Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
awesome-list — Cybersecurity oriented awesome list | Kitploit
أدوات/GitHubGitHub/0xor0ne/awesome-list
Vulnerability AnalysisExploitationReverse EngineeringMalware AnalysisCTFBinary AnalysisPapers & ResearchLearning & EducationCurated Resources
GitHub0xor0ne/awesome-list

awesome-list

Cybersecurity oriented awesome list

3.9k413منذ 3 أيامتمت المراجعة من قبل Kitploit
عرض المستودع

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Awesome Cybersecurity List

My personal collection of awesome blog posts, write-ups, and papers focusing on cybersecurity.

For a deeper dive into cybersecurity-related tools, check out the dedicated Cybersecurity Tools list.

Outline

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2014
  • 2011
  • Misc
  • Other Lists

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [Part 1][1241]
    • [Part 2][1242]
    • [Part 3][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
تنزيل الأداة
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]
  • 2025

    • ["A File Format Uncracked for 20 Years"][1202]
    • ["A First Glimpse of the Starlink User Ternimal"][1084]
    • ["A Fuzzy Escape - A tale of vulnerability research on hypervisors"][1151]
    • ["A look at an Android ITW DNG exploit"][1231]
    • ["A modern tale of blinkenlights"][1200]
    • ["A Quick Dive Into The Linux Kernel Page Allocator"][1098]
    • ["A Series of io_uring pbuf Vulnerabilities"][1083]
    • ["A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"][1181]
    • ["Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"][1021]
    • ["All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"][1142]
    • ["Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"][1174]
    • ["Analyzing IOS Kernel Panic Logs"][1037]
    • ["Android: Scudo"][1070]
    • ["Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"][1240]
    • ["APPROTECT Bypass on NRF52832"][1139]
    • ["APT28 Operation Phantom Net Voxel"][1171]
    • ["Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"][1132]
    • ["Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"][1106]
    • ["Being Overlord on the Steam Deck with 1 Byte"][1044]
    • "BPFDoor"
      • ["Part 1 - The Past"][1101]
      • ["Part 2 - The Present"][1102]
    • ["Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"][1189]
    • ["Best practices for key derivation"][1023]
    • ["Binder Fuzzing"][1146]
    • ["Blasting Past iOS 18"][1038]
    • ["Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"][1254]
    • ["Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"][1138]
    • ["Bootloader to Iris: A Security Teardown of a Hardware Wallet"][1199]
    • ["Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"][1125]
    • ["Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"][1196]
    • ["Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"][1217]
    • ["Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"][1039]
    • ["Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"][1179]
    • ["Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"][1209]
    • ["Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"][1124]
    • ["Bypassing disk encryption on systems with automatic TPM2 unlock"][1018]
    • ["Bypassing MTE with CVE-2025-0072"][1105]
    • ["Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"][1222]
    • ["Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"][1040]
    • ["Case Study: IOMobileFramebuffer NULL Pointer Dereference"][1041]
    • ["Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"][1107]
    • ["CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"][1061]
    • ["Control Flow Hijacking in the Linux Kernel"][1114]
    • ["Control Flow Hijacking via Data Pointers"][1085]
    • ["corCTF 2025 - corphone"][1168]
    • ["Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"][1212]
    • ["Cross Cache Attack CheetSheet"][1006]
    • ["CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"][1118]
    • ["CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"][1149]
    • ["CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"][1065]
    • ["CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"][1086]
    • ["CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"][1076]
    • ["CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"][1163]
    • ["CVE-2025-6554: The (rabbit) Hole"][1188]
    • ["Debugging the Pixel 8 kernel via KGDB"][1123]
    • ["Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"][1068]
    • ["Denial of Ruzzing: Rust in the Windows Kernel"][1185]
    • ["Dirty Pageflags: Revisiting PTE Exploitation in Linux"][1166]
    • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
    • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
    • ["Disassembling a binary: linear sweep and recursive traversal"][1019]
    • ["Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"][1047]
    • ["Don’t Phish-let Me Down: FIDO Authentication Downgrade"][1155]
    • ["EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"][1121]
    • ["Emulating an iPhone in QEMU"][1051]
    • ["Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"][1052]
    • ["Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"][1211]
    • ["Exploitation of AIxCC Nginx bugs: Part I"][1035]
    • ["Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
    • ["Exploiting a 13-years old bug on QEMU"][1218]
    • ["Exploiting CVE-2024-0582 via the Dirty Pagetable Method"][1081]
    • ["Exploiting CVE-2025-21479 on a Samsung S23"][1184]
    • ["Exploiting Retbleed in the real world"][1141]
    • ["Exploiting the Synology TC500 at Pwn2Own Ireland 2024"][1122]
    • ["Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"][1164]
    • ["Exploiting Heroes of Might and Magic V"][1119]
    • ["Exploring Grapheneos Secure Allocator: Hardened Malloc"][1167]
    • ["Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"][1029]
    • ["Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"][1172]
    • ["Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"][1152]
    • ["False Injections: Tales of Physics, Misconceptions and Weird Machines"][1120]
    • ["Fast & Faulty - A Use After Free in KGSL Fault Handling"][1182]
    • ["FiberGateway GR241AG - Full Exploit Chain"][1097]
    • ["First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"][1058]
    • ["FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"][1059]
    • ["Fundamental of Virtual Memory"][1162]
    • ["From Chrome renderer code exec to kernel with MSG_OOB"][1153]
    • ["Game Hacking - Valve Anti-Cheat (VAC)"][1074]
    • ["Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"][1215]
    • ["Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"][1103]
    • ["Google CTF 2025 Quals Writeup"][1131]
    • ["Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"][1031]
    • "Hacking the XBox 360 Hypervisor"
      • [Part 1][1109]
      • [Part 2][1110]
    • ["Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"][1129]
    • ["Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"][1198]
    • ["HITCON CTF 2025 -- calc"][1145]
    • ["How I ruined my vacation by reverse engineering WSC"][1077]
    • ["How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"][1090]
    • ["How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"][1115]
    • "Hydroph0bia (CVE-2025-4275)"
      • ["a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1143]
      • ["a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1144]
      • ["a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1108]
    • ["Hypervisors for Memory Introspection and Reverse Engineering"][1099]
    • ["Kernel Exploitation Techniques: Turning The (Page) Tables"][1100]
    • ["Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"][1180]
    • ["Inside Riot Vanguard's Dispatch Table Hooks"][1073]
    • ["Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"][1079]
    • "iOS 17: New Version, New Acronyms":
      • [Part 1][1042]
      • [Part 2][1043]
    • ["kASLR Internals and Evolution"][1095]
    • ["Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"][1082]
    • ["KernelSnitch: Side-Channel Attacks on Kernel Data Structures"][1005]
    • ksmbd (doyensec):
      • ["ksmbd vulnerability research"][1033]
      • ["Fuzzing Improvements and Vulnerability Discovery"][1175]
      • ["Exploiting CVE-2025-37947"][1176]
    • ["Laser Fault Injection on a Budget: RP2350 Edition"][1017]
    • ["Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"][1072]
    • ["Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"][1137]
    • ["Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"][1147]
    • ["Linux Kernel Exploitation For Beginners"][1113]
    • ["Linux Kernel Hfsplus Slab-out-of-bounds Write"][1066]
    • ["Linux kernel Rust module for rootkit detection"][1026]
    • ["Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution"][1011]
    • ["LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"][1177]
    • ["Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"][1050]
    • ["Malware Just Got Its Free Passes Back!"][1221]
    • ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
    • ["mediatek? more like media-rekt, amirite."][1220]
    • ["Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"][1069]
    • ["Modern (Kernel) Low Fragmentation Heap Exploitation"][1127]
    • ["My Emulation Goes to the Moon... Until False Flag"][1094]
    • ["NASA cFS version Aquila Software Vulnerability Assessment"][1056]
    • ["nRF51 RBPCONF bypass for firmware dumping"][1154]
    • ["One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"][1193]
    • ["Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"][1186]
    • ["Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"][1148]
    • ["Overview of Map Exploitation in v8"][1075]
    • ["Paint it Blue: Attacking the Bluetooth Stack"][1216]
    • ["Patch-Gapping the Google Container-Optimized OS for $0"][1032]
    • ["PatchGuard Internals"][1092]
    • ["PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"][1213]
    • ["Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"][1170]
    • ["Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"][1136]
    • ["Project Rain:L1TF"][1178]
    • ["Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"][1194]
    • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
    • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
    • ["pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"][1134]
    • ["Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"][1087]
    • ["Qualcomm DSP Kernel Internals"][1135]
    • ["Race Against Time in the Kernel’s Clockwork"][1160]
    • ["Recovering Metadata from .NET Native AOT Binaries"][1089]
    • ["Reliable system call interception"][1010]
    • ["Replacing a Space Heater Firmware Over WiFi"][1020]
    • ["Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"][1093]
    • ["Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"][1201]
    • ["Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"][1013]
    • ["Reversing Samsung's H-Arx Hypervisor Framework - Part 1"][1036]
    • ["Reversing the QardioArm"][1048]
    • ["Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields"][1226]
    • ["Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"][1071]
    • ["Root Shell on Credit Card Terminal"][1112]
    • ["Rooting the TP-Link Tapo C200 Rev.5"][1130]
    • ["ROPing our way to RCE"][1028]
    • ["Running code in a PAX Credit Card Payment Machine"][1272]
    • ["RV130X Firmware Analysis"][1025]
    • ["Security through Transparency: Tales from the RP2350 Hacking Challenge"][1256]
    • ["smoltalk: RCE in Open Source Agents"][1045]
    • ["Solo: A Pixel 6 Pro Story (When one bug is all you need)"][1128]
    • ["SoK: Security of EMV Contactless Payment Systems"][1088]
    • ["Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"][1034]
    • ["Stack Overflows, Heap Overflows, and Existential Dread"][1150]
    • ["State of Linux Snapshot Fuzzing"][1078]
    • ["STM32L05 Voltage Glitching"][1111]
    • ["Streaming Zero-Fi Shells to Your Smart Speaker"][1096]
    • ["Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"][1228]
    • ["System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"][1197]
    • ["The Art of Linux Kernel Rootkits"][1008]
    • ["The cryptography behind electronic passports"][1214]
    • "The Evolution of Dirty COW":
      • [Part 1][1062]
      • [Part 2][1063]
    • ["The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"][1116]
    • ["TLS NoVerify: Bypass All The Things"][1165]
    • ["Tp-Link Router Deep Research"][1203]
    • ["Tracing Back to the Source | SPTM Round 3"][1046]
    • ["Turning Camera Surveillance on its Axis"][1158]
    • ["Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"][1126]
    • ["Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"][1133]
    • ["VMware Workstation guest-to-host escape"][1161]
    • ["We are ARMed no more ROPpery Here"][1016]
    • "When a Wi-Fi SSID Gives You Root on an MT02 Repeater"
      • [Part 1][1156]
      • [Part 2][1157]
    • ["When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"][1067]
    • ["Windows arm64 Internals: Deconstructing Pointer Authentication"][1190]
    • ["Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"][1195]
    • "Windows Inter Process Communication A Deep Dive Beyond the Surface"
      • [Part 1][1204]
      • [Part 2][1205]
      • [Part 3][1206]
      • [Part 4][1207]
      • [Part 5][1208]
    • ["WireTap: Breaking Server SGX via DRAM Bus Interposition"][1183]
    • ["Workshop: Firmware Reverse Engineering"][1269]
    • ["Writing a Ghidra processor module"][1064]
    • ["Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique (CVE-2024-50629~50631)"][1247]
    • ["yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"][1210]
    • ["You Already Have Our Personal Data, Take Our Phone Calls Too"][1140]
    • ["Zen and the Art of Microcode Hacking"][1027]
    • ["Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"][1227]

