A Practical Guide to Building Exploits for Modern Systems
Ayukotsu Tenryoku Kazama

#Exploit
#COP
#DEP/NX
#RELRO
#CFG
#LFH
#MTE
#ASLR
#C++
#CodeQL
#x86
🛡️ هنر توسعه Exploit در سیستمهای مدرن
💥 هیچ دورهای سختتر از امروز برای نوشتن Exploit نبوده؛ اما همزمان زمان بهتری هم برای یادگیری آن وجود نداشته است. کتاب The Art of Exploit Development, Second Edition فرایند مدرن Exploitation را از ساخت Lab تحقیقاتی تا Memory Corruption، دورزدن Mitigationها، Browser و Kernel Exploitation و Vulnerability Research در مقیاس بالا بررسی میکنه.
✨ ویژگیهای کلیدی
🖥️ تکنیکهای اصلی Exploitation را روی هر دو معماری x86-64 و AArch64 بررسی میکنه؛ چون ARM بخش بزرگی از گوشیهای جهان، سختافزار Apple و سهم روبهرشدی از Cloud Serverها را اجرا میکنه.
🧠 کلاسهای ماندگار Memory-corruption Bug مثل Stack Overflow، Integer Bug و Format String را همراه با ROP، JOP و COP پوشش میده.
🛡️ دفاعهایی مثل ASLR، RELRO، FORTIFY_SOURCE، Clang CFI، Windows CFG/XFG، Intel CET، ARM PAC و ARM MTE و الگوهای Leak و Bypass مرتبط با آنها را بررسی میکنه.
🌐 یک مسیر End-to-end برای Browser، JIT، Linux Kernel و Windows Kernel Exploitation، از V8 و Renderer Sandbox تا VBS/HVCI، ارائه میده.
🧪 تمام Labها و Exploitها با Codeهای قابلاجرا در Companion Repository عمومی، محیط Pinشده و Continuous Integration خودکار ارائه میشن.
📘 توضیح کتاب
⚠️ در سیستمهای امروزی، یک Stack Overflow بهتنهایی دسترسی Shell ایجاد نمیکنه. میان ورودی و Operating System لایههایی مثل ASLR، Control-flow Integrity، Shadow Stack در Intel CET، Pointer Authentication در ARM، Memory Tagging، Browser Sandbox و Virtualization-based Security زیر Kernel قرار گرفتن.
🔗 Exploitation مدرن دیگه یک ترفند هوشمندانه منفرد نیست، بلکه یک Pipeline از Primitiveهاست. Primitiveها باید به هم متصل بشن تا Crash به Read، Read به Write و Write در نهایت به Control تبدیل بشه. ویرایش دوم کتاب همین Pipeline را مطابق ساختار واقعی سیستمهای امروزی آموزش میده.
🧠 کتاب در هفت بخش و ۳۴ فصل، یک Research Lab تکرارپذیر میسازه و از Targetهای واقعی اما عمداً آسیبپذیر برای بررسی لایههای مختلف سیستم استفاده میکنه. Memory Corruption، Code Reuse، Modern Mitigation Bypass، Heap، Browser، JIT و Kernel Exploitation در این مسیر پوشش داده میشن.
🗃️ بخش Heap روی glibc مدرن در Ubuntu 24.04 و سازوکارهایی مثل Safe-linking و Tcache Hardening تمرکز داره. کتاب مشخص میکنه کدام House Techniqueها هنوز قابلاستفادهاند و کدام روشها دیگه در سیستمهای جدید کاربرد ندارن.
🌐 بخش Browser و JIT به V8 Internals، Pointer Compression، addrof/fakeobj Primitiveها و عبور از Renderer Sandbox میپردازه. بخش Kernel نیز Targetهای دوره ۲۰۲۶، شامل io_uring، eBPF، Netfilter، Cross-cache Attackها، Data-only Escalationها و مقابله با VBS/HVCI را بررسی میکنه.
