git:20260629.9f4a1a5 to git:20260630.1a28660

10 added, 0 removed. Audit A to A.

---
name: exploit-development
description: Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox
metadata:
type: offensive
phase: exploitation
tools: pwntools, gdb-gef, pwndbg, radare2, ropper, ROPgadget, one_gadget, angr, d8, WinDbg, IDA
mitre: [T1203, T1068, T1211, T1212, T1055]
kill_chain:
phase: [weaponize, exploit]
step: [2, 4]
attck_tactics: [TA0042, TA0002, TA0004]
attck_techniques: [T1203, T1068, T1211, T1212, T1055.012]
depends_on: [recon-osint, vulnerability-analysis]
feeds_into: [edr-evasion, shellcode-dev, initial-access, privesc-linux, privesc-windows]
inputs: [vulnerability_list, attack_surface_map, crash_corpus, target_versions]
outputs: [exploit_poc, payload, primitive_chain, finding_record]
references:
- references/stack-rop-mitigations.md
- references/heap-glibc-fsop.md
- references/format-string-leaks.md
- references/browser-jit-uaf.md
- references/kernel-exploitation.md
scripts:
- scripts/rop_autochain.py
- scripts/offset_finder.py
- scripts/heap_fsop.py
- scripts/safe_linking.py
- scripts/fmtstr_leak.py
- scripts/v8_primitives.js
- scripts/kernel_lpe_skeleton.c
---
# Exploit Development
End-to-end weaponization: turn a confirmed bug class into a reliable, version-pinned PoC, then a primitive chain (leak -> R/W -> control flow), against current mitigations. Every cluster pairs the offensive path with detection telemetry and OPSEC.
## When to Activate
- A confirmed vulnerability needs a working, reliable PoC (>=90% success target).
- Userland binary exploitation: stack overflow, heap (UAF/overflow/double-free), format string.
- Defeating modern mitigations: ASLR/PIE, NX/DEP, stack canaries, Full RELRO, CFG, Intel CET shadow stack, V8 Sandbox/pointer compression.
- Browser/JIT engine exploitation (V8 type confusion, addrof/fakeobj, WASM jump-table pivot).
- Local privilege escalation via Linux/Windows kernel memory corruption.
- Converting a crash into a stable read/write/execute primitive chain.
## Technique Map
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Stack overflow -> ret2libc/ROP | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/offset_finder.py |
| ret2csu / SROP / stack pivot | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| ret2dlresolve (leakless) | T1203 | CWE-121 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| CET/CFG-aware control-flow hijack | T1203 | CWE-1419 | references/stack-rop-mitigations.md | scripts/rop_autochain.py |
| tcache/fastbin poisoning + safe-linking | T1203 | CWE-416 | references/heap-glibc-fsop.md | scripts/safe_linking.py |
| House of Botcake / Einherjar / Apple2 | T1203 | CWE-415 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |
| FSOP (stdout leak, House of Apple 2) | T1203 | CWE-787 | references/heap-glibc-fsop.md | scripts/heap_fsop.py |
| Format string leak + arbitrary write | T1203 | CWE-134 | references/format-string-leaks.md | scripts/fmtstr_leak.py |
| V8 type confusion -> addrof/fakeobj | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| V8 Sandbox escape (WASM jump table) | T1203 | CWE-843 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| UAF heap-spray reclaim | T1203 | CWE-416 | references/browser-jit-uaf.md | scripts/v8_primitives.js |
| Linux kernel UAF -> cross-cache | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| Dirty Pagetable / Pagedirectory | T1068 | CWE-416 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| msg_msg infoleak / spray | T1068 | CWE-125 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
| Windows PreviousMode / I/O Ring R/W | T1068 | CWE-787 | references/kernel-exploitation.md | scripts/kernel_lpe_skeleton.c |
## Quick Start
```bash
# 0. Fingerprint target + libc (pin every version)
file ./target; pwn checksec ./target
strings -a libc.so.6 | grep -m1 'release version' # exact glibc build
patchelf --set-interpreter ./ld.so --replace-needed libc.so.6 ./libc.so.6 ./target
# 1. Crash + offset (cyclic) — see scripts/offset_finder.py
python3 scripts/offset_finder.py ./target # auto pattern_create/offset
# 2. Gadgets + one_gadget
ROPgadget --binary ./libc.so.6 > gadgets.txt
ropper -f ./libc.so.6 --search 'pop rdi; ret'
one_gadget ./libc.so.6
# 3. Build chain (leak -> base -> system/execve) — scripts/rop_autochain.py
python3 scripts/rop_autochain.py ./target ./libc.so.6 --leak puts --remote host:port
# 4. Heap targets: poison fd with safe-linking math, FSOP for the endgame
python3 scripts/safe_linking.py --chunk 0x55...000 --target 0x7f... # encrypt fd
python3 scripts/heap_fsop.py --libc ./libc.so.6 --mode apple2 # FSOP payload
# 5. Verify reliability before delivery
for i in $(seq 1 50); do python3 exploit.py >/dev/null 2>&1 && echo ok; done | wc -l
```
+ > **Cache the target context once.** Steps 0–2 (file/checksec/libc build, gadget table,
+ > one_gadget) describe the *target*, not a single attempt — compute them once and reuse them across
+ > every PoC iteration. Re-running recon on each attempt wastes budget and pollutes telemetry; an
+ > autopilot loop should treat the fingerprint + gadget set as cached input, not a per-iteration step.
