0x9000 · Area
Kernel Exploitation
A memory-corruption bug in the kernel is not about a shell — it is about privilege. The attacker already runs code as an unprivileged user; the goal is to turn a kernel bug into root, or to escape a sandbox. This area covers how the kernel represents privilege, the classic privilege-escalation payload, why the kernel's shared address space made ret2usr so easy, and the mitigations — SMEP, SMAP, KASLR, KPTI — that closed each door. Examples target a deliberately vulnerable kernel module in a throwaway VM.
Guides in this area
A kernel memory-corruption bug is about privilege, not a shell. The credential model, the commit_creds(prepare_kernel_cred(0)) payload, and returning cleanly to userspace — in a lab VM.
The kernel once trusted userspace memory, so exploits just pointed kernel execution at a user payload. SMEP and SMAP ended that — and how kernel ROP works around them.
Kernel address randomization, page-table isolation, and the config options that harden a Linux kernel against memory-corruption exploits — what each one stops and how to enable it.
Other areas
Memory Fundamentals
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Vulnerability Classes
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Exploit Mitigations
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
Finding Bugs
AddressSanitizer, UBSan and coverage-guided fuzzing with libFuzzer and AFL++.
Crash Triage
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Secure Coding
Memory-safe languages, safer C++ and a realistic migration strategy.
Learning Path
A staged, legal path from C and assembly to CTF pwn challenges and security careers.
Exploitation Techniques
ret2win, ret2libc, ROP chains, GOT overwrites and format-string primitives, built and defeated in a lab.
ARM64 Exploitation
AArch64 calling conventions, the link register, ROP on ARM, and the PAC and BTI defences.
Windows Exploitation
SEH overwrites, DEP bypass with ROP, and the SafeSEH, SEHOP, ASLR, CFG and CET mitigations.