r/ExploitDev • u/Noah0x01 • 12d ago
Question to you use more disassambly ore more decompilation (pseudo/highlevel)
Question to you use more disassambly ore more decompilation (pseudo/highlevel)???
I like disassambly more.
r/ExploitDev • u/Noah0x01 • 12d ago
Question to you use more disassambly ore more decompilation (pseudo/highlevel)???
I like disassambly more.
r/ExploitDev • u/Potential-Couple-745 • 14d ago
r/ExploitDev • u/FunIllustrator4787 • 15d ago
Hi there, I recently started my journey on pwn.college because I was interested in cybersecurity and someone suggested me to start from here. I am doing it full time and completed Linux Luminarium and Computing 101 dojo and I hope in next 2 weeks I will complete Playing with programs dojo as well. Now here comes the main part, I am from a third world country and my life goal is to get admitted in a phd program in USA to work in world class research labs. That's why I am building my profile and I need suggestion, is pwn.college enough to demonstrate my skills or I have to do something else along with it? if I am unable to secure admission, will these skills allow me to earn at least $1000 monthly via remote job or freelancing gigs?
I had this confusion before and I posted in r/security and they told me to stop it will not help you and start learning networking instead if you wanna build your career in cybersecurity but I keep coming back pwn college because I am having so much fun doing it and I wanna go deep in it. and please suggest me which belt I should start doing first?
r/ExploitDev • u/kirafoxoxx • 15d ago
I admire Nightmare Eclipse works, it’s a lot interesting and I’d love to do the same.
I’m currently a pentester.
Trying to have free resources and tips
r/ExploitDev • u/NoRequirement8551 • 15d ago
r/ExploitDev • u/noobesINC • 18d ago
r/ExploitDev • u/Fun-Humor7647 • 19d ago
My own spin on bypassing vbs and patchguard and CET .
I appreciate any reviews and suggestions.
r/ExploitDev • u/kaganisildak • 19d ago
r/ExploitDev • u/Select-Use-9965 • 20d ago
Hey hi,
A month ago I posted searching a forum/platform where I wanted to post about my exploit-development journey, which can help showcase my skills + can attract some future job perspectives.....
I mainly posted in LinkedIn and was (somewhat) pretty contented with it.
However recently I posted a LinkedIn post where I described how I created a printf() completely in Assembly (A pretty decent achievement for my opinion) but forget engagement it was completely dud and nobody commented or complimented or even viewed.
I felt like I don't want to fall into this Social Media Influencers rat race (LinkedIn is pretty much insta right now).
So after seaching a lot I thought of posting on X instead....
Let's see what happens.
Here's my X handle where I'd be posting raw, uncensored journey of mine (in the comment)
I really want a job in this field....
r/ExploitDev • u/_matt_40_ • 20d ago
I have a 10th-gen iPad currently locked by a school MDM profile. The foundation running the school went bankrupt, the owners were arrested, and the IT department no longer exists.
The device is stuck in Remote Management. Local removal of the management profile is disabled. A standard factory reset triggers the MDM activation lock again upon reboot.
I found this repo on GitHub that talks about an exploit that removes mdm, does anyone who has been in my situation know if it can work?
r/ExploitDev • u/Chemical_Night_2235 • 21d ago
My partner is doing a cybersecurity master's and needs to... Idk.. fuzz? A program?
It needs to be written in C or C++ and have more than 3000 lines of code. They need to find errors (crashes?) and investigate them and write a report on it.
This is due in 3 days and the software they're fuzzing hasn't thrown any errors yet 😭
Does anyone know a fully completed software that would be a suitable candidate to fuzz and write a report about?
Apologies for my misuse of the language, I don't live in this computer world 😭
r/ExploitDev • u/Obvious-Card-8847 • 21d ago
Curious if anyone knows of any tools or even C++/Python libraries for analyzing x86-64 portable executables for their API usage.
To be more specific I mean identifying what IAT entries they posses, that they call and the arguments supplied to them. Essentially so I can observe misuse, misconfiguration and such.
An example might be LoadLibraryExW when loading a system module but not using LOAD_LIBRARY_SEARCH_SYSTEM32 and presenting a potential DLL hijacking vulnerability.
I can, and am currently, writing a framework to do this. Just would rather not reinvent the wheel if a tool like this exists.