+ > A future empirical **feasibility profile** (raptor-adoption PR-3) will rebuild the crash witness
+ > under several mitigation profiles and emit a machine-readable map of which techniques the target
+ > actually permits — the PoC is then forbidden from using a technique that map marks blocked. Until
+ > it lands: record the checksec/mitigation state explicitly and do not claim a technique the target's
+ > protections rule out.
+
## OPSEC & Detection (summary)
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|---------------|-----------------------|------------|
| ROP/ret2libc | Stack exec faults, abnormal `execve("/bin/sh")` child of network daemon | EDR: child shell from listener; auditd `execve` of `/bin/sh` w/ empty argv | Use in-memory ORW (open/read/write flag) instead of shell to avoid `execve` IOC |
| Heap/FSOP | glibc `*** stack smashing ***`/`malloc(): ...` aborts in logs; SIGABRT crash loops | Sigma: repeated SIGABRT/SIGSEGV from same PID; coredump bursts | Disable coredumps (`prctl(PR_SET_DUMPABLE,0)`); tune spray to avoid abort()s |
| Format string | `%n`/`%p` strings in request/argv logs; segfault on bad write | WAF/Sigma on `%n`,`%[0-9]+\$n` in inputs | Pre-stage write target; minimize `%` count, avoid huge field widths |
| V8 type confusion | Renderer crash dumps, `chrome_crashpad`, GPU/renderer restarts | Crashpad telemetry; EDR on renderer spawning unexpected processes | Keep corruption inside cage; clean up sprayed arrays; avoid renderer crash on failure |
| Kernel LPE | `dmesg` oops/RIP, KASAN splats, `apparmor`/`audit` LPE child = root | Sigma: process gaining uid=0 w/o setuid path; EDR kernel-callback | Fileless (no SUID drop); restore corrupted state; clear `dmesg` only if authorized |
## Deep Dives
- references/stack-rop-mitigations.md — Stack overflow, ret2libc/ROP, ret2csu, SROP, stack pivots, ret2dlresolve; defeating ASLR/PIE/NX/canary/RELRO and CET shadow stack / CFG-aware constraints. Backed by `offset_finder.py`, `rop_autochain.py`.
- references/heap-glibc-fsop.md — glibc 2.35-2.40 internals, tcache/fastbin poisoning under safe-linking, House of Botcake/Einherjar/Apple 2/Tangerine, stdout FSOP leak, post-hook-removal endgames. Backed by `safe_linking.py`, `heap_fsop.py`.
- references/format-string-leaks.md — Read/write mechanics, stack-arg indexing, `%n` arbitrary write, PIE/libc/canary leaks, fmtstr automation and one-shot GOT/exit-handler overwrite. Backed by `fmtstr_leak.py`.
- references/browser-jit-uaf.md — V8 element-kind confusion, addrof/fakeobj, arbitrary R/W under pointer compression, 2024-2025 Maglev/TurboFan CVEs, V8 Sandbox escape via WASM jump table, generic UAF reclaim. Backed by `v8_primitives.js`.
- references/kernel-exploitation.md — Linux UAF/cross-cache, Dirty Pagetable/Pagedirectory (CVE-2024-1086), msg_msg leak/spray, SLUBStick; Windows pool spray, PreviousMode + I/O Ring R/W, CLFS/AFD CVEs. Backed by `kernel_lpe_skeleton.c`.