Skip to content

Latest commit

 

History

History
74 lines (38 loc) · 1.09 KB

TODO.md

File metadata and controls

74 lines (38 loc) · 1.09 KB

libc scraping

debian scraping

ubuntu scraping

libc offset database

index package download urls

kernel exploit development

useful structure search

automatic loading of kernel modules into gdb

initramfs compress and decompress

btf type parsing for gdb

wrapper for userfaultfd, io_uring, bpf apis

check for unintendeds

kernel gdb scripting

  • searching for constant sections from kbase/absolute locations (LDT, IDT)

gdb scripting

better gdb api interaction from solve scripts

pwninit style setup

payloads

modern fsop

setcontext structure

automated printf tooling

setcontext32

got chaining

stdout/stdin leakless leak

tls destructor rip control

exit functions rip control

printf tables rip control

tls pthread async canel rip control

brute forcing

manager for launching concurrent brute force

binary patching

improved one gadget

v8/chrome

call the DebugPrint function in a safe context, so calling on invalid v8 objects does not crash the process in gdb

check for unintendeds

checkpointing?

binja integration

symbols, types, function locals, labels