0xa000 · Area
Windows Exploitation
Windows shares the memory-corruption fundamentals of Linux but has its own exploitation history and its own defences. This area covers the technique Windows made famous — overwriting a Structured Exception Handler to hijack control — then bypassing DEP with a ROP chain that calls VirtualProtect, and the flow-integrity mitigations that answered each: SafeSEH and SEHOP, ASLR, Control Flow Guard and, most recently, hardware CET. Examples build a deliberately vulnerable program in a throwaway Windows VM.
Guides in this area
Windows keeps a linked list of exception handlers on the stack. Overflow into one, point it at a pop-pop-ret, trigger a fault, and control is yours — the technique Windows made famous.
DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.
How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.
Other areas
Memory Fundamentals
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Vulnerability Classes
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Exploit Mitigations
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
Finding Bugs
AddressSanitizer, UBSan and coverage-guided fuzzing with libFuzzer and AFL++.
Crash Triage
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Secure Coding
Memory-safe languages, safer C++ and a realistic migration strategy.
Learning Path
A staged, legal path from C and assembly to CTF pwn challenges and security careers.
Exploitation Techniques
ret2win, ret2libc, ROP chains, GOT overwrites and format-string primitives, built and defeated in a lab.
ARM64 Exploitation
AArch64 calling conventions, the link register, ROP on ARM, and the PAC and BTI defences.
Kernel Exploitation
Privilege escalation from a kernel bug: the credential model, ret2usr, and SMEP, SMAP, KASLR and KPTI.