Back to Skills

binary-protection-bypass

Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.

1,292stars177forksUpdated 7/6/2026

Security Assessment

Low Risk(80/100)

Detected risks:

Privilege Escalation([PROTECTION_BYPASS_MATRIX.md] sudo)
Security Score80/100

About binary-protection-bypass

A security-testing playbook for identifying and bypassing binary protection mechanisms in ELF binaries to enable exploitation in authorized settings such as CTF challenges and lab targets. It covers ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET shadow stack, and ARM MTE, pairing each protection with its bypass methods and the primitives those methods require. The material is distilled from CTF-wiki mitigation sections and real-world exploitation, and it emphasizes the combinatorial effect of multiple protections that base models often get wrong.

It begins with protection identification using checksec and readelf, then walks through each defense. For ASLR it lists information leaks, partial overwrites, brute force on 32-bit, return-to-PLT, ret2dlresolve, format-string leaks, and stack reading, along with an entropy table for stack, mmap/libc, heap, and PIE regions. PIE bypasses include leaks, partial overwrites, and relative addressing. NX/DEP coverage includes ROP, ret2libc, ret2csu, ret2dlresolve, SROP, mprotect chains, and JIT spray, with an example mprotect ROP chain.

RELRO coverage distinguishes no, partial, and full RELRO and lists alternative targets when the GOT is read-only, such as __malloc_hook, __free_hook, the _IO_FILE vtable, __exit_funcs, TLS_dtor_list, and .fini_array. Canary bypasses include format-string leaks, brute force on fork servers, thread canary overwrite, and GOT overwrite of __stack_chk_fail, and FORTIFY_SOURCE coverage addresses restrictions on fortified functions. The skill cross-references related routes for stack overflow and ROP, format-string exploitation, heap exploitation, and arbitrary-write-to-RCE, plus a protection-bypass matrix reference.

FAQ

Which protections does it cover?

ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET shadow stack, and ARM MTE, each paired with bypass methods and required primitives.

How does it identify which protections are present?

Primarily with checksec, supplemented by readelf checks, plus reading /proc/sys/kernel/randomize_va_space for the OS-level ASLR setting.

What NX/DEP bypass methods are listed?

ROP, ret2libc, ret2csu, ret2dlresolve, SROP, an mprotect chain that makes a page executable, and JIT spray in JIT environments.

What can be targeted when Full RELRO makes the GOT read-only?

Alternative targets such as __malloc_hook, __free_hook, the _IO_FILE vtable, __exit_funcs, TLS_dtor_list, .fini_array, or the stack return address.

Which related skills does it reference?

It routes to stack-overflow-and-rop, format-string-exploitation, heap-exploitation, and arbitrary-write-to-rce, and points to a PROTECTION_BYPASS_MATRIX reference for a full matrix.

All Files

2 files
PROTECTION_BYPASS_MATRIX.md7.6 KB
View
SKILL.md11.4 KB
View

Install binary-protection-bypass

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill