Skip to content

0xa000 · Area

Windows Exploitation

Windows shares the memory-corruption fundamentals of Linux but has its own exploitation history and its own defences. This area covers the technique Windows made famous — overwriting a Structured Exception Handler to hijack control — then bypassing DEP with a ROP chain that calls VirtualProtect, and the flow-integrity mitigations that answered each: SafeSEH and SEHOP, ASLR, Control Flow Guard and, most recently, hardware CET. Examples build a deliberately vulnerable program in a throwaway Windows VM.

Guides in this area

  1. Windows keeps a linked list of exception handlers on the stack. Overflow into one, point it at a pop-pop-ret, trigger a fault, and control is yours — the technique Windows made famous.

  2. DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.

  3. How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.

Other areas