Low-Level Exploitation and Malware Engineering
- From Buffer Overflows to Rootkits: A Practitioner’s Guide
Introduction
- How to use this book
- Ethical note
Chapter 1: The Attacker’s View of Memory and Execution
- A Minimal Vulnerable Program
- Process Layout: Text, Data, Heap, Stack
- ELF Format and Why It Matters
- x86/x64 Registers and the Call Stack
- How a Function Call Really Works (Calling Conventions)
- From Source to Assembly: Tracing One Example
- Segmentation, Paging, and Virtual Memory
- Defensive Note: Why You Must Know This
Chapter 2: Buffer Overflows – The Classic Weapon
- Anatomy of a Stack Buffer Overflow
- Controlling the Return Address
- Finding the Offset: Fuzzing with Patterns
- NOP Sleds and Shellcode Placement
- A Complete Exploit Walkthrough (Linux, x86)
- Return-to-libc: Exploitation Without Shellcode
- Defensive Note: Stack Canaries, ASLR, and Hardening Trade-offs
Chapter 3: Format String Vulnerabilities
- How printf Parses Its Arguments
- Leaking the Stack with %x and %p
- Overwriting Arbitrary Memory with %n
- A Realistic Exploit Example
- Chained Format String Attacks
- Real-World Example: CVE-2024-29510 in Ghostscript
- Defensive Note: Safe Formatting and Static Analysis
Chapter 4: Heap Exploitation and Use-After-Free
- How the Heap Is Managed (ptmalloc / glibc Basics)
- Off-by-One and Heap Overflows
- Use-After-Free: The Concept
- Exploiting UAF via Struct Overwrite
- Fastbin Attacks: A Concrete Walkthrough
- Defensive Note: Hardened Allocators and Sanitizers
Chapter 5: Shellcoding – Code That Runs Anywhere
- Constraints of Shellcode (No Null Bytes, No Fixed Addresses)
- Writing a Simple execve(“/bin/sh”) on Linux (x86)
- Writing a Simple execve(“/bin/sh”) on Linux (x86_64)
- Reverse TCP Shellcode: Connecting Back
- Position-Independent Tricks (Self-Referencing RIP, Syscall Stubs)
- Encoding and Decoding Payloads
- Embedding Shellcode in C Exploits
- Defensive Note: DEP/NX, CFG, and Sandboxing
Chapter 6: Bypassing Protections – ASLR, DEP, Canaries
- ASLR: How It Works and Where It Leaks
- Information Leaks via Pointers and CRT
- ROP Chaining (Return-Oriented Programming)
- Bypassing DEP with ROP
- Defeating Stack Canaries (Leak + Reuse)
- Defensive Note: Full Mitigation Stacks and SECCOMP
Chapter 7: Position-Independent Code and Exploit Engineering
- Static vs Dynamic Linking
- Position-Independent Executables (PIE)
- GOT/PLT Overwrites as an Attack Vector
- Leveraging libc Offsets in Exploits
- Combining Leaks, ROP, and GOT Hijacking
- Defensive Note: RELRO, BindsNow, and Full Hardening
Chapter 8: Anti-Analysis Techniques
- Detecting Sandboxes and VMs (CPUID, Timing, Artifacts)
- String Obfuscation and Encrypted Payloads
- Packed Binaries and Custom Unpackers
- Anti-Debugging Tricks (PTRACE, Timing, sysenter tricks)
- Flow Obfuscation and Control Integrity
- Defensive Note: Dynamic Analysis Strategies
Chapter 9: Rootkits – Hiding in the Kernel
- Userland vs Kernel Rootkits
- Inline Hooking System Calls (Linux Example)
- Modifying the System Call Table (Conceptual)
- Hiding Processes, Files, and Network Sockets
- Driver-Based Persistence on Windows (Conceptual)
- Defensive Note: Integrity Checking, eBPF, and PatchGuard
Chapter 10: Malware Development Patterns
- Process Injection Techniques (CreateRemoteThread, APC Injection)
- Reflective DLL Loading
- Living Off the Land (LOLBins and Scripts)
- Command and Control (C2) Channel Design
- Fileless Persistence and Memory-Only Techniques
- Defensive Note: EDR, Telemetry, and Behavioral Detection
Chapter 11: Putting It All Together – A Controlled Case Study
- The Lab: Dockerized, Isolated Test Environment
- Target Service with Multiple Flaws
- Step-by-Step Exploit Development
- Adding Evasion and Persistence Layers
- Post-Exploitation View
- Defensive Note: How a Hardened System Would Resist This
- Defensive Note: How a Hardened System Would Resist This
