awesome-list — Cybersecurity oriented awesome list | Kitploit
0xor0ne/awesome-listawesome-list
Cybersecurity oriented awesome list
3.9k413hace 3 días
Descubre las herramientas más usadas por nuestra comunidad.
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés. Awesome Cybersecurity List
My personal collection of awesome blog posts, write-ups, and papers focusing on cybersecurity.
For a deeper dive into cybersecurity-related tools, check out the dedicated Cybersecurity Tools list.
Outline
2026
- "A 0-click exploit chain for the Pixel 9"
- [Part 1][1241]
- [Part 2][1242]
- [Part 3][1243]
- ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
- ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
- ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
- ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
- ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
- ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
["Carbonara: The MediaTek exploit nobody served"][1249]["CHECK Removed, Context Confused, Checkmate Achieved"][1287]["Clang Hardening Cheat Sheet - Ten Years Later"][1239]["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]["Creative approaches to coding FUD Stagers"][1299]"CVE-2025-38352":
- ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
- ["Extending The Race Window Without a Kernel Patch"][1225]
- ["Uncovering Chronomaly"][1265]
["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]["Damned OOB"][1297]["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302][Dirty Frag][1300]["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]["Exploiting MediaTek's Download Agent"][1232]["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]["HDD Firmware Hacking Part 1"][1290]"Hooked on Linux"
- ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
- ["Rootkit Detection Engineering"][1282]
["Jenny was a Friend of Mine - MCPs and Friends"][1274]["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]["Leveling Up Secure Code Reviews with Claude Code"][1273]["Living off the Process"][1236]["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]["N-Day Research with AI: Using Ollama and n8n"][1263]["Needle in the haystack: LLMs for vulnerability research"][1275]["Now You See mi: Now You're Pwned"][1278]["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]["Page-level UAF exploitation"][1268]["PageJack in Action: CVE-2022-0995 exploit"][1270]["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]["Some notes on the security properties of the pipe_buffer kernel object"][1285]["Static Devirtualization of Themida"][1292]["Table Manners: Diving into Linux Pagetables exp techniques"][1280]["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]["Trailmark turns code into graphs"][1286]["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]VulHunt
- ["A High-Level Look at Binary Vulnerability Detection"][1257]
- ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
- ["Vulnerability REsearch using VulHunt"][1259]
- ["Inside the Binary Vulnerability Analysis Framework"][1260]
- ["Agentic Vulnerability Research with VulHunt"][1261]
["When NAS Vendors Forget How TLS Works"][1251]["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]2025
- ["A File Format Uncracked for 20 Years"][1202]
- ["A First Glimpse of the Starlink User Ternimal"][1084]
- ["A Fuzzy Escape - A tale of vulnerability research on hypervisors"][1151]
- ["A look at an Android ITW DNG exploit"][1231]
- ["A modern tale of blinkenlights"][1200]
- ["A Quick Dive Into The Linux Kernel Page Allocator"][1098]
- ["A Series of io_uring pbuf Vulnerabilities"][1083]
- ["A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"][1181]
- ["Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"][1021]
- ["All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"][1142]
- ["Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"][1174]
- ["Analyzing IOS Kernel Panic Logs"][1037]
- ["Android: Scudo"][1070]
- ["Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"][1240]
- ["APPROTECT Bypass on NRF52832"][1139]
- ["APT28 Operation Phantom Net Voxel"][1171]
- ["Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"][1132]
- ["Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"][1106]
- ["Being Overlord on the Steam Deck with 1 Byte"][1044]
- "BPFDoor"
- ["Part 1 - The Past"][1101]
- ["Part 2 - The Present"][1102]
- ["Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"][1189]
- ["Best practices for key derivation"][1023]
- ["Binder Fuzzing"][1146]
- ["Blasting Past iOS 18"][1038]
- ["Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"][1254]
- ["Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"][1138]
- ["Bootloader to Iris: A Security Teardown of a Hardware Wallet"][1199]
- ["Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"][1125]
- ["Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"][1196]
- ["Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"][1217]
- ["Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"][1039]
- ["Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"][1179]
- ["Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"][1209]
- ["Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"][1124]
- ["Bypassing disk encryption on systems with automatic TPM2 unlock"][1018]
