Introduction to Binary Exploitation
Memory corruption from first principles, across all three places it matters: userland, the kernel, and the browser. The course is built around one idea - that exploitation is the business of turning a small memory-safety violation into a general one, one primitive at a time. You start with what a p
- 7
- Modules
- 15
- Lectures
- 6
- Hands-on labs
- 10h
- Of material
About this course
Memory corruption from first principles, across all three places it matters: userland, the kernel, and the browser.
The course is built around one idea - that exploitation is the business of turning a small memory-safety violation into a general one, one primitive at a time. You start with what a process actually looks like in memory, work through the bug classes (out-of-bounds, use-after-free, type confusion, integer issues, format strings, null dereference), then convert them into the primitives that matter: RIP control, arbitrary read, arbitrary write.
From there it is the mitigations - NX, canaries, ASLR and PIE, RELRO, CFI, shadow stacks - read not as obstacles but as a requirements list, because each one tells you precisely which extra primitive your exploit still needs.
The last third moves up the stack. Kernel exploitation covers double fetches, refcount bugs, KASLR, SMEP/SMAP, KPTI and the modern SLUB hardening. Browser exploitation covers V8 object layout, elements kinds, addrof/fakeobj, the Turbofan and Maglev JIT tiers and where their type reasoning goes wrong, and why arbitrary read/write in a renderer is only halfway to a compromise.
Six hands-on challenges, one per major primitive, from a missing lower bound through a check-then-use race to a full ret2libc against PIE and ASLR.
Syllabus
7 modules, 15 lectures, 7 quizzes and 6 hands-on challenges.
Foundations
What a running process actually looks like in memory, and why exploitation follows from the fact that code and data share an address space.
- The Shape of a Process
1 quiz
Bug Classes in Userland
The families of memory-safety failure: accessing the wrong place, the right place at the wrong time, arithmetic that produces a length nobody expected, and concurrency that invalidates a check before it is used.
- Out of Bounds
- Lifetime Bugs: UAF, Double Free, Type Confusion
- Integer Bugs and Format Strings
- Race Conditions
1 quiz 2 hands-on challenges
From Bug to Control
Converting a violation into capability: RIP control, shellcode that survives its input path, arbitrary read/write, and return-oriented programming.
- RIP Control and Shellcoding
- Arbitrary Read and Write
- Return-Oriented Programming
1 quiz 2 hands-on challenges
Mitigations
NX, canaries, ASLR and PIE, RELRO, FORTIFY, CET, shadow stacks and PAC - read as a list of the primitives your exploit still needs.
- The Mitigation Stack
1 quiz 1 hands-on challenge
Kernel Exploitation
The same bug classes in ring 0, plus the ones unique to the user/kernel boundary - and the mitigations built to police it.
- What Changes in the Kernel
- Kernel Mitigations
1 quiz
Browser and JIT Exploitation
V8 internals, the elements-kind confusion behind addrof/fakeobj, how Turbofan and Maglev speculation becomes type confusion, and why renderer R/W is only halfway.
- JavaScript Engine Internals
- The JIT: Turbofan, Maglev, and Where Bugs Come From
- Browser Mitigations and the Sandbox
1 quiz
Capstone: Method
The repeatable process from triage to shell, the habits that prevent wasted hours, and where to go next.
- The Method
1 quiz 1 hands-on challenge
Part of
This course is a leg of a longer track.
- The Pwny way.
7 modules about 10 hoursOpened from your Arena account
Take Introduction to Binary Exploitation
Create an account to open the lectures and launch this course's labs in the browser.
Create a free account