跳到主要内容
知仓学习社ZHICANG

exploit-development

Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/…

读文件写文件严重 3 · 高危 0hypnguyen1209/offensive-claude

它会碰到什么

扫了多少15 个文本文件,100 KB
它会碰到什么读文件写文件
命中总数7 处
命中统计严重 3 · 高 0 · 中 4 · 低 0
逐条看命中(3 条严重或高危)
  • 严重 references/heap-glibc-fsop.md:19instruction-harmful-additive
    A freed chunk's `fd` is stored **mangled**: `mangled_fd = (chunk_addr >> 12) ^ next_ptr`. To poison a tcache/fastbin `fd` to land an allocation at `target`, you
  • 严重 references/heap-glibc-fsop.md:57instruction-harmful-additive
    edit(A, p64(mangle(chunkA_addr, target)))      # poison A.fd
  • 严重 scripts/safe_linking.py:6instruction-harmful-additive
    mangled = (chunk_addr >> 12) ^ next_ptr

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Exploit Development

End-to-end weaponization: turn a confirmed bug class into a reliable, version-pinned PoC, then a primitive chain (leak -> R/W -> control flow), against current mitigations. Every cluster pairs the offensive path with detection telemetry and OPSEC.

When to Activate

  • A confirmed vulnerability needs a working, reliable PoC (>=90% success target).
  • Userland binary exploitation: stack overflow, heap (UAF/overflow/double-free), format string.
  • Defeating modern mitigations: ASLR/PIE, NX/DEP, stack canaries, Full RELRO, CFG, Intel CET shadow stack, V8 Sandbox/pointer compression.
  • Browser/JIT engine exploitation (V8 type confusion, addrof/fakeobj, WASM jump-table pivot).
  • Local privilege escalation via Linux/Windows kernel memory corruption.
  • Converting a crash into a stable read/write/execute primitive chain.

Technique Map

| Technique | ATT&CK | CWE | Reference | Script |

|-----------|--------|-----|-----------|--------|

| Stack overflow -> ret2libc/ROP | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/offset_finder.py |

| ret2csu / SROP / stack pivot | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |

| ret2dlresolve (leakless) | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |

| CET/CFG-aware control-flow hijack | T1203 | CWE-1419 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |

| tcache/fastbin poisoning + safe-linking | T1203 | CWE-416 | references/heap-glibc-fsop.md | scripts/safe_linking.py |

| House of Botcake / Einherjar / Apple2 | T1203 | CWE-415 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |

| FSOP (stdout leak, House of Apple 2) | T1203 | CWE-787 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |

| Format string leak + arbitrary write | T1203 | CWE-134 | references/format-string-leaks.md | scripts/fmtstr_leak.py |

| V8 type confusion -> addrof/fakeobj | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |

| V8 Sandbox escape (WASM jump table) | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |

| UAF heap-spray reclaim | T1203 | CWE-416 | references/browser-jit-uaf.md | scripts/v8_primitives.js |

| Linux kernel UAF -> cross-cache | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |

| Dirty Pagetable / Pagedirectory | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |

| msg_msg infoleak / spray | T1068 | CWE-125 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |

| Windows PreviousMode / I/O Ring R/W | T1068 | CWE-787 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |

| Empirical mitigation matrix (build witness under N profiles) | T1203 | CWE-693 | references/exploit-feasibility.md | scripts/feasibility_profile.py |

| Cached context + blocked-technique gate for /exploit | T1203 | CWE-693 | references/exploit-feasibility.md | scripts/exploit_context.py |

Quick Start

# 0. Fingerprint target + libc (pin every version)
file ./target; pwn checksec ./target
strings -a libc.so.6 | grep -m1 'release version'   # exact glibc build
patchelf --set-interpreter ./ld.so --replace-needed libc.so.6 ./libc.so.6 ./target

# 1. Crash + offset (cyclic) — see scripts/offset_finder.py
python3 scripts/offset_finder.py ./target            # auto pattern_create/offset

# 2. Gadgets + one_gadget
ROPgadget --binary ./libc.so.6 > gadgets.txt
ropper -f ./libc.so.6 --search 'pop rdi; ret'
one_gadget ./libc.so.6

# 3. Build chain (leak -> base -> system/execve) — scripts/rop_autochain.py
python3 scripts/rop_autochain.py ./target ./libc.so.6 --leak puts --remote host:port

