
My-Presentation-Slides
Collections of Orange Tsai's public presentation slides.

Collections of Orange Tsai's public presentation slides.

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

Proof-of-Concept and technical analysis for CVE-2026-27654, a heap-based buffer overflow vulnerability in the NGINX HTTP WebDAV module, including…

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

NGINX RCE exploits

Cisco RV110w UPnP stack overflow



CVE-2013-2028 python exploit

RTSPServer Code Execution Vulnerability CVE-2018-4013