0x7000 · Área
Técnicas de explotación
Un error solo es una vulnerabilidad cuando alguien lo convierte en control del programa. Esta área recorre de principio a fin las técnicas clásicas que lo logran — secuestrar una dirección de retorno guardada, encadenar código existente con ROP, volver a llamar a libc, sobrescribir la GOT — sobre pequeños programas deliberadamente vulnerables que compilas tú mismo, con las mitigaciones desactivadas, en un laboratorio desechable. Cada tutorial termina reactivando la mitigación que lo rompe, de modo que el paso ofensivo y la defensa que lo detiene quedan uno al lado del otro. Así es como los defensores aprenden contra qué se defienden.
Guías de esta área
A complete lab walkthrough: build a vulnerable C program, find the offset to the saved return address, redirect execution with pwntools, then watch each mitigation break the exploit.
With NX on, injected shellcode is dead — so we reuse the program's own code. A full lab walkthrough: find gadgets, hand-build an execve syscall chain with pwntools, then watch CET and CFI break it.
NX is on and the binary is tiny, but libc is mapped and full of useful code. Leak its base past ASLR, then return straight into system("/bin/sh") — a full two-stage pwntools walkthrough.
One printf(user_input) is a full read/write primitive. Leak with %p, overwrite with %n via pwntools, then watch -Wformat=2 and FORTIFY_SOURCE shut it down.
Lazy binding leaves the Global Offset Table writable. Aim an arbitrary write at a GOT entry, turn puts() into system(), then enable Full RELRO and watch the same write fault instantly.
The heap's own metadata is the write primitive. Build a use-after-free, poison the glibc tcache to allocate a chunk over a chosen address, and see why safe-linking and ASan raise the bar.
Modern exploits are leak-then-act. Build an out-of-bounds read, then use it to recover a stack canary, the PIE base and the libc base — the three secrets every mitigation relies on.
When gadgets are scarce, forge a signal frame. A sigreturn syscall restores every register from the stack at once — build one with pwntools to call execve, then see how seccomp and CET respond.
No pop rdx gadget? The C runtime's startup code has a universal sequence that loads several registers and makes a controlled call. Build it with pwntools, and see where it's gone.
When the overflow gives you only a few bytes past the return address, pivot the stack pointer into a buffer you fully control and run the real chain from there. A pwntools walkthrough.
When hooks are gone, the FILE object is the target. A stdio call dispatches through a vtable pointer in writable memory — corrupt it and the next fwrite runs your code.
No libc leak, no problem: forge the relocation the dynamic linker reads and make it resolve and call system for you. A pwntools walkthrough — and why Full RELRO ends it.
Sometimes you control just one pointer. A one-gadget is a single libc address that calls execve("/bin/sh") — if its register and stack constraints hold. Find one, check the constraints, and use it.
A seccomp policy that bans execve takes the shell off the table, so attackers switch goals: open the flag, read it, write it back. Build the ORW chain, and see what a tighter policy stops.
Las guías se publican primero en inglés. Las traducciones llegarán después.
Otras áreas
Fundamentos de memoria
Pila, heap, segmentos ELF y convenciones de llamada: el terreno de todo bug.
Clases de vulnerabilidades
Desbordamientos, use-after-free, double free, errores de enteros y de cadenas de formato, y cómo detectarlos.
Mitigaciones de explotación
Canarios, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET y PAC, y cómo verificarlos.
Encontrar errores
AddressSanitizer, UBSan y fuzzing guiado por cobertura con libFuzzer y AFL++.
Triaje de fallos
Leer señales, backtraces, informes de sanitizers y core dumps, y decidir qué corregir primero.
Programación segura
Lenguajes con seguridad de memoria, C++ más seguro y una estrategia de migración realista.
Ruta de aprendizaje
Una ruta legal y progresiva desde C y ensamblador hasta los retos pwn de CTF y las carreras en seguridad.
Explotación ARM64
Convenciones de llamada AArch64, registro de enlace, ROP en ARM y las defensas PAC y BTI.