# 4. Heap targets: poison fd with safe-linking math, FSOP for the endgame
python3 scripts/safe_linking.py --chunk 0x55...000 --target 0x7f...   # encrypt fd
python3 scripts/heap_fsop.py --libc ./libc.so.6 --mode apple2         # FSOP payload

# 5. Verify reliability before delivery
for i in $(seq 1 50); do python3 exploit.py >/dev/null 2>&1 && echo ok; done | wc -l

> Cache the target context once. Steps 0–2 (file/checksec/libc build, gadget table,

> one_gadget) describe the target, not a single attempt — compute them once and reuse them across

> every PoC iteration. Re-running recon on each attempt wastes budget and pollutes telemetry; an

> autopilot loop should treat the fingerprint + gadget set as cached input, not a per-iteration step.

> A future empirical feasibility profile (raptor-adoption PR-3) will rebuild the crash witness

> under several mitigation profiles and emit a machine-readable map of which techniques the target

> actually permits — the PoC is then forbidden from using a technique that map marks blocked. Until

> it lands: record the checksec/mitigation state explicitly and do not claim a technique the target's

> protections rule out.

OPSEC & Detection (summary)

| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |

|-----------|---------------|-----------------------|------------|

| ROP/ret2libc | Stack exec faults, abnormal execve("/bin/sh") child of network daemon | EDR: child shell from listener; auditd execve of /bin/sh w/ empty argv | Use in-memory ORW (open/read/write flag) instead of shell to avoid execve IOC |

| Heap/FSOP | glibc stack smashing /malloc(): ... aborts in logs; SIGABRT crash loops | Sigma: repeated SIGABRT/SIGSEGV from same PID; coredump bursts | Disable coredumps (prctl(PR_SET_DUMPABLE,0)); tune spray to avoid abort()s |

| Format string | %n/%p strings in request/argv logs; segfault on bad write | WAF/Sigma on %n,%[0-9]+\$n in inputs | Pre-stage write target; minimize % count, avoid huge field widths |

| V8 type confusion | Renderer crash dumps, chrome_crashpad, GPU/renderer restarts | Crashpad telemetry; EDR on renderer spawning unexpected processes | Keep corruption inside cage; clean up sprayed arrays; avoid renderer crash on failure |

| Kernel LPE | dmesg oops/RIP, KASAN splats, apparmor/audit LPE child = root | Sigma: process gaining uid=0 w/o setuid path; EDR kernel-callback | Fileless (no SUID drop); restore corrupted state; clear dmesg only if authorized |

Deep Dives

  • references/stack-rop-mitigations.md — Stack overflow, ret2libc/ROP, ret2csu, SROP, stack pivots, ret2dlresolve; defeating ASLR/PIE/NX/canary/RELRO and CET shadow stack / CFG-aware constraints. Backed by offset_finder.py, rop_autochain.py.
  • references/heap-glibc-fsop.md — glibc 2.35-2.40 internals, tcache/fastbin poisoning under safe-linking, House of Botcake/Einherjar/Apple 2/Tangerine, stdout FSOP leak, post-hook-removal endgames. Backed by safe_linking.py, heap_fsop.py.
  • references/format-string-leaks.md — Read/write mechanics, stack-arg indexing, %n arbitrary write, PIE/libc/canary leaks, fmtstr automation and one-shot GOT/exit-handler overwrite. Backed by fmtstr_leak.py.
  • references/browser-jit-uaf.md — V8 element-kind confusion, addrof/fakeobj, arbitrary R/W under pointer compression, 2024-2025 Maglev/TurboFan CVEs, V8 Sandbox escape via WASM jump table, generic UAF reclaim. Backed by v8_primitives.js.
  • references/kernel-exploitation.md — Linux UAF/cross-cache, Dirty Pagetable/Pagedirectory (CVE-2024-1086), msg_msg leak/spray, SLUBStick; Windows pool spray, PreviousMode + I/O Ring R/W, CLFS/AFD CVEs. Backed by kernel_lpe_skeleton.c.
  • references/exploit-feasibility.md — empirical mitigation matrix: rebuild the crash witness under permissive/distro/hardened/asan profiles, record which still fire, derive the blocked-technique map; /exploit is forbidden a technique the map marks blocked. Backed by feasibility_profile.py (build/replay, Linux/devcontainer) + exploit_context.py (cached checksec/libc + the assert_allowed gate). Pairs with reverse-engineering/references/rr-time-travel.md + coverage-reachability.md.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。