Windows Exploitation
Userland exploitation on 64-bit Windows. You start with the way the operating system fits together. You finish by breaking its heap. The course covers x86-64 only, not WOW64 and not 32-bit.
- 14
- Modules
- 35
- Lectures
- 33
- Hands-on labs
- 24h
- Of material
About this course
Userland exploitation on 64-bit Windows. You start with the way the operating system fits together. You finish by breaking its heap. The course covers x86-64 only, not WOW64 and not 32-bit. That limit is the point of the course, not a footnote.
Almost all the writing about Windows exploitation targets x86. About a third of it is wrong or useless on x64. The calling convention is different. Exception handling uses a different mechanism, so the famous SEH overwrite doesn't exist here. SafeSEH and SEHOP protect a structure that a 64-bit process doesn't have. This course teaches what is true inside a 64-bit process.
The course starts with the execution environment. You learn the NT architecture and the native API below the Win32 one. You learn the PE format, and what the loader does with it. You also learn the twenty or so WinAPI functions that exploits really call.
Next comes the Microsoft x64 ABI in detail: rcx, rdx, r8 and r9, the 32 bytes of shadow space, and the alignment rule. Shadow space breaks every chain that someone writes from Linux habits. The ABI also replaced the frame pointer with a table in .pdata and .xdata. You learn to read that table.
After that come the structures that make Windows leaks cheap. They are the gs segment base, the TEB, the PEB, and the loader's module lists. One read of memory can give you module bases, stack bounds, and the heap encoding key.
You then meet the mitigations. Read each one as a list of requirements, not as a wall. DEP and ASLR come first, with the per-boot DLL base that Linux has no equal for. The /GS cookie comes next, with the five ways to get past it.
The middle of the course is offensive technique. You write position-independent x64 shellcode that finds its own imports from a hash of the export table. You build ROP chains under the Microsoft ABI. You attack exception dispatch on x64, where only three surfaces are open. You get past Control Flow Guard in five different ways.
You also use the modules that every process already maps. NtContinue in ntdll sets every register from one structure. The C runtime gives you system, memcpy and initterm.
Syllabus
14 modules, 35 lectures, 14 quizzes and 33 hands-on challenges.
Setting Up
The lab, the toolchain, and enough WinDbg to do real work.
- The Lab and the Toolchain
- WinDbg for Exploitation
1 quiz
How Windows Works
The NT architecture, and the native API below the Win32 one. The PE format, and what the loader does with it. The small set of API calls that exploits really use.
- Windows Architecture and the Native API
- PE Files, the Loader, and Modules
- The WinAPI in Practice
1 quiz
The x64 Calling Convention
The Microsoft ABI in the detail that an exploit needs. It also covers the table that replaced the frame pointer.
- The Microsoft x64 Calling Convention
- Frames, Prologues, and Unwind Data
1 quiz 3 hands-on challenges
GS, the TEB and the PEB
The two structures that every Windows thread carries. They make a userland leak on Windows cheaper than on any other system.
- The GS Register, the TEB, and the PEB
- Getting Leaks by Pivoting
1 quiz 3 hands-on challenges
DEP, ASLR and GS
The three baseline mitigations. Read each one as a list of the primitives that your exploit still needs.
- DEP and ASLR on Windows
- /GS and the Security Cookie
1 quiz 3 hands-on challenges
Windows x64 Shellcoding
Position-independent code that finds all it needs through the PEB. It must also survive the path that carried it into the process.
- Writing Windows x64 Shellcode
- Constraints, Bad Characters and Encoding
1 quiz 2 hands-on challenges
ROP on Windows
Return-oriented programming under the Microsoft ABI. Here you meet DEP, ASLR and a stack cookie at the same time.
- Windows x64 ROP
- ROP with the Stack Cookie in Play
1 quiz 2 hands-on challenges
Exception Handling on x64
The module where x64 stops being x86 with wider registers. The technique that everyone expects is not there at all.
- Exception Handling on x64
- Attacking Exception Handling on x64
- SafeSEH, SEHOP, and What Replaced Them
1 quiz 3 hands-on challenges
Control Flow Guard
What CFG checks, what it does not check on purpose, and the five ways past it.
- How Control Flow Guard Works
- Bypassing CFG
1 quiz 2 hands-on challenges
Attacking Windows Modules
Mitigations apply to one module at a time, so the weakest module sets the difficulty. You then call the functions that every process already maps, and let them do the work.
- Module Mitigations and Finding the Weak One
- ntdll: NtContinue and the CONTEXT Record
- ucrtbase and msvcrt: the C Runtime as an Exploitation Library
1 quiz 2 hands-on challenges
Format String Vulnerabilities
What the Microsoft CRT does with a hostile format string on x64. Three argument slots are registers, `%n` is off by default, and the two runtimes disagree. You then spend the read on the three leaks that matter.
- Format Strings on Windows x64
- Turning the Read into the Three Leaks That Matter
- When You Do Get a Write, and What to Do When You Do Not
1 quiz 3 hands-on challenges
Race Conditions
Why a Windows race is a double fetch inside one process, not a file-system TOCTOU. How to widen the window instead of gambling on it. Where a won race leaves you.
- Race Conditions on Windows
- Double Fetch and TOCTOU in Practice
- From a Won Race to a Working Exploit
1 quiz 2 hands-on challenges
The Windows Heap
Which allocator, and which Windows build. How the heap changed from release to release. The metadata, and every check that guards it. The techniques, in the order to try them.
- The Windows Heap: Which Allocator, and Which Windows
- What Changed, and When
- Heap Metadata and the Checks That Guard It
- Use-After-Free and Double Free
- Arbitrary Allocation, Overlaps, and Heap Leaks
1 quiz 6 hands-on challenges
Capstone: The Method
The process that picks the technique to use, and the order to use it in. It also tells you what to check when nothing works.
- The Method
1 quiz 2 hands-on challenges
Part of
This course is a leg of a longer track.
- The Pwny way.
14 modules about 24 hoursOpened from your Arena account
Take Windows Exploitation
Create an account to open the lectures and launch this course's labs in the browser.
Create a free account