Binary Exploitation
Binary exploitation involves finding and leveraging memory safety bugs in compiled programs to gain unintended capabilities. You'll learn how the stack and heap are laid out in memory, why format strings are dangerous, and how attackers redirect program control flow. These skills underpin modern vulnerability research and exploit development.
Guides for this path
Read these alongside the challenges below. The first one orients you; the rest go deeper on the techniques each step needs.
- The picoCTF Binary Exploitation Roadmap: Stack to Heap to ROPHow to learn binary exploitation for CTF in order: a beginner-to-advanced pwn roadmap from x86 assembly and gdb through stack smashing, mitigations, ROP, and heap.
- Buffer Overflow and Binary Exploitation for CTFBuffer overflow and pwn for CTF: stack overflows, ret2win, format strings, heap exploits, and ASLR/PIE bypass, with a picoCTF challenge link for each technique.
- Format String Vulnerabilities for CTF Binary ExploitationFormat string vulnerabilities for CTF: how printf leaks memory, finding the format string offset, writing arbitrary values with %n, and the picoCTF series.
- Heap Exploitation for CTF: From heap Overflow to tcache PoisoningHeap exploitation on modern glibc (2.35+): four primitives that still work, mapped to picoCTF heap 0-3, Heap Havoc, and Pizza Router, with pwntools templates.
- Bypassing ASLR and PIE in CTF Binary Exploitation (picoCTF Guide)ASLR and PIE bypass in CTF pwn: memory leaks, ret2libc, ROP chains, one_gadget, and partial overwrites, with real pwntools scripts and picoCTF challenge links.
- pwntools for CTF: A Foundational Guide from import to ShellPwntools for CTF: the four pillars (Tubes, ELF, ROP, gdb) and six idioms that cover 90% of pwn, with picoCTF receipts and the GitHub issues that trap beginners.
- Step 01
Format String Vulnerabilities
When printf is called with user input as the format string argument - printf(user_input) instead of printf("%s", user_input) - attackers can read arbitrary memory with %x and write to it with %n. The picoCTF format string series walks you from a trivial leaking example up to a full arbitrary write.
- Step 02
Heap Exploitation
The heap is where dynamic memory allocations (malloc/free) live. Heap exploits take advantage of the metadata that the allocator writes between chunks. The heap series in picoCTF 2024 is one of the best beginner-friendly introductions available, building each concept on top of the last.
- Step 03
PIE and Address Space Randomization
Position-Independent Executables (PIE) and Address Space Layout Randomization (ASLR) randomize where code and the stack are loaded in memory, making it harder to jump to a hardcoded address. PIE TIME teaches you to defeat these mitigations by leaking an address at runtime and computing offsets from there.