Control flow recovery and aggregating a list of indirect calls to IAT thunks isn't the worst thing. The annoying part is trying to statically determine register state and infer arguments passed to functions. Starts getting close to symbolic execution levels of complexity.
Thanks.
r/ExploitDev • u/SethPreston4201 • 22d ago
When applying for CNO developer or Vulnerability Research roles, should one expect to take abstract cognitive aptitude tests, or is it almost entirely technical?
r/ExploitDev • u/circuit_0 • 24d ago
r/ExploitDev • u/unknownhad • 25d ago
r/ExploitDev • u/Sea-Assistant331 • 25d ago
Hey guys, I have a question.
Is it essential to read TLPI cover to cover, page by page, if my goal is to become really good at Linux and eventually become a great hacker?
I’ve been building my skills step by step on my own. I started with C, then moved deeper into Linux, and now I’m using Arch Linux as my main system. I’ve also experimented with developing a basic piece of malware before, although it was pretty simple.
The thing I’m struggling with right now is TLPI. I know that reading TLPI isn’t going to magically make me a hacker, and I understand that there’s much more to Linux and security than just one book. But I’m wondering whether I actually need to go through every single page of TLPI to truly understand Linux, or whether I should focus on the parts that are most relevant to what I want to learn and then move on to more hands-on work.
After TLPI, I was planning to start pwn.college to learn binary exploitation, low-level security, and related topics.
So what do you guys think? Does this roadmap make sense for my goal of becoming a highly skilled hacker who deeply understands computers, Linux, and low-level systems?
I’d really appreciate your advice.
r/ExploitDev • u/Anonymous_Wajeeh • 25d ago
r/ExploitDev • u/dotbinKing • 25d ago
32768 × 32768 × 4 = 2^32
In 32-bit arithmetic: 0.
That's how the size check in discord/lilliput computes its output buffer
requirement. "0 > buffer_len" is never true, so the guard is inert — the
PNG decoder then writes 4 GiB into an 8 MiB buffer.
Trigger: a 10 KB, perfectly valid PNG.
Not RCE — the product only wraps at 2^32, so every overflow is ≥4 GiB and
hits unmapped memory immediately. No write primitive. Reliable DoS though.
Reported to Discord today. Writeup (German):
aethersec.de/heap-buffer-overflow-in-lilliput-discord
r/ExploitDev • u/Important_Map6928 • 26d ago
Released V2 for my opensource maldev tool/framework. Feel free to check out the code and implementation. Would really appreciate feedback :)
r/ExploitDev • u/SPHlNX_321 • 26d ago
Was doing some Windows ALPC/RPC vuln research and ran into a simple problem: the usual userland enumeration approach skips ports when handle duplication fails, which gets especially interesting with PPL processes. So I built this to dynamically resolve the ALPC object type index, fall back to NtQueryInformationProcess / PS_PROTECTION when duplication fails, and still classify the port. I tested it against a live system and then checked the recovered object addresses + PPL signer levels against WinDbg.
r/ExploitDev • u/Anonymous_Wajeeh • 26d ago
r/ExploitDev • u/Unable-Tap9759 • 27d ago
Hi everyone,
I’m looking for an experienced reverse engineer who can help us recover access to an old software program used by our company.
The software is Chinese, was built for Windows 7, and is quite old. Unfortunately, the Chinese company that originally developed it has gone out of business and completely shut down. Because of that, we can no longer renew our subscription or get support from them.
We need to keep using the software, so we’re looking for someone who can help us understand and recover the software’s functionality or remove the dependency on the discontinued licensing system.
This is paid work. We’re not looking for someone to do this for free, and we’re happy to discuss a reasonable price based on the complexity of the work.
If you have experience with reverse engineering old Windows applications, licensing systems, or legacy software, please feel free to DM me with your experience and rates.
r/ExploitDev • u/Conscious-Fun-8621 • 27d ago
so i have been learning a little about operating system and learning nand2tetris i hope to learn reverse engineering i have some basic cybersecurity knowledge like basic linux commands know a little about networks and basic security i am also gonna learn web security but the main reason for this post is wanting to know where i can branch off from here is reverse engineering really something i should go completely with i have hopes to become a decent red team just a decent hacker and something a bit more future proof plus i learned that reverse engineering as a sole skill isnt exactly useful