    2024

    • ["1-click Exploit in South Korea's biggest mobile chat app"][965]
    • ["4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"][959]
    • "64 bytes and a ROP chain – A journey through nftables":
      • [Part 1][865]
      • [Part 2][866]
    • "nix libX11: Uncovering and exploiting a 35-year-old vulnerability":
      • [Part 1][703]
      • [Part 2][704]
    • ["A few notes on AWS Nitro Enclaves: Images and attestation"][738]
    • "A first look at Android 14 forensics"
    • ["A "Gau-Hack" from EuskalHack"][893]
    • ["A Journey From sudo iptables To Local Privilege Escalation"][1009]
    • ["A Practical Guide to PrintNightmare in 2024"][709]
    • ["A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "][714]
    • ["A Trip Down Memory Lane"][715]
    • [AArch64 memory and paging][1015]
    • ["An Introduction to Chrome Exploitation - Maglev Edition"][882]
    • ["An unexpected journey into Microsoft Defender's signature World"][876]
    • ["Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"][952]
    • ["Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"][736]
    • ["AES-GCM and breaking it on nonce reuse"][912]
    • ["Analyzing Mutation-Coded - VM Protect and Alcatraz English"][834]
    • ["ARLO: I'M WATCHING YOU"][810]
    • ["ASLRn’t: How memory alignment broke library ASLR"][731]
    • ["Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"][911]
    • ["Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"][852]
    • ["Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"][1173]
    • "Base64 Beyond Encoding"
      • [Part 1][945]
      • [Part 2][946]
    • ["Becoming any Android app via Zygote command injection"][863]
    • ["Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"][895]
    • ["BGGP4: A 420 Byte Self-Replicating UEFI App For x64"][728]
    • ["Binary type inference in Ghidra"][905]
    • ["Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"][803]
    • ["Breaking the Barrier: Post-Barrier Spectre Attacks"][970]
    • ["Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"][987]
    • ["Breaking Down Multipart Parsers: File upload validation bypass"][966]
    • "Breaking the Flash Encryption Feature of Espressif’s Parts"
    • ["Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"][886]
    • ["Buying Spying Insights into Commercial Surveillance Vendors"][733]
    • ["Bypassing EDRs With EDR-Preloading"][716]
    • ["Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"][920]
    • "Chaining N-days to Compromise All":
      • [Part 1][836]
      • [Part 2][837]
      • [Part 3][838]
      • [Part 4][839]
      • [Part 5][840]
    • ["Check Point - Wrong Check Point (CVE-2024-24919)"][875]
    • ["Code injection on Android without ptrace"][874]
    • "CodeQL zero to hero": [Part 1][858] [Part 2][859] [Part 3][860] [Part 4][1191] [Part 5][1192]
    • ["Commonly Abused Linux Initial Access Techniques and Detection Strategies"][896]
    • ["Compiler Options Hardening Guide for C and C++"][877]
    • ["Continuously fuzzing Python C extensions"][734]
    • ["corCTF 2024: trojan-turtles writeup"][929]
    • ["corMine 1 and 2"][948]
    • ["Cross-Process Spectre Exploitation"][969]
    • ["CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"][861]
    • ["CVE-2022-2586 Writeup"][849]
    • ["CVE-2020-27786 ( Race Condition + Use-After-Free )"][967]
    • ["CVE-2022-4262"][864]
    • ["CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"][1012]
    • ["CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"][697]
    • ["Declawing PUMAKIT"][989]
    • [Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)][1003]
    • ["Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"][699]
    • ["Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"][683]
    • ["Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"][805]
    • ["Diving Deep into F5 Secure Vault"][918]
    • ["DJI - The ART of obfuscation"][705]
    • ["Docker Security – Step-by-Step Hardening (Docker Hardening)"][729]
    • ["Driving forward in Android drivers"][908]
    • ["Emulating RH850 architecture with Unicorn Engine"][853]
    • "Everyday Ghidra: Ghidra Data Types"
      • [Part 1][973]
      • [Part 2][974]
    • ["Exploit detail about CVE-2024-26581"][944]
    • ["Exploring AMD Platform Secure Boot"][701]
    • ["Exploring GNU extensions in the Linux kernel"][878]
    • ["Exploiting Android’s Hardened Memory Allocator"][1030]
    • ["Exploiting Empire C2 Framework"][723]
    • "Exploiting Enterprise Backup Software For Privilege Escalation":
      • [Part 1][906]
      • [Part 2][907]
    • "Exploiting Reversing (ER) series":
      • Article 01
      • Article 02
    • ["Exploiting Steam: Usual and Unusual Ways in the CEF Framework"][898]
    • ["Exploring object file formats"][684]
    • ["Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"][735]
    • "Fault Injection Attacks against the ESP32-C3 and ESP32-C6"
    • ["Fault Injection – Down the Rabbit Hole"][993]
    • "Finding Bugs in Kernel":
      • [Part 1][996]
      • [Part 2][997]
    • ["Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"][883]
    • ["Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"][804]
    • ["From fault injection to RCE"][990]
    • ["From object transition to RCE in the Chrome renderer"][940]
    • ["Fuzzing between the lines in popular barcode software"][968]
    • ["Gaining kernel code execution on an MTE-enabled Pixel 8"][808]
    • ["Ghidra nanoMIPS ISA module"][873]
    • ["Going Native - Malicious Native Applications"][842]
    • "Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"
    • ["GhostRace: Exploiting and Mitigating Speculative Race Conditions"][802]
    • ["GPUAF - Two ways of Rooting All Qualcomm based Android phones"][994]
    • ["GraphStrike: Anatomy of Offensive Tool Development"][712]
    • ["Hacking a 2014 tablet... in 2024!"][932]
    • ["Hacking a Smart Home Device"][691]
    • ["Hacking Android Games"][949]
    • ["Heap exploitation, glibc internals and nifty tricks"][938]
    • ["HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"][818]
    • "Hi, My Name is Keyboard"
    • ["Hiding Linux Processes with Bind Mounts"][925]
    • ["How I Also Hacked my Car"][976]
    • ["How to Bypass Golang SSL Verification"][941]
    • ["Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"][995]
    • "Hunting down the HVCI bug in UEFI"
    • "Hunting for Unauthenticated n-days in Asus Routers"
    • "Iconv, Set the Charset to RCE":
      • [Part 1][870]
      • [Part 2][871]
    • ["Java Deserialization Tricks"][815]
    • ["JTAG Hacking with a Raspberry Pi"][851]
    • ["Kuiper Ransomware’s Evolution"][702]
    • ["Inside a New OT/IoT Cyberweapon: IOCONTROL"][1001]
