0
نام کتاب
The Art of Exploit Development

A Practical Guide to Building Exploits for Modern Systems

Ayukotsu Tenryoku Kazama

Print Length704 Pages
PublisherIndependently published
Edition1
LanguageEnglish
Year2026
ISBN9798173984937
756
A7217
انتخاب نوع چاپ:
جلد سخت
1,939,000ت
0
جلد نرم
2,069,000ت(2 جلدی)
0
طلق پاپکو و فنر
2,089,000ت(2 جلدی)
0
مجموع:
0تومان
کیفیت متن:اورجینال انتشارات
قطع:B5
رنگ صفحات:سیاه و سفید
پشتیبانی در روزهای تعطیل!
ارسال به سراسر کشور

#Exploit

#COP

#DEP/NX

#RELRO

#CFG

#LFH

#MTE

#ASLR

#C++

#CodeQL

#x86

توضیحات

🛡️ هنر توسعه Exploit در سیستم‌های مدرن


💥 هیچ دوره‌ای سخت‌تر از امروز برای نوشتن Exploit نبوده؛ اما هم‌زمان زمان بهتری هم برای یادگیری آن وجود نداشته است. کتاب The Art of Exploit Development, Second Edition فرایند مدرن Exploitation را از ساخت Lab تحقیقاتی تا Memory Corruption، دورزدن Mitigationها، Browser و Kernel Exploitation و Vulnerability Research در مقیاس بالا بررسی میکنه.


ویژگی‌های کلیدی

🖥️ تکنیک‌های اصلی Exploitation را روی هر دو معماری x86-64 و AArch64 بررسی میکنه؛ چون ARM بخش بزرگی از گوشی‌های جهان، سخت‌افزار Apple و سهم رو‌به‌رشدی از Cloud Serverها را اجرا میکنه.

🧠 کلاس‌های ماندگار Memory-corruption Bug مثل Stack Overflow،‏ Integer Bug و Format String را همراه با ROP،‏ JOP و COP پوشش میده.

🛡️ دفاع‌هایی مثل ASLR،‏ RELRO،‏ FORTIFY_SOURCE،‏ Clang CFI،‏ Windows CFG/XFG،‏ Intel CET،‏ ARM PAC و ARM MTE و الگوهای Leak و Bypass مرتبط با آن‌ها را بررسی میکنه.

🌐 یک مسیر End-to-end برای Browser،‏ JIT،‏ Linux Kernel و Windows Kernel Exploitation، از V8 و Renderer Sandbox تا VBS/HVCI، ارائه میده.

🧪 تمام Labها و Exploitها با Codeهای قابل‌اجرا در Companion Repository عمومی، محیط Pin‌شده و Continuous Integration خودکار ارائه میشن.

📘 توضیح کتاب

⚠️ در سیستم‌های امروزی، یک Stack Overflow به‌تنهایی دسترسی Shell ایجاد نمیکنه. میان ورودی و Operating System لایه‌هایی مثل ASLR،‏ Control-flow Integrity،‏ Shadow Stack در Intel CET،‏ Pointer Authentication در ARM،‏ Memory Tagging،‏ Browser Sandbox و Virtualization-based Security زیر Kernel قرار گرفتن.


🔗 Exploitation مدرن دیگه یک ترفند هوشمندانه منفرد نیست، بلکه یک Pipeline از Primitiveهاست. Primitiveها باید به هم متصل بشن تا Crash به Read،‏ Read به Write و Write در نهایت به Control تبدیل بشه. ویرایش دوم کتاب همین Pipeline را مطابق ساختار واقعی سیستم‌های امروزی آموزش میده.


🧠 کتاب در هفت بخش و ۳۴ فصل، یک Research Lab تکرارپذیر میسازه و از Targetهای واقعی اما عمداً آسیب‌پذیر برای بررسی لایه‌های مختلف سیستم استفاده میکنه. Memory Corruption،‏ Code Reuse،‏ Modern Mitigation Bypass،‏ Heap،‏ Browser،‏ JIT و Kernel Exploitation در این مسیر پوشش داده میشن.