🔍 بخش Vulnerability Research در مقیاس بالا، Coverage-guided و Structure-aware Fuzzing، Syzkaller، CodeQL Variant Analysis، Symbolic Execution و Patch Diffing را پوشش میده. پروژه نهایی یک Bug پیداشده توسط Fuzzer را تا ساخت Exploit قابلاعتماد و Self-checking دنبال میکنه.
🧪 تمام تکنیکها دارای Working Code در یک Companion Repository عمومی هستن. محیط کتاب روی Ubuntu 24.04 همراه با glibc 2.39، gcc 13 و clang 18 Pin شده و Continuous Integration در هر Commit، تمام Labها را Build و تمام Exploitها را روی Linux Runnerهای واقعی اجرا میکنه.
🎯 کتاب از مطالب قدیمی و کمکاربرد فاصله گرفته و محتوای آن برای سیستمهای واقعی امروز، Reproducible و بهروز طراحی شده است. بعد از مطالعه، میتونی از اجرای Toolهای آماده به درک سازوکار آنها، از موفقیت در CTF به Research واقعی و از خواندن Writeupها به نوشتن تحلیلهای خودت برسی.
🎯 چیزهایی که یاد میگیری
🧠 یاد میگیری Exploit Development را روی معماریهای x86-64 و AArch64 بررسی کنی.
💥 با Stack Overflow، Integer Bug، Format String و Primitiveهای Memory Corruption آشنا میشی.
🔗 میتونی منطق Code-reuse Techniqueهایی مثل ROP، JOP و COP را درک کنی.
🛡️ یاد میگیری Mitigationهایی مثل ASLR، CFI، CET، PAC و MTE چطور عمل میکنن و Bypass Patternهای آنها چطور تحلیل میشن.
🗃️ با ساختار Heap در glibc 2.39، Safe-linking، Tcache Hardening و Windows Segment Heap آشنا میشی.
🌐 مسیر Browser و JIT Exploitation را از V8 Primitiveها تا Renderer Code Execution و Sandbox Escape دنبال میکنی.
⚙️ با Linux و Windows Kernel Exploitation، eBPF، Netfilter، io_uring و Virtualization-based Security آشنا میشی.
🔍 یاد میگیری از Fuzzing، CodeQL، Symbolic Execution و Patch Diffing برای Vulnerability Research استفاده کنی.
👤 این کتاب برای چه کسانیه؟
🔐 این کتاب برای Security Researcherها، Exploit Developerها، Binary Analystها و متخصصان Offensive Security مناسبه که میخوان Exploitation مدرن را در سطح Architecture، Userland، Browser و Kernel درک کنن.
🧪 افرادی که تجربه CTF دارن و میخوان به Research واقعی برسن، کاربرانی که تاکنون بیشتر Tool اجرا کردهاند و حالا میخوان سازوکار آنها را بفهمن و کسانی که قصد دارن بهجای خواندن Writeup، تحلیل خودشان را بنویسن، مخاطبان اصلی کتاب هستن.
⚖️ تمام تمرینها در Labهای تکرارپذیر و روی Targetهای عمداً آسیبپذیر انجام میشن. کتاب همچنین Responsible Disclosure، Ethics و Law را در ضمیمهای مستقل پوشش میده.
