0x3000 · Area
Finding Bugs
The cheapest memory-safety bug is the one you find before release. Sanitizers turn silent corruption into loud, precise reports, and coverage-guided fuzzers generate the inputs that trigger them. Together they are the most effective bug-finding pair available to C and C++ teams.
Guides in this area
How ASan, UBSan, MSan, TSan and HWASan work, which flags and runtime options to use, how to read an ASan report line by line, and how to run sanitizers in CI.
Write a fuzz harness, build it with sanitizers, run libFuzzer and AFL++, manage corpora and dictionaries, and run continuous fuzzing in CI with OSS-Fuzz or ClusterFuzzLite.
Other areas
Memory Fundamentals
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Vulnerability Classes
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Exploit Mitigations
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
Crash Triage
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Secure Coding
Memory-safe languages, safer C++ and a realistic migration strategy.
Learning Path
A staged, legal path from C and assembly to CTF pwn challenges and security careers.