
http-breakout-proxy
HTTP Proxy Analysis for reverse engineering protocol communication

HTTP Proxy Analysis for reverse engineering protocol communication

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

Converts binary Thrift protocol messages to/from human-readable JSON for manual analysis and tampering, with support for integration into Burp and…

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

An API hooking framework for intercepting and monitoring Windows applications

Proof-of-concept exploit for PHPStudy backdoor with DLL detection, remote command execution via HTTP Accept-Charset header, and embedded C2 payloads…

Proof-of-concept exploit for CVE-2026-6307, a V8 TurboFan type confusion enabling addrof/fakeobj primitives for sandbox escape and remote code…

Local session observer that captures real browser cookies, tokens, and network traffic for use in automation tools. Bypasses bot detection by…

Proof-of-concept adaptation of CVE-2024-23222 (WebKit JSC TOCTOU) for Linux x86_64, demonstrating stale-cell UAF via DFG compiler race window with…

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

Step-by-step penetration testing walkthrough for a HackTheBox Linux box: API enumeration, vertical privilege escalation, OS command injection,…

Exploit implementation for CVE-2026-33439, a pre-authentication Java deserialization RCE in OpenAM. Includes detailed vulnerability analysis, gadget…

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

Step-by-step TryHackMe walkthrough for exploiting the Log4Shell vulnerability (CVE-2021-44228) to achieve remote code execution and capture flags.

Detailed analysis of CVE-2019-12489 command injection in Fastgate modem/router firmware, including firmware extraction, reverse engineering with…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.