    • ["Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"][692]
    • ["Introduction to Fuzzing Android Native Components"][984]
    • "Learning LLVM":
      • [Part 1][934]
      • [Part 2][935]
    • ["LeftoverLocals: Listening to LLM responses through leaked GPU local memory"][687]
    • "Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"
    • ["Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"][999]
    • "Linux Kernel Exploitation":
      • ["Environment"][922]
      • ["ret2usr"][923]
    • ["Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"][939]
    • "ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs":
      • [Part 1][901]
      • [Part 2][902]
      • [Part 3][903]
    • ["Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"][809]
    • ["Mali GPU Kernel LPE"][786]
    • ["MalpediaFLOSSed"][814]
    • ["Microsoft BitLocker Bypasses are Practical"][718]
    • ["Modern implant design: position independent malware development"][690]
    • ["My new superpower"][688]
    • ["Not the Drones You're Looking For"][825]
    • "Operation triangulation":
      • ["Keychain module analysis"][823]
      • ["audio module analysis"][824]
    • ["OtterRoot: Netfilter Universal Root 1-day"][986]
    • ["Out-of-bounds read & write in the glibc's qsort()"][698]
    • ["PageJack: A Powerful Exploit Technique With Page-Level UAF"][951]
    • ["Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code Pages"][1000]
    • ["Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"][835]
    • ["Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"][983]
    • ["PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"][711]
    • "Playing with libmalloc in 2024"
    • ["Puckungfu 2: Another NETGEAR WAN Command Injection"][730]
    • ["Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"][910]
    • ["Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"][933]
    • ["Pwning browsers like a kernel"][957]
    • "Pwn2Own: WAN-to-LAN Exploit Showcase":
      • ["Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"][950]
      • ["Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"][942]
    • "Pwn2Own Toronto 2023":
      • ["How it all started"][829]
      • ["Exploring the Attack Surface"][830]
      • ["Exploration"][831]
      • ["Memory Corruption Analysis"][832]
      • ["The Exploit"][833]
    • ["Pwning a Brother labelmaker, for fun and interop!"][897]
    • "Pwntools 10x":
      • [Part 1][867]
      • [Part 2][868]
      • [Part 3][869]
    • ["Pygmy Goat"][972]
    • ["Recovering an ECU firmware using disassembler and branches"][921]
    • ["regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"][919]
    • ["Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"][846]
    • ["Retrofitting encrypted firmware is a Bad Idea"][1024]
    • ["Reverse engineering a car key fob signal "][801]
    • ["Reverse Engineering and Dismantling Kekz Headphones"][962]
    • ["Reverse Engineering Protobuf Definitions From Compiled Binaries"][820]
    • ["Reverse engineering the 59-pound printer onboard the Space Shuttle"][943]
    • ["Reverse Engineering the AM335x Boot ROM"][947]
    • ["Reverse Engineering The Stream Deck Plus"][1004]
    • "Ring Around The Regex"
      • [Part 1][955]
      • [Part 2][956]
    • ["RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"][958]
    • ["RomCom exploits Firefox and Windows zero days in the wild"][981]
    • ["ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"][892]
    • ["Route to Safety: Navigating Router Pitfalls"][816]
    • ["Rooting a Hive Camera"][819]
    • ["SAME70 Emulator"][879]
    • "Say Friend and Enter":
      • [Part 1][812]
      • [Part 2][813]
    • ["Samsung NX related posts"][887]
    • ["Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"][975]
    • ["SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"][862]
    • ["SELinux bypasses"][963]
    • ["SLUB Internals for Exploit Developers"][980]
    • ["SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"][937]
    • ["Shell We Assemble?"][689]
    • ["Shellcode evasion using WebAssembly and Rust"][726]
    • "SMM isolation":
      • ["SMI deprivileging (ISRD)"][847]
      • ["Security policy reporting (ISSR)"][848]
    • ["SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"][1049]
    • "Strengthening the Shield: MTE in Heap Allocators"
    • ["Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"][913]
    • ["The architecture of SAST tools: An explainer for developers"][739]
    • ["The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"][880]
    • ["The Definitive Guide to Linux Process Injection"][971]
    • ["The 'Invisibility Cloak' - Slash-Proc Magic"][924]
    • ["The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"][1007]
    • ["The rev.ng decompiler goes open source + start of the UI closed beta"][694]
    • ["The tale of a GSM Kernel LP"][850]
    • ["The Wild West of Proof of Concept Exploit Code (PoC)"][926]
    • "The Windows Registry Adventure":
      • [Part 1][914]
      • [Part 2][915]
      • [Part 3][916]
    • ["TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"][894]
    • ["Tony Hawk’s Pro Strcpy"][928]
    • ["Toolchain Necromancy: Past Mistakes Haunting ASLR"][732]
    • ["TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"][988]
    • ["TP-Link TDDP Buffer Overflow Vulnerability"][695]
    • ["Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"][787]
    • ["Understanding AddressSanitizer: Better memory safety for your code"][889]
    • ["Understanding Unix Garbage Collection and its Interaction with io_uring"][891]
    • ["Understanding Windows x64 Assembly"][693]
    • ["Using Symbolic Execution to Devirtualise a Virtualised Binary"][936]
    • ["Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"][985]
    • ["VBA: having fun with macros, overwritten pointers & R/W/X memory"][843]
    • ["Vulnerabilities of Realtek SD card reader driver"][1002]
    • ["Why Code Security Matters - Even in Hardened Environments"][953]
    • ["Windows Secure-Launch on Qualcomm devices"][811]
    • ["Windows Sockets: From Registered I/O to SYSTEM Privileges"][998]
    • ["Windows vs Linux Loader Architecture"][844]
    • ["Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"][954]
    • "Writing a Debugger From Scratch"
      • "Attaching to a Process"
      • "Register State and Stepping"
      • "Reading Memory"
      • "Exports and Private Symbols"
      • "Breakpoints"
      • "Stacks"
      • "Disassembly"
    • ["Writing a system call tracer using eBPF"][931]
    • ["Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"][854]
    • ["x64 Return Address Spoofing"][991]
    • ["x64 Call Stack Spoofing"][992]