🗃️ بخش Heap روی glibc مدرن در Ubuntu 24.04 و سازوکارهایی مثل Safe-linking و Tcache Hardening تمرکز داره. کتاب مشخص میکنه کدام House Techniqueها هنوز قابل‌استفاده‌اند و کدام روش‌ها دیگه در سیستم‌های جدید کاربرد ندارن.


🌐 بخش Browser و JIT به V8 Internals،‏ Pointer Compression،‏ addrof/fakeobj Primitiveها و عبور از Renderer Sandbox میپردازه. بخش Kernel نیز Targetهای دوره ۲۰۲۶، شامل io_uring،‏ eBPF،‏ Netfilter،‏ Cross-cache Attackها، Data-only Escalationها و مقابله با VBS/HVCI را بررسی میکنه.


🔍 بخش Vulnerability Research در مقیاس بالا، Coverage-guided و Structure-aware Fuzzing،‏ Syzkaller،‏ CodeQL Variant Analysis،‏ Symbolic Execution و Patch Diffing را پوشش میده. پروژه نهایی یک Bug پیداشده توسط Fuzzer را تا ساخت Exploit قابل‌اعتماد و Self-checking دنبال میکنه.


🧪 تمام تکنیک‌ها دارای Working Code در یک Companion Repository عمومی هستن. محیط کتاب روی Ubuntu 24.04 همراه با glibc 2.39،‏ gcc 13 و clang 18 Pin شده و Continuous Integration در هر Commit، تمام Labها را Build و تمام Exploitها را روی Linux Runnerهای واقعی اجرا میکنه.


🎯 کتاب از مطالب قدیمی و کم‌کاربرد فاصله گرفته و محتوای آن برای سیستم‌های واقعی امروز، Reproducible و به‌روز طراحی شده است. بعد از مطالعه، میتونی از اجرای Toolهای آماده به درک سازوکار آن‌ها، از موفقیت در CTF به Research واقعی و از خواندن Writeupها به نوشتن تحلیل‌های خودت برسی.


🎯 چیزهایی که یاد میگیری

🧠 یاد میگیری Exploit Development را روی معماری‌های x86-64 و AArch64 بررسی کنی.

💥 با Stack Overflow،‏ Integer Bug،‏ Format String و Primitiveهای Memory Corruption آشنا میشی.

🔗 میتونی منطق Code-reuse Techniqueهایی مثل ROP،‏ JOP و COP را درک کنی.

🛡️ یاد میگیری Mitigationهایی مثل ASLR،‏ CFI،‏ CET،‏ PAC و MTE چطور عمل میکنن و Bypass Patternهای آن‌ها چطور تحلیل میشن.

🗃️ با ساختار Heap در glibc 2.39،‏ Safe-linking،‏ Tcache Hardening و Windows Segment Heap آشنا میشی.

🌐 مسیر Browser و JIT Exploitation را از V8 Primitiveها تا Renderer Code Execution و Sandbox Escape دنبال میکنی.

⚙️ با Linux و Windows Kernel Exploitation،‏ eBPF،‏ Netfilter،‏ io_uring و Virtualization-based Security آشنا میشی.

🔍 یاد میگیری از Fuzzing،‏ CodeQL،‏ Symbolic Execution و Patch Diffing برای Vulnerability Research استفاده کنی.


👤 این کتاب برای چه کسانیه؟

🔐 این کتاب برای Security Researcherها، Exploit Developerها، Binary Analystها و متخصصان Offensive Security مناسبه که میخوان Exploitation مدرن را در سطح Architecture،‏ Userland،‏ Browser و Kernel درک کنن.

🧪 افرادی که تجربه CTF دارن و میخوان به Research واقعی برسن، کاربرانی که تاکنون بیشتر Tool اجرا کرده‌اند و حالا میخوان سازوکار آن‌ها را بفهمن و کسانی که قصد دارن به‌جای خواندن Writeup، تحلیل خودشان را بنویسن، مخاطبان اصلی کتاب هستن.