📖 فهرست مطالب
بخش اول. میدان نبرد مدرن
فصل ۱. ذهنیت Exploit Developer
فصل ۲. راهاندازی یک Research Lab مدرن
فصل ۳. Computer Architecture برای Exploitation
فصل ۴. دوره فشرده Reverse Engineering
بخش دوم. Memory Corruption در سیستمهای مدرن
فصل ۵. بازنگری Stack-based Memory Corruption
فصل ۶. Shellcode برای عصر مدرن
فصل ۷. Format String و Integer Bugها
فصل ۸. دورزدن DEP/NX با Return-oriented Programming
فصل ۹. Code Reuse پیشرفته؛ JOP، COP و روشهای دیگر
بخش سوم. شکستدادن Mitigationهای مدرن
فصل ۱۰. ASLR و هنر Information Leak
فصل ۱۱. Stack Canaryها، RELRO و FORTIFY
فصل ۱۲. Control-flow Integrity؛ CFG، XFG و CFI
فصل ۱۳. دفاعهای Hardware-enforced؛ CET، PAC و MTE
بخش چهارم. Userland Heap
فصل ۱۴. اجزای داخلی Heap؛ glibc malloc در سال ۲۰۲۶
فصل ۱۵. Primitiveهای Heap Exploitation
فصل ۱۶. مدرنسازی House Techniqueها
فصل ۱۷. Use-after-free و Type Confusion در C++
فصل ۱۸. Windows Heap Exploitation؛ Segment Heap و LFH
بخش پنجم. Browser و JIT Exploitation
فصل ۱۹. ساختار یک Browser مدرن و Sandbox آن
فصل ۲۰. اجزای داخلی JavaScript Engine برای Exploitation
فصل ۲۱. Exploit کردن JIT؛ addrof و fakeobj
فصل ۲۲. از Arbitrary Read/Write تا Code Execution در Renderer مقاومسازیشده
فصل ۲۳. خروج از Sandbox
بخش ششم. Kernel Exploitation
فصل ۲۴. Operating System Kernelها برای Exploit Developerها
فصل ۲۵. Linux Kernel Exploitation یک؛ Bugها و Primitiveها
فصل ۲۶. Linux Kernel Exploitation دو؛ Targetهای مدرن
فصل ۲۷. Windows Kernel Exploitation
فصل ۲۸. شکستدادن Virtualization-based Security
بخش هفتم. Vulnerability Research در مقیاس بالا
فصل ۲۹. Fuzzing یک؛ Coverage-guided Fuzzing
فصل ۳۰. Fuzzing دو؛ Structure-aware و Snapshot Fuzzing
فصل ۳۱. Static Analysis و Variant Analysis
فصل ۳۲. Symbolic و Concolic Execution
فصل ۳۳. Patch Diffing و N-day Analysis
فصل ۳۴. زنجیره کامل؛ از Crash تا Exploit قابلاعتماد
ضمیمه A. Companion Lab
ضمیمه B. مرجع ابزارها
ضمیمه C. مرجع سریع x86-64 و AArch64
ضمیمه D. Responsible Disclosure، Ethics و Law
ضمیمه E. منابع تکمیلی مطالعه و پژوهش
👤 درباره نویسنده
🔐 آیوکوتسو تنریوکو کازاما، Vulnerability Researcher و Exploit Developer است و در Offensive Security، Vulnerability Discovery، Binary Exploitation و Reverse Engineering تخصص داره.
🧠 حوزههای موردعلاقه او شامل Web Application Security، Memory-corruption Vulnerabilityها، دورزدن Modern Exploit Mitigationها، Fuzzing، Symbolic Execution و Linux و Windows Kernel Exploitation میشه.
📚 کازاما نویسنده کتاب The Art of Exploit Development است؛ راهنمایی عملی و Lab-driven که تکنیکهای مدرن Exploitation را در سیستمهای x86-64 و AArch64 پوشش میده.
🧪 او همچنین منابع Open Source همراه کتاب را نگهداری میکنه و Codeهای Reproducible و تمرینهای Hands-on را در اختیار خوانندگان قرار میده.
🎓 کازاما از طریق فعالیتهای پژوهشی و آموزشی خود تلاش میکنه دانش پیشرفته Exploit Development را برای Security Researcherهای تازهکار، بهخصوص افرادی که به آموزش رسمی یا Mentorship حرفهای دسترسی ندارن، قابلدسترستر کنه.
There has never been a harder time to write an exploit — or a better time to learn how.
A stack overflow no longer buys you a shell. Between your input and the operating system stand ASLR, control-flow integrity, Intel CET's shadow stack, ARM pointer authentication, memory tagging, a browser sandbox, and a virtualization-based security layer beneath the kernel. Modern exploitation is no longer a single clever trick. It is a pipeline: chain primitives together until a crash becomes a read, a read becomes a write, and a write becomes control.
