Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/0xor0ne/awesome-list
Análisis de VulnerabilidadesExplotaciónIngeniería InversaAnálisis de MalwareCTFAnálisis de BinariosPapers e InvestigaciónAprendizaje y EducaciónRecursos Curados
GitHub0xor0ne/awesome-list

awesome-list

Lista increíble orientada a la ciberseguridad

3.9k41326hace 1 díaRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio

Awesome Cybersecurity List

Mi colección personal de publicaciones de blog, write-ups y papers increíbles centrados en ciberseguridad.

Para profundizar en herramientas relacionadas con la ciberseguridad, consulta la lista dedicada Cybersecurity Tools.

Índice

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2014
  • 2011
  • Misc
  • Other Lists

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [Parte 1][1241]
    • [Parte 2][1242]
    • [Parte 3][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes"][1307]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["How LLMs Actually Work"][1308]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • "Sleeping Beauty"
    • ["Putting Adaptix to Bed with Crystal Palace"][1309]
    • ["CFG, CET, and Stack Spoofing"][1310]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]

2025- ["Un formato de archivo sin descifrar durante 20 años"][1202]

  • ["Un primer vistazo al terminal de usuario de Starlink"][1084]
  • ["Una fuga difusa - Un relato de investigación de vulnerabilidades en hipervisores"][1151]
  • ["Un vistazo a un exploit DNG de Android ITW"][1231]
  • ["Un relato moderno de blinkenlights"][1200]
  • ["Una inmersión rápida en el asignador de páginas del kernel de Linux"][1098]
  • ["Una serie de vulnerabilidades de io_uring pbuf"][1083]
  • ["Un recorrido por eBPF en el kernel de Linux: Observabilidad, Seguridad y Redes"][1181]
  • ["Descubriendo accidentalmente una vulnerabilidad de siete años en el kernel de Linux"][1021]
  • ["Todo lo que necesitas es MCP - LLMs resolviendo un desafío de las finales del DEF CON CTF"][1142]
  • ["Analizando una vulnerabilidad de 1-day en el subsistema TLS del kernel de Linux"][1174]
  • ["Analizando registros de pánico del kernel de iOS"][1037]
  • ["Android: Scudo"][1070]
  • ["Otra grieta en la cadena de confianza: Descubriendo (aún otra) elusión de Secure Boot"][1240]
  • ["Elusión de APPROTECT en NRF52832"][1139]
  • ["APT28 Operación Phantom Net Voxel"][1171]
  • ["Atacando aplicaciones de GenAI y LLMs – ¡A veces todo lo que se necesita es pedir amablemente!"][1132]
  • ["Atención, alto voltaje: Explorando la superficie de ataque del Rockwell Automation PowerMonitor 1000"][1106]
  • ["Ser Overlord en la Steam Deck con 1 byte"][1044]
  • "BPFDoor"
    • ["Parte 1 - El pasado"][1101]
    • ["Parte 2 - El presente"][1102]
  • ["Venciendo a xloader en velocidad: IA generativa como multiplicador de fuerza para la ingeniería inversa"][1189]
  • ["Mejores prácticas para la derivación de claves"][1023]
  • ["Fuzzing de Binder"][1146]
  • ["Superando iOS 18"][1038]
  • ["Jacking de auriculares Bluetooth: Divulgación completa de las vulnerabilidades Airoha RACE"][1254]
  • ["Arrancando hacia brechas: Cazando las superficies de ataque remoto de Windows SecureBoot"][1138]
  • ["Del bootloader al Iris: Un desmontaje de seguridad de una cartera de hardware"][1199]
  • ["Rompiendo el desensamblado — Abusando de la resolución de símbolos en programas Linux para ofuscar llamadas a librerías"][1125]
  • ["Entrando en una Brother (MFC-J1010DW): Tres fallos de seguridad en una impresora aparentemente inocente"][1196]
  • ["Rrompiendo la Beestation: Dentro de nuestro viaje de exploits en Pwn2Own 2025"][1217]
  • ["Rompiendo la barrera del sonido Parte I: Fuzzing de CoreAudio con mensajes Mach"][1039]
  • ["Confianza rota: Un bug corregido de Supermicro BMC cobra nueva vida en dos nuevas vulnerabilidades"][1179]
  • ["Domador de bugs: Convirtiendo un desbordamiento de heap limitado en un escape completo de VMware"][1209]

2024- ["Exploit de un clic en la aplicación de chat móvil más grande de Corea del Sur"][965]

  • ["4 exploits, 1 bug: explotando cve-2024-20017 de 4 maneras diferentes"][959]
  • "64 bytes y una cadena ROP – Un viaje a través de nftables":
    • [Parte 1][865]
    • [Parte 2][866]
  • "nix libX11: Descubriendo y explotando una vulnerabilidad de 35 años":
    • [Parte 1][703]
    • [Parte 2][704]
  • ["Algunas notas sobre AWS Nitro Enclaves: Imágenes y atestación"][738]
  • "Un primer vistazo a la forense de Android 14"
  • ["Un "Gau-Hack" de EuskalHack"][893]
  • ["Un viaje desde sudo iptables hasta la escalada de privilegios local"][1009]
  • ["Una guía práctica de PrintNightmare en 2024"][709]
  • ["Una inmersión técnica profunda: Comparando Anti-Cheat Bypass y EDR Bypass "][714]
  • ["Un viaje por la memoria"][715]
  • [Memoria y paginación en AArch64][1015]
  • ["Una introducción a la explotación de Chrome - Edición Maglev"][882]
  • ["Un viaje inesperado al mundo de firmas de Microsoft Defender"][876]
  • ["Análisis de CVE-2024-21310 Desbordamiento de Pool en el Controlador de Filtro de Nube de Windows"][952]
  • ["Técnicas avanzadas de CyberChef para análisis de malware - Guía detallada y ejemplos"][736]
  • ["AES-GCM y su ruptura por reutilización de nonce"][912]
  • ["Analizando código mutado - VM Protect y Alcatraz en inglés"][834]
  • ["ARLO: TE ESTOY VIGILANDO"][810]
  • ["ASLRn’t: Cómo la alineación de memoria rompió el ASLR de bibliotecas"][731]
  • ["El ataque de los clones: Obteniendo RCE en el renderizador de Chrome con propiedades de objetos duplicadas"][911]
  • ["Atacando Android Binder: Análisis y explotación de CVE-2023-20938"][852]
  • ["Unidades de Protección de Memoria Automotrices: Descubriendo vulnerabilidades ocultas"][1173]
  • "Base64 más allá de la codificación"
    • [Parte 1][945]
    • [Parte 2][946]
  • ["Convirtiéndose en cualquier aplicación Android mediante inyección de comandos en Zygote"][863]
  • ["Más allá del control: Explorando nuevos objetos del sistema de archivos para ataques solo de datos en sistemas Linux"][895]
  • ["BGGP4: Una aplicación UEFI autorreplicante de 420 bytes para x64"][728]
  • ["Inferencia de tipos binarios en Ghidra"][905]
  • ["Fuzzing de caja negra de dispositivos IoT usando el router TL-WR902AC como ejemplo"][803]
  • ["Rompiendo la barrera: Ataques Spectre post-barrera"][970]
  • ["Desglosando ataques de aprendizaje automático adversario a través de desafíos de Red Team"][987]

2023- ["A Deep Dive Into Brute Ratel C4 Payloads"][374]

  • ["A Deep Dive into Penetration Testing of macOS Applications (Part 1)"][49]

  • "A Deep Dive into TPM-based BitLocker Drive Encryption"

  • ["A Detailed Look at Pwn2own Automotive EV Charger Hardware"][537]

  • ["A LibAFL Introductory Workshop"][826]

  • ["A look at CVE-2023-29360, a beautiful logical LPE vuln"][260]

  • ["A Journey Into Hacking Google Search Appliance"][203]

  • ["A new method for container escape using file-based DirtyCred"][201]

  • ["A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"][273]

  • ["A Potholing Tour in a SoC"][189]

  • "A Practical Tutorial on PCIe for Total Beginners on Windows":

    • [Part 1][806]
    • [Part 2][807]
  • ["A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"][255]

  • ["A Red-Teamer diaries"][156]

  • ["A story about tampering EDRs"][293]

  • ["Abusing Liftoff assembly and efficiently escaping from sbx"][677]

  • ["Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"][857]

  • ["Abusing undocumented features to spoof PE section headers"][139]

  • ["Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"][587]

  • ["All about LeakSanitizer"][460]

  • ["All cops are broadcasting: TETRA under scrutiny"][237]

  • ["All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"][513]

  • ["An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit"][392]

  • ["An Introduction into Stack Spoofing"][580]

  • ["Analysis on legit tools abused in human operated ransomware"][4]

  • "Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway":

    • [Part 1][196]
    • [Part 2][197]
  • ["Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"][119]

  • ["Analyzing a Modern In-the-wild Android Exploit"][379]

  • ["Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"][326]

2021

  • "A dive into the PE file format":
    • ["Introduction"][332]
    • ["DOS Header, DOS Stub and Rich Header"][333]
    • ["NT Headers"][334]
    • ["Data Directories, Section Headers and Sections"][335]
    • ["Imports (Import Direcory Table, ILT, IAT)"][336]
    • ["PE Base Relocations"][337]
    • ["Writing a PE Parser"][338]
  • ["A Nerve-Racking Bug Collision in Samsung's NPU Driver"][855]
  • "A Practical Approach to Attacking IoT Embedded Designs":
    • [Part 1][721]
    • [Part 2][722]
  • ["Attacking Samsung RKP"][909]
  • ["Automatic unpacking with Qiling framework"][558]
  • ["BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"][755]
  • ["Breaking 64 bit aslr on Linux x86-64"][234]
  • ["Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"][375]
  • ["Complete Guide to Stack Buffer Overflow (OSCP Preparation)"][317]
  • ["CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"][561]
  • ["CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."][179]
  • ["CVE-2021-22555: Turning \x00\x00 into 10000$"][977]
  • ["Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"][756]
  • "Digging into Linux namespaces":
    • [Part 1][157]
    • [Part 2][158]
  • ["Exploiting crash handlers: LPE on Ubuntu"][760]
  • "Extending Ghidra Part 1: Setting up a Development Environment"
  • ["Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"][252]
  • "Fuzzing101 with LibAFL":
    • ["Fuzzing Xpdf"][468]
    • ["Speed Improvements to Part I"][469]
    • ["Fuzzing libexif"][470]
  • ["Getting to know memblock"][771]
  • "Ghidra 101":
    • ["Cursor Text Highlighting"][416]
    • ["Slice Highlighting"][417]
    • ["Decoding Stack Strings"][418]
    • ["Loading Windows Symbols (PDB files)"][419]
    • ["Creating Structures in Ghidra"][420]
    • ["Loading Windows Symbols (PDB files) in Ghidra 10.x"][421]
  • ["GRCON 2021 - Capture the Signal"][403]
  • "Hacking the Furbo Dog Camera":
    • [Part 1][744]
    • [Part 2][745]
    • [Part 3][746]
  • ["How AUTOSLAB Changes the Memory Unsafety Game"][536]

