From Buffer Overflows to Rootkits: A Practitioner’s Guide to Offensive Security
Introduction
- How to use this book
- Ethical note
Chapter 1: The Attacker’s View of Memory and Execution
- A Minimal Vulnerable Program
- Process Layout: Text, Data, Heap, Stack
- ELF Format and Why It Matters
- x86/x64 Registers and the Call Stack
- How a Function Call Really Works (Calling Conventions)
- From Source to Assembly: Tracing One Example
- Segmentation, Paging, and Virtual Memory
- Defensive Note: Why You Must Know This
Chapter 2: Buffer Overflows: The Classic Weapon
- Anatomy of a Stack Buffer Overflow
- Controlling the Return Address
- Finding the Offset: Fuzzing with Patterns
- NOP Sleds and Shellcode Placement
- A Complete Exploit Walkthrough (Linux, x86)
- Return-to-libc: Exploitation Without Shellcode
- Defensive Note: Stack Canaries, ASLR, and Hardening Trade-offs
Chapter 3: Format String Vulnerabilities
- How printf Parses Its Arguments
- Leaking the Stack with %x and %p
- Overwriting Arbitrary Memory with %n
- A Realistic Exploit Example
- Chained Format String Attacks
- Real-World Example: CVE-2024-29510 in Ghostscript
- Defensive Note: Safe Formatting and Static Analysis
Chapter 4: Heap Exploitation and Use-After-Free
- How the Heap Is Managed (ptmalloc / glibc Basics)
- Off-by-One and Heap Overflows
- Use-After-Free: The Concept
- Exploiting UAF via Struct Overwrite
- Fastbin Attacks: A Concrete Walkthrough
- Defensive Note: Hardened Allocators and Sanitizers
Chapter 5: Shellcoding: Code That Runs Anywhere
- Constraints of Shellcode (No Null Bytes, No Fixed Addresses)
- Writing a Simple execve(“/bin/sh”) on Linux (x86)
- Writing a Simple execve(“/bin/sh”) on Linux (x86_64)
- Reverse TCP Shellcode: Connecting Back
- Position-Independent Tricks (Self-Referencing RIP, Syscall Stubs)
- Encoding and Decoding Payloads
- Embedding Shellcode in C Exploits
- Defensive Note: DEP/NX, CFG, and Sandboxing
Chapter 6: Bypassing Protections: ASLR, DEP, Canaries
- ASLR: How It Works and Where It Leaks
- Information Leaks via Pointers and CRT
- ROP Chaining (Return-Oriented Programming)
- Bypassing DEP with ROP
- Defeating Stack Canaries (Leak + Reuse)
- Defensive Note: Full Mitigation Stacks and SECCOMP
Chapter 7: Position-Independent Code and Exploit Engineering
- Static vs Dynamic Linking
- Position-Independent Executables (PIE)
- GOT/PLT Overwrites as an Attack Vector
- Leveraging libc Offsets in Exploits
- Combining Leaks, ROP, and GOT Hijacking
- Defensive Note: RELRO, BindsNow, and Full Hardening
Chapter 8: Anti-Analysis Techniques
- Detecting Sandboxes and VMs (CPUID, Timing, Artifacts)
- String Obfuscation and Encrypted Payloads
- Packed Binaries and Custom Unpackers
- Anti-Debugging Tricks (PTRACE, Timing, sysenter tricks)
- Flow Obfuscation and Control Integrity
- Defensive Note: Dynamic Analysis Strategies
Chapter 9: Rootkits: Hiding in the Kernel
- Userland vs Kernel Rootkits
- Inline Hooking System Calls (Linux Example)
- Modifying the System Call Table (Conceptual)
- Hiding Processes, Files, and Network Sockets
- Driver-Based Persistence on Windows (Conceptual)
- Defensive Note: Integrity Checking, eBPF, and PatchGuard
Chapter 10: Malware Development Patterns
- Process Injection Techniques (CreateRemoteThread, APC Injection)
- Reflective DLL Loading
- Living Off the Land (LOLBins and Scripts)
- Command and Control (C2) Channel Design
- Fileless Persistence and Memory-Only Techniques
- Defensive Note: EDR, Telemetry, and Behavioral Detection
Chapter 11: Putting It All Together: A Controlled Case Study
- The Lab: Dockerized, Isolated Test Environment
- Target Service with Multiple Flaws
- Step-by-Step Exploit Development
- Adding Evasion and Persistence Layers
- Post-Exploitation View
- Defensive Note: How a Hardened System Would Resist This
Chapter 12: Network Exploitation – Remote Code Execution via Services
- The Remote Exploitation Problem
- A Minimal Network Vulnerable Service
- Crafting a Network Payload
- Protocol-Specific Exploitation
- Reliability and Reboot Resilience
- Defensive Note: Securing Network Services
Chapter 13: Privilege Escalation – From User to Root/Admin
- The Privilege Escalation Landscape
- SUID Binaries and Privilege Escalation
- Sudo Misconfigurations
- Kernel Exploits and Dirty Pipe
- Capability Abuse and Namespaces
- Windows Privilege Escalation (Overview)
- Defensive Note: Hardening Against Privilege Escalation
Chapter 14: Windows Exploitation Fundamentals
- PE Format: Windows’ Answer to ELF
- Structured Exception Handling (SEH) and Overwrites
- Windows Stack Overflows and Shellcode
- Windows Heap Exploitation
- ROP on Windows
- Windows Mitigations and Bypasses
- Defensive Note: Hardening Windows Systems
Chapter 15: Fuzzing and Exploit Reliability – Making Exploits Work in the Wild
- Fuzzing as a Vulnerability Discovery Tool
- Exploit Reliability: The Gap Between Lab and Wild
- pwntools and Automation
- Defensive Note: Fuzzing in CI and Exploit Mitigation
Chapter 16: Container and Cloud Escapes
- How Container Isolation Works (And Where It Is Fragile)
- CVE-2022-0492: Cgroup Release Agent Privilege Escalation
- Docker Socket Escapes and Privileged Containers
- Kubernetes Pod Escapes
- Cloud Metadata Service Abuses
- Namespace and Seccomp Evasion Techniques
- Defensive Note: Hardening Container Environments
Chapter 17: Advanced ROP and Code Reuse
- Return-to-dl-resolve: Calling Functions Without Gadgets
- ORW Chains: Open, Read, Write Without execve
- JIT Spraying: Weaponizing Just-In-Time Compilation
- Call-Oriented Programming (COOP)
- Defensive Note: Hardening Against Code Reuse
Chapter 18: Sandbox Escape Techniques
- Seccomp Filters: How They Work and How They Fail
- Chrome Sandbox Escapes
- Namespace and chroot Escapes
- Real-World Sandbox Escape Examples
- Defensive Note: Designing Robust Sandboxes
Chapter 19: eBPF Abuse for Post-Exploitation
- What eBPF Is and Why It Matters
- eBPF-Based Rootkit Capabilities
- A Conceptual eBPF Rootkit Example
- Detection and Defense Against eBPF Rootkits
- Defensive Note: Using eBPF Responsibly