⚖️ تمام تمرین‌ها در Labهای تکرارپذیر و روی Targetهای عمداً آسیب‌پذیر انجام میشن. کتاب همچنین Responsible Disclosure،‏ Ethics و Law را در ضمیمه‌ای مستقل پوشش میده.


📖 فهرست مطالب

بخش اول. میدان نبرد مدرن

فصل ۱. ذهنیت Exploit Developer

فصل ۲. راه‌اندازی یک Research Lab مدرن

فصل ۳. Computer Architecture برای Exploitation

فصل ۴. دوره فشرده Reverse Engineering


بخش دوم. Memory Corruption در سیستم‌های مدرن

فصل ۵. بازنگری Stack-based Memory Corruption

فصل ۶. Shellcode برای عصر مدرن

فصل ۷. Format String و Integer Bugها

فصل ۸. دورزدن DEP/NX با Return-oriented Programming

فصل ۹. Code Reuse پیشرفته؛ JOP،‏ COP و روش‌های دیگر


بخش سوم. شکست‌دادن Mitigationهای مدرن

فصل ۱۰. ASLR و هنر Information Leak

فصل ۱۱. Stack Canaryها،‏ RELRO و FORTIFY

فصل ۱۲. Control-flow Integrity؛‏ CFG،‏ XFG و CFI

فصل ۱۳. دفاع‌های Hardware-enforced؛‏ CET،‏ PAC و MTE


بخش چهارم. Userland Heap

فصل ۱۴. اجزای داخلی Heap؛‏ glibc malloc در سال ۲۰۲۶

فصل ۱۵. Primitiveهای Heap Exploitation

فصل ۱۶. مدرن‌سازی House Techniqueها

فصل ۱۷. Use-after-free و Type Confusion در C++

فصل ۱۸. Windows Heap Exploitation؛‏ Segment Heap و LFH


بخش پنجم. Browser و JIT Exploitation

فصل ۱۹. ساختار یک Browser مدرن و Sandbox آن

فصل ۲۰. اجزای داخلی JavaScript Engine برای Exploitation

فصل ۲۱. Exploit کردن JIT؛‏ addrof و fakeobj

فصل ۲۲. از Arbitrary Read/Write تا Code Execution در Renderer مقاوم‌سازی‌شده

فصل ۲۳. خروج از Sandbox


بخش ششم. Kernel Exploitation

فصل ۲۴. Operating System Kernelها برای Exploit Developerها

فصل ۲۵. Linux Kernel Exploitation یک؛ Bugها و Primitiveها

فصل ۲۶. Linux Kernel Exploitation دو؛ Targetهای مدرن

فصل ۲۷. Windows Kernel Exploitation

فصل ۲۸. شکست‌دادن Virtualization-based Security


بخش هفتم. Vulnerability Research در مقیاس بالا

فصل ۲۹. Fuzzing یک؛ Coverage-guided Fuzzing

فصل ۳۰. Fuzzing دو؛ Structure-aware و Snapshot Fuzzing

فصل ۳۱. Static Analysis و Variant Analysis

فصل ۳۲. Symbolic و Concolic Execution

فصل ۳۳. Patch Diffing و N-day Analysis

فصل ۳۴. زنجیره کامل؛ از Crash تا Exploit قابل‌اعتماد

ضمیمه A. Companion Lab

ضمیمه B. مرجع ابزارها

ضمیمه C. مرجع سریع x86-64 و AArch64

ضمیمه D. Responsible Disclosure،‏ Ethics و Law

ضمیمه E. منابع تکمیلی مطالعه و پژوهش


👤 درباره نویسنده

🔐 آیوکوتسو تنریوکو کازاما، Vulnerability Researcher و Exploit Developer است و در Offensive Security،‏ Vulnerability Discovery،‏ Binary Exploitation و Reverse Engineering تخصص داره.

🧠 حوزه‌های موردعلاقه او شامل Web Application Security،‏ Memory-corruption Vulnerabilityها، دورزدن Modern Exploit Mitigationها،‏ Fuzzing،‏ Symbolic Execution و Linux و Windows Kernel Exploitation میشه.

