
vucsa
Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Annual small file competition repository with binary golf challenges across themes like polyglots, crashes, self-replication, and downloads,…

Binary Exploitation and Reverse-Engineering (from assembly into C)

Real world and CTFs exploiting web/binary POCs.

Technical analysis and proof-of-concept exploit for CVE-2026-8389, a SpiderMonkey BaselineJIT type confusion vulnerability in Firefox, demonstrated…

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Challenge handouts, source code, and solutions for UofTCTF 2025

Personal collection of exploits including n-days, 0-days, CTFs, kernel and browser vulnerabilities for security research and penetration testing.

Exploit for CVE-2023-4427 targeting Chrome 117 V8, using many cross-origin iframes to brute-force ASLR and achieve code execution. Provides…

A collection of web browser CTF challenges and solutions.

Linux kernel exploit development notes and scripts for CTF challenges, covering initramfs extraction, msg_msg/ldt_struct abuse, and practical…

A plugin that provides resources for beginners to learn reverse engineering using Binary Ninja. It automatically installs several other plugins, and…

Proof-of-concept exploit for CVE-2026-8461, a heap out-of-bounds write in FFmpeg's MagicYUV decoder, achieving remote code execution via…

Christmas-themed CTF Advent Calendar with 12 structured challenges across binary exploitation, cryptography, reverse engineering, forensics, OSINT,…

CVE-2026-46331 and CVE-2026-43503

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

PoC demonstrating dyld as a PAC signing oracle via hand-crafted Mach-O chained fixups on arm64e, achieving controlled PAC-valid pointer writes and…

This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM.…