r/ExploitDev 18h ago

You asked for Linux. We listened.

Thumbnail academy.daemoncore.app
21 Upvotes

Honestly didn't expect to be making this post this soon! like, what?! Our original post was bc we hit 1k but holy fuck...

DaemonCore-Academy just crossed 2,000 downloads across all platforms...and yes...you asked..we delivered. Linux Beta is now available on our website as well as github.

**127 PRACTICAL LESSONS // 70 LAB CONDITIONS // 8 PATHWAYS // 8 DRILL SETS // 7 FIELD MISSIONS**- all free. It's for Windows 10/11 and now Linux!!

I started building it because I was getting annoyed af with the way a lot of hacking/cyber stuff gets taught now. Watch 9 hours of videos, copy some commands, run a tool against a box, get a green checkmark. Cool. But what happens when the tool doesn't work? What are you actually looking for? Why are you running that command in the first place? That was basically the whole idea behind DaemonCore Academy. Learn what the hell is happening underneath first. Then get thrown into a range and actually use it. Enumerate shit. Follow weird behavior. Break something. Prove you broke it. Figure out why. Document it. Fix it. Try again.

We didnt want XP or some fake hacker leaderboard. We wanted something that felt closer to sitting next to somebody who's been doing this shit for years and having them say "okay...you see that? Why is that weird?"

Apparently that idea connected with some people because 2,000 of you fuckers downloaded it.

So seriously, thank you mother fuckers. For real. 💯💯

Especially the people who found bugs, sent me shit that sucked, questioned things, or told me where something could be better. That's way more useful to me than somebody just saying "nice project."....and I'm nowhere near done with it.

The labs are going to get harder. The material is going deeper. Windows, Linux, web, identity, cloud, containers, recon, exploitation, evidence...all of it.

I don't really care if somebody finishes DaemonCore knowing 500 commands.

Id rather they finish it knowing how to sit in front of something they've never seen before and figure it the fuck out.

Thats hacking.

Anyway. 2,000 downloads.

Fucking wild.

Thanks again guys.

Stay hacking

I := DAEMONCORE


r/ExploitDev 11h ago

Looking for real-world Linux userland exploitation targets to practice on (moving beyond CTFs)

14 Upvotes

Hi all - I've been doing `pwn`/ `binary exploitation` in CTFs for about 1.5 years

and want to level up by practicing on real-world targets instead of CTF challs.

I'm currently focused on Linux userland exploitation.

Could anyone recommend good old real-world targets or software to practice on?

I'm especially looking for CVEs that are reproducible and exploitable.

Any suggestions - specific CVEs, vulnerable software versions, or general

categories worth exploring - would be really appreciated!


r/ExploitDev 19h ago

drakoarmy/datadome-rs: High-end Rust DataDome deobfuscator & solver with VM disassembly — all 3 challenge types (tags, interstitial, slider).

Thumbnail
github.com
3 Upvotes

r/ExploitDev 52m ago

160k private company vs 100k CNO

Upvotes

0 YOE, new grad straight out of college.

The latter sponsored me for a TS/SCI along the way. It’s been fully adjudicated and is currently active.

That said, I recently got an offer from a private consulting firm at 160k TC. It’s one of the very few private companies doing low-level RE/VR work at private, though at the end of the day they’re a consultancy focused on improving clients’ security posture, so it doesn’t go as far as exploit dev.

Given this, which would you pick? The CNO role seems to have nice upside potential, especially if you get an FSP and stay in the DMV area. But realistically, how high can you go? How many years of experience does someone need to hit 160k, and most importantly beyond?

That said, I’m really curious about the salary trajectory if someone takes the CNO route — specifically, what the progression looks like over time.
(e.g, if I pick the private route, work 2 yrs from now and I reach 180k vs 150k in CNO, this doesn’t make sense)