- ["Bypassing MTE with CVE-2025-0072"][1105]
- ["Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"][1222]
- ["Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"][1040]
- ["Case Study: IOMobileFramebuffer NULL Pointer Dereference"][1041]
- ["Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"][1107]
- ["CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"][1061]
- ["Control Flow Hijacking in the Linux Kernel"][1114]
- ["Control Flow Hijacking via Data Pointers"][1085]
- ["corCTF 2025 - corphone"][1168]
- ["Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"][1212]
- ["Cross Cache Attack CheetSheet"][1006]
- ["CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"][1118]
- ["CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"][1149]
- ["CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"][1065]
- ["CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"][1086]
- ["CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"][1076]
- ["CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"][1163]
- ["CVE-2025-6554: The (rabbit) Hole"][1188]
- ["Debugging the Pixel 8 kernel via KGDB"][1123]
- ["Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"][1068]
- ["Denial of Ruzzing: Rust in the Windows Kernel"][1185]
- ["Dirty Pageflags: Revisiting PTE Exploitation in Linux"][1166]
- ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
- ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
- ["Disassembling a binary: linear sweep and recursive traversal"][1019]
- ["Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"][1047]
- ["Don’t Phish-let Me Down: FIDO Authentication Downgrade"][1155]
- ["EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"][1121]
- ["Emulating an iPhone in QEMU"][1051]
- ["Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"][1052]
- ["Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"][1211]
- ["Exploitation of AIxCC Nginx bugs: Part I"][1035]
- ["Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
- ["Exploiting a 13-years old bug on QEMU"][1218]
- ["Exploiting CVE-2024-0582 via the Dirty Pagetable Method"][1081]
- ["Exploiting CVE-2025-21479 on a Samsung S23"][1184]
- ["Exploiting Retbleed in the real world"][1141]
- ["Exploiting the Synology TC500 at Pwn2Own Ireland 2024"][1122]
- ["Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"][1164]
- ["Exploiting Heroes of Might and Magic V"][1119]
- ["Exploring Grapheneos Secure Allocator: Hardened Malloc"][1167]
- ["Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"][1029]
- ["Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"][1172]
- ["Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"][1152]
- ["False Injections: Tales of Physics, Misconceptions and Weird Machines"][1120]
- ["Fast & Faulty - A Use After Free in KGSL Fault Handling"][1182]
- ["FiberGateway GR241AG - Full Exploit Chain"][1097]
- ["First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"][1058]
- ["FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"][1059]
- ["Fundamental of Virtual Memory"][1162]
- ["From Chrome renderer code exec to kernel with MSG_OOB"][1153]
- ["Game Hacking - Valve Anti-Cheat (VAC)"][1074]
- ["Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"][1215]
- ["Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"][1103]
- ["Google CTF 2025 Quals Writeup"][1131]
- ["Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"][1031]
- "Hacking the XBox 360 Hypervisor"
- [Part 1][1109]
- [Part 2][1110]
- ["Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"][1129]
- ["Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"][1198]
- ["HITCON CTF 2025 -- calc"][1145]
- ["How I ruined my vacation by reverse engineering WSC"][1077]
- ["How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"][1090]
- ["How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"][1115]
- "Hydroph0bia (CVE-2025-4275)"
- ["a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1143]
- ["a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1144]
- ["a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1108]
- ["Hypervisors for Memory Introspection and Reverse Engineering"][1099]
- ["Kernel Exploitation Techniques: Turning The (Page) Tables"][1100]
- ["Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"][1180]
- ["Inside Riot Vanguard's Dispatch Table Hooks"][1073]
- ["Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"][1079]
- "iOS 17: New Version, New Acronyms":
- [Part 1][1042]
- [Part 2][1043]
- ["kASLR Internals and Evolution"][1095]
- ["Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"][1082]
- ["KernelSnitch: Side-Channel Attacks on Kernel Data Structures"][1005]
- ksmbd (doyensec):
- ["ksmbd vulnerability research"][1033]
- ["Fuzzing Improvements and Vulnerability Discovery"][1175]
- ["Exploiting CVE-2025-37947"][1176]
- ["Laser Fault Injection on a Budget: RP2350 Edition"][1017]
- ["Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"][1072]
- ["Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"][1137]
- ["Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"][1147]
- ["Linux Kernel Exploitation For Beginners"][1113]
- ["Linux Kernel Hfsplus Slab-out-of-bounds Write"][1066]
- ["Linux kernel Rust module for rootkit detection"][1026]
- ["Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution"][1011]
- ["LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"][1177]
- ["Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"][1050]
- ["Malware Just Got Its Free Passes Back!"][1221]
- ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
- ["mediatek? more like media-rekt, amirite."][1220]
- ["Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"][1069]
- ["Modern (Kernel) Low Fragmentation Heap Exploitation"][1127]
- ["My Emulation Goes to the Moon... Until False Flag"][1094]
- ["NASA cFS version Aquila Software Vulnerability Assessment"][1056]
- ["nRF51 RBPCONF bypass for firmware dumping"][1154]
- ["One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"][1193]
- ["Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"][1186]
- ["Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"][1148]
- ["Overview of Map Exploitation in v8"][1075]
- ["Paint it Blue: Attacking the Bluetooth Stack"][1216]
- ["Patch-Gapping the Google Container-Optimized OS for $0"][1032]
- ["PatchGuard Internals"][1092]
- ["PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"][1213]
- ["Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"][1170]
- ["Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"][1136]
- ["Project Rain:L1TF"][1178]
- ["Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"][1194]
- ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
- ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
- ["pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"][1134]
- ["Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"][1087]
- ["Qualcomm DSP Kernel Internals"][1135]
- ["Race Against Time in the Kernel’s Clockwork"][1160]
- ["Recovering Metadata from .NET Native AOT Binaries"][1089]
- ["Reliable system call interception"][1010]
- ["Replacing a Space Heater Firmware Over WiFi"][1020]
- ["Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"][1093]
- ["Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"][1201]
- ["Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"][1013]
- ["Reversing Samsung's H-Arx Hypervisor Framework - Part 1"][1036]
- ["Reversing the QardioArm"][1048]
- ["Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields"][1226]
- ["Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"][1071]
- ["Root Shell on Credit Card Terminal"][1112]
- ["Rooting the TP-Link Tapo C200 Rev.5"][1130]
- ["ROPing our way to RCE"][1028]
- ["Running code in a PAX Credit Card Payment Machine"][1272]
- ["RV130X Firmware Analysis"][1025]
- ["Security through Transparency: Tales from the RP2350 Hacking Challenge"][1256]
- ["smoltalk: RCE in Open Source Agents"][1045]
- ["Solo: A Pixel 6 Pro Story (When one bug is all you need)"][1128]
- ["SoK: Security of EMV Contactless Payment Systems"][1088]
- ["Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"][1034]
- ["Stack Overflows, Heap Overflows, and Existential Dread"][1150]
- ["State of Linux Snapshot Fuzzing"][1078]
- ["STM32L05 Voltage Glitching"][1111]
- ["Streaming Zero-Fi Shells to Your Smart Speaker"][1096]
- ["Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"][1228]
- ["System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"][1197]
- ["The Art of Linux Kernel Rootkits"][1008]
- ["The cryptography behind electronic passports"][1214]
- "The Evolution of Dirty COW":
- [Part 1][1062]
- [Part 2][1063]
- ["The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"][1116]
- ["TLS NoVerify: Bypass All The Things"][1165]
- ["Tp-Link Router Deep Research"][1203]
- ["Tracing Back to the Source | SPTM Round 3"][1046]
- ["Turning Camera Surveillance on its Axis"][1158]
- ["Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"][1126]
- ["Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"][1133]
- ["VMware Workstation guest-to-host escape"][1161]
- ["We are ARMed no more ROPpery Here"][1016]
- "When a Wi-Fi SSID Gives You Root on an MT02 Repeater"
- [Part 1][1156]
- [Part 2][1157]
- ["When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"][1067]
- ["Windows arm64 Internals: Deconstructing Pointer Authentication"][1190]
- ["Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"][1195]
- "Windows Inter Process Communication A Deep Dive Beyond the Surface"
- [Part 1][1204]
- [Part 2][1205]
- [Part 3][1206]
- [Part 4][1207]
- [Part 5][1208]
- ["WireTap: Breaking Server SGX via DRAM Bus Interposition"][1183]
- ["Workshop: Firmware Reverse Engineering"][1269]
- ["Writing a Ghidra processor module"][1064]
- ["Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique (CVE-2024-50629~50631)"][1247]
- ["yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"][1210]
- ["You Already Have Our Personal Data, Take Our Phone Calls Too"][1140]
- ["Zen and the Art of Microcode Hacking"][1027]
- ["Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"][1227]
2024
- ["1-click Exploit in South Korea's biggest mobile chat app"][965]
- ["4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"][959]
- "64 bytes and a ROP chain – A journey through nftables":
- [Part 1][865]
- [Part 2][866]
- "nix libX11: Uncovering and exploiting a 35-year-old vulnerability":
- [Part 1][703]
- [Part 2][704]
- ["A few notes on AWS Nitro Enclaves: Images and attestation"][738]
- "A first look at Android 14 forensics"
- ["A "Gau-Hack" from EuskalHack"][893]
- ["A Journey From sudo iptables To Local Privilege Escalation"][1009]
- ["A Practical Guide to PrintNightmare in 2024"][709]
- ["A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "][714]
- ["A Trip Down Memory Lane"][715]
- [AArch64 memory and paging][1015]
- ["An Introduction to Chrome Exploitation - Maglev Edition"][882]
- ["An unexpected journey into Microsoft Defender's signature World"][876]
- ["Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"][952]
- ["Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"][736]
- ["AES-GCM and breaking it on nonce reuse"][912]
- ["Analyzing Mutation-Coded - VM Protect and Alcatraz English"][834]
- ["ARLO: I'M WATCHING YOU"][810]
- ["ASLRn’t: How memory alignment broke library ASLR"][731]
- ["Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"][911]
- ["Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"][852]
- ["Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"][1173]
- "Base64 Beyond Encoding"
- [Part 1][945]
- [Part 2][946]
- ["Becoming any Android app via Zygote command injection"][863]
- ["Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"][895]
- ["BGGP4: A 420 Byte Self-Replicating UEFI App For x64"][728]
- ["Binary type inference in Ghidra"][905]
- ["Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"][803]
- ["Breaking the Barrier: Post-Barrier Spectre Attacks"][970]
- ["Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"][987]
- ["Breaking Down Multipart Parsers: File upload validation bypass"][966]
- "Breaking the Flash Encryption Feature of Espressif’s Parts"
- ["Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"][886]
- ["Buying Spying Insights into Commercial Surveillance Vendors"][733]
- ["Bypassing EDRs With EDR-Preloading"][716]
- ["Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"][920]
- "Chaining N-days to Compromise All":
- [Part 1][836]
- [Part 2][837]
- [Part 3][838]
- [Part 4][839]
- [Part 5][840]
- ["Check Point - Wrong Check Point (CVE-2024-24919)"][875]
- ["Code injection on Android without ptrace"][874]
- "CodeQL zero to hero":
[Part 1][858]
[Part 2][859]
[Part 3][860]
[Part 4][1191]
[Part 5][1192]
- ["Commonly Abused Linux Initial Access Techniques and Detection Strategies"][896]
- ["Compiler Options Hardening Guide for C and C++"][877]
- ["Continuously fuzzing Python C extensions"][734]
- ["corCTF 2024: trojan-turtles writeup"][929]
- ["corMine 1 and 2"][948]
- ["Cross-Process Spectre Exploitation"][969]
- ["CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"][861]
- ["CVE-2022-2586 Writeup"][849]
- ["CVE-2020-27786 ( Race Condition + Use-After-Free )"][967]
- ["CVE-2022-4262"][864]
- ["CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"][1012]
- ["CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"][697]
- ["Declawing PUMAKIT"][989]
- [Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)][1003]
- ["Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"][699]
- ["Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"][683]
- ["Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"][805]
- ["Diving Deep into F5 Secure Vault"][918]
- ["DJI - The ART of obfuscation"][705]
- ["Docker Security – Step-by-Step Hardening (Docker Hardening)"][729]
- ["Driving forward in Android drivers"][908]
- ["Emulating RH850 architecture with Unicorn Engine"][853]
- "Everyday Ghidra: Ghidra Data Types"
- [Part 1][973]
- [Part 2][974]
- ["Exploit detail about CVE-2024-26581"][944]
- ["Exploring AMD Platform Secure Boot"][701]
- ["Exploring GNU extensions in the Linux kernel"][878]
- ["Exploiting Android’s Hardened Memory Allocator"][1030]
- ["Exploiting Empire C2 Framework"][723]
- "Exploiting Enterprise Backup Software For Privilege Escalation":
- [Part 1][906]
- [Part 2][907]
- "Exploiting Reversing (ER) series":
- ["Exploiting Steam: Usual and Unusual Ways in the CEF Framework"][898]
- ["Exploring object file formats"][684]
- ["Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"][735]
- "Fault Injection Attacks against the ESP32-C3 and ESP32-C6"
- ["Fault Injection – Down the Rabbit Hole"][993]
- "Finding Bugs in Kernel":
- [Part 1][996]
- [Part 2][997]
- ["Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"][883]
- ["Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"][804]
- ["From fault injection to RCE"][990]
- ["From object transition to RCE in the Chrome renderer"][940]
- ["Fuzzing between the lines in popular barcode software"][968]
- ["Gaining kernel code execution on an MTE-enabled Pixel 8"][808]
- ["Ghidra nanoMIPS ISA module"][873]
- ["Going Native - Malicious Native Applications"][842]
- "Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"
- ["GhostRace: Exploiting and Mitigating Speculative Race Conditions"][802]
- ["GPUAF - Two ways of Rooting All Qualcomm based Android phones"][994]
- ["GraphStrike: Anatomy of Offensive Tool Development"][712]
- ["Hacking a 2014 tablet... in 2024!"][932]
- ["Hacking a Smart Home Device"][691]
- ["Hacking Android Games"][949]
- ["Heap exploitation, glibc internals and nifty tricks"][938]
- ["HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"][818]
