--- name: exploit-development description: Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox metadata: type: offensive phase: exploitation tools: pwntools, gdb-gef, pwndbg, radare2, ropper, ROPgadget, one_gadget, angr, d8, WinDbg, IDA mitre: [T1203, T1068, T1211, T1212, T1055] kill_chain: phase: [weaponize, exploit] step: [2, 4] attck_tactics: [TA0042, TA0002, TA0004] attck_techniques: [T1203, T1068, T1211, T1212, T1055.012] depends_on: [recon-osint, vulnerability-analysis] feeds_into: [edr-evasion, shellcode-dev, initial-access, privesc-linux, privesc-windows] inputs: [vulnerability_list, attack_surface_map, crash_corpus, target_versions] outputs: [exploit_poc, payload, primitive_chain, finding_record] references: - references/stack-rop-mitigations.md - references/heap-glibc-fsop.md - references/format-string-leaks.md - references/browser-jit-uaf.md - references/kernel-exploitation.md - references/exploit-feasibility.md scripts: - scripts/rop_autochain.py - scripts/offset_finder.py - scripts/heap_fsop.py - scripts/safe_linking.py - scripts/fmtstr_leak.py - scripts/v8_primitives.js - scripts/kernel_lpe_skeleton.c - scripts/exploit_context.py - scripts/feasibility_profile.py --- # Exploit Development End-to-end weaponization: turn a confirmed bug class into a reliable, version-pinned PoC, then a primitive chain (leak -> R/W -> control flow), against current mitigations. Every cluster pairs the offensive path with detection telemetry and OPSEC. ## When to Activate - A confirmed vulnerability needs a working, reliable PoC (>=90% success target). - Userland binary exploitation: stack overflow, heap (UAF/overflow/double-free), format string. - Defeating modern mitigations: ASLR/PIE, NX/DEP, stack canaries, Full RELRO, CFG, Intel CET shadow stack, V8 Sandbox/pointer compression. - Browser/JIT engine exploitation (V8 type confusion, addrof/fakeobj, WASM jump-table pivot). - Local privilege escalation via Linux/Windows kernel memory corruption. - Converting a crash into a stable read/write/execute primitive chain. ## Technique Map | Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | Stack overflow -> ret2libc/ROP | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/offset_finder.py | | ret2csu / SROP / stack pivot | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py | | ret2dlresolve (leakless) | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py | | CET/CFG-aware control-flow hijack | T1203 | CWE-1419 | references/stack-rop-mitigations.md | scripts/rop_autochain.py | | tcache/fastbin poisoning + safe-linking | T1203 | CWE-416 | references/heap-glibc-fsop.md | scripts/safe_linking.py | | House of Botcake / Einherjar / Apple2 | T1203 | CWE-415 | references/heap-glibc-fsop.md | scripts/heap_fsop.py | | FSOP (stdout leak, House of Apple 2) | T1203 | CWE-787 | references/heap-glibc-fsop.md | scripts/heap_fsop.py | | Format string leak + arbitrary write | T1203 | CWE-134 | references/format-string-leaks.md | scripts/fmtstr_leak.py | | V8 type confusion -> addrof/fakeobj | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js | | V8 Sandbox escape (WASM jump table) | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js | | UAF heap-spray reclaim | T1203 | CWE-416 | references/browser-jit-uaf.md | scripts/v8_primitives.js | | Linux kernel UAF -> cross-cache | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c | | Dirty Pagetable / Pagedirectory | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c | | msg_msg infoleak / spray | T1068 | CWE-125 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c | | Windows PreviousMode / I/O Ring R/W | T1068 | CWE-787 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c | | Empirical mitigation matrix (build witness under N profiles) | T1203 | CWE-693 | references/exploit-feasibility.md | scripts/feasibility_profile.py | | Cached context + blocked-technique gate for /exploit | T1203 | CWE-693 | references/exploit-feasibility.md | scripts/exploit_context.py | ## Quick Start ```bash # 0. Fingerprint target + libc (pin every version) file ./target; pwn checksec ./target strings -a libc.so.6 | grep -m1 'release version' # exact glibc build patchelf --set-interpreter ./ld.so --replace-needed libc.so.6 ./libc.so.6 ./target # 1. Crash + offset (cyclic) — see scripts/offset_finder.py python3 scripts/offset_finder.py ./target # auto pattern_create/offset # 2. Gadgets + one_gadget ROPgadget --binary ./libc.so.6 > gadgets.txt ropper -f ./libc.so.6 --search 'pop rdi; ret' one_gadget ./libc.so.6 # 3. Build chain (leak -> base -> system/execve) — scripts/rop_autochain.py python3 scripts/rop_autochain.py ./target ./libc.so.6 --leak puts --remote host:port # 4. Heap targets: poison fd with safe-linking math, FSOP for the endgame python3 scripts/safe_linking.py --chunk 0x55...000 --target 0x7f... # encrypt fd python3 scripts/heap_fsop.py --libc ./libc.so.6 --mode apple2 # FSOP payload # 5. Verify reliability before delivery for i in $(seq 1 50); do python3 exploit.py >/dev/null 2>&1 && echo ok; done | wc -l ``` > **Cache the target context once.