2020

  • "A Deep Dive Into Samsung's TrustZone"
    • [Part 1][487]
    • [Part 2][488]
    • [Part 3][489]
  • ["An iOS hacker tries Android"][856]
  • "BGET Explained Binary Heap Exploitation on OP-TEE":
    • [Part 1][187]
    • [Part 2][188]
  • ["BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"][372]
  • ["Building a Basic C2"][1057]
  • ["CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"][890]
  • ["CVE-2020-16040 Analysis & Exploitation"][725]
  • "Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"
  • "Espressif ESP32: Bypassing Secure Boot using EMFI"
  • "Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"
  • "Espressif ESP32: Controlling PC during Secure Boot"
  • ["Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"][430]
  • ["Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"][161]
  • ["Flashback Connects - Cisco RV340 SSL VPN RCE"][525]
  • "Hardware Debugging for Reverse Engineers":
    • "SWD, OpenOCD and Xbox One Controllers"
    • "TAG, SSDs and Firmware Extraction"Manipulating AES Traffic
  • ["Hardware Hacking 101: Identifying and Dumping eMMC Flash"][87]
  • ["House of Muney - Leakless Heap Exploitation Technique"][181]
  • ["Learning to Decapsulate Integrated Circuits Using Acid Deposition"][727]
  • ["Loading Dynamic Libraries on Mac"][458]
  • ["Minesweeper - TP-Link Archer C7 LAN RCE"][446]
  • ["My Methods To Achieve Persistence In Linux Systems"][247]
  • "nRF52 Debug Resurrection":
    • [Part 1][279]
    • [Part 2][280]
  • ["NTLM Relay"][56]
  • "Patch Diffing a Cisco RV110W Firmware Update"
    • [Part 1][506]
    • [Part 2][507]
  • ["Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"][783]

2019

  • ["Breaking out of Docker via runC – Explaining CVE-2019-5736"][369]
  • "Executable and Linkable Format 101":
    • ["Sections and Segments"][135]
    • ["Symbols"][136]
    • ["Relocations"][137]
    • ["Dynamic Linking"][138]
  • ["Exploiting Qualcomm WLAN and Modem Over the Air"][773]
  • ["Hacking microcontroller firmware through a USB"][243]
  • ["Hardening Secure Boot on Embedded Devices for Hostile Environments"][175]
  • ["How to Weaponize the Yubikey"][743]
  • ["Pew Pew Pew: Designing Secure Boot Securely"][176]
  • ["Pwn the ESP32 crypto-core"][757]
  • ["Pwn the ESP32 Secure Boot"][289]
  • ["Reverse Engineering Architecture And Pinout of Custom Asics"][398]
  • ["Reverse-engineering Broadcom wireless chipsets"][200]
  • "Reverse Engineering of a Not-so-Secure IoT Device"
  • "Virtualization Internals":
    • [Part 1][216]
    • [Part 2][217]
    • [Part 3][218]
    • [Part 4][219]

2018

  • ["A Deep dive into (implicit) Thread Local Storage"][581]
  • ["A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"][464]
  • "ARM Exploitation":
    • ["Return oriented Programming"][788]
    • ["Setup and Tools"][789]
    • ["Defeating DEP - execute system()"][790]
    • ["Defeating DEP - executing mprotect()"][791]
  • "CVE-2017-11176: A step-by-step Linux Kernel exploitation":
    • [Part 1][19]
    • [Part 2][20]
    • [Part 3][21]
    • [Part 4][22]
  • ["eMMC Data Recovery from Damaged Smartphone"][88]
  • ["Kinibi TEE: Trusted Application Exploitation"][781]
  • ["My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"][302]
  • ["Reverse Engineering BLE Devices"][761]
  • "Reversing ESP8266 Firmware":
    • [Part 1][545]
    • [Part 2][546]
    • [Part 3][547]
    • [Part 4][548]
    • [Part 5][549]
    • [Part 6][550]
  • "Vectorized Emulation":[438]
    • ["Hardware accelerated taint tracking at 2 trillion instructions per second"][382]
    • ["MMU Design"][383]

2017

  • ["Escalating Privileges in Linux using Fault Injection"][774]
  • ["Hardware hacking tutorial: Dumping and reversing firmware"][557]
  • ["HiSilicon DVR hack"][236]
  • ["How I Reverse Engineered and Exploited a Smart Massager"][301]
  • "Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"
  • ["Linux ptrace introduction AKA injecting into sshd for fun"][229]
  • "Over The Air":
    • ["Exploiting Broadcom’s Wi-Fi Stack (Part 1)"][539]
    • ["Exploiting Broadcom’s Wi-Fi Stack (Part 2)"][540]
    • ["Exploiting The Wi-Fi Stack on Apple Devices"][541]

2016

  • ["Bypassing Secure Boot using Fault Injection"][174]
  • ["munmap madness"][199]
  • ["Implementation of Signal Handling"][23]
  • "Practical Reverse Engineering"
    • ["Digging Through the Firmware"][114]
    • ["Scouting the Firmware"][115]
    • ["Following the Data"][116]
    • ["Dumping the Flash"][117]
    • ["Digging Through the Firmware"][118]
  • ["Understanding and Hardening Linux Containers"][50]

2014

  • ["ret2dir: Rethinking Kernel Isolation"][384]

2011

  • ["Load-time relocation of shared libraries"][592]
  • ["Position Independent Code (PIC) in shared libraries"][593]

Misc- 0xtriboulet

  • ["A Noobs Guide to ARM Exploitation"][241]
  • ["Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent fuzzing"][71]
  • ["Advanced Compilers: The Self-Guided Online Course"][298]
  • ["Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"][559]
  • ["Android Kernel Exploitation"][571]
  • [Anti-Debug Tricks][585]
  • ["ARM TrustZone: pivoting to the secure world"][304]
  • ["ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"][927]
  • [Awesome binary parsing][769]
  • [Awesome Executable Packing][717]
  • [Awesome Industrial Protocols][510]
  • ["Brute Ratel - Scandinavian Defence"][436]
  • Comprehensive Rust
  • [cryptopals][1022]
  • [CVE North Stars][708]
  • ["Debugger Ghidra Class"][232]
  • [DhavalKapil/heap-exploitation][363]
  • [Diffing Portal][378]
  • [exploit_mitigations][526]
  • ["fenrir"][1169]
  • [Ghidriff - Ghidra Binary Diffing Engine][490]
  • ["Grand Theft Auto A peek of BLE relay attack"][433]
  • ["Hands-on Firmware Extraction, Exploration, and Emulation"][979]
  • [ice9-bluetooth-sniffer][437]
  • "Illustrated Connections":
    • [dtls][519]
    • [quic][518]
    • [tls 1.2][521]
    • [tls 1.3][520]
  • "Introduction to encryption for embedded Linux"
    • ["Introduction to encryption for embedded Linux developers"][0]
    • ["A hands-on approach to symmetric-key encryption"][1]
    • ["Asymmetric-Key Encryption and Digital Signatures in Practice"][2]
  • ["Introduction to Malware Analysis and Reverse Engineering"][407]
  • ["Kernel Address Space Layout Derandomization"][529]
  • ["Kernel Exploit Recipes Notebook"][776]
  • ["Laser-Based Audio Injection on Voice-Controllable Systems"][328]
  • [Linux Kernel CVEs][385]
  • ["Linux kernel exploit development"][573]
  • ["Linux Kernel map"][225]
  • ["Linux Insides"][246]
  • ["Linux Privilege Escalation"][982]
  • ["Linux Syscalls Reference"][17]
  • ["Lytro Unlock - Making a bad camera slightly better"][373]
  • ["Minimizing Rust Binary Size"][476]
  • ["mjsxj09cm Recovering Firmware And Backdooring"][62]
  • ["Offensive security (0xtriboulet)"][405]
  • ["Operating System development tutorials in Rust on the Raspberry Pi"][357]

