Client Engagement · Confidential

Binary Exploitation — memory corruption to remote code execution

Developing low-level memory bugs in compiled services into reliable control of execution — the deepest end of the offensive stack.

Client: Classified — under NDA
Engagement: Live engagement against a production-grade system (under NDA)
Use-after-freeHeap groomingGOT/PLTROPRemote RCE

What we did

Reverse-engineered a compiled network service, identified a use-after-free in its object-management logic, and turned it into arbitrary code execution against the remote target. The chain required controlling heap layout so a freed object was reallocated with attacker-controlled data, then redirecting a corrupted function pointer into a controlled sequence.

Why it matters to a client

Most application testers stop at the web tier. Memory-corruption skill matters when your product ships a compiled component — an on-prem agent, a native service, an embedded device, or a parser handling untrusted input. The same instinct that turns a use-after-free into RCE is what finds the deep bug a scanner never sees.

← Back to case studies