
Formbook-Payload-Extraction-XOR-Decryption-Net-Assembly-Analysis
Reverse engineering analysis of Formbook, an info-stealer that uses .NET assembly manipulation and XOR decryption. Full payload extracted via x32dbg,…

Reverse engineering analysis of Formbook, an info-stealer that uses .NET assembly manipulation and XOR decryption. Full payload extracted via x32dbg,…

CVE-2020-25578 and CVE-2020-25579: Some FreeBSD info leak bugs I found in 2020.

cldflt.sys information disclosure vulnerability (KB5034765 - KB5035853, Win 11).

Integer overflow in Oniguruma

Kernel pointers copied to output user mode buffer with ioctl 0x22A014 in the appid.sys driver.

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

The PoC of information disclosure in Microsoft Desktop Windows Management.

HikCentral Professional - Pre-Auth License ActiveCode Leak

CVE-2017-9627 CVE-2017-9629 CVE-2017-9631

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read

Technical disclosure of CVE-2018-15968: an out-of-bounds read vulnerability in Adobe Reader's PDF parsing, enabling information disclosure and…

Standalone zero-driver Windows system and API monitor in Rust

CVE-2026-50416: Windows 11 KASLR bypass