop

0x8000 · ARM64 Exploitation

ROP on ARM64: Gadgets and the Link Register

AArch64 gadgets end in ret, which branches to x30 — so the chain is threaded through the link register with ldp gadgets. Build a system("/bin/sh") chain, then watch PAC and BTI break it.

0x7000 · Exploitation Techniques

Seccomp Sandboxes and the open-read-write Chain

A seccomp policy that bans execve takes the shell off the table, so attackers switch goals: open the flag, read it, write it back. Build the ORW chain, and see what a tighter policy stops.

0x7000 · Exploitation Techniques

ret2csu: Borrowing the Runtime's Universal Gadget

No pop rdx gadget? The C runtime's startup code has a universal sequence that loads several registers and makes a controlled call. Build it with pwntools, and see where it's gone.

0x7000 · Exploitation Techniques

SROP: Exploiting with a Fake Signal Frame

When gadgets are scarce, forge a signal frame. A sigreturn syscall restores every register from the stack at once — build one with pwntools to call execve, then see how seccomp and CET respond.

0x7000 · Exploitation Techniques

Stack Pivoting: Relocating the ROP Chain

When the overflow gives you only a few bytes past the return address, pivot the stack pointer into a buffer you fully control and run the real chain from there. A pwntools walkthrough.

0x7000 · Exploitation Techniques

Returning into libc: the ret2libc Technique

NX is on and the binary is tiny, but libc is mapped and full of useful code. Leak its base past ASLR, then return straight into system("/bin/sh") — a full two-stage pwntools walkthrough.

0x7000 · Exploitation Techniques

Building a ROP Chain Step by Step

With NX on, injected shellcode is dead — so we reuse the program's own code. A full lab walkthrough: find gadgets, hand-build an execve syscall chain with pwntools, then watch CET and CFI break it.