    2023

    • "A Deep Dive Into Brute Ratel C4 Payloads"
    • "A Deep Dive into Penetration Testing of macOS Applications (Part 1)"
    • "A Deep Dive into TPM-based BitLocker Drive Encryption"
    • "A Detailed Look at Pwn2own Automotive EV Charger Hardware"
    • ["A LibAFL Introductory Workshop"][826]
    • "A look at CVE-2023-29360, a beautiful logical LPE vuln"
    • "A Journey Into Hacking Google Search Appliance"
    • "A new method for container escape using file-based DirtyCred"
    • "A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"
    • "A Potholing Tour in a SoC"
    • "A Practical Tutorial on PCIe for Total Beginners on Windows":
      • [Part 1][806]
      • [Part 2][807]
    • "A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"
    • "A Red-Teamer diaries"
    • "A story about tampering EDRs"
    • ["Abusing Liftoff assembly and efficiently escaping from sbx"][677]
    • ["Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"][857]
    • "Abusing undocumented features to spoof PE section headers"
    • "Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"
    • "All about LeakSanitizer"
    • "All cops are broadcasting: TETRA under scrutiny"
    • "All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"
    • "An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit"
    • "An Introduction into Stack Spoofing"
    • "Analysis on legit tools abused in human operated ransomware"
    • "Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway":
      • Part 1
      • Part 2
    • "Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"
    • "Analyzing a Modern In-the-wild Android Exploit"
    • "Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"
    • "ARM64 Reversing And Exploitation" (8ksec)
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
      • Part 7
      • Part 8
      • Part 9
      • Part 10
    • "Attacking an EDR"
      • Part 1
      • Part 2
    • "Attacking IoT Devices from Web Perspective"
    • ["Attacking JS engines: Fundamentals for understanding memory corruption crashes"][720]
    • "Audio with embedded Linux training"
    • "Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"
    • "b3typer - bi0sCTF 2022"
    • "Back to the Future with Platform Security"
    • "Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"
    • "Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"
    • "Behind the Shield: Unmasking Scudos's Defenses"
    • "BlackLotus UEFI bootkit: Myth confirmed"
    • "BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"
    • ["BPF Memory Forensics with Volatility 3"][881]
    • "Breaking Fortinet Firmware Encryption"
    • "Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"
    • "Breaking Secure Boot on the Silicon Labs Gecko platform"
    • "Building a Custom Mach-O Memory Loader for macOS"
    • "Building an Exploit for FortiGate Vulnerability CVE-2023-27997"
    • "Bypassing a noexec by elf roping"
    • "Bypassing PPL in Userland (again)"
    • "Bypassing SELinux with init_module"
    • "C101101: D-Link DIR-865L":
      • "Remote Code Execution (pre-auth)"
      • "Unsigned firmware upload lead to persistent backdoor (pre-auth)"
      • "Memory corruptions lead to Remote Code Execution (pre-auth)"
    • "CAN Injection: keyless car theft"
    • "chonked"
      • "minidlna 1.3.2 http chunk parsing heap overflow (cve-2023-33476) root cause analysis"
      • "exploiting cve-2023-33476 for remote code execution"
    • ["Code Execution in Chromium’s V8 Heap Sandbox"][896]
    • "Coffee: A COFF loader made in Rust"
    • "Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"
    • "Conquering the memory through io_uring - Analysis of CVE-2023-2598"
    • "Cracking Windows Kernel with HEVD"
      • "Chapter 0"
      • "Chapter 1"
      • "Chapter 2"
      • "Chapter 3"
      • "Chapter 4"
    • "Cueing up a calculator: an introduction to exploit development on Linux"
    • "Customizing Sliver":
      • Part 1
      • Part 2
      • Part 3
    • "CVE-2022-27666: My file your memory"
    • "CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"
    • "CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"
    • "CVE-2023-23504: XNU Heap Underwrite in dlil.c"
    • "CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"
    • "CVE-2023-36844 And Friends: RCE In Juniper Devices"
    • "CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"
    • "cURL audit: How a joke led to significant findings"
    • ["D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."][964]
    • "Debugger Ghidra Class"
    • "Debugging D-Link: Emulating firmware and hacking hardware"
    • "Decompilation Debugging"
    • "Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"
    • "Defining the cobalt strike reflective loader"
    • "Demystifying bitwise operations, a gentle C tutorial"
    • "Detecting and decrypting Sliver C2 – a threat hunter’s guide"
    • "Detecting BPFDoor Backdoor Variants Abusing BPF Filters"
    • "Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"
    • "Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"
    • "Diving Into Smart Contract Decompilation"
    • "Diving into Starlink's User Terminal Firmware"
    • "DJI Mavic 3 Drone Research"
      • "Firmware Analysis"
      • ["Vulnerability Analysis"][713]
    • "Drone Security and Fault Injection Attacks"
    • "DualShock4 Reverse Engineering":
      • Part 1
      • Part 3
      • Part 3
    • "eBPF: A new frontier for malware"
    • "Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"
    • "Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"
    • "ENLBufferPwn (CVE-2022-47949)"
    • "Escaping the Google kCTF Container with a Data-Only Exploit"
    • ["Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"][827]
    • "Exploitation of Openfire CVE-2023-32315"
    • "Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"
    • "Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"
    • "Exploiting CVE-2021-3490 for Container Escapes"
    • "Exploiting null-dereferences in the Linux kernel"
    • "Exploring UNIX pipes for iOS kernel exploit primitives"
    • "EPF: Evil Packet Filter"
    • "Escaping from Bhyve"
    • "ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"
    • "Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"
    • "Espressif ESP32: Breaking HW AES with Power Analysis"
    • "Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"
    • "Executing Arbitrary Code & Executables in Read-Only FileSystems"
    • "Exploit Engineering – Attacking the Linux Kernel"
    • "Exploiting a Remote Heap Overflow with a Custom TCP Stack"
    • "Exploring Hell's Gate"
    • "Exploiting a bug in the Linux kernel with Zig"
    • "Exploiting HTTP Parsers Inconsistencies"
    • "Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"
    • "Exploring Android Heap Allocations in Jemalloc 'New'"
    • "Exploring Linux's New Random Kmalloc Caches"
    • "Exploring the section layout in linker output"
    • "Fantastic Rootkits: And Where To Find Them":
      • Part 1
      • Part 2
      • Part 3
    • "Few lesser known tricks, quirks and features of C"
    • "Finding and exploiting process killer drivers with LOL for 3000$"
    • "Finding bugs in C code with Multi-Level IR and VAST"
    • "Finding Gadgets for CPU Side-Channels with Static Analysis Tools"
    • "For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"
    • "FortiNAC - Just a few more RCEs"
    • "Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"
    • "Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"
    • "From C, with inline assembly, to shellcode"
    • "Fuzzing Farm":
      • "Fuzzing GEGL with fuzzuf"
      • "Evaluating Performance of Fuzzer"
      • "Patch Analysis and PoC Development"
      • "Hunting and Exploiting 0-day [CVE-2022-24834]"
    • "Fuzzing Golang msgpack for fun and panic"
    • "Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"
    • "Ghidra" (Craig Young):
      • "A Guide to Reversing Shared Objects with Ghidra"
      • "Reversing a Simple CrackMe with Ghidra Decompiler"
      • "Vulnerability Hunting with Ghidra"
      • "Patching a Bug from a Ghidra Listing"
      • "Vulnerability Analysis with Ghidra Scripting"
    • "Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"
    • "Google Chrome V8 ArrayShift Race Condition Remote Code Execution"
    • "Hacking a Tapo TC60 Camera"
    • "Hacking Amazon's eero 6 (part 1)"
    • "Hacking Brightway scooters: A case study"
    • "Hacking ICS Historians: The Pivot Point from IT to OT"
    • "Hacking the Nintendo DSi Browser"
    • "Hardware Hacking to Bypass BIOS Passwords"
    • "Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"
    • "How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"
    • "How does Linux start a process"
    • "How NATs Work":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "How I Hacked my Car":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
