# Exploit Development Basics

> Use when developing security exploits and payloads.

- Skill: `loopyluci/exploit-development-basics` (Agent Skill)
- Install (CLI): `npx skillmds@latest add loopyluci/exploit-development-basics`
- Raw SKILL.md: https://api.skillmd.com/api/skills/loopyluci/exploit-development-basics/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- License: MIT
- Author: LoopyLuci (https://skillmd.com/u/loopyluci)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/loopyluci/exploit-development-basics

---


# Exploit Development Basics

Developing security exploits — from buffer overflows and structured exception handling through ROP chains, shellcode, and fuzzing techniques.

## When to Use

- Developing PoC exploits for authorized testing
- Understanding exploitation techniques for defensive purposes
- Fuzzing applications to discover vulnerabilities
- Writing custom shellcode and payloads
- Creating exploit PoCs for vulnerability disclosure

## Exploit Patterns

```python
EXPLOIT_TYPES = {
    'buffer_overflow': 'Overwrite buffer to control EIP/RIP, redirect execution to shellcode',
    'seh_overflow': 'Overwrite Structured Exception Handler to gain control on exception',
    'rop': 'Return-Oriented Programming — chain gadget addresses to bypass DEP/NX',
    'use_after_free': 'Access freed memory to corrupt heap, achieve arbitrary read/write',
    'integer_overflow': 'Overflow integer to bypass bounds checking, allocate too-small buffer',
    'format_string': 'Use %x %n format specifiers for arbitrary memory read/write',
}

# Basic buffer overflow skeleton (Python)
BUFFER_OVERFLOW_TEMPLATE = """
import socket

target = "10.0.0.1"
port = 9999

# Pattern to find EIP offset (use pattern_create.rb)
payload = "A" * offset  # Fill buffer to EIP
payload += "BBBB"       # Overwrite EIP (control execution)
payload += "C" * 500    # Space for shellcode (after EIP)

s = socket.socket()
s.connect((target, port))
s.send(payload)
s.close()
"""
```

## Verification Checklist

- [ ] Exploit environment isolated (VM sandbox)
- [ ] Target application crash verified
- [ ] EIP/SEH offset identified with pattern
- [ ] Bad characters identified and removed from payload
- [ ] Exploit achieves code execution (pop calc, bind shell, or reverse shell)
- [ ] Exploit reliable across multiple runs
- [ ] No unintended targets affected
- [ ] Exploit PoC documented with mitigations
- [ ] Responsible disclosure process followed