Otras listas

  • Exploitation: recursos dedicados al mundo de la explotación binaria
  • Linux Kernel: colección de recursos dedicados al kernel de Linux (internals)
  • Wireless: recursos dedicados a las tecnologías inalámbricas y la seguridad
  • OT/IoT Security
  • Red Teaming and Offensive Security[0]: https://sergioprado.blog/introduction-to-encryption-for-embedded-linux-developers/ [1]: https://sergioprado.blog/a-hands-on-approach-to-symmetric-key-encryption/ [2]: https://sergioprado.blog/asymmetric-key-encryption-and-digital-signatures-in-practice/ [3]: https://sysprog21.github.io/lkmpg/ [4]: https://jsac.jpcert.or.jp/archive/2023/pdf/JSAC2023_1_1_yamashige-nakatani-tanaka_en.pdf [5]: http://conference.hitb.org/files/hitbsecconf2023ams/materials/D1T1%20-%20Your%20Not%20So%20Home%20Office%20-%20Soho%20Hacking%20at%20Pwn2Own%20-%20McCaulay%20Hudson%20&%20Alex%20Plaskett.pdf [7]: https://www.synacktiv.com/publications/exploring-android-heap-allocations-in-jemalloc-new [8]: https://www.synacktiv.com/en/publications/behind-the-shield-unmasking-scudos-defenses [10]: https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html [11]: https://idov31.github.io/2022/08/04/lord-of-the-ring0-p2.html [12]: [13]: [14]: [15]: [16]: [17]: [18]: [19]: [20]: [21]: [22]: [23]: [24]: [25]: [26]: [27]: [28]: [29]: [30]: [31]: [32]: [33]: [34]: [35]: [36]: [37]: [38]: [39]: [40]: [41]: [42]: [43]: [44]: [45]: [46]: [47]: [48]: [49]: [50]: [51]: [52]: [53]: [54]: [55]: [56]: [57]: [58]: [59]: [60]: [61]: [62]: [63]: [64]: [65]: [66]: [67]: [68]: [69]: [70]: [71]: [72]: [73]: [74]: [75]: [76]: [77]: [78]: [79]: [80]: [81]: [82]: [83]: [84]: [85]: [86]: [87]: [88]: [89]: [90]: [91]: [92]: [93]: [94]: [95]: [96]: [97]: [98]: [99]: [100]: [101]: [102]: [103]: [104]: [105]: [106]: [107]: [108]: [109]: [110]: [111]: [112]: [113]: [114]: [115]: [116]: [117]: [118]: [119]: [120]: [121]: [122]: [123]: [124]: [125]: [126]: [127]: [128]: [129]: [130]: [131]: [132]: [133]: [134]: [135]: [136]: [137]: [138]: [139]: [140]: [141]: [142]: [143]: [144]: [145]: [146]: [147]: [148]: [149]: [150]: [151]: [152]: [153]: [154]: [155]: [156]: [157]: [158]: [159]: [160]: [161]: [162]: [163]: [164]: [165]: [166]: [167]: [168]: [169]: [170]: [171]: [172]: [173]: [174]: [175]: [176]: [177]: [178]: [179]: [180]: [181]: [182]: [183]: [184]: [185]: [186]: [187]: [188]: [189]: [190]: [191]: [192]: [193]: [194]: [195]: [196]: [197]: [198]: [199]: [200]: [201]: [202]: [203]: [204]: [205]: [206]: [207]: [208]: [209]: [210]: [211]: [212]: [213]: [214]: [215]: [216]: [217]: [218]: [219]: [220]: [221]: [222]: [223]: [224]: [225]: [226]: [227]: [228]: [229]: [230]: [231]: [232]: [233]: [234]: [235]: [236]: [237]: [238]: [239]: [240]: [241]: [242]: [243]: [244]: [245]: [246]: [247]: [248]: [249]: [250]: [251]: [252]: [253]: [254]: [255]: [256]: [257]: [258]: [259]: [260]: [261]: [262]: [263]: [264]: [265]: [266]: [267]: [268]: [269]: [270]: [271]: [272]: [273]: [274]: [275]: [276]: [277]: [278]: [279]: [280]: [281]: [282]: [283]: [284]: [285]: [286]: [287]: [288]: [289]: [290]: [291]: [292]: [293]: [294]: ]: [422]: [423]: [424]: [425]: [426]: [427]: [428]: [429]: [430]: [431]: [432]: [433]: [434]: [435]: [436]: [437]: [438]: [439]: [440]: [441]: [442]: [443]: [444]: [445]: [446]: [447]: [448]: [449]: [450]: [451]: [452]: [453]: [454]: [455]: [456]: [457]: [458]: [459]: [460]: [461]: [462]: [463]: [464]: [465]: [466]: [467]: [468]: [469]: [470]: [471]: [472]: [473]: [474]: [475]: [476]: [477]: [478]: [479]: [480]: [481]: [482]: [483]: [484]: [485]: [486]: [487]: [488]: [489]: [490]: [491]: [492]: [493]: [494]: [495]: [496]: [497]: [498]: [499]: [500]: [501]: [502]: [503]: [504]: [505]: [506]: [507]: [508]: [509]: [510]: [511]: [512]: [513]: [514]: [515]: [516]: [517]: [518]: [519]: [520]: [521]: [522]: [523]: [524]: [525]: [526]: [527]: [528]: [529]: [530]: [531]: [532]: [533]: [534]: [535]: [536]: [537]: [539]: [540]: [541]: [542]: [543]: [544]: [545]: [546]: [547]: [548]: [549]: [550]: [551]: [552]: [553]: [554]: [555]: [556]: [557]: [558]: [559]: [560]: [561]: [562]: [563]: [564]: [565]: [566]: [567]: [569]: [571]: [572]: [573]: [574]: [575]: [576]: [577]: [578]: [579]: [580]: [581]: [582]: [583]: [584]: [585]: [586]: [587]: [588]: [589]: [590]: [591]: [592]: [593]: [594]: [595]: [596]: [597]: [598]: [599]: [600]: [601]: [602]: [603]:

