mediumFreebinary-exploitationpwnmemory-corruptionrace-conditions
Course

Introduction to Binary Exploitation

Memory corruption from first principles, across all three places it matters: userland, the kernel, and the browser. The course is built around one idea - that exploitation is the business of turning a small memory-safety violation into a general one, one primitive at a time. You start with what a p

7
Modules
15
Lectures
6
Hands-on labs
10h
Of material

About this course

Memory corruption from first principles, across all three places it matters: userland, the kernel, and the browser.

The course is built around one idea - that exploitation is the business of turning a small memory-safety violation into a general one, one primitive at a time. You start with what a process actually looks like in memory, work through the bug classes (out-of-bounds, use-after-free, type confusion, integer issues, format strings, null dereference), then convert them into the primitives that matter: RIP control, arbitrary read, arbitrary write.

From there it is the mitigations - NX, canaries, ASLR and PIE, RELRO, CFI, shadow stacks - read not as obstacles but as a requirements list, because each one tells you precisely which extra primitive your exploit still needs.

The last third moves up the stack. Kernel exploitation covers double fetches, refcount bugs, KASLR, SMEP/SMAP, KPTI and the modern SLUB hardening. Browser exploitation covers V8 object layout, elements kinds, addrof/fakeobj, the Turbofan and Maglev JIT tiers and where their type reasoning goes wrong, and why arbitrary read/write in a renderer is only halfway to a compromise.

Six hands-on challenges, one per major primitive, from a missing lower bound through a check-then-use race to a full ret2libc against PIE and ASLR.

Syllabus

7 modules, 15 lectures, 7 quizzes and 6 hands-on challenges.

  1. Foundations

    What a running process actually looks like in memory, and why exploitation follows from the fact that code and data share an address space.

    • The Shape of a Process

    1 quiz

  2. Bug Classes in Userland

    The families of memory-safety failure: accessing the wrong place, the right place at the wrong time, arithmetic that produces a length nobody expected, and concurrency that invalidates a check before it is used.

    • Out of Bounds
    • Lifetime Bugs: UAF, Double Free, Type Confusion
    • Integer Bugs and Format Strings
    • Race Conditions

    1 quiz 2 hands-on challenges

  3. From Bug to Control

    Converting a violation into capability: RIP control, shellcode that survives its input path, arbitrary read/write, and return-oriented programming.

    • RIP Control and Shellcoding
    • Arbitrary Read and Write
    • Return-Oriented Programming

    1 quiz 2 hands-on challenges

  4. Mitigations

    NX, canaries, ASLR and PIE, RELRO, FORTIFY, CET, shadow stacks and PAC - read as a list of the primitives your exploit still needs.

    • The Mitigation Stack

    1 quiz 1 hands-on challenge

  5. Kernel Exploitation

    The same bug classes in ring 0, plus the ones unique to the user/kernel boundary - and the mitigations built to police it.

    • What Changes in the Kernel
    • Kernel Mitigations

    1 quiz

  6. Browser and JIT Exploitation

    V8 internals, the elements-kind confusion behind addrof/fakeobj, how Turbofan and Maglev speculation becomes type confusion, and why renderer R/W is only halfway.

    • JavaScript Engine Internals
    • The JIT: Turbofan, Maglev, and Where Bugs Come From
    • Browser Mitigations and the Sandbox

    1 quiz

  7. Capstone: Method

    The repeatable process from triage to shell, the habits that prevent wasted hours, and where to go next.

    • The Method

    1 quiz 1 hands-on challenge

Part of

This course is a leg of a longer track.

  • The Pwny way.

7 modules about 10 hoursOpened from your Arena account

Take Introduction to Binary Exploitation

Create an account to open the lectures and launch this course's labs in the browser.

Create a free account