    • ["How I hacked smart lights: the story behind CVE-2022-47758"][841]
    • "How to Emulate Android Native Libraries Using Qiling"
    • ["How to Voltage Fault Injection"][685]
    • "How To Secure A Linux Server"
    • "Hunting Vulnerable Kernel Drivers"
    • "Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"
    • "In-depth analysis on Valorant’s Guarded Regions"
    • "In-Memory-Only ELF Execution (Without tmpfs)"
    • "Intel BIOS Advisory – Memory Corruption in HID Drivers "
    • "Intercepting Allocations with the Global Allocator"
    • "Intro to Cutter"
    • "Introduction to SELinux"
    • "IoT Series":
      • "Are People Ready to go?"
      • "How To Build Kernel Image From Scratch"
      • "Firmware testing in QEMU"
      • "Debugging with GDB & GHIDRA + Zero-day"
    • "JTAG 'Hacking' the Original Xbox in 2023"
    • "Kernel Exploit Factory"
    • "Learn Makefiles With the tastiest examples"
    • "Let's build a Chrome extension that steals everything"
    • "Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"
      • Part 1
      • [Part 2][904]
      • [Part 3][930]
    • "Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"
    • "lexmark printer haxx"
    • linux-re-101
    • "Linux debugging, profiling and tracing training"
    • "Linux Kernel Exploitation"
      • ["Getting started & BOF"][678]
      • ["Heap techniques"][679]
      • ["Exploiting race-condition + UAF"][680]
    • "Linux Kernel PWN":
      • ["ret2dir"][899]
      • ["DirtyCred"][900]
    • "Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"
    • "Linux Kernel Teaching"
    • "Linux Malware: Defense Evasion Techniques"
    • "Linux Red Team":
      • "Exploitation Techniques"
      • "Privilege Escalation Techniques"
      • "Persistence Techniques"
    • "Linux Remote Process Injection - (Injecting into a firefox process)"
    • "Linux rootkits explained – Part 1: Dynamic linker hijacking"
    • "Linux Shellcode 101: From Hell to Shell"
    • "Local Privilege Escalation on the DJI RM500 Smart Controller"
    • "Lord Of The Ring0":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "Low-Level Software Security for Compiler Developers"
    • "LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"
    • "Making TOCTOU Great again – X(R)IP"
    • "Malware Reverse Engineering for Beginners":
      • Part 1
      • Part 2
    • "Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"
    • "mast1c0re"
      • "Introduction – Exploiting the PS4 and PS5 through a game save"
      • "Part 1 – Modifying PS2 game save files"
      • "Part 2 – Arbitrary PS2 code execution"
      • "Part 3 – Escaping the emulator"
    • "Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"
    • "Meterpreter vs Modern EDR(s)"
    • "MTE As Implemented":
      • Part 1
      • Part 2
    • "mTLS: When certificate authentication is done wrong"
    • "MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"
    • "Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"
    • "NetGear Series: Emulating Netgear R6700V3 circled binary ":
      • Part 1
      • Part 2
    • "New HiatusRAT Router Malware Covertly Spies On Victims"
    • ["No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"][1091]
    • "NVMe: New Vulnerabilities Made Easy"
    • "nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"
    • "Obscure Windows File Types"
    • "Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"
    • ["One shot, Triple kill"][700]
    • "OPC UA Deep Dive Series":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"
    • "OrBit: advanced analysis of a Linux dedicated malware"
    • "OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"
    • "P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"
    • "P4wnP1-LTE"
    • "Patches, Collisions, and Root Shells: A Pwn2Own Adventure"
    • "Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"
    • "Persistence Techniques That Persist"
    • "Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"
    • "prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"
    • "Producing a POC for CVE-2022-42475 (Fortinet RCE)"
    • "Protecting Android clipboard content from unintended exposure"
    • "Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI"
      • Part 1
      • Part 2
      • Part 3
    • "Prototype Pollution in Python"
    • ["PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"][758]
    • "PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"
    • "PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"
    • "Pwnassistant - Controlling /home's via a Home Assistant RCE"
    • "Pwning Pixel 6 with a leftover patch"
    • "Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"
    • "Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"
    • "Readline crime: exploiting a SUID logic bug"
    • "Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"
    • "Reptar"
    • "Restoring Dyld Memory Loading"
    • "Retreading The AMLogic A113X TrustZone Exploit Process"
    • "Reversing UK mobile rail tickets"
    • "Reversing Windows Container":
      • [Part 1][821]
      • [Part 2][822]
    • "RISC-V Bytes: Exploring a Custom ESP32 Bootloader"
    • "REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"
    • "Revisiting CVE-2017-11176"
    • "Rooting the FiiO M6":
      • "Using the "World's Worst Fuzzer" To Find A Kernel Bug"
      • "Writing an LPE Exploit For Our Overflow Bug"
    • ["Rooting Xiaomi WiFi Routers"][817]
    • "Rust Binary Analysis, Feature by Feature"
    • "Rust to Assembly: Understanding the Inner Workings of Rust"
    • "Rustproofing Linux":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • ["scudo Hardened Allocator — Unofficial Internals Documentation"][706]
    • "Securing our home labs: Frigate code review"
    • "Securing our home labs: Home Assistant code review"
    • "SHA-1 gets SHAttered"
    • "Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"
    • "Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"
    • "Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"
    • "Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"
    • "Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"
    • "Smashing the state machine: the true potential of web race conditions"
    • "SRE deep dive into Linux Page Cache"
    • "Sshimpanzee"
    • "Stepping Insyde System Management Mode"
    • "Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"
    • "THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"
    • "The ARM32 Scheduling and Kernelspace/Userspace Boundary"
    • "The art of Fuzzing: Introduction"
    • "The art of fuzzing: Windows Binaries"
    • "The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"
    • ["The Art Of Linux Persistence"][872]
    • "The Blitz Tutorial Lab on Fuzzing with AFL++"
    • "The code that wasn’t there: Reading memory on an Android device by accident"
    • "The Dragon Who Sold His camaro: Analyzing Custom Router Implant"
    • "The Importance of Reverse Engineering in Network Analysis"
    • "The Linux Kernel Module Programming Guide"
    • "The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"
    • "The Role of the Control Flow Graph in Static Analysis"
    • "The Silent Spy Among Us: Smart Intercom Attacks"
    • "The Stack Series: The X64 Stack"
    • "The Untold Story of the BlackLotus UEFI Bootkit"
    • "Tickling ksmbd: fuzzing SMB in the Linux kernel"
    • "Tool Release: Cartographer"
    • "Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"
    • "Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"
    • "Your not so "Home Office" - SOHO Hacking at Pwn2Own"
    • "Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"
    • "Unauthenticated RCE on a RIGOL oscilloscope"
    • "UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"
    • "Uncovering a crazy privilege escalation from Chrome extensions"
    • "Uncovering HinataBot: A Deep Dive into a Go-Based Threat"
    • "Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"
    • "Understanding a Payload’s Life Featuring Meterpreter & Other Guests "
    • "Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"
    • "Understanding the Heap - a beautiful mess"
    • ["Unleashing ksmbd: crafting remote exploits of the Linux kernel"][828]
    • "Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)"
    • "Unlimited Results: Breaking Firmware Encryption of ESP32-V3"
    • "Unveiling secrets of the ESP32":
      • "creating an open-source MAC Layer"
      • "reverse engineering RX"
    • "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More"
    • ["What is Loader Lock?"][845]
    • "Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"
    • "Windows Installer EOP (CVE-2023-21800)"
    • "Writing your own RDI /sRDI loader using C and ASM"
    • "Zenbleed"
    • "Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"