Leer más

Descargar herramienta
  • ["Enterrado en el registro. Explotando una vulnerabilidad NTFS de 20 años"][1124]
  • ["Eludiendo el cifrado de disco en sistemas con desbloqueo automático TPM2"][1018]
  • ["Eludiendo MTE con CVE-2025-0072"][1105]
  • ["El infierno de los callbacks: abusando de callbacks, tail-calls y marcos proxy para ofuscar la pila"][1222]
  • ["Estudio de caso: Analizando el problema de denegación de servicio del driver IONVMeFamily de macOS"][1040]
  • ["Estudio de caso: Desreferencia de puntero NULL en IOMobileFramebuffer"][1041]
  • ["Desafíos y dificultades al emular seis routers domésticos islandeses actuales"][1107]
  • ["CimFS: Crasheando en memoria, encontrando SYSTEM (Edición Kernel)"][1061]
  • ["Secuestro de flujo de control en el kernel de Linux"][1114]
  • ["Secuestro de flujo de control mediante punteros de datos"][1085]
  • ["corCTF 2025 - corphone"][1168]
  • ["Descifrando el Pixel 8: Explotando el DSP no documentado para eludir MTE"][1212]
  • ["CheatSheet de ataques Cross Cache"][1006]
  • ["CVE-2023-52927 - Convirtiendo un informe olvidado de Syzkaller en un exploit kCTF"][1118]
  • ["CVE-2024-30088 Dominando el kernel de Windows @ Pwn2Own Vancouver 2024 (Más Xbox)"][1149]
  • ["CVE-2024-53141: una vulnerabilidad de escritura fuera de límites en Netfilter Ipset"][1065]
  • ["CVE-2025-23016 - EXPLOTANDO LA LIBRERÍA FASTCGI"][1086]
  • ["CVE-2025-37752 Dos bytes de locura: Dominando el kernel de Linux con una escritura de 0x0000 de 262636 bytes fuera de límites"][1076]
  • ["CVE-2025-38001 Explotando todas las instancias de kernelCTF de Google y Debian 12 con un 0-Day por $82k: Un drama familiar de RBTree"][1163]
  • ["CVE-2025-6554: El agujero (de conejo)"][1188]
  • ["Depurando el kernel del Pixel 8 mediante KGDB"][1123]
  • ["Derrotando la ofuscación de cadenas en malware NodeJS ofuscado usando AST"][1068]
  • ["Denegación de Ruzzing: Rust en el kernel de Windows"][1185]
  • ["Dirty Pageflags: Revisitando la explotación de PTE en Linux"][1166]
  • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
  • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
  • ["Desensamblando un binario: barrido lineal y recorrido recursivo"][1019]
  • ["Diseccionando el stealer 'AppleProcessHub' de macOS: Análisis técnico de un ataque multi-etapa"][1047]
  • ["No me hagas phishing: Degradación de la autenticación FIDO"][1155]
  • ["Privilegios EL3vados: Glitcheando el Google WiFi Pro de root a EL3"][1121]
  • ["Emulando un iPhone en QEMU"][1051]
  • ["Exploits sin fin: La saga de una vulnerabilidad de macOS golpeada nueve veces"][1052]
  • ["Desarrollo de exploits: Investigando las pilas sombra en modo kernel en Windows"][1211]
  • ["Explotación de bugs de Nginx en AIxCC: Parte I"][1035]
  • ["Guía de explotación y técnicas - RCE en Ivanti Connect Secure (CVE-2025-0282)"][1014]
  • ["Explotando un bug de hace 13 años en QEMU"][1218]
  • ["Explotando CVE-2024-0582 mediante el método Dirty Pagetable"][1081]
  • ["Explotando CVE-2025-21479 en un Samsung S23"][1184]
  • ["Explotando Retbleed en el mundo real"][1141]
  • ["Explotando el Synology TC500 en Pwn2Own Ireland 2024"][1122]
  • ["Explotando la vulnerabilidad Zero-Day (CVE-2025–9961) en el router TP-Link AX10"][1164]
  • ["Explotando Heroes of Might and Magic V"][1119]
  • ["Explorando el asignador seguro de GrapheneOS: Hardened Malloc"][1167]
  • ["Explorando los mecanismos de explotación de heap: Entendiendo la técnica House of Force"][1029]
  • ["Eternal-Tux: Creando un exploit RCE 0-Click para KSMBD del kernel de Linux a partir de N-Days"][1172]
  • ["Extracción de archivos cifrados de Synology - Pwn2Own Ireland 2024"][1152]
  • ["Inyecciones falsas: Relatos de física, conceptos erróneos y máquinas extrañas"][1120]
  • ["Rápido y defectuoso - Un use after free en el manejo de fallos de KGSL"][1182]
  • ["FiberGateway GR241AG - Cadena de exploit completa"][1097]
  • ["Primer análisis de la elusión del Modo Restringido USB de Apple (CVE-2025-24200)"][1058]
  • ["FLOP: Rompiendo la CPU Apple M3 mediante predicciones falsas de salida de carga"][1059]
  • ["Fundamentos de la memoria virtual"][1162]
  • ["De la ejecución de código en el renderer de Chrome al kernel con MSG_OOB"][1153]
  • ["Hacking de juegos - Valve Anti-Cheat (VAC)"][1074]
  • ["Fantasma en el controlador: Abusando de la verificación de firmware de Supermicro BMC"][1215]
  • ["Desaparecido en 5 segundos: Cómo WARN_ON robó 10 minutos"][1103]
  • ["Writeup de las clasificatorias del Google CTF 2025"][1131]
  • ["Hackea el planeta emulado: Caza de vulnerabilidades en switches industriales Planet WGS-804HPT"][1031]
  • "Hackeando el hipervisor de la XBox 360"
    • [Parte 1][1109]
    • [Parte 2][1110]
  • ["Hackeando el dispositivo IoT Sonoff Smart Home - ¡Extraer, Modificar, Arrancar, Interceptar, Clonar!"][1129]
  • ["Hackeando el router Nokia Beacon 1: UART, inyección de comandos y generación de contraseñas con Qiling"][1198]
  • ["HITCON CTF 2025 -- calc"][1145]
  • ["Cómo arruiné mis vacaciones haciendo ingeniería inversa de WSC"][1077]
  • ["Cómo usé o3 para encontrar CVE-2025-37899, una vulnerabilidad zeroday remota en la implementación SMB del kernel de Linux"][1090]
  • ["¿Cuánto más debemos sangrar? - Divulgación de memoria en Citrix NetScaler (CitrixBleed 2 CVE-2025-5777)"][1115]
  • "Hydroph0bia (CVE-2025-4275)"
    • ["una elusión trivial de SecureBoot para firmware compatible con UEFI basado en Insyde H2O"][1143]
    • ["un poco más que una simple elusión trivial de SecureBoot para firmware compatible con UEFI basado en Insyde H2O"][1144]
    • ["una elusión corregida de SecureBoot para firmware compatible con UEFI basado en Insyde H2O"][1108]
  • ["Hipervisores para introspección de memoria e ingeniería inversa"][1099]
  • ["Técnicas de explotación del kernel: Dando la vuelta a las tablas (de páginas)"][1100]
  • ["Kernel-hack-drill y un nuevo enfoque para explotar CVE-2024-50264 en el kernel de Linux"][1180]
  • ["Dentro de los hooks de la tabla de despacho de Riot Vanguard"][1073]
  • ["Interceptando la comunicación HTTPS en Flutter: Yendo al modo hardcore total con Frida"][1079]
  • "iOS 17: Nueva versión, nuevos acrónimos":
    • [Parte 1][1042]
    • [Parte 2][1043]
  • ["Internals y evolución de kASLR"][1095]
  • ["Kernel-Hack-Drill: Entorno para desarrollar exploits del kernel de Linux"][1082]
  • ["KernelSnitch: Ataques de canal lateral en estructuras de datos del kernel"][1005]
  • ksmbd (doyensec):
    • ["investigación de vulnerabilidades en ksmbd"][1033]
    • ["Mejoras en fuzzing y descubrimiento de vulnerabilidades"][1175]
    • ["Explotando CVE-2025-37947"][1176]
  • ["Inyección de fallos por láser con presupuesto ajustado: Edición RP2350"][1017]
  • ["Última barrera destruida, o compromiso de la clave de cifrado de fusibles para los fusibles de seguridad de Intel"][1072]
  • ["Déjame cocinarte una vulnerabilidad: Explotando el Thermomix TM5"][1137]
  • ["Elevando binarios, Parte 0: Desvirtualizando VMProtect y Themida: ¿Es solo aplanamiento?"][1147]
  • ["Explotación del kernel de Linux para principiantes"][1113]
  • ["Escritura fuera de límites en el slab de Hfsplus del kernel de Linux"][1066]
  • ["Módulo Rust del kernel de Linux para detección de rootkits"][1026]
  • ["La paradoja de Llama - Profundizando en Llama.cpp y explotando el laberinto de heap de Llama.cpp, del desbordamiento de heap a la ejecución remota de código"][1011]
  • ["LunoBotnet: Una botnet de Linux autorreparable con capacidades modulares de DDoS y cryptojacking"][1177]
  • ["Intención Mali-ciosa: Explotando vulnerabilidades de GPU (CVE-2022-22706 / CVE-2021-39793)"][1050]
  • ["¡El malware acaba de recuperar sus pases gratuitos!"][1221]
  • ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
  • ["mediatek? más bien media-rekt, ¿verdad?"][1220]
  • ["Mindshare: Usando la API de Binary Ninja para detectar vulnerabilidades potenciales de use-after-free"][1069]
  • ["Explotación moderna del Low Fragmentation Heap (del kernel)"][1127]
  • ["Mi emulación se va a la luna... hasta el falso positivo"][1094]
  • ["Evaluación de vulnerabilidades del software Aquila de NASA cFS"][1056]
  • ["Elusión de RBPCONF en nRF51 para el volcado de firmware"][1154]
  • ["Corrupción de memoria con un clic en el navegador UC de Alibaba: Explotando vulnerabilidades V8 de patch-gap para robar tus datos"][1193]
  • ["¡Ups! Es un use-after-free de la pila del kernel: Explotando los drivers Linux de GPU de NVIDIA"][1186]
  • ["Lectura fuera de límites en ANGLE CopyNativeVertexData desde un renderer comprometido"][1148]
  • ["Visión general de la explotación de Map en v8"][1075]
  • ["Píntalo de azul: Atacando la pila Bluetooth"][1216]
  • ["Patch-Gapping del Google Container-Optimized OS por $0"][1032]
  • ["Internals de PatchGuard"][1092]
  • ["PerfektBlue Exploit universal de 1 clic para dominar la industria automotriz"][1213]
  • ["Phoenix: Ataques Rowhammer en DDR5 con sincronización autocorrectiva"][1170]
  • ["Hacks de impresión y escaneo: Identificando múltiples vulnerabilidades en varios dispositivos Brother"][1136]
  • ["Proyecto Rain:L1TF"][1178]
  • ["Pwn2Own 2025: Dominando el procesador Postscript de Lexmark"][1194]
  • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
  • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
  • ["pyghidra-mcp: Servidor MCP de Ghidra headless para análisis multi-binario de todo el proyecto"][1134]
  • ["Escritura arbitraria de archivos en Python Dirty a RCE mediante la escritura de archivos de objetos compartidos o la sobrescritura de archivos de bytecode"][1087]
  • ["Internals del kernel DSP de Qualcomm"][1135]
  • ["Carrera contra el tiempo en el mecanismo de relojería del kernel"][1160]
  • ["Recuperando metadatos de binarios .NET Native AOT"][1089]
  • ["Intercepción fiable de llamadas al sistema"][1010]
  • ["Reemplazando el firmware de un calentador de ambiente por WiFi"][1020]
  • ["Ingeniería inversa del descifrado de archivos de firmware de cámaras de seguridad Hanwha con IDA Pro"][1093]
  • ["Ingeniería inversa de los chips Bluetooth Realtek RTL8761B*, para crear mejores herramientas y clases de seguridad Bluetooth"][1201]
  • ["Invirtiendo, descubriendo y explotando una vulnerabilidad de router TP-Link — CVE-2024–54887"][1013]
  • ["Ingeniería inversa del framework de hipervisor H-Arx de Samsung - Parte 1"][1036]
  • ["Ingeniería inversa del QardioArm"][1048]
  • ["Reviviendo vulnerabilidades descartadas: Explotando bugs del kernel de Linux previamente no explotables mediante campos de metadatos de control"][1226]
  • ["Reviviendo la técnica modprobe_path: Superando el parche de search_binary_handler()"][1071]
  • ["Shell de root en un terminal de tarjeta de crédito"][1112]
  • ["Obteniendo root en el TP-Link Tapo C200 Rev.5"][1130]
  • ["ROP hasta el RCE"][1028]
  • ["Ejecutando código en una máquina de pago con tarjeta de crédito PAX"][1272]
  • ["Análisis de firmware del RV130X"][1025]
  • ["Seguridad a través de la transparencia: Relatos del desafío de hacking del RP2350"][1256]
  • ["smoltalk: RCE en agentes de código abierto"][1045]
  • ["Solo: Una historia del Pixel 6 Pro (Cuando un solo bug es todo lo que necesitas)"][1128]
  • ["SoK: Seguridad de los sistemas de pago sin contacto EMV"][1088]
  • ["Generación sólida y eficiente de exploits orientados a datos mediante síntesis de lenguajes de programación"][1034]
  • ["Desbordamientos de pila, desbordamientos de heap y angustia existencial"][1150]
  • ["Estado del fuzzing de snapshots de Linux"][1078]
  • ["Glitching de voltaje en STM32L05"][1111]
  • ["Transmitiendo shells Zero-Fi a tu altavoz inteligente"][1096]
  • ["Singularity: Inmersión profunda en un rootkit sigiloso moderno para el kernel de Linux"][1228]
  • ["Secuestro de registros del sistema: Comprometiendo la integridad del kernel volviendo los registros del sistema contra el sistema"][1197]
  • ["El arte de los rootkits del kernel de Linux"][1008]
  • ["La criptografía detrás de los pasaportes electrónicos"][1214]
  • "La evolución de Dirty COW":
    • [Parte 1][1062]
    • [Parte 2][1063]
  • ["El viaje de eludir la restricción de namespaces sin privilegios de Ubuntu"][1116]
  • ["TLS NoVerify: Eludiendo todo"][1165]
  • ["Investigación profunda del router Tp-Link"][1203]
  • ["Rastreando hasta la fuente | SPTM Ronda 3"][1046]
  • ["Poniendo la vigilancia por cámaras patas arriba"][1158]
  • ["Desenredando el nudo: Rompiendo el control de acceso en redes mesh inalámbricas domésticas"][1126]
  • ["Vulnerabilidad de use-after-free en el subsistema Can BCM que conduce a la divulgación de información (CVE-2023-52922)"][1133]
  • ["Escape de invitado a anfitrión en VMware Workstation"][1161]
  • ["Estamos ARMados, aquí no hay más ROPpery"][1016]
  • "Cuando un SSID Wi-Fi te da root en un repetidor MT02"
    • [Parte 1][1156]
    • [Parte 2][1157]
  • ["Cuando las buenas defensas del kernel se vuelven malas: Exploits del kernel fiables y estables mediante fugas de canal lateral de TLB amplificadas por defensas"][1067]
  • ["Internals de Windows arm64: Deconstruyendo la autenticación de punteros"][1190]
  • ["Explotación de heap en Windows - Del desbordamiento de heap a R/W arbitrario"][1195]
  • "Comunicación entre procesos en Windows: Una inmersión profunda más allá de la superficie"
    • [Parte 1][1204]
    • [Parte 2][1205]
    • [Parte 3][1206]
    • [Parte 4][1207]
    • [Parte 5][1208]
  • ["WireTap: Rompiendo el SGX del servidor mediante interposición del bus DRAM"][1183]
  • ["Taller: Ingeniería inversa de firmware"][1269]
  • ["Escribiendo un módulo de procesador para Ghidra"][1064]
  • ["Escribiendo Sync, Reventando Cron: RCE en Synology BeeStation de DEVCORE y una novedosa técnica de RCE por inyección SQLite (CVE-2024-50629~50631)"][1247]
  • ["yIKEs (Escritura fuera de límites en IKEv2 de WatchGuard Fireware OS CVE-2025-9242)"][1210]