📚 کازاما نویسنده کتاب The Art of Exploit Development است؛ راهنمایی عملی و Lab-driven که تکنیک‌های مدرن Exploitation را در سیستم‌های x86-64 و AArch64 پوشش میده.

🧪 او همچنین منابع Open Source همراه کتاب را نگهداری میکنه و Codeهای Reproducible و تمرین‌های Hands-on را در اختیار خوانندگان قرار میده.

🎓 کازاما از طریق فعالیت‌های پژوهشی و آموزشی خود تلاش میکنه دانش پیشرفته Exploit Development را برای Security Researcherهای تازه‌کار، به‌خصوص افرادی که به آموزش رسمی یا Mentorship حرفه‌ای دسترسی ندارن، قابل‌دسترس‌تر کنه.


There has never been a harder time to write an exploit — or a better time to learn how.


A stack overflow no longer buys you a shell. Between your input and the operating system stand ASLR, control-flow integrity, Intel CET's shadow stack, ARM pointer authentication, memory tagging, a browser sandbox, and a virtualization-based security layer beneath the kernel. Modern exploitation is no longer a single clever trick. It is a pipeline: chain primitives together until a crash becomes a read, a read becomes a write, and a write becomes control.


The Art of Exploit Development, Second Edition, teaches that pipeline as it actually exists today. Across seven parts and thirty-four chapters, you will build a reproducible research lab and use it to attack real, deliberately vulnerable targets across every layer of a modern system:

  • x86-64 and AArch64 as first-class citizens — every core technique on both architectures, because ARM now runs most of the world's phones, Apple hardware, and a growing share of cloud servers.
  • The durable memory-corruption bug classes — stack overflows, integer bugs, format strings — and the return-, jump-, and call-oriented programming that replaced injected shellcode once the stack stopped being executable.
  • The mitigations that define the current arms race: ASLR, RELRO, FORTIFY_SOURCE, Clang CFI, Windows CFG/XFG, Intel CET, ARM PAC, and ARM MTE — and the concrete leak-and-bypass patterns that get around each.
  • The modern glibc heap on Ubuntu 24.04 with safe-linking and tcache hardening, including which "house" techniques still work and which are dead.
  • Browser and JIT exploitation end to end: V8 internals with pointer compression, addrof/fakeobj primitives, escaping the renderer sandbox.
  • Linux and Windows kernel exploitation on 2026-era targets: io_uring, eBPF, netfilter, cross-cache attacks, data-only escalations, and defeating VBS/HVCI.
  • Vulnerability research at scale: coverage-guided and structure-aware fuzzing, syzkaller, CodeQL variant analysis, symbolic execution, patch diffing, and a full-chain capstone that takes a fuzzer-found bug all the way to a reliable, self-checking exploit.


Every technique has working code in a public companion repository, pinned to Ubuntu 24.04 with glibc 2.39, gcc 13, and clang 18. Continuous integration builds every lab and runs every exploit on real Linux runners on every commit — when this book says an exploit works, a machine has just checked that claim.


Nothing here is legacy filler. Everything is pinned, reproducible, and current for the systems you actually attack today. If you have wanted to move from running tools to understanding them, from CTF wins to real research, from reading writeups to writing your own — this is the book.


Table of Contents

Part I. The Modern Battlefield

Chapter 1. The Exploit Developer's Mindset

Chapter 2. Setting Up a Modern Research Lab

Chapter 3. Computer Architecture for Exploitation

Chapter 4. A Crash Course in Reverse Engineering


Part II. Memory Corruption on Modern Systems

Chapter 5. Stack-Based Memory Corruption Revisited

Chapter 6. Shellcode for the Modern Age

Chapter 7. Format String and Integer Bugs

Chapter 8. Bypassing DEP/NX with Return-Oriented Programming

Chapter 9. Advanced Code Reuse: JOP, COP, and Friends


Part III. Defeating Modern Mitigations

Chapter 10. ASLR and the Art of the Information Leak

Chapter 11. Stack Canaries, RELRO, and FORTIFY

Chapter 12. Control-Flow Integrity: CFG, XFG, and CFI

Chapter 13. Hardware-Enforced Defenses: CET, PAC, and MTE


Part IV. The Userland Heap

Chapter 14. Heap Internals: glibc malloc in 2026

Chapter 15. Heap Exploitation Primitives

Chapter 16. The House Techniques, Modernized

Chapter 17. Use-After-Free and Type Confusion in C++

Chapter 18. Windows Heap Exploitation: Segment Heap and the LFH


Part V. Browser and JIT Exploitation

Chapter 19. Anatomy of a Modern Browser and Its Sandbox

Chapter 20. JavaScript Engine Internals for Exploitation

Chapter 21. Exploiting the JIT (addrof and fakeobj)