    2022

    • "A journey into IoT":
      • "Chip identification, BUSSide, and I2C"
      • "Discover components and ports"
      • "Firmware dump and analysis"
      • ["Radio communications"][681]
      • ["Internal communications"][682]
    • ["A Kernel Hacker Meets Fuchsia OS"][710]
    • "A Technical Analysis of Pegasus for Android":
      • part 1
      • Part 2
      • Part 3
    • ["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]
    • ["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]
    • "ARM 64 Assembly Series":
      • "Basic definitions and registers"
      • "Offset and Addressing modes"
      • "Load and Store"
      • "Branch"
      • "Data Processing (Part 1)"
      • "Data Processing (Part 2)"
      • "selections and loops"
      • "Subroutines"
    • ["Attacking the Android kernel using the Qualcomm TrustZone"][885]
    • "Attacking Titan M with Only One Byte"
    • "Avoiding Detection with Shellcode Mutator"
    • "BasicFUN Series":
      • "Hardware Analysis / SPI Flash Extraction"
      • "Reverse Engineering Firmware / Reflashing SPI Flash"
      • "Dumping Parallel Flash via I2C I/O Expanders"
      • "I2C Sniffing, EEPROM Extraction and Parallel Flash Extraction"
    • ["Basics for Binary Exploitation"][749]
    • "Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"
    • ["BrokenPrint: A Netgear stack overflow"][782]
    • "Bypassing software update package encryption ":
      • "Extracting the Lexmark MC3224i printer firmware"
      • "Exploiting the Lexmark MC3224i printer"
    • "Bypassing vtable Check in glibc File Structures"
    • "Blind Exploits to Rule Watchguard Firewalls"
    • "BPFDoor - An Evasive Linux Backdoor Technical Analysis"
    • ["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]
    • "Chrome Browser Exploitation":
      • [Part 1][1053]
      • [Part 2][1054]
      • [Part 3][1055]
    • "Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"
    • ["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]
    • ["Corrupting memory without memory corruption"][762]
    • ["Creating a Rootkit to Learn C"][719]
    • "CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"
    • "[CVE-2022-1786] A Journey To The Dawn"
    • "CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"
    • "CVE-2022-27666: Exploit esp6 modules in Linux kernel"
    • "CVE-2022-29582 An io_uring vulnerability"
    • ["Deconstructing and Exploiting CVE-2020-6418"][778]
    • "DirtyCred Remastered: how to turn an UAF into Privilege Escalation"
    • "Disclosing information with a side-channel in Django"
    • "Dumping the Amlogic A113X Bootrom"
    • "Dynamic analysis of firmware components in IoT devices"
    • "Embedded Systems Security and TrustZone"
    • ["Emulate Until You Make it"][748]
    • "EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"
    • "Expanding the Dragon: Adding an ISA to Ghidra"
    • ["Exploiting: Buffer overflow in Xiongmai DVRs"][742]
    • "Exploiting CSN.1 Bugs in MediaTek Basebands"
    • "exploiting CVE-2019-2215"
    • "Exploiting CVE-2022-42703 - Bringing back the stack attack"
    • ["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]
    • "Exploring the Hidden Attack Surface of OEM IoT Devices"
    • "Firmware key extraction by gaining EL3"
    • "Fortigate - Authentication Bypass Lead to Full Device Takeover"
    • "Fourchain":
      • ["Prologue"][765]
      • ["Hole"][766]
      • ["Sandbox"][767]
    • ["Fuzzing ping(8) … and finding a 24 year old bug"][751]
    • "Hacking Bluetooth to Brew Coffee from Github Actions":
      • [Part 1][752]
      • [Part 2][753]
      • [Part 3][754]
    • "Hackign More Secure Portable Storage Devices"
    • ["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]
    • "How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"
    • "Huawei Security Hypervisor Vulnerability"
    • "Hunting for Persistence in Linux"
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "Hacking Some More Secure USB Flash Drives":
      • Part 1
      • Part 2
    • ["Learning eBPF exploitation"][768]
    • "Intro to Embedded RE":
      • "Tools and Series"
      • "UART Discovery and Firmware Extraction via UBoot"
    • "Introduction to x64 Linux Binary Exploitation":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • ["io_uring - new code, new bugs, and a new exploit technique"][978]
    • "Linux Hardening Guide"
    • "Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"
    • "Linux Kernel Exploit (CVE-2022–32250) with mqueue"
    • "Linux SLUB Allocator Internals and Debugging":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "Linternals: Introducing Memory Allocators & The Page Allocator"
    • "Linternals: The Slab Allocator"
    • "Linux kernel heap feng shui in 2022"
    • "Looking for Remote Code Execution bugs in the Linux kernel"
    • "Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"
    • ["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]
    • "Missing Manuals - io_uring worker pool"
    • ["Modifying Embedded Filesystems in ARM Linux zImages"][775]
    • "Netgear Orbi":
      • "orbi hunting 0x0: introduction, uart access, recon"
      • "orbi hunting 0x1: crashes in soap-api"
      • "nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"
    • "nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"
    • "NFC Relay Attack on Tesla Model Y"
    • "Nightmare: One Byte to ROP // Deep Dive Edition"
    • "Overview of GLIBC heap exploitation techniques"
    • "Parsing TFTP in Rust"
    • "Patching, Instrumenting & Debugging Linux Kernel Modules"
    • "PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"
    • "pipe_buffer arbitrary read write"
    • "Pixel 6 Bootloader"
      • "Booting up"
      • "Emulation, ROP"
      • "Exploitation"
    • "Port knocking from the scratch"
    • "Pulling MikroTik into the Limelight"
    • "Racing against the clock -- hitting a tiny kernel race window"
    • ["Replicating CVEs with KLEE"][763]
    • "Reversing C++, Qt based applications using Ghidra"
    • "Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"
    • "Replicant: Reproducing a Fault Injection "
    • "Researching Xiaomi’s Tee to Get to Chinese Money"
    • "Reversing embedded device bootloader (U-Boot)":
      • Part 1
      • Part 2
    • "Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"
    • "Reverse engineering an EV charger"
    • "Reverse Engineering Dark Souls 3":
      • "Connection"
      • "Packets"
      • "Key Exchange"
      • "Reliable UDP"
    • "Reverse engineering integrity checks in Black Ops 3"
    • "Reverse engineering thermal printers"
    • "Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"
    • "SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"
    • "Shedding Light on Huawei's Security Hypervisor"
    • "Shikitega - New stealthy malware targeting Linux"
    • "side channels: power analysis"
    • "side channels: using the chipwhisperer"
    • "SIM Hijacking"
    • "Spoofing Call Stacks To Confuse EDRs"
    • ["SROP Exploitation with radare2"][770]
    • "Stealing the Bitlocker key from a TPM"
    • "Stranger Strings: An exploitable flaw in SQLite"
    • "Survey of security mitigations and architectures, December 2022"
    • "Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"
    • "Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"
    • "The Dirty Pipe Vulnerability"
    • ["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]
    • "The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"
    • ["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]
    • "The toddler’s introduction to Heap exploitation":
      • "Part 1"
      • "Part 2"
      • "Overflows"
      • "Use After Free & Double free"
      • "FastBin Dup to Stack"
      • "FastBin Dup Consolidate"
      • "Unsafe Unlink"
      • "House of Spirit"
      • "House of Lore"
    • "TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"
    • ["Tracing and Manipulating with DynamoRIO"][750]
    • "Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"
    • "Turning Google smart speakers into wiretaps for $100k"
    • "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"
    • "Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"
    • "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":
      • Part 1
      • Part 2
    • "Vulnerability Details for CVE-2022-41218"
    • "Vulnerabilities in Tenda's W15Ev2 AC1200 Router"
    • "When an N-Day turns into a 0day"
    • ["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]
    • "Write a Linux firewall from scratch based on Netfilter"
    • "Yet another bug into Netfilter"
    • "Xiongmai IoT Exploitation"
    • "Zyxel authentication bypass patch analysis (CVE-2022-0342)"