  • ["Ya tienes nuestros datos personales, llévate también nuestras llamadas telefónicas"][1140]
  • ["Zen y el arte del hacking de microcódigo"][1027]
  • ["Investigación de vulnerabilidades en routers Zyxel Zyxel DX3301-T0/EX3301-T0"][1227]
  • ["Desglosando parsers multipart: Evasión de validación de carga de archivos"][966]
  • ["Rompiendo la función de cifrado flash de los componentes de Espressif"][589]
  • ["Bus Pirate 5: La navaja suiza ARRRmy del hacking de hardware"][886]
  • ["Comprando espionaje: Perspectivas sobre vendedores de vigilancia comercial"][733]
  • ["Evadiendo EDRs con EDR-Preloading"][716]
  • ["Análisis de bytecode: Desentrañando las fallas de seguridad de Lua en Factorio"][920]
  • "Encadenando N-days para comprometerlo todo":
    • [Parte 1][836]
    • [Parte 2][837]
    • [Parte 3][838]
    • [Parte 4][839]
    • [Parte 5][840]
  • ["Check Point - Punto de control erróneo (CVE-2024-24919)"][875]
  • ["Inyección de código en Android sin ptrace"][874]
  • "CodeQL de cero a héroe": [Parte 1][858] [Parte 2][859] [Parte 3][860] [Parte 4][1191] [Parte 5][1192]
  • ["Técnicas de acceso inicial en Linux comúnmente abusadas y estrategias de detección"][896]
  • ["Guía de endurecimiento de opciones del compilador para C y C++"][877]
  • ["Fuzzing continuo de extensiones C de Python"][734]
  • ["corCTF 2024: writeup de trojan-turtles"][929]
  • ["corMine 1 y 2"][948]
  • ["Explotación de Spectre entre procesos"][969]
  • ["CVE-2024-20356: Liberando un dispositivo Cisco para ejecutar DOOM"][861]
  • ["Writeup de CVE-2022-2586"][849]
  • ["CVE-2020-27786 ( Condición de carrera + Use-After-Free )"][967]
  • ["CVE-2022-4262"][864]
  • ["CVE-2024-5274: Un fallo menor en el parser de V8 que lleva a catástrofes"][1012]
  • ["CVE-2023-6246: Desbordamiento de búfer basado en heap en el syslog() de glibc"][697]
  • ["Desarmando PUMAKIT"][989]
  • [Inmersión profunda en la condición de carrera de RCU: Análisis de UAF en TCP-AO (CVE-2024–27394)][1003]
  • ["Negación del placer: Atacando objetivos BLE inusuales con un Flipper Zero"][699]
  • ["Deofuscando cadenas ARM64 de Android con Ghidra: Emulando, parcheando y automatizando"][683]
  • ["Diseccionando una vulnerabilidad compleja y logrando ejecución de código arbitrario en Ichitaro Word"][805]
  • ["Inmersión profunda en F5 Secure Vault"][918]
  • ["DJI - El ARTE de la ofuscación"][705]
  • ["Seguridad en Docker – Endurecimiento paso a paso (Docker Hardening)"][729]
  • ["Avanzando en los drivers de Android"][908]
  • ["Emulando la arquitectura RH850 con Unicorn Engine"][853]
  • "Ghidra cotidiano: Tipos de datos en Ghidra"
    • [Parte 1][973]
    • [Parte 2][974]
  • ["Detalles del exploit sobre CVE-2024-26581"][944]
  • ["Explorando AMD Platform Secure Boot"][701]
  • ["Explorando las extensiones GNU en el kernel de Linux"][878]
  • ["Explotando el asignador de memoria endurecido de Android"][1030]
  • ["Explotando el framework Empire C2"][723]
  • "Explotando software de respaldo empresarial para escalada de privilegios":
    • [Parte 1][906]
    • [Parte 2][907]
  • "Serie Exploiting Reversing (ER)":
    • [Artículo 01][583]
    • [Artículo 02][584]
  • ["Explotando Steam: Formas usuales e inusuales en el framework CEF"][898]
  • ["Explorando formatos de archivos de objetos"][684]
  • ["Extrayendo claves de Comunicación Segura a Bordo (SecOC) de un Toyota RAV4 Prime 2021"][735]
  • ["Ataques de inyección de fallos contra el ESP32-C3 y ESP32-C6"][590]
  • ["Inyección de fallos – Por la madriguera del conejo"][993]
  • "Encontrando bugs en el kernel":
    • [Parte 1][996]
    • [Parte 2][997]
  • ["Plano: Analizando el firmware de Pulse Secure y evadiendo la verificación de integridad"][883]
  • ["Pasando páginas: Un análisis de una nueva vulnerabilidad de Linux en nf_tables y técnicas de explotación endurecidas"][804]
  • ["De la inyección de fallos al RCE"][990]
  • ["De la transición de objetos al RCE en el renderizador de Chrome"][940]
  • ["Fuzzing entre líneas en software de códigos de barras popular"][968]
  • ["Obteniendo ejecución de código en el kernel en un Pixel 8 con MTE habilitado"][808]
  • ["Módulo de ISA nanoMIPS para Ghidra"][873]
  • ["Volviéndose nativo - Aplicaciones nativas maliciosas"][842]
  • ["Ejecución de código con escritura fuera de límites en Google Chrome V8 CVE-2024-0517"][674]
  • ["GhostRace: Explotando y mitigando condiciones de carrera especulativas"][802]
  • ["GPUAF - Dos formas de rootear todos los teléfonos Android basados en Qualcomm"][994]
  • ["GraphStrike: Anatomía del desarrollo de herramientas ofensivas"][712]
  • ["¡Hackeando una tablet de 2014... en 2024!"][932]
  • ["Hackeando un dispositivo de hogar inteligente"][691]
  • ["Hackeando juegos de Android"][949]
  • ["Explotación de heap, internals de glibc y trucos ingeniosos"][938]
  • ["HEAP HEAP HOORAY — Revelando la vulnerabilidad de desbordamiento de heap en GLIBC (CVE-2023–6246)"][818]
  • ["Hola, mi nombre es Teclado"][676]
  • ["Ocultando procesos de Linux con Bind Mounts"][925]
  • ["Cómo también hackeé mi coche"][976]
  • ["Cómo evadir la verificación SSL de Golang"][941]
  • ["Cazando bugs en el kernel de Linux con KASAN: ¿Cómo usarlo y cuál es el beneficio?"][995]
  • "Cazando el bug de HVCI en UEFI"
  • "Cazando n-days no autenticados en routers Asus"
  • "Iconv, establece el charset para RCE":
    • [Parte 1][870]
    • [Parte 2][871]
  • ["Trucos de deserialización en Java"][815]
  • ["Hackeando JTAG con una Raspberry Pi"][851]
  • ["La evolución del ransomware Kuiper"][702]
  • ["Dentro de una nueva ciberarma OT/IoT: IOCONTROL"][1001]
  • ["Dentro del PoC de LogoFAIL: Del desbordamiento de enteros a la ejecución de código arbitrario"][692]
  • ["Introducción al fuzzing de componentes nativos de Android"][984]
  • "Aprendiendo LLVM":
    • [Parte 1][934]
    • [Parte 2][935]
  • ["LeftoverLocals: Escuchando respuestas de LLM a través de memoria local de GPU filtrada"][687]
  • "Aprovechando Binary Ninja il para revertir una ISA personalizada: Descifrando la "olla de oro" 37C3"
  • ["Superficie de ataque del kernel de Linux: más allá de IOCTL. DMA-BUF"][999]
  • "Explotación del kernel de Linux":
    • ["Entorno"][922]
    • ["ret2usr"][923]
  • ["Escucha: Explotación remota del kernel y escucha encubierta por aire en Sonos – Whitepaper de BlackHat USA 2024"][939]
  • "ManageEngine ADAudit - Ingeniería inversa de RPC de Windows para encontrar CVEs":
    • [Parte 1][901]
    • [Parte 2][902]
    • [Parte 3][903]
  • ["Cuidado con la brecha de parches: Explotando una vulnerabilidad de io_uring en Ubuntu"][809]
  • ["LPE en el kernel de la GPU Mali"][786]
  • ["MalpediaFLOSSed"][814]
  • ["Las evasiones de Microsoft BitLocker son prácticas"][718]
  • ["Diseño moderno de implantes: desarrollo de malware independiente de la posición"][690]
  • ["Mi nuevo superpoder"][688]
  • ["No son los drones que buscas"][825]
  • "Operación triangulación":
    • ["Análisis del módulo Keychain"][823]
    • ["Análisis del módulo de audio"][824]
  • ["OtterRoot: Root universal 1-day en Netfilter"][986]
  • ["Lectura y escritura fuera de límites en el qsort() de glibc"][698]
  • ["PageJack: Una poderosa técnica de exploit con UAF a nivel de página"][951]
  • ["Programación orientada a páginas: Subvirtiendo la integridad de flujo de control de kernels de sistemas operativos comerciales con páginas de código no escribibles"][1000]
  • ["Diffing del Patch Tuesday: CVE-2024-20696 - RCE en Windows Libarchive"][835]
  • ["Fijando páginas de espacio de usuario en el kernel de Linux: Explorando get_user_pages, pin_user_pages y el recorrido de tablas de páginas"][983]
  • ["PixieFail: Nueve vulnerabilidades en la pila de red IPv6 de EDK II de Tianocore"][711]
  • "Jugando con libmalloc en 2024"
  • ["Puckungfu 2: Otra inyección de comandos en WAN de NETGEAR"][730]
  • ["Pumping Iron en el heap de Musl – Explotación real de CVE-2022-24834 en un heap mallocng de Alpine"][910]
  • ["Pwn2Own Automotive 2024: Hackeando el ChargePoint Home Flex (y su nube...)"][933]
  • ["Pwning de navegadores como un kernel"][957]
  • "Pwn2Own: Demostración de exploit de WAN a LAN":
    • ["Pwn2Own: Demostración de exploit de WAN a LAN, Parte 1"][950]
    • ["Pwn2Own: Pivotando de WAN a LAN para atacar una cámara IP Synology BC500, Parte 2"][942]
  • "Pwn2Own Toronto 2023":
    • ["Cómo empezó todo"][829]
    • ["Explorando la superficie de ataque"][830]
    • ["Exploración"][831]
    • ["Análisis de corrupción de memoria"][832]
    • ["El exploit"][833]
  • ["Pwning de una etiquetadora Brother, ¡por diversión e interoperabilidad!"][897]
  • "Pwntools 10x":
    • [Parte 1][867]
    • [Parte 2][868]
    • [Parte 3][869]
  • ["Pygmy Goat"][972]
  • ["Recuperando el firmware de una ECU usando desensamblador y ramas"][921]
  • ["regreSSHion: RCE en el servidor de OpenSSH, en sistemas Linux basados en glibc (CVE-2024-6387)"][919]
  • ["Resolviendo cadenas de pila con el desensamblador Capstone y Unicorn en Python"][846]
  • ["Adaptar firmware cifrado es una mala idea"][1024]
  • ["Ingeniería inversa de la señal de un llavero de coche "][801]
  • ["Ingeniería inversa y desmantelamiento de auriculares Kekz"][962]
  • ["Ingeniería inversa de definiciones Protobuf a partir de binarios compilados"][820]
  • ["Ingeniería inversa de la impresora de 59 libras a bordo del Transbordador Espacial"][943]
  • ["Ingeniería inversa de la Boot ROM del AM335x"][947]
  • ["Ingeniería inversa del Stream Deck Plus"][1004]
  • "Ring Around The Regex"
    • [Parte 1][955]
    • [Parte 2][956]
  • ["RISCVuzz: Descubriendo vulnerabilidades arquitectónicas de CPU mediante fuzzing diferencial de hardware"][958]
  • ["RomCom explota zero days de Firefox y Windows en el wild"][981]
  • ["ROPeando routers desde cero: Flujo paso a paso de ROP con control de flujo 0day en Tenda Ac8v4 Mips -> RCE"][892]
  • ["Ruta hacia la seguridad: Navegando los peligros de los routers"][816]
  • ["Rooteando una cámara Hive"][819]
  • ["Emulador SAME70"][879]
  • "Di amigo y entra":
    • [Parte 1][812]
    • [Parte 2][813]
  • ["Publicaciones relacionadas con Samsung NX"][887]
  • ["Scavy: Descubrimiento automatizado de objetivos de corrupción de memoria en el kernel de Linux para escalada de privilegios"][975]
  • ["SECGlitcher (Parte 1) - Glitching de voltaje reproducible en microcontroladores STM32"][862]
  • ["Evasiones de SELinux"][963]
  • ["Internals de SLUB para desarrolladores de exploits"][980]
  • ["SLUBStick: Escrituras arbitrarias en memoria mediante ataques prácticos de cross-cache en el kernel de Linux"][937]
  • ["¿Ensamblamos?"][689]
  • ["Evasión de shellcode usando WebAssembly y Rust"][726]
  • "Aislamiento de SMM":
    • ["Desprivilegiando SMI (ISRD)"][847]
    • ["Reporte de políticas de seguridad (ISSR)"][848]
  • ["SoK: ¿Dónde está el "arriba"?! Un estudio exhaustivo (bottom-up) sobre la seguridad de los sistemas Arm Cortex-M"][1049]
  • ["Fortaleciendo el escudo: MTE en asignadores de heap"][596]
  • ["Dando un paso más: Entendiendo el Page Spray en la explotación del kernel de Linux"][913]
  • ["La arquitectura de las herramientas SAST: Una explicación para desarrolladores"][739]
  • ["El lado oscuro de UEFI: Una inmersión técnica profunda en la explotación entre silicios"][880]
  • ["La guía definitiva de inyección de procesos en Linux"][971]
  • ["La 'Capa de invisibilidad' - Magia de Slash-Proc"][924]
  • ["El driver DSP de Qualcomm - Excavando inesperadamente un exploit"][1007]
  • ["El descompilador rev.ng se vuelve open source + inicio de la beta cerrada de la UI"][694]
  • ["La historia de un LP en el kernel de GSM"][850]
  • ["El Salvaje Oeste del código de prueba de concepto de exploits (PoC)"][926]
  • "La aventura del Registro de Windows":
    • [Parte 1][914]
    • [Parte 2][915]
    • [Parte 3][916]
  • ["TIKTAG: Rompiendo la Extensión de Etiquetado de Memoria de ARM con ejecución especulativa"][894]
  • ["Tony Hawk’s Pro Strcpy"][928]
  • ["Nigromancia de toolchain: Errores del pasado que acechan al ASLR"][732]
  • ["Descifrado de firmware TP-Link C210 V2 bootloaders de cámara en la nube"][988]
  • ["Vulnerabilidad de desbordamiento de búfer en TP-Link TDDP"][695]
  • ["Dos bytes son suficientes: RCE en FortiGate con CVE-2024-21762"][787]
  • ["Entendiendo AddressSanitizer: Mejor seguridad de memoria para tu código"][889]
  • ["Entendiendo la recolección de basura de Unix y su interacción con io_uring"][891]
  • ["Entendiendo el ensamblador x64 de Windows"][693]
  • ["Usando ejecución simbólica para desvirtualizar un binario virtualizado"][936]
  • ["Utilizando la asignación entre CPUs para explotar el kernel de Linux con preempción deshabilitada"][985]
  • ["VBA: divirtiéndose con macros, punteros sobrescritos y memoria R/W/X"][843]
  • ["Vulnerabilidades del driver del lector de tarjetas SD de Realtek"][1002]
  • ["Por qué importa la seguridad del código - Incluso en entornos endurecidos"][953]
  • ["Secure-Launch de Windows en dispositivos Qualcomm"][811]
  • ["Windows Sockets: De E/S registrada a privilegios SYSTEM"][998]
  • ["Arquitectura del cargador de Windows vs Linux"][844]
  • ["Vulnerabilidad RCE en el driver Wi-Fi de Windows – CVE-2024-30078"][954]
  • "Escribiendo un depurador desde cero"
    • ["Adjuntándose a un proceso"][449]
    • ["Estado de registros y stepping"][450]
    • ["Leyendo memoria"][451]
    • ["Exportaciones y símbolos privados"][452]
    • ["Puntos de interrupción"][453]
    • ["Pilas"][454]
    • ["Desensamblado"][455]
  • ["Escribiendo un rastreador de llamadas al sistema usando eBPF"][931]
  • ["Tu NVMe ha sido Syz’ed: Fuzzing del driver NVMe-oF/TCP para Linux con Syzkaller"][854]
  • ["Suplantación de dirección de retorno en x64"][991]
  • ["Suplantación de pila de llamadas en x64"][992]
  • "ARM64 Reversing And Exploitation" (8ksec)

