Skip to content

Guides tagged: #windows

0xa000 · Windows Exploitation

Bypassing DEP on Windows with ROP

DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.

0xa000 · Windows Exploitation

Windows Flow-Integrity Mitigations: CFG and CET

How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.

0xa000 · Windows Exploitation

SEH Overwrites: Hijacking Windows Exceptions

Windows keeps a linked list of exception handlers on the stack. Overflow into one, point it at a pop-pop-ret, trigger a fault, and control is yours — the technique Windows made famous.