Master the fundamental concepts of binary exploitation through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksThe NX (No-eXecute) bit marks memory regions like the stack and heap as non-executable. This prevents attackers from injecting and executing shellcode directly on the stack, which was the classic exploitation technique before NX became standard.
Memory pages have permission bits: read (R), write (W), execute (X). Stack and heap are typically RW- (no execute). Attempting to jump to shellcode on the stack triggers SIGSEGV.
Return-Oriented Programming (ROP) bypasses NX by reusing existing executable code:
ret (gadgets)ret pops the next gadget addressCommon x86-64 gadgets:
pop rdi; ret: set first function argumentpop rsi; ret: set second argumentsyscall; ret: invoke a system callYou will classify a target address against a real /proc/self/maps-style memory map: parse regions with their permission strings, find which region contains the target, and decide whether the target is executable, NX-protected, or unmapped. This is the lookup an exploit writer performs before every jump, and why a stack address fails under NX while code-segment addresses still work.
NX does not execute new instructions; it only prevents the stack and heap from being executable. ROP reuses instructions already in executable regions. A chain calling mprotect can mark a stack page executable, reviving classic shellcode techniques. More commonly, chains call system or execve directly. Intel CET shadow stacks and ARM Pointer Authentication record return addresses to detect ROP, but the technique remains central to exploit development education.
Write a C program that reads a memory map in /proc/self/maps format and a target address from stdin, then classifies the target address.
Requirements:
Success Criteria: