Hacking: The Art of Exploitation, 2nd Edition – Jon Erickson

Master buffer overflows, shellcode, and network exploits with this classic hands-on guide. Your complete exploit development foundation starts here.

eBook Details
Author Jon Erickson
ISBN-13 9781593271442
Published 2008
Format Digital Download (PDF/EPUB)
Language English
Publisher No Starch Press
ISBN-10 1593271441
Edition 2nd Edition
File Size 6.5 MB
Pages 492

$20.99$40.00

About This Book

The Problem This Book Solves

Every modern software system is riddled with vulnerabilities waiting to be discovered. Whether you are a security professional, a developer, or a curious student, the gap between understanding how exploits work and actually building them from scratch is huge. Most resources show you how to run pre-written tools but never explain the underlying mechanics. This book eliminates that gap.

Hacking: The Art of Exploitation is the definitive hands-on guide to understanding and creating exploits. It does not just teach you what a buffer overflow is — it teaches you to think like an attacker so you can defend more effectively.

What Is Hacking: The Art of Exploitation? A Complete Overview

Hacking: The Art of Exploitation is a 2nd edition (2008) textbook by Jon Erickson, published by No Starch Press. It is widely regarded as the classic introduction to the art of exploitation — creative problem solving through finding unconventional solutions and exploiting security holes.

The book covers low-level programming concepts, assembly language, networking, cryptography, and shellcode development. Unlike other security books, it provides a complete Linux environment on a companion CD-ROM so you can practice every technique in a controlled, legal sandbox. The entire approach is learn-by-doing: you write your own exploits, debug them with GDB, and watch your code execute step by step.

Who Should Read Hacking: The Art of Exploitation?

This book is designed for readers who already have basic programming knowledge (C or assembly preferred) and want to dive deep into computer security. It is ideal for:

  • Security researchers who need to understand exploit development from the ground up
  • Penetration testers moving beyond script-kiddie tools to custom exploits
  • Software developers who want to write more secure code by understanding how attackers think
  • Computer science students studying operating systems, compilers, or network security
  • Hobbyist hackers with a strong foundation in C programming and a Linux environment

If you have ever run a Metasploit module and wondered “how does that actually work?”, this is the book that answers that question.

5 Key Things You Will Learn

  • Buffer overflows inside and out — how stack, heap, and integer overflows work, and how to write your own shellcode to exploit them
  • Assembly language fundamentals — x86 instructions, registers, and the stack frame, all explained in practical exploit contexts
  • Network-level exploitation — understanding TCP/IP, sniffing, spoofing, and remote exploit delivery
  • Cryptography weaknesses — common implementation flaws in encryption algorithms and how to break them
  • Defensive countermeasures — how to detect and prevent the very attacks you learn to build, including ASLR and stack canaries

Each chapter builds on the previous one. You start with a simple shellcode program and progress to writing a complete exploit that compromises a remote system. The companion CD contains all source code and a bootable Linux environment so you can follow along without any risk to your main machine.

Why Hacking: The Art of Exploitation Outperforms Every Alternative

Many security books exist — The Hacker Playbook, Penetration Testing: A Hands-On Introduction to Hacking, and Gray Hat Hacking are popular choices. Yet none match the deep, foundational approach of Hacking: The Art of Exploitation. Here is why:

First, this book focuses on conceptual understanding, not tool usage. While other titles teach you how to run Nmap or Burp Suite, Erickson teaches you to read assembly, manipulate the stack, and craft shellcode by hand. You leave with transferable knowledge, not memorized commands.

Second, the hands-on practice environment is unparalleled. The included bootable Linux CD lets you compile and test exploits immediately, with no fear of damaging your system. Most competitors assume you already have a lab set up — this book provides one.

Third, the depth of coverage on buffer overflows and shellcode is unmatched. The book dedicates hundreds of pages to these core topics, while others skim over them in a chapter or two. If you truly want to master exploitation, this is the definitive text.

Author Authority & Publisher Credibility

Jon Erickson is a computer security researcher with deep expertise in low-level systems programming. His ability to explain complex exploit techniques clearly stems from years of hands-on vulnerability research. While specific formal credentials are not detailed in this edition, the book’s reputation among security professionals speaks for itself.

Published by No Starch Press, a leading publisher of technical books in the security and programming space, the 2nd edition (2008) has been continuously recommended by security communities, university courses, and professional trainers worldwide. No Starch Press is known for rigorous technical editing and a focus on actionable, practical content — a perfect match for this subject.

Is Hacking: The Art of Exploitation Worth It? Our Verdict

If you are serious about understanding how computer systems are exploited, this book is essential reading. It is not a light overview — it demands time, patience, and a willingness to write and debug assembly code. For that effort, you gain a skill set that few possession: the ability to create custom exploits from first principles.

The 2nd edition is still highly relevant today. While it predates some modern mitigations (like Windows 10 protections or ARM mobile exploits), the core principles of stack overflows, shellcode, and network attacks remain unchanged. Many contemporary exploitation techniques are just variations of what this book teaches. For under $40, you get a full self-contained course in offensive security.

Verdict: Buy it. Pair it with a modern update on web or mobile security, and you will have a formidable foundation in the art of exploitation.

Get Hacking: The Art of Exploitation — Master Exploit Development Today

Whether you are a security student, a professional pentester, or a developer who wants to write bulletproof code, this book gives you the deepest possible understanding of exploitation. The included bootable Linux environment means you can start learning in minutes, not days.

Order your digital copy now and start building the skills that separate script kiddies from true hackers. This 2nd edition from No Starch Press is a lifetime reference — do not wait until the next vulnerability disclosure to wish you had studied exploits.

Add to cart today and take the first step toward mastering the art of exploitation.