Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox
Scanned 9/2/2026
Install to Claude Code
npx -y skills add majiayu000/claude-skill-registry --skill exploit-development --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Exploit Development?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/majiayu000-exploit-development-claude-skill-registry)More formats (shields.io, HTML) on the badges page.
---
name: exploit-development
description: Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox
metadata:
type: offensive
phase: exploitation
tools: pwntools, gdb-gef, pwndbg, radare2, ropper, ROPgadget, one_gadget, angr, d8, WinDbg, IDA
mitre: [T1203, T1068, T1211, T1212, T1055]
kill_chain:
phase: [weaponize, exploit]
step: [2, 4]
attck_tactics: [TA0042, TA0002, TA0004]
attck_techniques: [T1203, T1068, T1211, T1212, T1055.012]
depends_on: [recon-osint, vulnerability-analysis]
feeds_into: [edr-evasion, shellcode-dev, initial-access, privesc-linux, privesc-windows]
inputs: [vulnerability_list, attack_surface_map, crash_corpus, target_versions]
outputs: [exploit_poc, payload, primitive_chain, finding_record]
references:
- references/stack-rop-mitigations.md
- references/heap-glibc-fsop.md
- references/format-string-leaks.md
- references/browser-jit-uaf.md
- references/kernel-exploitation.md
scripts:
- scripts/rop_autochain.py
- scripts/offset_finder.py
- scripts/heap_fsop.py
- scripts/safe_linking.py
- scripts/fmtstr_leak.py
- scripts/v8_primitives.js
- scripts/kernel_lpe_skeleton.c
---
# Exploit Development
End-to-end weaponization: turn a confirmed bug class into a reliable, version-pinned PoC, then a primitive chain (leak -> R/W -> control flow), against current mitigations. Every cluster pairs the offensive path with detection telemetry and OPSEC.
## When to Activate
- A confirmed vulnerability needs a working, reliable PoC (>=90% success target).
- Userland binary exploitation: stack overflow, heap (UAF/overflow/double-free), format string.
- Defeating modern mitigations: ASLR/PIE, NX/DEP, stack canaries, Full RELRO, CFG, Intel CET shadow stack, V8 Sandbox/pointer compression.
- Browser/JIT engine exploitation (V8 type confusion, addrof/fakeobj, WASM jump-table pivot).
- Local privilege escalation via Linux/Windows kernel memory corruption.
- Converting a crash into a stable read/write/execute primitive chain.
## Technique Map
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Stack overflow -> ret2libc/ROP | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/offset_finder.py |
| ret2csu / SROP / stack pivot | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| ret2dlresolve (leakless) | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| CET/CFG-aware control-flow hijack | T1203 | CWE-1419 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| tcache/fastbin poisoning + safe-linking | T1203 | CWE-416 | references/heap-glibc-fsop.md | scripts/safe_linking.py |
| House of Botcake / Einherjar / Apple2 | T1203 | CWE-415 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |
| FSOP (stdout leak, House of Apple 2) | T1203 | CWE-787 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |
| Format string leak + arbitrary write | T1203 | CWE-134 | references/format-string-leaks.md | scripts/fmtstr_leak.py |
| V8 type confusion -> addrof/fakeobj | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| V8 Sandbox escape (WASM jump table) | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| UAF heap-spray reclaim | T1203 | CWE-416 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| Linux kernel UAF -> cross-cache | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| Dirty Pagetable / Pagedirectory | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| msg_msg infoleak / spray | T1068 | CWE-125 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| Windows PreviousMode / I/O Ring R/W | T1068 | CWE-787 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
