Memory-corruption exploitation
SkillDocs & knowledgeTurn a memory-corruption bug in a native binary into code execution, stack overflows, format strings, and ROP against modern mitigations. Load when you control input to a compiled program and it crashes or misbehaves: a network daemon, a thick client, a setuid/SUID helper, or extracted firmware. Signals: segfault on long/`%n` input, a crash with control of a register, no source, checksec output, "exploit this binary/service".
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Memory-corruption exploitation skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/exploit-dev/exploit-memory-corruption/SKILL.md and read by ahel’s review.
When it applies
You have a native binary or service on an authorized target that mishandles your input — a
network-facing daemon, a thick-client, a setuid helper found during privesc, or a binary carved
from firmware (reverse-eng-firmware). reverse-eng-binary-triage located the bug; this skill turns
that crash into controlled execution. Pentest-only — this is destructive and can crash the service.
Why it works
C/C++ has no memory safety: writing past a buffer overwrites saved return addresses and pointers, and a user-controlled format string reads/writes arbitrary memory. Redirect execution to your code or to existing code (ROP) and the process does your bidding. Modern mitigations (NX, ASLR, PIE, stack canaries) don't remove the bug — they shape the technique.
Method
- Check protections first —
checksec ./bin(orpwntools): NX, PIE, RELRO, canary. This decides everything. No canary + NX → ROP; PIE → you need a leak; no PIE, no NX → maybe shellcode. - Find the offset — send a cyclic pattern (
cyclic 200/ pattern_create), crash it undergdb+GEF/pwndbg, read the value in$rip/$eip, andcyclic -l <value>for the exact offset to the saved return address. - Pick the primitive by protections:
- ret2win — a target function already in the binary; overwrite the return address with it.
- ret2libc / ROP — with NX, chain gadgets: leak a libc address (call
puts(puts@got)via the PLT), compute the libc base, return tosystem("/bin/sh")or aone_gadget. Build gadgets withROPgadget/ropper, the chain withpwntoolsROP(). - Format string (
printf(user)) — leak stack/canary/PIE base with%p, then do arbitrary writes with%n(GOT overwrite → redirect a call tosystem).fmtstr_payloadautomates it.
- Defeat mitigations with leaks — ASLR/PIE need a leaked address (from a format string or an info-leak bug) to rebase; a stack canary must be leaked (or brute-forced byte-by-byte on a forking server) and replayed in your overflow so the check passes.
- Build it with pwntools — a repeatable script:
process()/remote(),recvuntil, pack withp64(), stage the leak, then send the final chain; iterate locally, then fire at the target. - Land a shell — reuse
payloads-reverse-shellsfor what to run once you have execution.
Gotchas
- Match the exact libc — remote exploitation fails on the wrong libc version/offsets; identify it
(leaked addresses → a libc-database lookup) before computing
system/one_gadget. - Bad bytes —
\x00,\x0a,\x20can truncate input depending on the read function; check and avoid them in addresses/payload. - Local works, remote doesn't — environment/stack alignment differs; the
movapsalignment crash beforesystemis fixed by an extraretgadget. - This crashes the target — it's inherently disruptive; only on authorized pentest targets, never a live bug-bounty production service, and note the risk in the RoE.
Verify success
Reliable control of execution demonstrated on the target — a returned shell, a run command, or a
controlled $rip with a working ROP chain — reproducible from your pwntools script.
References
pwntools docs & tutorials; checksec; GEF/pwndbg; ROPgadget/ropper; one_gadget; libc-database.
Find the bug with reverse-eng-binary-triage; shell payloads in payloads-reverse-shells.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
exploit-memory-corruption- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · davila7
The pick for C / C++handoff
Skill · mattpocock
More in Docs & knowledgecanvas-design
Skill · anthropics
More in Docs & knowledgedoc-coauthoring
Skill · anthropics
More in Docs & knowledgewriting-for-agents
Skill · mattpocock
More in Docs & knowledgespec-driven-development
Skill · addyosmani
More in Docs & knowledge