    • [Part 1][107]
    • [Part 2][108]
    • [Part 3][109]
    • [Part 4][110]
    • [Part 5][111]
    • [Part 6][112]
    • [Part 7][113]
    • [Part 8][388]
    • [Part 9][389]
    • [Part 10][390]
  • "Attacking an EDR"

    • [Part 1][395]
    • [Part 2][396]
  • "Attacking IoT Devices from Web Perspective"

  • ["Attacking JS engines: Fundamentals for understanding memory corruption crashes"][720]

  • ["Audio with embedded Linux training"][267]

  • ["Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"][300]

  • ["b3typer - bi0sCTF 2022"][554]

  • ["Back to the Future with Platform Security"][97]

  • ["Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"][100]

  • ["Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"][91]

  • ["Behind the Shield: Unmasking Scudos's Defenses"][8]

  • ["BlackLotus UEFI bootkit: Myth confirmed"][429]

  • "BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"

  • ["BPF Memory Forensics with Volatility 3"][881]

  • ["Breaking Fortinet Firmware Encryption"][233]

  • ["Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"][81]

  • ["Breaking Secure Boot on the Silicon Labs Gecko platform"][262]

  • ["Building a Custom Mach-O Memory Loader for macOS"][523]

  • ["Building an Exploit for FortiGate Vulnerability CVE-2023-27997"][475]

  • ["Bypassing a noexec by elf roping"][528]

  • ["Bypassing PPL in Userland (again)"][308]

  • ["Bypassing SELinux with init_module"][494]

  • "C101101: D-Link DIR-865L":

    • ["Remote Code Execution (pre-auth)"][599]
    • ["Unsigned firmware upload lead to persistent backdoor (pre-auth)"][600]
    • ["Memory corruptions lead to Remote Code Execution (pre-auth)"][601]
  • ["CAN Injection: keyless car theft"][195]

  • "chonked"

    • ["minidlna 1.3.2 http chunk parsing heap overflow (cve-2023-33476) root cause analysis"][193]
    • ["exploiting cve-2023-33476 for remote code execution"][194]
  • ["Code Execution in Chromium’s V8 Heap Sandbox"][896]

  • ["Coffee: A COFF loader made in Rust"][93]

  • ["Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"][397]

  • ["Conquering the memory through io_uring - Analysis of CVE-2023-2598"][528]

  • "Cracking Windows Kernel with HEVD"

    • "Chapter 0"
    • "Chapter 1"
    • "Chapter 2"
    • "Chapter 3"
    • "Chapter 4"
  • ["Cueing up a calculator: an introduction to exploit development on Linux"][534]

  • "Customizing Sliver":

    • [Part 1][603]
    • Part 2
    • Part 3
  • "CVE-2022-27666: My file your memory"

  • ["CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"][567]

  • ["CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"][72]

  • ["CVE-2023-23504: XNU Heap Underwrite in dlil.c"][543]

  • ["CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"][99]

  • ["CVE-2023-36844 And Friends: RCE In Juniper Devices"][281]

  • ["CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"][186]

  • ["cURL audit: How a joke led to significant findings"][459]

  • ["D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."][964]

  • ["Debugger Ghidra Class"][28]

  • ["Debugging D-Link: Emulating firmware and hacking hardware"][290]

  • ["Decompilation Debugging"][508]

  • ["Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"][253]

  • ["Defining the cobalt strike reflective loader"][320]

  • ["Demystifying bitwise operations, a gentle C tutorial"][400]

  • ["Detecting and decrypting Sliver C2 – a threat hunter’s guide"][480]

  • ["Detecting BPFDoor Backdoor Variants Abusing BPF Filters"][183]

  • ["Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"][51]

  • ["Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"][164]

  • ["Diving Into Smart Contract Decompilation"][204]

  • ["Diving into Starlink's User Terminal Firmware"][268]

  • "DJI Mavic 3 Drone Research"

    • ["Firmware Analysis"][376]
    • ["Vulnerability Analysis"][713]
  • ["Drone Security and Fault Injection Attacks"][82]

  • "DualShock4 Reverse Engineering":

    • [Part 1][149]
    • [Part 3][150]
    • [Part 3][151]
  • "eBPF: A new frontier for malware"

  • ["Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"][47]

  • ["Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"][182]

  • ["ENLBufferPwn (CVE-2022-47949)"][422]

  • ["Escaping the Google kCTF Container with a Data-Only Exploit"][178]

  • ["Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"][827]

  • ["Exploitation of Openfire CVE-2023-32315"][283]

  • ["Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"][572]

  • ["Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"][130]

  • ["Exploiting CVE-2021-3490 for Container Escapes"][552]

  • ["Exploiting null-dereferences in the Linux kernel"][148]

  • ["Exploring UNIX pipes for iOS kernel exploit primitives"][514]

  • ["EPF: Evil Packet Filter"][73]

  • ["Escaping from Bhyve"][192]

  • ["ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"][69]

  • ["Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"][394]

  • ["Espressif ESP32: Breaking HW AES with Power Analysis"][393]

  • ["Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"][324]

  • ["Executing Arbitrary Code & Executables in Read-Only FileSystems"][52]

  • ["Exploit Engineering – Attacking the Linux Kernel"][146]

  • ["Exploiting a Remote Heap Overflow with a Custom TCP Stack"][322]

  • ["Exploring Hell's Gate"][594]

  • ["Exploiting a bug in the Linux kernel with Zig"][597]

  • ["Exploiting HTTP Parsers Inconsistencies"][391]

  • ["Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"][198]

  • ["Exploring Android Heap Allocations in Jemalloc 'New'"][7]

  • ["Exploring Linux's New Random Kmalloc Caches"][511]

  • "Exploring the section layout in linker output"

  • "Fantastic Rootkits: And Where To Find Them":

    • [Part 1][275]
    • [Part 2][276]
    • [Part 3][277]
  • ["Few lesser known tricks, quirks and features of C"][354]

  • ["Finding and exploiting process killer drivers with LOL for 3000$"][172]

  • ["Finding bugs in C code with Multi-Level IR and VAST"][92]

  • ["Finding Gadgets for CPU Side-Channels with Static Analysis Tools"][75]

  • ["For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"][70]

  • ["FortiNAC - Just a few more RCEs"][95]

