Introduction to Binary Exploitation: Understanding ret2libc - Part 2
The challenge can be downloaded from: Download Link (Password: 0000)
Solution Approach
ret2libc involves hijacking program control flow to execute funcsions from the standard C library (libc). Typically, this is achieved by redirecting execution to a function's PLT entry or a specific address within the GOT table. Usual, the goal is to invoke s ...
Posted on Tue, 15 Sep 2026 16:30:59 +0000 by oriental_express
Exploiting Java Deserialization via Commons Collections CC1 Gadget Chain
Environment Setup
Java version: 1.8.0_65
Apache Commons Collections: 3.2.2
Vulnerability Overview
The CC1 gadget chain leverages the Transformer interface in Apache Commons Collections to achieve remote code execution (RCE) during Java deserialization when untrusted data is processed.
Exploitation Details
Step 1: Command Execution Primitive
T ...
Posted on Mon, 24 Aug 2026 16:28:50 +0000 by Bootsman123