A Binary Exploitation Learning Path Through CTFs
A staged, legal path from C and assembly to CTF pwn challenges: what to learn in which order, practice platforms built for it, lab rules, and how it leads to defensive careers.
Guides approfondis sur les classes de vulnérabilités mémoire, les mitigations d'exploitation, les sanitizers, le fuzzing et le triage des crashs.
Les guides sont publiés d'abord en anglais. Les traductions suivront.
A staged, legal path from C and assembly to CTF pwn challenges: what to learn in which order, practice platforms built for it, lab rules, and how it leads to defensive careers.
Why memory-safe languages remove whole bug classes, what Rust's ownership model guarantees, where unsafe code and FFI remain risky, and how to harden the C++ you keep.
Write a fuzz harness, build it with sanitizers, run libFuzzer and AFL++, manage corpora and dictionaries, and run continuous fuzzing in CI with OSS-Fuzz or ClusterFuzzLite.
Triage native crashes like a defender: what SIGSEGV and SIGABRT mean, glibc abort messages, gdb and core dumps, ASan reports, WinDbg, and how to prioritise memory-safety crashes.
How ASan, UBSan, MSan, TSan and HWASan work, which flags and runtime options to use, how to read an ASan report line by line, and how to run sanitizers in CI.
How forward-edge and backward-edge control-flow integrity work, from Clang CFI and Microsoft CFG to Intel CET shadow stacks and Arm pointer authentication, and their limits.
What each classic exploit mitigation protects, the GCC and Clang flags that enable it, what it costs, and how to verify a binary with checksec and readelf.
How integer overflow, truncation and signedness errors turn into memory corruption, why user-controlled format strings are dangerous, and the checks and warnings that prevent both.
How heap memory bugs corrupt allocator metadata and object state, why use-after-free is so dangerous, and the allocator hardening, sanitizers and ownership rules that stop them.
Why writing past a stack buffer is dangerous, the C patterns that cause it, how compilers and sanitizers catch it, and the fixes and mitigations that contain it.
A defender's tour of a Linux process's address space: ELF segments, the stack and calling conventions, the heap, mmap, and why permissions and randomization matter.