- "Hi, My Name is Keyboard"
- ["Hiding Linux Processes with Bind Mounts"][925]
- ["How I Also Hacked my Car"][976]
- ["How to Bypass Golang SSL Verification"][941]
- ["Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"][995]
- "Hunting down the HVCI bug in UEFI"
- "Hunting for Unauthenticated n-days in Asus Routers"
- "Iconv, Set the Charset to RCE":
- [Part 1][870]
- [Part 2][871]
- ["Java Deserialization Tricks"][815]
- ["JTAG Hacking with a Raspberry Pi"][851]
- ["Kuiper Ransomware’s Evolution"][702]
- ["Inside a New OT/IoT Cyberweapon: IOCONTROL"][1001]
- ["Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"][692]
- ["Introduction to Fuzzing Android Native Components"][984]
- "Learning LLVM":
- [Part 1][934]
- [Part 2][935]
- ["LeftoverLocals: Listening to LLM responses through leaked GPU local memory"][687]
- "Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"
- ["Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"][999]
- "Linux Kernel Exploitation":
- ["Environment"][922]
- ["ret2usr"][923]
- ["Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"][939]
- "ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs":
- [Part 1][901]
- [Part 2][902]
- [Part 3][903]
- ["Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"][809]
- ["Mali GPU Kernel LPE"][786]
- ["MalpediaFLOSSed"][814]
- ["Microsoft BitLocker Bypasses are Practical"][718]
- ["Modern implant design: position independent malware development"][690]
- ["My new superpower"][688]
- ["Not the Drones You're Looking For"][825]
- "Operation triangulation":
- ["Keychain module analysis"][823]
- ["audio module analysis"][824]
- ["OtterRoot: Netfilter Universal Root 1-day"][986]
- ["Out-of-bounds read & write in the glibc's qsort()"][698]
- ["PageJack: A Powerful Exploit Technique With Page-Level UAF"][951]
- ["Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code Pages"][1000]
- ["Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"][835]
- ["Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"][983]
- ["PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"][711]
- "Playing with libmalloc in 2024"
- ["Puckungfu 2: Another NETGEAR WAN Command Injection"][730]
- ["Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"][910]
- ["Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"][933]
- ["Pwning browsers like a kernel"][957]
- "Pwn2Own: WAN-to-LAN Exploit Showcase":
- ["Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"][950]
- ["Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"][942]
- "Pwn2Own Toronto 2023":
- ["How it all started"][829]
- ["Exploring the Attack Surface"][830]
- ["Exploration"][831]
- ["Memory Corruption Analysis"][832]
- ["The Exploit"][833]
- ["Pwning a Brother labelmaker, for fun and interop!"][897]
- "Pwntools 10x":
- [Part 1][867]
- [Part 2][868]
- [Part 3][869]
- ["Pygmy Goat"][972]
- ["Recovering an ECU firmware using disassembler and branches"][921]
- ["regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"][919]
- ["Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"][846]
- ["Retrofitting encrypted firmware is a Bad Idea"][1024]
- ["Reverse engineering a car key fob signal "][801]
- ["Reverse Engineering and Dismantling Kekz Headphones"][962]
- ["Reverse Engineering Protobuf Definitions From Compiled Binaries"][820]
- ["Reverse engineering the 59-pound printer onboard the Space Shuttle"][943]
- ["Reverse Engineering the AM335x Boot ROM"][947]
- ["Reverse Engineering The Stream Deck Plus"][1004]
- "Ring Around The Regex"
- [Part 1][955]
- [Part 2][956]
- ["RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"][958]
- ["RomCom exploits Firefox and Windows zero days in the wild"][981]
- ["ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"][892]
- ["Route to Safety: Navigating Router Pitfalls"][816]
- ["Rooting a Hive Camera"][819]
- ["SAME70 Emulator"][879]
- "Say Friend and Enter":
- [Part 1][812]
- [Part 2][813]
- ["Samsung NX related posts"][887]
- ["Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"][975]
- ["SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"][862]
- ["SELinux bypasses"][963]
- ["SLUB Internals for Exploit Developers"][980]
- ["SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"][937]
- ["Shell We Assemble?"][689]
- ["Shellcode evasion using WebAssembly and Rust"][726]
- "SMM isolation":
- ["SMI deprivileging (ISRD)"][847]
- ["Security policy reporting (ISSR)"][848]
- ["SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"][1049]
- "Strengthening the Shield: MTE in Heap Allocators"
- ["Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"][913]
- ["The architecture of SAST tools: An explainer for developers"][739]
- ["The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"][880]
- ["The Definitive Guide to Linux Process Injection"][971]
- ["The 'Invisibility Cloak' - Slash-Proc Magic"][924]
- ["The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"][1007]
- ["The rev.ng decompiler goes open source + start of the UI closed beta"][694]
- ["The tale of a GSM Kernel LP"][850]
- ["The Wild West of Proof of Concept Exploit Code (PoC)"][926]
- "The Windows Registry Adventure":
- [Part 1][914]
- [Part 2][915]
- [Part 3][916]
- ["TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"][894]
