Aller au contenu

Guides

Guides approfondis sur les classes de vulnérabilités mémoire, les mitigations d'exploitation, les sanitizers, le fuzzing et le triage des crashs.

Les guides sont publiés d'abord en anglais. Les traductions suivront.

0x6000 · Parcours d'apprentissageAnglais

A Binary Exploitation Learning Path Through CTFs

A staged, legal path from C and assembly to CTF pwn challenges: what to learn in which order, practice platforms built for it, lab rules, and how it leads to defensive careers.

0x3000 · Trouver les bugsAnglais

Coverage-Guided Fuzzing with libFuzzer and AFL++

Write a fuzz harness, build it with sanitizers, run libFuzzer and AFL++, manage corpora and dictionaries, and run continuous fuzzing in CI with OSS-Fuzz or ClusterFuzzLite.

0x2000 · Mitigations d'exploitationAnglais

Control-Flow Integrity: CFI, Intel CET and Arm PAC/BTI

How forward-edge and backward-edge control-flow integrity work, from Clang CFI and Microsoft CFG to Intel CET shadow stacks and Arm pointer authentication, and their limits.

0x1000 · Classes de vulnérabilitésAnglais

Integer Overflows and Format-String Bugs, Explained

How integer overflow, truncation and signedness errors turn into memory corruption, why user-controlled format strings are dangerous, and the checks and warnings that prevent both.

0x1000 · Classes de vulnérabilitésAnglais

Heap Overflows, Use-After-Free and Double Free

How heap memory bugs corrupt allocator metadata and object state, why use-after-free is so dangerous, and the allocator hardening, sanitizers and ownership rules that stop them.

0x1000 · Classes de vulnérabilitésAnglais

Stack Buffer Overflows Explained for Defenders

Why writing past a stack buffer is dangerous, the C patterns that cause it, how compilers and sanitizers catch it, and the fixes and mitigations that contain it.