hardadvanced tierwindowsbinary-exploitationx64rop
Course

Windows Exploitation

Userland exploitation on 64-bit Windows. You start with the way the operating system fits together. You finish by breaking its heap. The course covers x86-64 only, not WOW64 and not 32-bit.

14
Modules
35
Lectures
33
Hands-on labs
24h
Of material

About this course

Userland exploitation on 64-bit Windows. You start with the way the operating system fits together. You finish by breaking its heap. The course covers x86-64 only, not WOW64 and not 32-bit. That limit is the point of the course, not a footnote.

Almost all the writing about Windows exploitation targets x86. About a third of it is wrong or useless on x64. The calling convention is different. Exception handling uses a different mechanism, so the famous SEH overwrite doesn't exist here. SafeSEH and SEHOP protect a structure that a 64-bit process doesn't have. This course teaches what is true inside a 64-bit process.

The course starts with the execution environment. You learn the NT architecture and the native API below the Win32 one. You learn the PE format, and what the loader does with it. You also learn the twenty or so WinAPI functions that exploits really call.

Next comes the Microsoft x64 ABI in detail: rcx, rdx, r8 and r9, the 32 bytes of shadow space, and the alignment rule. Shadow space breaks every chain that someone writes from Linux habits. The ABI also replaced the frame pointer with a table in .pdata and .xdata. You learn to read that table.

After that come the structures that make Windows leaks cheap. They are the gs segment base, the TEB, the PEB, and the loader's module lists. One read of memory can give you module bases, stack bounds, and the heap encoding key.

You then meet the mitigations. Read each one as a list of requirements, not as a wall. DEP and ASLR come first, with the per-boot DLL base that Linux has no equal for. The /GS cookie comes next, with the five ways to get past it.

The middle of the course is offensive technique. You write position-independent x64 shellcode that finds its own imports from a hash of the export table. You build ROP chains under the Microsoft ABI. You attack exception dispatch on x64, where only three surfaces are open. You get past Control Flow Guard in five different ways.

You also use the modules that every process already maps. NtContinue in ntdll sets every register from one structure. The C runtime gives you system, memcpy and initterm.

Syllabus

14 modules, 35 lectures, 14 quizzes and 33 hands-on challenges.

  1. Setting Up

    The lab, the toolchain, and enough WinDbg to do real work.

    • The Lab and the Toolchain
    • WinDbg for Exploitation

    1 quiz

  2. How Windows Works

    The NT architecture, and the native API below the Win32 one. The PE format, and what the loader does with it. The small set of API calls that exploits really use.

    • Windows Architecture and the Native API
    • PE Files, the Loader, and Modules
    • The WinAPI in Practice

    1 quiz

  3. The x64 Calling Convention

    The Microsoft ABI in the detail that an exploit needs. It also covers the table that replaced the frame pointer.

    • The Microsoft x64 Calling Convention
    • Frames, Prologues, and Unwind Data

    1 quiz 3 hands-on challenges

  4. GS, the TEB and the PEB

    The two structures that every Windows thread carries. They make a userland leak on Windows cheaper than on any other system.

    • The GS Register, the TEB, and the PEB
    • Getting Leaks by Pivoting

    1 quiz 3 hands-on challenges

  5. DEP, ASLR and GS

    The three baseline mitigations. Read each one as a list of the primitives that your exploit still needs.

    • DEP and ASLR on Windows
    • /GS and the Security Cookie

    1 quiz 3 hands-on challenges

  6. Windows x64 Shellcoding

    Position-independent code that finds all it needs through the PEB. It must also survive the path that carried it into the process.

    • Writing Windows x64 Shellcode
    • Constraints, Bad Characters and Encoding

    1 quiz 2 hands-on challenges

  7. ROP on Windows

    Return-oriented programming under the Microsoft ABI. Here you meet DEP, ASLR and a stack cookie at the same time.

    • Windows x64 ROP
    • ROP with the Stack Cookie in Play

    1 quiz 2 hands-on challenges

  8. Exception Handling on x64

    The module where x64 stops being x86 with wider registers. The technique that everyone expects is not there at all.

    • Exception Handling on x64
    • Attacking Exception Handling on x64
    • SafeSEH, SEHOP, and What Replaced Them

    1 quiz 3 hands-on challenges

  9. Control Flow Guard

    What CFG checks, what it does not check on purpose, and the five ways past it.

    • How Control Flow Guard Works
    • Bypassing CFG

    1 quiz 2 hands-on challenges

  10. Attacking Windows Modules

    Mitigations apply to one module at a time, so the weakest module sets the difficulty. You then call the functions that every process already maps, and let them do the work.

    • Module Mitigations and Finding the Weak One
    • ntdll: NtContinue and the CONTEXT Record
    • ucrtbase and msvcrt: the C Runtime as an Exploitation Library

    1 quiz 2 hands-on challenges

  11. Format String Vulnerabilities

    What the Microsoft CRT does with a hostile format string on x64. Three argument slots are registers, `%n` is off by default, and the two runtimes disagree. You then spend the read on the three leaks that matter.

    • Format Strings on Windows x64
    • Turning the Read into the Three Leaks That Matter
    • When You Do Get a Write, and What to Do When You Do Not

    1 quiz 3 hands-on challenges

  12. Race Conditions

    Why a Windows race is a double fetch inside one process, not a file-system TOCTOU. How to widen the window instead of gambling on it. Where a won race leaves you.

    • Race Conditions on Windows
    • Double Fetch and TOCTOU in Practice
    • From a Won Race to a Working Exploit

    1 quiz 2 hands-on challenges

  13. The Windows Heap

    Which allocator, and which Windows build. How the heap changed from release to release. The metadata, and every check that guards it. The techniques, in the order to try them.

    • The Windows Heap: Which Allocator, and Which Windows
    • What Changed, and When
    • Heap Metadata and the Checks That Guard It
    • Use-After-Free and Double Free
    • Arbitrary Allocation, Overlaps, and Heap Leaks

    1 quiz 6 hands-on challenges

  14. Capstone: The Method

    The process that picks the technique to use, and the order to use it in. It also tells you what to check when nothing works.

    • The Method

    1 quiz 2 hands-on challenges

Part of

This course is a leg of a longer track.

  • The Pwny way.

14 modules about 24 hoursOpened from your Arena account

Take Windows Exploitation

Create an account to open the lectures and launch this course's labs in the browser.

Create a free account