Skip to content

0x2000 · Area

Exploit Mitigations

Mitigations do not fix bugs; they make the bugs that slip through far harder to turn into code execution. This area explains what each compiler, linker, kernel and hardware mitigation actually protects, what it costs, and how to confirm a binary really ships with it.

Guides in this area

  1. What each classic exploit mitigation protects, the GCC and Clang flags that enable it, what it costs, and how to verify a binary with checksec and readelf.

  2. How forward-edge and backward-edge control-flow integrity work, from Clang CFI and Microsoft CFG to Intel CET shadow stacks and Arm pointer authentication, and their limits.

Other areas