** Steps 0–2 (file/checksec/libc build, gadget table, > one_gadget) describe the *target*, not a single attempt — compute them once and reuse them across > every PoC iteration. Re-running recon on each attempt wastes budget and pollutes telemetry; an > autopilot loop should treat the fingerprint + gadget set as cached input, not a per-iteration step. > A future empirical **feasibility profile** (raptor-adoption PR-3) will rebuild the crash witness > under several mitigation profiles and emit a machine-readable map of which techniques the target > actually permits — the PoC is then forbidden from using a technique that map marks blocked. Until > it lands: record the checksec/mitigation state explicitly and do not claim a technique the target's > protections rule out. ## OPSEC & Detection (summary) | Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note | |-----------|---------------|-----------------------|------------| | ROP/ret2libc | Stack exec faults, abnormal `execve("/bin/sh")` child of network daemon | EDR: child shell from listener; auditd `execve` of `/bin/sh` w/ empty argv | Use in-memory ORW (open/read/write flag) instead of shell to avoid `execve` IOC | | Heap/FSOP | glibc `*** stack smashing ***`/`malloc(): ...` aborts in logs; SIGABRT crash loops | Sigma: repeated SIGABRT/SIGSEGV from same PID; coredump bursts | Disable coredumps (`prctl(PR_SET_DUMPABLE,0)`); tune spray to avoid abort()s | | Format string | `%n`/`%p` strings in request/argv logs; segfault on bad write | WAF/Sigma on `%n`,`%[0-9]+\$n` in inputs | Pre-stage write target; minimize `%` count, avoid huge field widths | | V8 type confusion | Renderer crash dumps, `chrome_crashpad`, GPU/renderer restarts | Crashpad telemetry; EDR on renderer spawning unexpected processes | Keep corruption inside cage; clean up sprayed arrays; avoid renderer crash on failure | | Kernel LPE | `dmesg` oops/RIP, KASAN splats, `apparmor`/`audit` LPE child = root | Sigma: process gaining uid=0 w/o setuid path; EDR kernel-callback | Fileless (no SUID drop); restore corrupted state; clear `dmesg` only if authorized | ## Deep Dives - references/stack-rop-mitigations.md — Stack overflow, ret2libc/ROP, ret2csu, SROP, stack pivots, ret2dlresolve; defeating ASLR/PIE/NX/canary/RELRO and CET shadow stack / CFG-aware constraints. Backed by `offset_finder.py`, `rop_autochain.py`. - references/heap-glibc-fsop.md — glibc 2.35-2.40 internals, tcache/fastbin poisoning under safe-linking, House of Botcake/Einherjar/Apple 2/Tangerine, stdout FSOP leak, post-hook-removal endgames. Backed by `safe_linking.py`, `heap_fsop.py`. - references/format-string-leaks.md — Read/write mechanics, stack-arg indexing, `%n` arbitrary write, PIE/libc/canary leaks, fmtstr automation and one-shot GOT/exit-handler overwrite. Backed by `fmtstr_leak.py`. - references/browser-jit-uaf.md — V8 element-kind confusion, addrof/fakeobj, arbitrary R/W under pointer compression, 2024-2025 Maglev/TurboFan CVEs, V8 Sandbox escape via WASM jump table, generic UAF reclaim. Backed by `v8_primitives.js`. - references/kernel-exploitation.md — Linux UAF/cross-cache, Dirty Pagetable/Pagedirectory (CVE-2024-1086), msg_msg leak/spray, SLUBStick; Windows pool spray, PreviousMode + I/O Ring R/W, CLFS/AFD CVEs. Backed by `kernel_lpe_skeleton.c`. - references/exploit-feasibility.md — empirical mitigation matrix: rebuild the crash witness under permissive/distro/hardened/asan profiles, record which still fire, derive the blocked-technique map; `/exploit` is forbidden a technique the map marks blocked. Backed by `feasibility_profile.py` (build/replay, Linux/devcontainer) + `exploit_context.py` (cached checksec/libc + the `assert_allowed` gate). Pairs with `reverse-engineering/references/rr-time-travel.md` + `coverage-reachability.md`.