Browse CTFs New CTF Sign in
Back to Learning Paths
Exploit Development & Binary Security
Specialist Wave 2

Exploit Development & Binary Security

18.0h estimated 3 Courses

Specialist certification in binary exploitation covering stack, heap, format strings, and sandbox escapes.

Sign in to enroll

Heap Exploitation, Sandbox Escapes and Binary Logic Bugs

15 cards

Advanced Multi-Layer Encoding with Compression: gzip/zlib Layer Identification and Programmatic Decoding

reverse_engineering Difficulty 1–5 30 min

Custom VM Obfuscation Reversal: Dispatcher Loop Analysis and Python Disassembler Construction

reverse_engineering Difficulty 1–5 30 min

Password check

reverse_engineering Difficulty 1–5 30 min

License key generation

reverse_engineering Difficulty 1–5 30 min

Simple Buffer Overflow Without Protections: Return Address Overwrite and Program Flow Redirection

reverse_engineering Difficulty 1–5 30 min

ret2libc on x86-64: GOT-Based libc Leak, ROP Gadget Setup and system("/bin/sh") Invocation

reverse_engineering Difficulty 1–5 30 min

ROP Chain Construction: Gadget Chaining for execve Syscall with Stack Alignment and Bad-Byte Avoidance

reverse_engineering Difficulty 1–5 30 min

Canary Brute-Force on Forking Servers: Byte-by-Byte Enumeration Exploiting fork() Memory Inheritance

reverse_engineering Difficulty 1–5 30 min

Advanced seccomp Bypass: 32-Bit int 0x80 Syscall Table Exploitation Outside 64-Bit Filter Coverage

binary_exploitation Difficulty 1–5 30 min

Kubernetes RBAC Privilege Escalation: ClusterRoleBinding Abuse and Service Account Token Misuse

binary_exploitation Difficulty 1–5 30 min

Kubernetes Secret Enumeration in Cluster: Namespace Traversal and Sensitive Data Extraction

binary_exploitation Difficulty 1–5 30 min

Kubernetes Service Account Abuse: Token-Based API Access and Lateral Movement Within Cluster

binary_exploitation Difficulty 1–5 30 min

IAM policy misconfig

binary_exploitation Difficulty 1–5 30 min

Analyzing Kerberoasting PCAP Captures via TGS-REQ Identification and Hashcat Ticket Extraction

binary_exploitation Difficulty 1–5 30 min

Analyzing gRPC PCAP Captures via HTTP/2 Stream Identification and Protobuf Parameter Extraction

binary_exploitation Difficulty 1–5 30 min
🏅

CTFFactory Binary Exploitation — Specialist

Specialist credential — awarded upon completion