  • ["Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"][32]

  • ["Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"][90]

  • ["From C, with inline assembly, to shellcode"][235]

  • "Fuzzing Farm":

    • ["Fuzzing GEGL with fuzzuf"][43]
    • ["Evaluating Performance of Fuzzer"][44]
    • ["Patch Analysis and PoC Development"][45]
    • ["Hunting and Exploiting 0-day [CVE-2022-24834]"][46]
  • "Fuzzing Golang msgpack for fun and panic"

  • ["Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"][486]

  • "Ghidra" (Craig Young):

    • ["A Guide to Reversing Shared Objects with Ghidra"][121]
    • ["Reversing a Simple CrackMe with Ghidra Decompiler"][122]
    • ["Vulnerability Hunting with Ghidra"][123]
    • ["Patching a Bug from a Ghidra Listing"][124]
    • ["Vulnerability Analysis with Ghidra Scripting"][125]
  • ["Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"][481]

  • ["Google Chrome V8 ArrayShift Race Condition Remote Code Execution"][530]

  • ["Hacking a Tapo TC60 Camera"][350]

  • ["Hacking Amazon's eero 6 (part 1)"][86]

  • ["Hacking Brightway scooters: A case study"][29]

  • ["Hacking ICS Historians: The Pivot Point from IT to OT"][444]

  • ["Hacking the Nintendo DSi Browser"][456]

  • ["Hardware Hacking to Bypass BIOS Passwords"][5]

  • ["Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"][443]

  • ["How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"][240]

  • ["How does Linux start a process"][501]

  • "How NATs Work":

    • [Part 1][152]
    • [Part 2][153]
    • [Part 3][154]
    • [Part 4][155]
  • "How I Hacked my Car":

    • [Part 1][101]
    • [Part 2][102]
    • [Part 3][103]
    • [Part 4][104]
    • [Part 5][105]
    • [Part 6][106]
  • ["How I hacked smart lights: the story behind CVE-2022-47758"][841]

  • ["How to Emulate Android Native Libraries Using Qiling"][482]

  • ["How to Voltage Fault Injection"][685]

  • ["How To Secure A Linux Server"][140]

  • "Hunting Vulnerable Kernel Drivers"

  • ["Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"][171]

  • ["In-depth analysis on Valorant’s Guarded Regions"][141]

  • ["In-Memory-Only ELF Execution (Without tmpfs)"][355]

  • ["Intel BIOS Advisory – Memory Corruption in HID Drivers "][257]

  • ["Intercepting Allocations with the Global Allocator"][79]

  • "Intro to Cutter"

  • ["Introduction to SELinux"][59]

  • "IoT Series":

    • ["Are People Ready to go?"][465]
    • ["How To Build Kernel Image From Scratch"][466]
    • ["Firmware testing in QEMU"][467]
    • ["Debugging with GDB & GHIDRA + Zero-day"][468]
  • ["JTAG 'Hacking' the Original Xbox in 2023"][244]

  • ["Kernel Exploit Factory"][159]

  • ["Learn Makefiles With the tastiest examples"][24]

  • ["Let's build a Chrome extension that steals everything"][463]

  • ["Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"][387]

    • [Part 1][387]
    • [Part 2][904]
    • [Part 3][930]
  • ["Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"][327]

  • "lexmark printer haxx"

  • [linux-re-101][169]

  • ["Linux debugging, profiling and tracing training"][353]

  • "Linux Kernel Exploitation"

    • ["Getting started & BOF"][678]
    • ["Heap techniques"][679]
    • ["Exploiting race-condition + UAF"][680]
  • "Linux Kernel PWN":

    • ["ret2dir"][899]
    • ["DirtyCred"][900]
  • ["Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"][544]

  • ["Linux Kernel Teaching"][131]

  • ["Linux Malware: Defense Evasion Techniques"][165]

  • "Linux Red Team":

    • ["Exploitation Techniques"][222]
    • ["Privilege Escalation Techniques"][223]
    • ["Persistence Techniques"][224]
  • ["Linux Remote Process Injection - (Injecting into a firefox process)"][569]

  • ["Linux rootkits explained – Part 1: Dynamic linker hijacking"][60]

  • ["Linux Shellcode 101: From Hell to Shell"][53]

  • ["Local Privilege Escalation on the DJI RM500 Smart Controller"][160]

  • "Lord Of The Ring0":

    • [Part 1][10]
    • [Part 2][11]
    • [Part 3][12]
    • [Part 4][13]
    • [Part 5][14]
  • ["Low-Level Software Security for Compiler Developers"][15]

  • ["LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"][202]

  • ["Making TOCTOU Great again – X(R)IP"][474]

  • "Malware Reverse Engineering for Beginners":

    • [Part 1][128]
    • [Part 2][129]
  • ["Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"][285]

  • "mast1c0re"

    • ["Introduction – Exploiting the PS4 and PS5 through a game save"][38]
    • ["Part 1 – Modifying PS2 game save files"][39]
    • ["Part 2 – Arbitrary PS2 code execution"][40]
    • ["Part 3 – Escaping the emulator"][41]
  • ["Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"][330]

  • ["Meterpreter vs Modern EDR(s)"][170]

  • "MTE As Implemented":

    • [Part 1][366]
    • [Part 2][367]
  • ["mTLS: When certificate authentication is done wrong"][270]

  • ["MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"][177]

  • ["Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"][404]

  • "NetGear Series: Emulating Netgear R6700V3 circled binary ":

    • [Part 1][441]
    • [Part 2][442]
  • ["New HiatusRAT Router Malware Covertly Spies On Victims"][402]

  • ["No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"][1091]

  • ["NVMe: New Vulnerabilities Made Easy"][264]

  • ["nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"][365]

  • ["Obscure Windows File Types"][74]

  • ["Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"][254]

  • ["One shot, Triple kill"][700]

  • "OPC UA Deep Dive Series":

    • [Part 1][211]
    • [Part 2][212]
    • [Part 3][213]
    • [Part 4][214]
    • [Part 5][215]
  • ["OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"][42]

  • ["OrBit: advanced analysis of a Linux dedicated malware"][427]

  • ["OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"][428]

  • ["P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"][206]

  • ["P4wnP1-LTE"][209]

  • ["Patches, Collisions, and Root Shells: A Pwn2Own Adventure"][278]

  • ["Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"][297]

  • ["Persistence Techniques That Persist"][299]

  • ["Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"][166]

  • ["prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"][184]

  • ["Producing a POC for CVE-2022-42475 (Fortinet RCE)"][323]

  • ["Protecting Android clipboard content from unintended exposure"][448]

  • "Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI"

    • [Part 1][477]
    • [Part 2][478]
    • [Part 3][479]
  • "Prototype Pollution in Python"

  • ["PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"][758]

  • ["PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"][98]

  • ["PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"][318]

  • "Pwnassistant - Controlling /home's via a Home Assistant RCE"

  • ["Pwning Pixel 6 with a leftover patch"][310]

  • ["Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"][309]

  • ["Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"][185]

  • ["Readline crime: exploiting a SUID logic bug"][439]

  • ["Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"][30]

  • ["Reptar"][527]

  • ["Restoring Dyld Memory Loading"][522]

  • ["Retreading The AMLogic A113X TrustZone Exploit Process"][77]

  • ["Reversing UK mobile rail tickets"][551]

  • "Reversing Windows Container":

    • [Part 1][821]
    • [Part 2][822]
  • ["RISC-V Bytes: Exploring a Custom ESP32 Bootloader"][493]

  • ["REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"][364]

  • ["Revisiting CVE-2017-11176"][48]

  • "Rooting the FiiO M6":

    • ["Using the "World's Worst Fuzzer" To Find A Kernel Bug"][499]
    • ["Writing an LPE Exploit For Our Overflow Bug"][500]
  • ["Rooting Xiaomi WiFi Routers"][817]

  • ["Rust Binary Analysis, Feature by Feature"][231]

  • ["Rust to Assembly: Understanding the Inner Workings of Rust"][134]

  • "Rustproofing Linux":

    • [Part 1][575]
    • [Part 2][576]
    • [Part 3][577]
    • [Part 4][578]
  • ["scudo Hardened Allocator — Unofficial Internals Documentation"][706]

  • "Securing our home labs: Frigate code review"

  • "Securing our home labs: Home Assistant code review"

  • ["SHA-1 gets SHAttered"][325]

  • ["Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"][55]

  • ["Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"][76]

  • ["Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"][261]

  • ["Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"][531]

  • ["Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"][504]

  • ["Smashing the state machine: the true potential of web race conditions"][271]

  • ["SRE deep dive into Linux Page Cache"][94]

  • ["Sshimpanzee"][16]

  • ["Stepping Insyde System Management Mode"][256]

  • ["Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"][562]

  • ["THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"][31]

  • ["The ARM32 Scheduling and Kernelspace/Userspace Boundary"][512]

  • ["The art of Fuzzing: Introduction"][57]

  • ["The art of fuzzing: Windows Binaries"][89]

  • ["The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"][54]

  • ["The Art Of Linux Persistence"][872]

  • ["The Blitz Tutorial Lab on Fuzzing with AFL++"][303]

  • ["The code that wasn’t there: Reading memory on an Android device by accident"][462]

  • ["The Dragon Who Sold His camaro: Analyzing Custom Router Implant"][228]

  • ["The Importance of Reverse Engineering in Network Analysis"][426]

  • ["The Linux Kernel Module Programming Guide"][3]

  • ["The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"][284]

  • ["The Role of the Control Flow Graph in Static Analysis"][509]

  • ["The Silent Spy Among Us: Smart Intercom Attacks"][331]

  • ["The Stack Series: The X64 Stack"][356]

  • ["The Untold Story of the BlackLotus UEFI Bootkit"][205]

  • ["Tickling ksmbd: fuzzing SMB in the Linux kernel"][386]

  • ["Tool Release: Cartographer"][371]

  • ["Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"][445]

  • ["Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"][80]

  • ["Your not so "Home Office" - SOHO Hacking at Pwn2Own"][5]

  • ["Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"][524]

  • ["Unauthenticated RCE on a RIGOL oscilloscope"][210]

  • ["UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"][37]

  • ["Uncovering a crazy privilege escalation from Chrome extensions"][502]

  • ["Uncovering HinataBot: A Deep Dive into a Go-Based Threat"][311]

  • ["Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"][180]

  • ["Understanding a Payload’s Life Featuring Meterpreter & Other Guests "][315]

  • ["Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"][591]

  • ["Understanding the Heap - a beautiful mess"][348]

  • ["Unleashing ksmbd: crafting remote exploits of the Linux kernel"][828]

  • ["Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)"][533]

  • ["Unlimited Results: Breaking Firmware Encryption of ESP32-V3"][598]

  • "Unveiling secrets of the ESP32":