    2021

    • "A dive into the PE file format":
      • "Introduction"
      • "DOS Header, DOS Stub and Rich Header"
      • "NT Headers"
      • "Data Directories, Section Headers and Sections"
      • "Imports (Import Direcory Table, ILT, IAT)"
      • "PE Base Relocations"
      • "Writing a PE Parser"
    • ["A Nerve-Racking Bug Collision in Samsung's NPU Driver"][855]
    • "A Practical Approach to Attacking IoT Embedded Designs":
      • [Part 1][721]
      • [Part 2][722]
    • ["Attacking Samsung RKP"][909]
    • "Automatic unpacking with Qiling framework"
    • ["BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"][755]
    • "Breaking 64 bit aslr on Linux x86-64"
    • "Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"
    • "Complete Guide to Stack Buffer Overflow (OSCP Preparation)"
    • "CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"
    • "CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."
    • ["CVE-2021-22555: Turning \x00\x00 into 10000$"][977]
    • ["Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"][756]
    • "Digging into Linux namespaces":
      • Part 1
      • Part 2
    • ["Exploiting crash handlers: LPE on Ubuntu"][760]
    • "Extending Ghidra Part 1: Setting up a Development Environment"
    • "Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"
    • "Fuzzing101 with LibAFL":
      • "Fuzzing Xpdf"
      • "Speed Improvements to Part I"
      • "Fuzzing libexif"
    • ["Getting to know memblock"][771]
    • "Ghidra 101":
      • "Cursor Text Highlighting"
      • "Slice Highlighting"
      • "Decoding Stack Strings"
      • "Loading Windows Symbols (PDB files)"
      • "Creating Structures in Ghidra"
      • "Loading Windows Symbols (PDB files) in Ghidra 10.x"
    • "GRCON 2021 - Capture the Signal"
    • "Hacking the Furbo Dog Camera":
      • [Part 1][744]
      • [Part 2][745]
      • [Part 3][746]
    • "How AUTOSLAB Changes the Memory Unsafety Game"
    • "Learning Linux Kernel Exploitation":
      • Part 1
      • Part 2
      • Part 3
    • "LinkSys EA6100 AC1200":
      • [Part 1][740]
      • [Part 1][741]
    • "Linux Internals: How /proc/self/mem writes to unwritable memory"
    • "Linux Kernel Exploitation":
      • "Debugging the Kernel with QEMU"
      • "Smashing Stack Overflows in the Kernel"
      • "Controlling RIP and Escalating privileges via Stack Overflow"
    • "Live Debugging Techniques for the Linux Kernel"
      • Part 1
      • Part 2
      • Part 3
    • "Malware development (0xPat)"
      • [Part 1][792]
      • [Part 2][793]
      • [Part 3][794]
      • [Part 4][795]
      • [Part 5][796]
      • [Part 6][797]
      • [Part 7][798]
      • [Part 8][799]
      • [Part 9][800]
    • "mooosl"
    • "My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"
    • "New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"
    • "New Old Bugs in the Linux Kernel"
    • ["Practical Introduction to CodeQL"][1233]
    • ["Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug"]
    • "Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"
    • "Recovering a Full PEM Private key when Half of it is Redacted"
    • "Reverse Engineering an Unknown Microcontroller"
    • "Reverse Engineering Bare-Metal Firmware":
      • Part 1
      • Part 2
      • Part 3
    • "Reverse Engineering Yaesu FT-70D Firmware Encryption"
    • "Syzkaller diving":
      • Part 1
      • Part 2
      • Part 3
    • "The Art of Exploiting UAF by Ret2bpf in Android Kernel"
    • "The Oddest Place You Will Ever Find PAC"
    • ["Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"][888]
    • "VMProtect 2"
      • [Part 1][960]
      • [Part 2][961]
    • "Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"

