Understanding the Book, Then Actually Using It
Hacking: The Art of Exploitation Jon Erickson is one of the few programming and security books that doesn't treat exploitation as magic. It treats it as a systems problem. The book covers C, assembly, buffer overflows, network programming, and forensic analysis in Linux. It assumes you can compile code and read terminal output without panicking. That assumption is where most people fall out. I've gone through this book twice. The first time I read it cover to cover. The second time I actually ran the code on real vulnerable binaries. They're very different experiences. The first pass gives you a general idea of what's possible. The second pass makes you understand why certain techniques work and why they fail under conditions you didn't expect. The core methodology is straightforward. You learn C first. You learn how the stack works. You learn how the calling convention operates in x86. Then you start writing buffer overflow exploits against intentionally vulnerable programs. The book walks through the math step by step. NOP sleds, shellcode placement, return address overwrites, and offset calculations. The exercises use a Linux environment with older kernels and deliberately weak protections.
Here's the part the book doesn't stress enough. Compiling the vulnerable programs with specific flags changes everything. By default, the book uses gcc -fno-stack-protector -z execstack -no-pie. If you forget any of those, your exploit won't work the way the example shows. I spent an afternoon chasing a shellcode that worked perfectly until I realized I'd accidentally enabled stack canaries on a newer gcc version. The crash was happening before my overwrite even completed. Switching back to the exact flags from the book fixed it immediately.
Setting Up the Environment
The book recommends Ubuntu or Debian in a virtual machine. Use 32-bit x86 if possible. Most examples target i386 architecture. The newer ARM and x86_64 examples exist but the bulk of the material is x86. Get a Kali or BackBox install going, or just stick to Ubuntu Desktop. Install gcc, gdb, radare2, and netcat. That's your basic toolkit. Disable ASLR while you're learning. Set it to zero with echo 0 | sudo tee /proc/sys/kernel/randomize_va_space. You can re-enable it later once you understand the basics. Leaving ASLR on during your first attempts will waste hours on problems that have nothing to do with the actual technique.
Get the Full Details

The Exploitation Workflow
The standard process is repeating. You write a vulnerable program or download one from the book's companion site. You identify the input length that causes a crash. You determine which part of your input overwrites the return address. You calculate the exact offset. You replace the return address with a jump instruction or the address of your shellcode. You test. You adjust. You repeat. The hardest part is usually the offset calculation. You send a pattern of A's, B's, and C's until the program crashes. Then you use a tool like patterncraft or the Metasploit utility to figure out where exactly the EIP landed. I found this step surprisingly unreliable on some systems because the compiler sometimes reorders memory layout between runs even with ASLR disabled. If your offset is off by a few bytes across multiple attempts, check whether struct padding is shifting things around. Align your payload to 4-byte boundaries and pad accordingly. This fixed my most persistent offset drift issue.
Shellcode Writing
The book teaches you to write shellcode from scratch rather than relying exclusively on msfvenom output. That's the right call. When you generate shellcode blindly, you don't understand why certain bytes are forbidden or why your payload contains null bytes that break the overflow. Writing a basic /bin/sh shellcode in assembly takes about an hour if you follow the book's examples. You'll learn syscalls, string pushing, register setup, and avoiding bad characters. The shellcode should be under 50 bytes for most simple overflows. Anything larger introduces alignment issues and makes the NOP sled much longer. I once had a shellcode that was 87 bytes because I included extra cleanup instructions. It exploded on any target shorter than 200 bytes of buffer space. Trimming it down to 44 bytes with radare2 analysis fixed the reliability problem entirely.
Network Exploitation Chapters
The network portions of the book cover socket programming, packet crafting with Python, and remote exploits. The remote buffer overflow examples assume you have control of an input vector that comes from a network service. You connect to the target, send your crafted payload, and hope the shellcode executes. This part gets more complex because you're dealing with timing, connectivity, and service behavior. One thing I noticed that the book glosses over. Many modern services have input sanitization or length limits. If the service truncates your input at 1024 bytes and your exploit requires 1200 bytes, you need a different approach. Writing a small Python script that probes the service for its actual input limit before launching the full exploit saves a lot of trial and error. I use a script that sends incrementally longer payloads until the service drops the connection or returns an error. That tells me the ceiling.

Forensics and Countermeasures
The second half of the book shifts toward incident response and malware analysis. You learn how to extract artifacts from memory dumps, analyze registry hives, and reverse engineer basic rootkits. The practical labs here involve taking a raw memory dump from a compromised Windows machine and finding evidence of the attack you just practiced exploiting. It's a useful reversal of perspective. The forensics section is weaker than the exploitation sections. The tools mentioned are older and some of the techniques have been superseded. Volatility is still relevant but the book predates its current plugin system. I supplemented the forensics material with recent Volatility documentation and the SIFT workbench suite. The concepts transfer fine. The tool commands need updating.
Limitations and What This Book Won't Teach You
This is not a comprehensive guide to modern exploitation. The book focuses on 32-bit x86 Linux with minimal protections. Modern systems use ASLR, DEP, stack canaries, CFI, and Control Flow Integrity. Full RELRO and other hardening measures make the majority of the book's examples irrelevant on current production systems. If your goal is to exploit real-world software today, you need additional study beyond this book. The material is still valuable for understanding fundamentals. Buffer overflows exist in legacy systems, embedded devices, and IoT hardware that never patched their toolchains. The conceptual framework the book builds applies to understanding modern vulnerabilities even when the specific techniques need adaptation. You should supplement this book with coverage of ROP chains, return-to-libc attacks, and kernel-level exploitation to get a more complete picture.
Where to Get It
The book is published by No Starch Press. You can buy the physical copy or the Kindle edition directly from their website. The companion website at elsewhere.mirror.com hosts the vulnerable source code and lab files, though the site has been occasionally unreliable. The source code also appears on GitHub under various mirrors if the official link is down. I'd recommend grabbing the code as soon as you start reading rather than waiting, because missing the example programs slows down the labs significantly. If you work through the exercises methodically and actually run the code instead of skimming past it, you'll gain a working understanding of exploitation that most certification courses don't provide. The depth comes from doing, not from reading.
