Skip to content
All modules
AdvancedModule 24 of 27150 minutes

Binary exploitation

Read a binary's protections, find an overflow offset in one crash, and build a ROP chain when the stack is not executable.

Assumes21. Reverse engineering

By the end you can

  • Read NX, PIE, canary, and RELRO from a binary and say what each rules out
  • Find an overflow offset with a de Bruijn pattern in a single crash
  • Build a ret2libc chain, including stack alignment
  • Turn a leaked pointer into a libc base and resolve arbitrary symbols
  • Turn a format string into an arbitrary read and then an arbitrary write
  • Name the four heap bugs that matter and the allocator behaviour each one abuses
  • Write shellcode that survives the challenge's constraints - length, character set, and seccomp

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 66 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Forgetting the stack-alignment ret gadget on 64-bit. The chain is correct and crashes inside system anyway, and students conclude the whole thing is wrong.
  • Hardcoding a libc address from your own machine. The remote libc differs; the leak exists so that the base is computed, not assumed.
  • Counting the offset by hand from the source. A cyclic pattern gives it in one crash and does not care about padding, alignment or the compiler's opinions.
  • Testing only under a debugger. GDB disables ASLR and rewrites the environment, so the stack layout differs from the one the target actually runs with and a working exploit can still be untested.
  • Building a chain without checking which bytes survive the read. scanf stops at whitespace and strcpy at a null, so the primitive that gets your payload in defines the alphabet the whole chain has to live inside.

Checkpoint

Given a 64-bit binary with NX and no PIE, produce a working ret2libc exploit and explain each entry in the chain.

Teaching note

The alignment `ret` gadget is the single most common blocker: the exploit is correct and crashes inside `system` anyway. Warn about it in advance or students will conclude their whole chain is wrong.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.