- ["Tony Hawk’s Pro Strcpy"][928]
- ["Toolchain Necromancy: Past Mistakes Haunting ASLR"][732]
- ["TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"][988]
- ["TP-Link TDDP Buffer Overflow Vulnerability"][695]
- ["Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"][787]
- ["Understanding AddressSanitizer: Better memory safety for your code"][889]
- ["Understanding Unix Garbage Collection and its Interaction with io_uring"][891]
- ["Understanding Windows x64 Assembly"][693]
- ["Using Symbolic Execution to Devirtualise a Virtualised Binary"][936]
- ["Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"][985]
- ["VBA: having fun with macros, overwritten pointers & R/W/X memory"][843]
- ["Vulnerabilities of Realtek SD card reader driver"][1002]
- ["Why Code Security Matters - Even in Hardened Environments"][953]
- ["Windows Secure-Launch on Qualcomm devices"][811]
- ["Windows Sockets: From Registered I/O to SYSTEM Privileges"][998]
- ["Windows vs Linux Loader Architecture"][844]
- ["Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"][954]
- "Writing a Debugger From Scratch"
- ["Writing a system call tracer using eBPF"][931]
- ["Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"][854]
- ["x64 Return Address Spoofing"][991]
- ["x64 Call Stack Spoofing"][992]
2023
- "A Deep Dive Into Brute Ratel C4 Payloads"
- "A Deep Dive into Penetration Testing of macOS Applications (Part 1)"
- "A Deep Dive into TPM-based BitLocker Drive Encryption"
- "A Detailed Look at Pwn2own Automotive EV Charger Hardware"
- ["A LibAFL Introductory Workshop"][826]
- "A look at CVE-2023-29360, a beautiful logical LPE vuln"
- "A Journey Into Hacking Google Search Appliance"
- "A new method for container escape using file-based DirtyCred"
- "A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"
- "A Potholing Tour in a SoC"
- "A Practical Tutorial on PCIe for Total Beginners on Windows":
- [Part 1][806]
- [Part 2][807]
- "A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"
- "A Red-Teamer diaries"
- "A story about tampering EDRs"
- ["Abusing Liftoff assembly and efficiently escaping from sbx"][677]
- ["Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"][857]
- "Abusing undocumented features to spoof PE section headers"
- "Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"
- "All about LeakSanitizer"
- "All cops are broadcasting: TETRA under scrutiny"
- "All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"
- "An analysis of an in-the-wild iOS Safari WebContent to GPU Process
exploit"
- "An Introduction into Stack Spoofing"
- "Analysis on legit tools abused in human operated ransomware"
- "Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway":
- "Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"
- "Analyzing a Modern In-the-wild Android Exploit"
- "Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"
- "ARM64 Reversing And Exploitation" (8ksec)
- "Attacking an EDR"
- "Attacking IoT Devices from Web Perspective"
- ["Attacking JS engines: Fundamentals for understanding memory corruption crashes"][720]
- "Audio with embedded Linux training"
- "Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"
- "b3typer - bi0sCTF 2022"
- "Back to the Future with Platform Security"
- "Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"
- "Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"
- "Behind the Shield: Unmasking Scudos's Defenses"
- "BlackLotus UEFI bootkit: Myth confirmed"
- "BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"
- ["BPF Memory Forensics with Volatility 3"][881]
- "Breaking Fortinet Firmware Encryption"
- "Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"
- "Breaking Secure Boot on the Silicon Labs Gecko platform"
- "Building a Custom Mach-O Memory Loader for macOS"
- "Building an Exploit for FortiGate Vulnerability CVE-2023-27997"
- "Bypassing a noexec by elf roping"
- "Bypassing PPL in Userland (again)"
- "Bypassing SELinux with init_module"
- "C101101: D-Link DIR-865L":
- "CAN Injection: keyless car theft"
- "chonked"
- ["Code Execution in Chromium’s V8 Heap Sandbox"][896]
- "Coffee: A COFF loader made in Rust"
- "Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"
- "Conquering the memory through io_uring - Analysis of CVE-2023-2598"
- "Cracking Windows Kernel with HEVD"
- "Cueing up a calculator: an introduction to exploit development on Linux"
- "Customizing Sliver":
- "CVE-2022-27666: My file your memory"
- "CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"
- "CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"
- "CVE-2023-23504: XNU Heap Underwrite in dlil.c"
- "CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"
- "CVE-2023-36844 And Friends: RCE In Juniper Devices"
- "CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"
- "cURL audit: How a joke led to significant findings"
- ["D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."][964]
- "Debugger Ghidra Class"
- "Debugging D-Link: Emulating firmware and hacking hardware"
- "Decompilation Debugging"
- "Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"
- "Defining the cobalt strike reflective loader"
- "Demystifying bitwise operations, a gentle C tutorial"
- "Detecting and decrypting Sliver C2 – a threat hunter’s guide"
