esCoaching

Android Kernel Exploitation: Binder

Trainees master Binder internals and build a full local privilege escalation exploit for CVE-2023-20938, a use-after-free vulnerability, using Time Travel Debugging to trace kernel crashes, reverse-engineer heap states, and debug the exploit in a controlled Android 12 (aarch64) environment.

Online
1-3 people
4 days
Advanced
Training Program

Module Overview

Android image 1
Binder Internals and Architecture

Master the internals of Android's Binder IPC mechanism, including its core data structures (binder_proc, binder_thread, binder_node), transaction flows, and lifetime management, building the foundation needed for kernel-level exploitation work.

CVE-2023-20938: Root Cause Analysis

Analyze a real use-after-free vulnerability in the Binder driver, from its root cause in misaligned offsets_size handling to the exploitation primitives it enables, including leaks and arbitrary read/write. Using Time Travel Debugging, you'll trace kernel crashes, reverse-engineer heap states, and debug complex race conditions and double-free scenarios.

Building a Privilege Escalation Exploit

Build a complete exploit chain for local privilege escalation: trigger the use-after-free via a two-process Binder setup, craft exploitation primitives such as leaks and arbitrary read/write, and overwrite credential structures to escalate privileges.

Debugging and Validating the Exploit

Use Time Travel Debugging to stabilize the exploit, identifying and resolving issues such as heap-spray evictions or double-free. The final exploit is validated in a controlled Android 12 (aarch64) emulator environment with vulnerable kernel images.

Why us

Over 10 Years of Hands-On Expertise.

Effective security testing comes from the combination of the right tools, deep technical knowledge, and the people who know how to apply them. eShard has spent over 10 years developing all three, and our coaching programs put that same expertise directly in your hands.

FAQ

Frequently Asked Questions

We are always here to help you and answer your questions.

We are always here to help you and answer your questions.

Can training be delivered remotely? 

Most courses can be delivered online. Some modules, particularly those involving lab equipment, require onsite presence. Onsite training can be held at eShard's headquarters in Bordeaux, France, or at your own premises. The delivery format can be discussed and agreed upon before the final proposal.

What level of experience is required to attend? 

Prerequisites vary by module. Some courses include introductory content for participants new to a topic, while others assume prior knowledge of cryptography or security testing. Each module page indicates the expected background.

How many participants can join a session?

Most programs accommodate 3 trainees per coach. Based on our experience, this ratio ensures everyone progresses at the same pace and gets the most out of the session. Contact us to discuss larger groups or custom arrangements.

Can the training content be adapted to our specific targets or use cases?

Yes. Training programs are tailored to each team's technical level and objectives. If your team works on specific targets or protocols, this can be factored into the program before the session begins.