No description
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
【One-Line Pitch】
A hands-on, CTF-driven introduction to Linux pwn exploitation, walking beginners from environment setup and stack overflows through shellcode, ROP, format strings, and advanced bypass techniques. Ideal for CTF newcomers and security students who want a practical, example-based path into binary exploitation.
【Book Arc】
- **Opening (~0%–9%)**: Sets up the learning environment using Docker containers, IDA for remote debugging, and pwntools for scripting. Explains the basics of function prologues/epilogues and demonstrates a first stack overflow that hijacks EIP to call a hidden backdoor function.
- **Early (~9%–26%)**: Moves from simple backdoors to writing and using shellcode, including encoding tricks to bypass character filters. Introduces ROP as a way to bypass NX by chaining gadgets, covering calls to system, int 0x80/syscall, and leveraging provided libc for address calculations.
- **Early–Middle (~26%–35%)**: Explores advanced ROP techniques, including "universal gadgets" for x64 argument setup and one-gadget RCE for a single-address getshell. Introduces stack pivoting to control the stack pointer when direct control is limited, a key skill for later topics.
- **Middle (~35%–48%)**: Covers information disclosure and bypassing ASLR. Teaches how to leak memory addresses using write/puts, handle partial leaks, and use tools or other challenges' libc to resolve symbols. Introduces format string vulnerabilities as a powerful leak and write primitive.
- **Middle–Late (~48%–52%)**: Focuses on bypassing PIE (Position Independent Executable) protections. Discusses partial overwrite techniques to brute-force or redirect execution, and using vsyscall pages as a stable address source for NOP-sled-like ret chains when no other leak is available.
- **Late (~52%–end)**: Introduces SROP (Sigreturn-Oriented Programming), a technique that uses the sigreturn syscall to set all registers from a forged frame on the stack, simplifying exploitation when traditional ROP gadgets are scarce. The book concludes with practical examples and exercises.
【Key Takeaways】
- **Environment setup is the first hurdle** (Early): The book provides Docker images and IDA/pwntools integration to create a reproducible lab, solving the common problem of scattered tools and hard-to-find practice binaries.
- **Understanding the stack frame is fundamental** (Early): By tracing EIP, EBP, and ESP through function calls, you learn that overwriting the saved return address on the stack is the core of stack overflow exploitation.
- **Shellcode is not always ready to use** (Early): Real-world constraints like bad characters (e.g., \x00, \x0A) or encoding filters (e.g., base64) require transforming shellcode, either with tools or by hand, to fit the input restrictions.
- **ROP is the primary NX bypass** (Early): Since NX prevents executing code on the stack, ROP chains existing instructions (gadgets) ending in `ret` to call functions like system, using the stack to control arguments and control flow.
- **Leaking addresses is key to defeating ASLR** (Middle): Techniques like using `puts` or `write` to print GOT entries, and then calculating offsets from a known libc, turn a single leak into full control over function calls.
- **Format strings are a dual leak/write primitive** (Middle): By controlling the format string, you can read arbitrary stack data (`%x`, `%s`) and, with Partial RELRO, overwrite GOT entries to redirect function calls to system.
- **PIE can be bypassed with partial overwrites** (Middle): Because PIE randomizes only the base address, the lower 12 bits of instruction addresses remain fixed; overwriting just the last bytes of a saved return address can redirect execution with brute force.
- **SROP simplifies register control** (Late): By invoking the `sigreturn` syscall, you can place a fake signal frame on the stack to set all registers at once, making exploitation possible even with very few gadgets.
【Reading Tips】
- **Skim the Docker setup if you already have a lab** (Opening): The first chunk is mostly environment configuration; if you have a working Linux VM with Docker, IDA, and pwntools, you can jump straight to the stack overflow section.
- **Deep-read the stack overflow and ROP chapters** (Early): These are the foundation of everything else. Trace the examples in a debugger yourself—modify EIP, build the ROP chain, and watch each step in IDA to internalize the mechanics.
- **Pay close attention to the exploit scripts** (Throughout): The provided Python scripts with pwntools are the most valuable part. Don't just read them—run them against the provided binaries, change addresses, and see what breaks.
- **Treat stack pivot and SROP as advanced topics** (Middle–Late): These are conceptually trickier. If you're a beginner, first master basic ROP and leaks, then return to these chapters for a deeper understanding of stack control.
- **Use the exercises to test yourself** (End of chapters): Each section ends with practice problems from real CTFs. Attempt them without looking at the solutions first, then compare your approach with the book's scripts.
【Coverage Limits】
This guide covers the core topics from the excerpts: stack overflows, shellcode, ROP, ASLR/PIE bypasses, format strings, and SROP. It does not cover heap exploitation, integer overflows, or race conditions in detail, as those are mentioned but not elaborated in the sampled chunks.
Page 6
需要使用脚本来完成此类操作。我们选用的是著名的python库pwntools。 pwntools库可以使用pip进行安 装,其官方文档地址为http://docs.pwntools.com/en/stable/ 。在本节中我们将使用pwntools和IDA配合 调试程序。 首先我们在kali中安装pwntools...
View in text
Excerpt 2
"\x57\x48\x89\xe6\xb0\x3b\x0f\x05" #第二部分shellcode #push rdi #mov rsi, rsp #mov al, 0x3b #syscall print io.recvuntil("Location:") #读取到"Location:",紧接着就是泄露 出来的栈...
View in text
Excerpt 3
注意的是,stack pivot是一个比较重要的技术。在接下来的SROP和ret2dl_resolve中我们还将利用到 这个技术。 附件请点击跳转到原文下载 59 我们可以构造一个payload如下: elf = ELF(‘./ropasaurusrex’) #别忘了在脚本所在目录下放一个程序文件ropasaur...
View in text
Excerpt 4
(payload) io.recv() try: io.recv(timeout = 1) #要么崩溃要么爆破成功,若崩溃io会 关闭,io.recv()会触发EOFError except EOFError: io.close() continue else: sleep(0.1) 80 我们可以看到栈上有大量...
View in text
Excerpt 5
interactive()开shell了。 0x02 SROP实例2 上一节中我们学习了如何使用SROP完成一次攻击。这一节我们将通过另一个例子继续巩固SROP技巧,并通过 另一种方法完成攻击。我们打开例子~/360ichunqiu 2017-smallest/smallest。这同样是个非常简单的程序 97 泄...
View in text
Excerpt 6
?其实这行jmp的意思并不是跳转到地址0x0804a008执行代码,而是跳转到地址0x0804a008中保存 的地址处。同理,一开始的jmp ds:off_804a018也不是跳转到地址0x0804a018.OK,我们来看一下这两个地 址里保存了什么。 回到call _write F7跟进后的那张图,跟进后的第一...
View in text
Excerpt 7
一个有趣的,没有使用说明的项目ROPutils(https://github.com/ inaz2/roputils) 这个python库的作者似乎挺懒的,不仅不写文档,而且代码也好几年没更新了。不过这并不妨碍其便利性。 我们直接看代码roputils.py,其大部分我们会用到的东西都在ROP*和FormatSt...
View in text
Excerpt 8
#r_ info index设置为0,最后一字节必须为7 fake_Elf64_Rela += p64(0) #r_ addend 随意设置 fake_Elf64_Sym = "" fake_Elf64_Sym += p32(0) #st_ name 随意设置 fake_Elf64_Sym += 'AAAA' #...
View in text
Tags
AI categories
CybersecurityProgramming LanguageCode
Text Preview (First 20 pages)
Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Generating text preview…
Loading comments...
Reply to Comment
Edit Comment