- "Detecting BPFDoor Backdoor Variants Abusing BPF Filters"
- "Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"
- "Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"
- "Diving Into Smart Contract Decompilation"
- "Diving into Starlink's User Terminal Firmware"
- "DJI Mavic 3 Drone Research"
- "Drone Security and Fault Injection Attacks"
- "DualShock4 Reverse Engineering":
- "eBPF: A new frontier for malware"
- "Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"
- "Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"
- "ENLBufferPwn (CVE-2022-47949)"
- "Escaping the Google kCTF Container with a Data-Only Exploit"
- ["Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"][827]
- "Exploitation of Openfire CVE-2023-32315"
- "Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"
- "Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"
- "Exploiting CVE-2021-3490 for Container Escapes"
- "Exploiting null-dereferences in the Linux kernel"
- "Exploring UNIX pipes for iOS kernel exploit primitives"
- "EPF: Evil Packet Filter"
- "Escaping from Bhyve"
- "ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"
- "Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"
- "Espressif ESP32: Breaking HW AES with Power Analysis"
- "Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"
- "Executing Arbitrary Code & Executables in Read-Only FileSystems"
- "Exploit Engineering – Attacking the Linux Kernel"
- "Exploiting a Remote Heap Overflow with a Custom TCP Stack"
- "Exploring Hell's Gate"
- "Exploiting a bug in the Linux kernel with Zig"
- "Exploiting HTTP Parsers Inconsistencies"
- "Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"
- "Exploring Android Heap Allocations in Jemalloc 'New'"
- "Exploring Linux's New Random Kmalloc Caches"
- "Exploring the section layout in linker output"
- "Fantastic Rootkits: And Where To Find Them":
- "Few lesser known tricks, quirks and features of C"
- "Finding and exploiting process killer drivers with LOL for 3000$"
- "Finding bugs in C code with Multi-Level IR and VAST"
- "Finding Gadgets for CPU Side-Channels with Static Analysis Tools"
- "For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"
- "FortiNAC - Just a few more RCEs"
- "Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"
- "Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"
- "From C, with inline assembly, to shellcode"
- "Fuzzing Farm":
- "Fuzzing Golang msgpack for fun and panic"
- "Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"
- "Ghidra" (Craig Young):
- "Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"
- "Google Chrome V8 ArrayShift Race Condition Remote Code Execution"
- "Hacking a Tapo TC60 Camera"
- "Hacking Amazon's eero 6 (part 1)"
- "Hacking Brightway scooters: A case study"
- "Hacking ICS Historians: The Pivot Point from IT to OT"
- "Hacking the Nintendo DSi Browser"
- "Hardware Hacking to Bypass BIOS Passwords"
- "Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"
- "How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"
- "How does Linux start a process"
- "How NATs Work":
- "How I Hacked my Car":
- ["How I hacked smart lights: the story behind CVE-2022-47758"][841]
- "How to Emulate Android Native Libraries Using Qiling"
- ["How to Voltage Fault Injection"][685]
- "How To Secure A Linux Server"
- "Hunting Vulnerable Kernel Drivers"
- "Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"
- "In-depth analysis on Valorant’s Guarded Regions"
- "In-Memory-Only ELF Execution (Without tmpfs)"
- "Intel BIOS Advisory – Memory Corruption in HID Drivers "
- "Intercepting Allocations with the Global Allocator"
- "Intro to Cutter"
- "Introduction to SELinux"
- "IoT Series":
- "JTAG 'Hacking' the Original Xbox in 2023"
- "Kernel Exploit Factory"
- "Learn Makefiles With the tastiest examples"
- "Let's build a Chrome extension that steals everything"
- "Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"
- Part 1
- [Part 2][904]
- [Part 3][930]
- "Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"
- "lexmark printer haxx"
- linux-re-101
- "Linux debugging, profiling and tracing training"
- "Linux Kernel Exploitation"
- ["Getting started & BOF"][678]
- ["Heap techniques"][679]
- ["Exploiting race-condition + UAF"][680]
- "Linux Kernel PWN":
- ["ret2dir"][899]
- ["DirtyCred"][900]
- "Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"
- "Linux Kernel Teaching"
- "Linux Malware: Defense Evasion Techniques"
- "Linux Red Team":
- "Linux Remote Process Injection - (Injecting into a firefox process)"
- "Linux rootkits explained – Part 1: Dynamic linker hijacking"
- "Linux Shellcode 101: From Hell to Shell"
- "Local Privilege Escalation on the DJI RM500 Smart Controller"
- "Lord Of The Ring0":
- "Low-Level Software Security for Compiler Developers"
- "LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"
- "Making TOCTOU Great again – X(R)IP"
- "Malware Reverse Engineering for Beginners":
- "Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"
- "mast1c0re"
- "Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"
- "Meterpreter vs Modern EDR(s)"
- "MTE As Implemented":
- "mTLS: When certificate authentication is done wrong"
- "MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"
- "Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"
