jonoberheide / kstructhunter
Routines for hunting down kernel structs.
☆40Updated 13 years ago
Related projects ⓘ
Alternatives and complementary repositories for kstructhunter
- A ROP and binary analysis exploit challenge for edurange☆15Updated 9 years ago
- CansecWest2016 - Getting Physical: Extreme Abuse of Intel Based Paging Systems☆27Updated 8 years ago
- Proof of Concept files for SensePost's blog - Painless intro to the linux userland heap☆22Updated 7 years ago
- ARM rop chain gadget searcher☆37Updated 7 years ago
- Memory awesomeness.☆29Updated 9 years ago
- PoC code for our presentation titled "Stackjacking Your Way to grsec/PaX Bypass"☆46Updated 13 years ago
- A tool to add simple inline patches to a binary to rearrange its stack frames, and other things!☆45Updated 2 years ago
- Triton based R2 plugin for concolic execution and total control☆30Updated 5 years ago
- ☆28Updated 2 years ago
- A pin tool to visualise heap operations☆21Updated 9 years ago
- Nosy Newt is a simple concolic execution tool for exploring the input space of a binary executable program based in Triton☆61Updated 7 years ago
- Use ltrace with pwnlib.tubes.process instances, useful for heap exploitation. Pwntools rocks!☆52Updated 6 years ago
- A pip wrapper around our ridiculous amount of qemu forks.☆48Updated 9 months ago
- IDAPython script for quick vulnerability analysis☆33Updated 10 years ago
- Fuzzing scripts for the American Fuzzy Lop (AFL) fuzzer☆47Updated 8 years ago
- Python repository containing parsed standard C library function and argument information☆26Updated 6 years ago
- ropc-llvm is a PoC of a Turing complete ROP compiler with support for a subset of LLVM IR. It is an extension of ropc.☆66Updated 11 years ago
- Binary Analysis Platform☆73Updated 11 years ago
- Use angr inside the radare2 debugger. Create an angr state from the current debugger state.☆34Updated 5 years ago
- AFL "mostly" ported to cygwin☆26Updated 8 years ago
- Vulnerability research and development.☆25Updated 9 years ago
- Bootloader research tools (very much a work in progress)☆37Updated 5 years ago
- ☆26Updated 8 years ago
- A distributed corpus distillation tool for windows applications.☆32Updated 7 years ago
- Automatic function exporting and linking for fuzzing cross-architecture binaries.☆50Updated 6 years ago
- A little tool to execute functions without debugging an entire executable. Originally written by Gonzalo J. Carracedo (BatchDrake).☆28Updated 10 years ago
- SIGSTOPing ELF binaries since 0x7E1☆50Updated 3 months ago
- Memory fuzzing based on sinn3r's In Memory Fuzzer☆26Updated 12 years ago