ctf-pwn
Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc, shellcode, kernel exploitation, seccomp bypass, sandbox escape, or Windows/Linux exploit chains. Do not use it when the main blocker is understanding what the binary does; use reverse engineering first. D
Security Assessment
Detected risks:
About ctf-pwn
The ctf-pwn skill provides guidance and reference material for binary exploitation challenges commonly found in Capture The Flag (CTF) competitions. It is designed for situations where a vulnerable native binary or service has already been identified and the goal is to escalate low-level memory corruption primitives into code execution, privilege escalation, or sandbox escape. The skill focuses on exploit development techniques rather than reverse engineering or binary analysis, making it most useful after the target’s behavior and vulnerabilities are already understood. It supports workflows involving stack overflows, heap corruption, format string vulnerabilities, return-oriented programming (ROP), shellcode execution, kernel exploitation, seccomp bypasses, and exploit chaining on Linux and Windows targets.
The skill includes a curated set of exploitation references covering both foundational and advanced techniques. Documented topics include ret2libc, syscall-oriented ROP, Sigreturn-Oriented Programming (SROP), heap exploitation methods such as House of Orange and House of Einherjar, GOT overwrites, ret2dlresolve, seccomp bypass strategies, stack pivots, shell interaction primitives, blind exploitation, and custom allocator abuse. It also provides setup instructions for common exploitation tooling such as pwntools, ROPgadget, ropper, gdb, pwndbg, strace, ltrace, qemu, one_gadget, and seccomp-tools. Supporting markdown files organize exploit categories into focused references for overflow exploitation, heap techniques, format string attacks, and advanced exploitation workflows.
This skill is intended for security researchers, CTF participants, exploit developers, and advanced students studying binary exploitation. It is best suited for filesystem-based AI agents with access to Bash, Python 3, and internet connectivity for installing dependencies. Typical use cases include solving pwnable challenges, developing proof-of-concept exploits, bypassing modern mitigations such as stack canaries and seccomp filters, experimenting with heap allocator internals, and practicing low-level offensive security techniques in controlled environments.
FAQ
What types of vulnerabilities does the ctf-pwn skill cover?
The skill covers binary exploitation topics including buffer overflows, format string vulnerabilities, heap corruption, return-oriented programming, shellcode execution, seccomp bypasses, sandbox escapes, ret2libc, kernel exploitation basics, and exploit chaining techniques.
What tools and dependencies are required to use this skill?
The skill requires a filesystem-based agent environment with Bash, Python 3, and internet access for installing tools. Recommended dependencies include pwntools, ROPgadget, ropper, gdb, qemu, pwndbg, strace, ltrace, one_gadget, and seccomp-tools.
Can this skill be used for reverse engineering unknown binaries?
No. The skill is intended for exploitation after the vulnerability or target behavior is already understood. If the primary challenge is understanding what the binary does, reverse engineering tools and workflows should be used first.
Does the skill support both Linux and macOS environments?
Yes. Installation instructions are provided for Linux systems using apt and macOS systems using Homebrew. Cross-platform Python and Ruby package installation instructions are also included.
What kinds of challenges is this skill not intended for?
The skill is not intended for pure web vulnerabilities, standalone cryptography or math problems, disk forensics, packet analysis, or non-native application exploitation tasks.
All Files
19 filesInstall ctf-pwn
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
ljagiello/ctf-skills