- "NetGear Series: Emulating Netgear R6700V3 circled binary ":
- "New HiatusRAT Router Malware Covertly Spies On Victims"
- ["No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"][1091]
- "NVMe: New Vulnerabilities Made Easy"
- "nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"
- "Obscure Windows File Types"
- "Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"
- ["One shot, Triple kill"][700]
- "OPC UA Deep Dive Series":
- "OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"
- "OrBit: advanced analysis of a Linux dedicated malware"
- "OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"
- "P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"
- "P4wnP1-LTE"
- "Patches, Collisions, and Root Shells: A Pwn2Own Adventure"
- "Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"
- "Persistence Techniques That Persist"
- "Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"
- "prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"
- "Producing a POC for CVE-2022-42475 (Fortinet RCE)"
- "Protecting Android clipboard content from unintended exposure"
- "Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI"
- "Prototype Pollution in Python"
- ["PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"][758]
- "PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"
- "PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"
- "Pwnassistant - Controlling /home's via a Home Assistant RCE"
- "Pwning Pixel 6 with a leftover patch"
- "Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"
- "Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"
- "Readline crime: exploiting a SUID logic bug"
- "Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"
- "Reptar"
- "Restoring Dyld Memory Loading"
- "Retreading The AMLogic A113X TrustZone Exploit Process"
- "Reversing UK mobile rail tickets"
- "Reversing Windows Container":
- [Part 1][821]
- [Part 2][822]
- "RISC-V Bytes: Exploring a Custom ESP32 Bootloader"
- "REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"
- "Revisiting CVE-2017-11176"
- "Rooting the FiiO M6":
- ["Rooting Xiaomi WiFi Routers"][817]
- "Rust Binary Analysis, Feature by Feature"
- "Rust to Assembly: Understanding the Inner Workings of Rust"
- "Rustproofing Linux":
- ["scudo Hardened Allocator — Unofficial Internals Documentation"][706]
- "Securing our home labs: Frigate code review"
- "Securing our home labs: Home Assistant code review"
- "SHA-1 gets SHAttered"
- "Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"
- "Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"
- "Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"
- "Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"
- "Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"
- "Smashing the state machine: the true potential of web race conditions"
- "SRE deep dive into Linux Page Cache"
- "Sshimpanzee"
- "Stepping Insyde System Management Mode"
- "Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"
- "THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"
- "The ARM32 Scheduling and Kernelspace/Userspace Boundary"
- "The art of Fuzzing: Introduction"
- "The art of fuzzing: Windows Binaries"
- "The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"
- ["The Art Of Linux Persistence"][872]
- "The Blitz Tutorial Lab on Fuzzing with AFL++"
- "The code that wasn’t there: Reading memory on an Android device by accident"
- "The Dragon Who Sold His camaro: Analyzing Custom Router Implant"
- "The Importance of Reverse Engineering in Network Analysis"
- "The Linux Kernel Module Programming Guide"
- "The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"
- "The Role of the Control Flow Graph in Static Analysis"
- "The Silent Spy Among Us: Smart Intercom Attacks"
- "The Stack Series: The X64 Stack"
- "The Untold Story of the BlackLotus UEFI Bootkit"
- "Tickling ksmbd: fuzzing SMB in the Linux kernel"
- "Tool Release: Cartographer"
- "Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"
- "Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"
- "Your not so "Home Office" - SOHO Hacking at Pwn2Own"
- "Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"
- "Unauthenticated RCE on a RIGOL oscilloscope"
- "UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"
- "Uncovering a crazy privilege escalation from Chrome extensions"
- "Uncovering HinataBot: A Deep Dive into a Go-Based Threat"
- "Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"
- "Understanding a Payload’s Life Featuring Meterpreter & Other Guests "
- "Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"
- "Understanding the Heap - a beautiful mess"
- ["Unleashing ksmbd: crafting remote exploits of the Linux kernel"][828]
- "Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)"
- "Unlimited Results: Breaking Firmware Encryption of ESP32-V3"
- "Unveiling secrets of the ESP32":
- "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More"
- ["What is Loader Lock?"][845]
- "Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"
- "Windows Installer EOP (CVE-2023-21800)"
- "Writing your own RDI /sRDI loader using C and ASM"
- "Zenbleed"
- "Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"
2022
2021
2020
2019
2018
2017
2016
2014
2011
Misc
Other Lists