Reverse Engineering & Binary Analysis Basics · Lezione

Mitigazioni moderne degli exploit e tecniche di bypass

Comprendete le difese che si frappongono tra una vulnerabilità e un exploit funzionante: ASLR, DEP/NX, stack canary, CFG e i concetti generali alla base del loro bypass.

Lezione 4 di 413 passaggi

Mitigazioni moderne degli exploit e tecniche di bypass è una lezione Reverse Engineering & Binary Analysis Basics gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Reverse Engineering & Binary Analysis Basics, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Reverse Engineering & Binary Analysis Basics include 4 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Why Exploits Got Harder

You can identify binary vulnerabilities, fuzz for bugs, and understand exploit primitives. Modern systems add mitigations that turn an easy bug into a hard one.

Knowing these defenses tells you what a working exploit must overcome.

Data Execution Prevention (DEP/NX)

DEP (a.k.a. the NX bit) marks memory as non-executable. Code injected onto the stack will not run.

This killed classic 'shellcode on the stack' attacks and pushed exploiters toward code reuse.

Return-Oriented Programming

To bypass DEP, attackers reuse existing executable code. ROP chains together short instruction sequences (gadgets) ending in ret to perform arbitrary actions without injecting code.

; a gadget
pop rdi
ret
; chained: set rdi, then call a real function

Address Space Layout Randomization

ASLR randomizes where modules, stack, and heap load each run, so attackers cannot hardcode addresses.

Without a known address, both shellcode and ROP gadgets are hard to target.

Defeating ASLR with Leaks

ASLR is bypassed with an information leak: a bug that discloses a real runtime address. From one leaked pointer you compute the module base and locate your gadgets.

Many modern exploits are really 'leak then exploit' two-stage attacks.

Stack Canaries

A stack canary is a random value placed before the saved return address. A linear stack overflow overwrites it, and the function aborts on mismatch.

; epilogue check
mov rax, [rbp-8]
xor rax, fs:[0x28]
jne __stack_chk_fail

Bypassing Canaries

Canaries are defeated by:

  • Leaking the canary value, then writing it back unchanged
  • Overwriting structures that skip the check (e.g. a non-linear write)

This is why info leaks are so valuable.

Control-Flow Integrity

CFI and Windows' CFG validate indirect calls and returns against a set of legitimate targets, breaking many ROP chains.

Hardware features like Intel CET add a shadow stack to protect return addresses.

RELRO and Fortify

Other hardening you will encounter:

  • Full RELRO makes the GOT read-only, blocking GOT-overwrite tricks
  • FORTIFY_SOURCE adds bounds checks to common functions

Check which are enabled before planning an approach.

checksec --file=./target
# RELRO: Full   Canary: Yes   NX: Yes   PIE: Yes

The Mitigation Mindset

Exploit development is an enumerate-then-bypass process: list active mitigations, then find the bug or leak that neutralizes each. Strong defenses do not make exploitation impossible, only more demanding.

PIE and Position Independence

PIE (Position Independent Executable) lets ASLR randomize the main binary itself, not just libraries. Without PIE, the executable loads at a fixed base, giving attackers reliable gadget addresses.

checksec reporting 'PIE: No' is a meaningful weakness worth noting.

Quick Check

Which technique is specifically designed to bypass DEP/NX by reusing existing executable code instead of injecting new code?

Recap

You now map the modern defensive landscape:

  • DEP/NX blocks injected code; ROP reuses existing code
  • ASLR randomizes addresses; info leaks defeat it
  • Canaries, CFI/CFG, RELRO add further hurdles

Real exploitation means enumerating these and chaining bugs to bypass each.

Gratis per iniziare

Impara Assembly con un tutor IA — gratis

Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.

Corsi
12
Lezioni
48

Domande Frequenti

La lezione «Mitigazioni moderne degli exploit e tecniche di bypass» è gratuita?

Sì — il testo completo di «Mitigazioni moderne degli exploit e tecniche di bypass» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Reverse Engineering & Binary Analysis Basics, passa a CoddyKit PRO. Il corso Reverse Engineering & Binary Analysis Basics include 4 lezioni in totale.

Cosa imparerò in «Mitigazioni moderne degli exploit e tecniche di bypass»?

Comprendete le difese che si frappongono tra una vulnerabilità e un exploit funzionante: ASLR, DEP/NX, stack canary, CFG e i concetti generali alla base del loro bypass. Eserciti Reverse Engineering & Binary Analysis Basics con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare Reverse Engineering & Binary Analysis Basics?

Non è richiesta alcuna esperienza precedente. Reverse Engineering & Binary Analysis Basics su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.

Quanto tempo richiede la lezione «Mitigazioni moderne degli exploit e tecniche di bypass»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione Reverse Engineering & Binary Analysis Basics?

Sì. Ogni lezione Reverse Engineering & Binary Analysis Basics include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Identificazione delle vulnerabilità nei binari
  2. Introduzione al fuzzing
  3. Panoramica delle primitive di exploit
  4. Mitigazioni moderne degli exploit e tecniche di bypass
← Torna a Reverse Engineering & Binary Analysis Basics