0x8000 · Area
ARM64 Exploitation
The phone in your pocket, most modern laptops and a growing share of servers run AArch64, and its exploitation model differs from x86-64 in ways that matter: return addresses live in a register, not on the stack by default, and the architecture ships hardware defences — pointer authentication and branch-target identification — that directly attack code reuse. This area builds the same techniques from the x86-64 guides on ARM, in a lab, and explains how PAC and BTI change the game.
Guides in this area
On AArch64 the return address lives in a register, not on the stack — until a non-leaf function saves it. Build the ARM ret2win in a lab and see where the saved link register sits.
AArch64 gadgets end in ret, which branches to x30 — so the chain is threaded through the link register with ldp gadgets. Build a system("/bin/sh") chain, then watch PAC and BTI break it.
Pointer authentication signs return addresses so a forged one faults; BTI forces indirect branches onto landing pads. How both work, how to enable and verify them, and their limits.
Other areas
Memory Fundamentals
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Vulnerability Classes
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Exploit Mitigations
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
Finding Bugs
AddressSanitizer, UBSan and coverage-guided fuzzing with libFuzzer and AFL++.
Crash Triage
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Secure Coding
Memory-safe languages, safer C++ and a realistic migration strategy.
Learning Path
A staged, legal path from C and assembly to CTF pwn challenges and security careers.
Exploitation Techniques
ret2win, ret2libc, ROP chains, GOT overwrites and format-string primitives, built and defeated in a lab.