## Quick Start
```bash
# 0. Fingerprint target + libc (pin every version)
file ./target; pwn checksec ./target
strings -a libc.so.6 | grep -m1 'release version' # exact glibc build
patchelf --set-interpreter ./ld.so --replace-needed libc.so.6 ./libc.so.6 ./target
# 1. Crash + offset (cyclic) — see scripts/offset_finder.py
python3 scripts/offset_finder.py ./target # auto pattern_create/offset
# 2. Gadgets + one_gadget
ROPgadget --binary ./libc.so.6 > gadgets.txt
ropper -f ./libc.so.6 --search 'pop rdi; ret'
one_gadget ./libc.so.6
# 3. Build chain (leak -> base -> system/execve) — scripts/rop_autochain.py
python3 scripts/rop_autochain.py ./target ./libc.so.6 --leak puts --remote host:port
# 4. Heap targets: poison fd with safe-linking math, FSOP for the endgame
python3 scripts/safe_linking.py --chunk 0x55...000 --target 0x7f... # encrypt fd
python3 scripts/heap_fsop.py --libc ./libc.so.6 --mode apple2 # FSOP payload
# 5. Verify reliability before delivery
for i in $(seq 1 50); do python3 exploit.py >/dev/null 2>&1 && echo ok; done | wc -l
```
## OPSEC & Detection (summary)
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|---------------|-----------------------|------------|
| ROP/ret2libc | Stack exec faults, abnormal `execve("/bin/sh")` child of network daemon | EDR: child shell from listener; auditd `execve` of `/bin/sh` w/ empty argv | Use in-memory ORW (open/read/write flag) instead of shell to avoid `execve` IOC |
| Heap/FSOP | glibc `*** stack smashing ***`/`malloc(): ...` aborts in logs; SIGABRT crash loops | Sigma: repeated SIGABRT/SIGSEGV from same PID; coredump bursts | Disable coredumps (`prctl(PR_SET_DUMPABLE,0)`); tune spray to avoid abort()s |
| Format string | `%n`/`%p` strings in request/argv logs; segfault on bad write | WAF/Sigma on `%n`,`%[0-9]+\$n` in inputs | Pre-stage write target; minimize `%` count, avoid huge field widths |
| V8 type confusion | Renderer crash dumps, `chrome_crashpad`, GPU/renderer restarts | Crashpad telemetry; EDR on renderer spawning unexpected processes | Keep corruption inside cage; clean up sprayed arrays; avoid renderer crash on failure |
| Kernel LPE | `dmesg` oops/RIP, KASAN splats, `apparmor`/`audit` LPE child = root | Sigma: process gaining uid=0 w/o setuid path; EDR kernel-callback | Fileless (no SUID drop); restore corrupted state; clear `dmesg` only if authorized |
## Deep Dives
- references/stack-rop-mitigations.md — Stack overflow, ret2libc/ROP, ret2csu, SROP, stack pivots, ret2dlresolve; defeating ASLR/PIE/NX/canary/RELRO and CET shadow stack / CFG-aware constraints. Backed by `offset_finder.py`, `rop_autochain.py`.
- references/heap-glibc-fsop.md — glibc 2.35-2.40 internals, tcache/fastbin poisoning under safe-linking, House of Botcake/Einherjar/Apple 2/Tangerine, stdout FSOP leak, post-hook-removal endgames. Backed by `safe_linking.py`, `heap_fsop.py`.
- references/format-string-leaks.md — Read/write mechanics, stack-arg indexing, `%n` arbitrary write, PIE/libc/canary leaks, fmtstr automation and one-shot GOT/exit-handler overwrite. Backed by `fmtstr_leak.py`.
- references/browser-jit-uaf.md — V8 element-kind confusion, addrof/fakeobj, arbitrary R/W under pointer compression, 2024-2025 Maglev/TurboFan CVEs, V8 Sandbox escape via WASM jump table, generic UAF reclaim. Backed by `v8_primitives.js`.
- references/kernel-exploitation.md — Linux UAF/cross-cache, Dirty Pagetable/Pagedirectory (CVE-2024-1086), msg_msg leak/spray, SLUBStick; Windows pool spray, PreviousMode + I/O Ring R/W, CLFS/AFD CVEs. Backed by `kernel_lpe_skeleton.c`.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!