Skip to content

0x8000 · Area

ARM64 Exploitation

The phone in your pocket, most modern laptops and a growing share of servers run AArch64, and its exploitation model differs from x86-64 in ways that matter: return addresses live in a register, not on the stack by default, and the architecture ships hardware defences — pointer authentication and branch-target identification — that directly attack code reuse. This area builds the same techniques from the x86-64 guides on ARM, in a lab, and explains how PAC and BTI change the game.

Guides in this area

  1. On AArch64 the return address lives in a register, not on the stack — until a non-leaf function saves it. Build the ARM ret2win in a lab and see where the saved link register sits.

  2. AArch64 gadgets end in ret, which branches to x30 — so the chain is threaded through the link register with ldp gadgets. Build a system("/bin/sh") chain, then watch PAC and BTI break it.

  3. Pointer authentication signs return addresses so a forged one faults; BTI forces indirect branches onto landing pads. How both work, how to enable and verify them, and their limits.

Other areas