
slides
CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU


Fuzzing Framework for Modules in Apache HTTPD Server

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

Laravel debug mode - Remote Code Execution (RCE)

.NET deobfuscator and unpacker.