    2020

    • "A Deep Dive Into Samsung's TrustZone"
      • Part 1
      • Part 2
      • Part 3
    • ["An iOS hacker tries Android"][856]
    • "BGET Explained Binary Heap Exploitation on OP-TEE":
      • Part 1
      • Part 2
    • "BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"
    • ["Building a Basic C2"][1057]
    • ["CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"][890]
    • ["CVE-2020-16040 Analysis & Exploitation"][725]
    • "Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"
    • "Espressif ESP32: Bypassing Secure Boot using EMFI"
    • "Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"
    • "Espressif ESP32: Controlling PC during Secure Boot"
    • "Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"
    • "Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"
    • "Flashback Connects - Cisco RV340 SSL VPN RCE"
    • "Hardware Debugging for Reverse Engineers":
      • "SWD, OpenOCD and Xbox One Controllers"
      • "TAG, SSDs and Firmware Extraction"Manipulating AES Traffic
    • "Hardware Hacking 101: Identifying and Dumping eMMC Flash"
    • "House of Muney - Leakless Heap Exploitation Technique"
    • ["Learning to Decapsulate Integrated Circuits Using Acid Deposition"][727]
    • "Loading Dynamic Libraries on Mac"
    • "Minesweeper - TP-Link Archer C7 LAN RCE"
    • "My Methods To Achieve Persistence In Linux Systems"
    • "nRF52 Debug Resurrection":
      • Part 1
      • Part 2
    • "NTLM Relay"
    • "Patch Diffing a Cisco RV110W Firmware Update"
      • Part 1
      • Part 2
    • ["Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"][783]
    • "ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"
    • ["Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"][780]
    • "SSHD Injection and Password Harvesting"
    • ["There’s A Hole In Your SoC: Glitching The MediaTek BootROM"][737]
    • "Weekend Destroyer - RCE in Western Digital PR4100 NAS"
    • "What're you telling me, Ghidra?"

    2019

    • "Breaking out of Docker via runC – Explaining CVE-2019-5736"
    • "Executable and Linkable Format 101":
      • "Sections and Segments"
      • "Symbols"
      • "Relocations"
      • "Dynamic Linking"
    • ["Exploiting Qualcomm WLAN and Modem Over the Air"][773]
    • "Hacking microcontroller firmware through a USB"
    • "Hardening Secure Boot on Embedded Devices for Hostile Environments"
    • ["How to Weaponize the Yubikey"][743]
    • "Pew Pew Pew: Designing Secure Boot Securely"
    • ["Pwn the ESP32 crypto-core"][757]
    • "Pwn the ESP32 Secure Boot"
    • "Reverse Engineering Architecture And Pinout of Custom Asics"
    • "Reverse-engineering Broadcom wireless chipsets"
    • "Reverse Engineering of a Not-so-Secure IoT Device"
    • "Virtualization Internals":
      • Part 1
      • Part 2
      • Part 3
      • Part 4

    2018

    • "A Deep dive into (implicit) Thread Local Storage"
    • "A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"
    • "ARM Exploitation":
      • ["Return oriented Programming"][788]
      • ["Setup and Tools"][789]
      • ["Defeating DEP - execute system()"][790]
      • ["Defeating DEP - executing mprotect()"][791]
    • "CVE-2017-11176: A step-by-step Linux Kernel exploitation":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "eMMC Data Recovery from Damaged Smartphone"
    • ["Kinibi TEE: Trusted Application Exploitation"][781]
    • "My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"
    • ["Reverse Engineering BLE Devices"][761]
    • "Reversing ESP8266 Firmware":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
    • "Vectorized Emulation":438
      • "Hardware accelerated taint tracking at 2 trillion instructions per second"
      • "MMU Design"

    2017

    • ["Escalating Privileges in Linux using Fault Injection"][774]
    • "Hardware hacking tutorial: Dumping and reversing firmware"
    • "HiSilicon DVR hack"
    • "How I Reverse Engineered and Exploited a Smart Massager"
    • "Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"
    • "Linux ptrace introduction AKA injecting into sshd for fun"
    • "Over The Air":
      • "Exploiting Broadcom’s Wi-Fi Stack (Part 1)"
      • "Exploiting Broadcom’s Wi-Fi Stack (Part 2)"
      • "Exploiting The Wi-Fi Stack on Apple Devices"

    2016

    • "Bypassing Secure Boot using Fault Injection"
    • "munmap madness"
    • "Implementation of Signal Handling"
    • "Practical Reverse Engineering"
      • "Digging Through the Firmware"
      • "Scouting the Firmware"
      • "Following the Data"
      • "Dumping the Flash"
      • "Digging Through the Firmware"
    • "Understanding and Hardening Linux Containers"

    2014

    • "ret2dir: Rethinking Kernel Isolation"

    2011

    • "Load-time relocation of shared libraries"
    • "Position Independent Code (PIC) in shared libraries"

    Misc

    • 0xtriboulet
    • "A Noobs Guide to ARM Exploitation"
    • "Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent fuzzing"
    • "Advanced Compilers: The Self-Guided Online Course"
    • "Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"
    • "Android Kernel Exploitation"
    • Anti-Debug Tricks
    • "ARM TrustZone: pivoting to the secure world"
    • ["ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"][927]
    • [Awesome binary parsing][769]
    • [Awesome Executable Packing][717]
    • Awesome Industrial Protocols
    • "Brute Ratel - Scandinavian Defence"
    • Comprehensive Rust
    • [cryptopals][1022]
    • [CVE North Stars][708]
    • "Debugger Ghidra Class"
    • DhavalKapil/heap-exploitation
    • Diffing Portal
    • exploit_mitigations
    • ["fenrir"][1169]
    • Ghidriff - Ghidra Binary Diffing Engine
    • "Grand Theft Auto A peek of BLE relay attack"
    • ["Hands-on Firmware Extraction, Exploration, and Emulation"][979]
    • ice9-bluetooth-sniffer
    • "Illustrated Connections":
      • dtls
      • quic
      • tls 1.2
      • tls 1.3
    • "Introduction to encryption for embedded Linux"
      • "Introduction to encryption for embedded Linux developers"
      • "A hands-on approach to symmetric-key encryption"
      • "Asymmetric-Key Encryption and Digital Signatures in Practice"
    • "Introduction to Malware Analysis and Reverse Engineering"
    • "Kernel Address Space Layout Derandomization"
    • ["Kernel Exploit Recipes Notebook"][776]
    • "Laser-Based Audio Injection on Voice-Controllable Systems"
    • Linux Kernel CVEs
    • "Linux kernel exploit development"
    • "Linux Kernel map"
    • "Linux Insides"
    • ["Linux Privilege Escalation"][982]
    • "Linux Syscalls Reference"
    • "Lytro Unlock - Making a bad camera slightly better"
    • "Minimizing Rust Binary Size"
    • "mjsxj09cm Recovering Firmware And Backdooring"
    • "Offensive security (0xtriboulet)"
    • "Operating System development tutorials in Rust on the Raspberry Pi"
    • ["parking-game-fuzzer"][1159]
    • ["Practical Cryprography for Developers"][785]
    • Red-Team-Infrastructure-Wiki
    • "Reverse Engineering For Everyone!"
    • "Reverse Engineering WiFi on RISC-V BL602"
    • "Rust Atomics and Locks"
    • ["RustRedOps"][686]
    • "Satellite Hacking Demystified(RTC0007)"
    • TEE Reversing
    • "THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"
    • tmpout.sh: collection of writeups on low-level stuff
    • ["Trail of Bits Testing Handbook"][724]
    • [TripleCross][696]
    • USB-WiFi
    • "VSS: Beginners Guide to Building a Hardware Hacking Lab"
    • "WinDBG quick start tutorial"

    Other Lists

    • Exploitation: resources dedicated to the world of binary exploitation
    • Linux Kernel: collection of resources dedicated to Linux kernel (internals)
    • Wireless: resources dedicated to wireless technologies and security
    • OT/IoT Security
    • Red Teaming and Offensive Security

    Read more