The Art of Exploit Development, Second Edition, teaches that pipeline as it actually exists today. Across seven parts and thirty-four chapters, you will build a reproducible research lab and use it to attack real, deliberately vulnerable targets across every layer of a modern system:
Every technique has working code in a public companion repository, pinned to Ubuntu 24.04 with glibc 2.39, gcc 13, and clang 18. Continuous integration builds every lab and runs every exploit on real Linux runners on every commit — when this book says an exploit works, a machine has just checked that claim.
Nothing here is legacy filler. Everything is pinned, reproducible, and current for the systems you actually attack today. If you have wanted to move from running tools to understanding them, from CTF wins to real research, from reading writeups to writing your own — this is the book.
Table of Contents
Part I. The Modern Battlefield
Chapter 1. The Exploit Developer's Mindset
Chapter 2. Setting Up a Modern Research Lab
Chapter 3. Computer Architecture for Exploitation
Chapter 4. A Crash Course in Reverse Engineering
Part II. Memory Corruption on Modern Systems
Chapter 5. Stack-Based Memory Corruption Revisited
Chapter 6. Shellcode for the Modern Age
Chapter 7. Format String and Integer Bugs
Chapter 8. Bypassing DEP/NX with Return-Oriented Programming
Chapter 9. Advanced Code Reuse: JOP, COP, and Friends
Part III. Defeating Modern Mitigations
Chapter 10. ASLR and the Art of the Information Leak
Chapter 11. Stack Canaries, RELRO, and FORTIFY
Chapter 12. Control-Flow Integrity: CFG, XFG, and CFI
Chapter 13. Hardware-Enforced Defenses: CET, PAC, and MTE
Part IV. The Userland Heap
Chapter 14. Heap Internals: glibc malloc in 2026
Chapter 15. Heap Exploitation Primitives
Chapter 16. The House Techniques, Modernized
Chapter 17. Use-After-Free and Type Confusion in C++
Chapter 18. Windows Heap Exploitation: Segment Heap and the LFH
Part V. Browser and JIT Exploitation
Chapter 19. Anatomy of a Modern Browser and Its Sandbox
Chapter 20. JavaScript Engine Internals for Exploitation
Chapter 21. Exploiting the JIT (addrof and fakeobj)
Chapter 22. From Arbitrary R/W to Code Execution in a Hardened Renderer
Chapter 23. Escaping the Sandbox
Part VI. Kernel Exploitation
Chapter 24. Operating System Kernels for Exploit Developers
Chapter 25. Linux Kernel Exploitation I: Bugs and Primitives
Chapter 26. Linux Kernel Exploitation II: Modern Targets
Chapter 27. Windows Kernel Exploitation
Chapter 28. Defeating Virtualization-Based Security
Part VII. Vulnerability Research at Scale
Chapter 29. Fuzzing I: Coverage-Guided Fuzzing
Chapter 30. Fuzzing II: Structure-Aware and Snapshot Fuzzing
Chapter 31. Static Analysis and Variant Analysis
Chapter 32. Symbolic and Concolic Execution
Chapter 33. Patch Diffing and N-Day Analysis
Chapter 34. The Full Chain: From Crash to Reliable Exploit
Appendix A. The Companion Lab
Appendix B. Tooling Reference
Appendix C. x86-64 and AArch64 Quick Reference
Appendix D. Responsible Disclosure, Ethics, and the Law
Appendix E. Further Reading and Research Resources
About the Author
Ayukotsu Tenryoku Kazama is a vulnerability researcher and exploit developer specializing in offensive security, vulnerability discovery, binary exploitation, and reverse engineering. His areas of interest include web application security, memory-corruption vulnerabilities, modern exploit-mitigation bypasses, fuzzing, symbolic execution, and Linux and Windows kernel exploitation.
Kazama is the author of The Art of Exploit Development, a practical, lab-driven guide covering modern exploitation techniques across x86-64 and AArch64 systems. He also maintains the book’s open-source companion materials, providing reproducible code and hands-on exercises. Through his research and educational work, he aims to make advanced exploit-development knowledge more accessible to aspiring security researchers, particularly those without access to formal training or professional mentorship.