Chapter 22. From Arbitrary R/W to Code Execution in a Hardened Renderer

Chapter 23. Escaping the Sandbox


Part VI. Kernel Exploitation

Chapter 24. Operating System Kernels for Exploit Developers

Chapter 25. Linux Kernel Exploitation I: Bugs and Primitives

Chapter 26. Linux Kernel Exploitation II: Modern Targets

Chapter 27. Windows Kernel Exploitation

Chapter 28. Defeating Virtualization-Based Security


Part VII. Vulnerability Research at Scale

Chapter 29. Fuzzing I: Coverage-Guided Fuzzing

Chapter 30. Fuzzing II: Structure-Aware and Snapshot Fuzzing

Chapter 31. Static Analysis and Variant Analysis

Chapter 32. Symbolic and Concolic Execution

Chapter 33. Patch Diffing and N-Day Analysis

Chapter 34. The Full Chain: From Crash to Reliable Exploit


Appendix A. The Companion Lab

Appendix B. Tooling Reference

Appendix C. x86-64 and AArch64 Quick Reference

Appendix D. Responsible Disclosure, Ethics, and the Law

Appendix E. Further Reading and Research Resources


About the Author

Ayukotsu Tenryoku Kazama is a vulnerability researcher and exploit developer specializing in offensive security, vulnerability discovery, binary exploitation, and reverse engineering. His areas of interest include web application security, memory-corruption vulnerabilities, modern exploit-mitigation bypasses, fuzzing, symbolic execution, and Linux and Windows kernel exploitation.

Kazama is the author of The Art of Exploit Development, a practical, lab-driven guide covering modern exploitation techniques across x86-64 and AArch64 systems. He also maintains the book’s open-source companion materials, providing reproducible code and hands-on exercises. Through his research and educational work, he aims to make advanced exploit-development knowledge more accessible to aspiring security researchers, particularly those without access to formal training or professional mentorship.

دیدگاه خود را بنویسید
نظرات کاربران (0 دیدگاه)
نظری وجود ندارد.
کتاب های مشابه
هک و امنیت
767
Certificate of Cloud Security Knowledge (CCSK v5) Study Guide
934,000 تومان
هک و امنیت
854
Privacy and Security for Large Language Models
960,000 تومان
هک و امنیت
1,183
Threat Modeling
1,898,000 تومان
هک و امنیت
1,472
Burp Suite Cookbook
1,250,000 تومان
هک و امنیت
772
The Hacker Mindset
454,000 تومان
هک و امنیت
1,076
Snowflake Security
720,000 تومان
هک و امنیت
1,242
Beginning Ethical Hacking with Python
694,000 تومان
Network
2,133
Network Security
1,719,000 تومان
هک و امنیت
7,759
Bug Bounty Bootcamp
1,180,000 تومان
هک و امنیت
674
Hacking Exposed - Wireless
1,717,000 تومان
قیمت
منصفانه
ارسال به
سراسر کشور
تضمین
کیفیت
پشتیبانی در
روزهای تعطیل
خرید امن
و آسان
آرشیو بزرگ
کتاب‌های تخصصی
هـر روز با بهتــرین و جــدیــدتـرین
کتاب های روز دنیا با ما همراه باشید
آدرس
پشتیبانی
مدیریت
ساعات پاسخگویی
درباره اسکای بوک
دسترسی های سریع
  • راهنمای خرید
  • راهنمای ارسال
  • سوالات متداول
  • قوانین و مقررات
  • وبلاگ
  • درباره ما