    • "creating an open-source MAC Layer"
    • "reverse engineering RX"
  • "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More"

  • ["What is Loader Lock?"][845]

  • ["Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"][58]

  • ["Windows Installer EOP (CVE-2023-21800)"][314]

  • ["Writing your own RDI /sRDI loader using C and ASM"][307]

  • ["Zenbleed"][207]

  • ["Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"][248]## 2022

  • "A journey into IoT":

    • ["Chip identification, BUSSide, and I2C"][294]
    • ["Discover components and ports"][295]
    • ["Firmware dump and analysis"][296]
    • ["Radio communications"][681]
    • ["Internal communications"][682]
  • ["A Kernel Hacker Meets Fuchsia OS"][710]

  • "A Technical Analysis of Pegasus for Android":

    • [part 1][564]
    • [Part 2][565]
    • [Part 3][566]
  • ["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]

  • ["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]

  • "ARM 64 Assembly Series":

    • ["Basic definitions and registers"][408]
    • ["Offset and Addressing modes"][409]
    • ["Load and Store"][410]
    • ["Branch"][411]
    • ["Data Processing (Part 1)"][412]
    • ["Data Processing (Part 2)"][413]
    • ["selections and loops"][414]
    • ["Subroutines"][415]
  • ["Attacking the Android kernel using the Qualcomm TrustZone"][885]

  • ["Attacking Titan M with Only One Byte"][259]

  • ["Avoiding Detection with Shellcode Mutator"][432]

  • "BasicFUN Series":

    • "Hardware Analysis / SPI Flash Extraction"
    • "Reverse Engineering Firmware / Reflashing SPI Flash"
    • "Dumping Parallel Flash via I2C I/O Expanders"
    • "I2C Sniffing, EEPROM Extraction and Parallel Flash Extraction"
  • ["Basics for Binary Exploitation"][749]

  • ["Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"][238]

  • ["BrokenPrint: A Netgear stack overflow"][782]

  • "Bypassing software update package encryption ":

    • ["Extracting the Lexmark MC3224i printer firmware"][190]
    • ["Exploiting the Lexmark MC3224i printer"][191]
  • ["Bypassing vtable Check in glibc File Structures"][208]

  • ["Blind Exploits to Rule Watchguard Firewalls"][173]

  • ["BPFDoor - An Evasive Linux Backdoor Technical Analysis"][292]

  • ["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]

  • "Chrome Browser Exploitation":

    • [Part 1][1053]
    • [Part 2][1054]
    • [Part 3][1055]
  • ["Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"][556]

  • ["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]

  • ["Corrupting memory without memory corruption"][762]

  • ["Creating a Rootkit to Learn C"][719]

  • ["CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"][377]

  • ["[CVE-2022-1786] A Journey To The Dawn"][401]

  • ["CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"][168]

  • ["CVE-2022-27666: Exploit esp6 modules in Linux kernel"][532]

  • ["CVE-2022-29582 An io_uring vulnerability"][495]

  • ["Deconstructing and Exploiting CVE-2020-6418"][778]

  • ["DirtyCred Remastered: how to turn an UAF into Privilege Escalation"][167]

  • "Disclosing information with a side-channel in Django"

  • ["Dumping the Amlogic A113X Bootrom"][78]

  • ["Dynamic analysis of firmware components in IoT devices"][250]

  • ["Embedded Systems Security and TrustZone"][145]

  • ["Emulate Until You Make it"][748]

  • ["EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"][473]

  • ["Expanding the Dragon: Adding an ISA to Ghidra"][542]

  • ["Exploiting: Buffer overflow in Xiongmai DVRs"][742]

  • ["Exploiting CSN.1 Bugs in MediaTek Basebands"][272]

  • ["exploiting CVE-2019-2215"][61]

  • "Exploiting CVE-2022-42703 - Bringing back the stack attack"

  • ["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]

  • "Exploring the Hidden Attack Surface of OEM IoT Devices"

  • ["Firmware key extraction by gaining EL3"][316]

  • ["Fortigate - Authentication Bypass Lead to Full Device Takeover"][291]

  • "Fourchain":

    • ["Prologue"][765]
    • ["Hole"][766]
    • ["Sandbox"][767]
  • ["Fuzzing ping(8) … and finding a 24 year old bug"][751]

  • "Hacking Bluetooth to Brew Coffee from Github Actions":

    • [Part 1][752]
    • [Part 2][753]
    • [Part 3][754]
  • "Hackign More Secure Portable Storage Devices"

  • ["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]

  • ["How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"][266]

  • ["Huawei Security Hypervisor Vulnerability"][435]

  • "Hunting for Persistence in Linux"

    • [Part 1][64]
    • [Part 2][65]
    • [Part 3][66]
    • [Part 4][67]
    • [Part 5][68]
  • "Hacking Some More Secure USB Flash Drives":

    • [Part 1][132]
    • [Part 2][133]
  • ["Learning eBPF exploitation"][768]

  • "Intro to Embedded RE":

    • ["Tools and Series"][351]
    • ["UART Discovery and Firmware Extraction via UBoot"][352]
  • "Introduction to x64 Linux Binary Exploitation":

    • Part 1
    • Part 2
    • Part 3
    • Part 4
    • Part 5
  • ["io_uring - new code, new bugs, and a new exploit technique"][978]

  • ["Linux Hardening Guide"][349]

  • ["Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"][269]

  • ["Linux Kernel Exploit (CVE-2022–32250) with mqueue"][242]

  • "Linux SLUB Allocator Internals and Debugging":

    • [Part 1][359]
    • [Part 2][360]
    • [Part 3][361]
    • [Part 4][362]
  • ["Linternals: Introducing Memory Allocators & The Page Allocator"][516]

  • ["Linternals: The Slab Allocator"][517]

  • ["Linux kernel heap feng shui in 2022"][535]

  • ["Looking for Remote Code Execution bugs in the Linux kernel"][503]

  • ["Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"][319]

  • ["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]

  • ["Missing Manuals - io_uring worker pool"][265]

  • ["Modifying Embedded Filesystems in ARM Linux zImages"][775]

  • "Netgear Orbi":

    • ["orbi hunting 0x0: introduction, uart access, recon"][33]
    • ["orbi hunting 0x1: crashes in soap-api"][34]
    • ["nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"][35]
  • ["nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"][63]

  • ["NFC Relay Attack on Tesla Model Y"][574]

  • ["Nightmare: One Byte to ROP // Deep Dive Edition"][582]

  • ["Overview of GLIBC heap exploitation techniques"][239]

  • "Parsing TFTP in Rust"

  • ["Patching, Instrumenting & Debugging Linux Kernel Modules"][483]

  • "PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"

  • ["pipe_buffer arbitrary read write"][282]

  • "Pixel 6 Bootloader"

    • ["Booting up"][286]
    • ["Emulation, ROP"][287]
    • ["Exploitation"][288]
  • ["Port knocking from the scratch"][227]

  • ["Pulling MikroTik into the Limelight"][120]

  • ["Racing against the clock -- hitting a tiny kernel race window"][492]

  • ["Replicating CVEs with KLEE"][763]

  • ["Reversing C++, Qt based applications using Ghidra"][586]

  • ["Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"][406]

  • ["Replicant: Reproducing a Fault Injection "][675]

  • ["Researching Xiaomi’s Tee to Get to Chinese Money"][274]

  • "Reversing embedded device bootloader (U-Boot)":

    • [Part 1][162]
    • [Part 2][163]
  • ["Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"][368]

  • "Reverse engineering an EV charger"

  • "Reverse Engineering Dark Souls 3":

    • "Connection"
    • "Packets"
    • "Key Exchange"
    • "Reliable UDP"
  • ["Reverse engineering integrity checks in Black Ops 3"][220]

  • ["Reverse engineering thermal printers"][245]

  • ["Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"][491]

  • ["SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"][484]

  • ["Shedding Light on Huawei's Security Hypervisor"][434]

  • ["Shikitega - New stealthy malware targeting Linux"][438]

  • ["side channels: power analysis"][380]

  • ["side channels: using the chipwhisperer"][381]

  • ["SIM Hijacking"][579]

  • ["Spoofing Call Stacks To Confuse EDRs"][431]

  • ["SROP Exploitation with radare2"][770]

  • ["Stealing the Bitlocker key from a TPM"][505]

  • ["Stranger Strings: An exploitable flaw in SQLite"][588]

  • "Survey of security mitigations and architectures, December 2022"

  • ["Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"][461]

  • ["Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"][226]

  • ["The Dirty Pipe Vulnerability"][321]

  • ["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]

  • ["The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"][36]

  • ["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]

  • "The toddler’s introduction to Heap exploitation":

    • ["Part 1"][339]
    • ["Part 2"][340]
    • ["Overflows"][341]
    • ["Use After Free & Double free"][342]
    • ["FastBin Dup to Stack"][343]
    • ["FastBin Dup Consolidate"][344]
    • ["Unsafe Unlink"][345]
    • ["House of Spirit"][346]
    • ["House of Lore"][347]
  • ["TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"][553]

  • ["Tracing and Manipulating with DynamoRIO"][750]

  • ["Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"][312]

  • ["Turning Google smart speakers into wiretaps for $100k"][18]

  • "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"

  • ["Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"][126]

  • "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":

    • [Part 1][496]
    • [Part 2][497]
  • ["Vulnerability Details for CVE-2022-41218"][563]

  • ["Vulnerabilities in Tenda's W15Ev2 AC1200 Router"][127]

  • "When an N-Day turns into a 0day"

  • ["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]

  • ["Write a Linux firewall from scratch based on Netfilter"][313]

  • ["Yet another bug into Netfilter"][457]

  • "Xiongmai IoT Exploitation"

  • "Zyxel authentication bypass patch analysis (CVE-2022-0342)"

  • "Learning Linux Kernel Exploitation":
    • [Part 1][83]
    • [Part 2][84]
    • [Part 3][85]
  • "LinkSys EA6100 AC1200":
    • [Part 1][740]
    • [Part 1][741]
  • "Linux Internals: How /proc/self/mem writes to unwritable memory"
  • "Linux Kernel Exploitation":
    • ["Debugging the Kernel with QEMU"][25]
    • ["Smashing Stack Overflows in the Kernel"][26]
    • ["Controlling RIP and Escalating privileges via Stack Overflow"][27]
  • "Live Debugging Techniques for the Linux Kernel"
    • [Part 1][470]
    • [Part 2][471]
    • [Part 3][472]
  • "Malware development (0xPat)"
    • [Part 1][792]
    • [Part 2][793]
    • [Part 3][794]
    • [Part 4][795]
    • [Part 5][796]
    • [Part 6][797]
    • [Part 7][798]
    • [Part 8][799]
    • [Part 9][800]
  • ["mooosl"][602]
  • ["My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"][560]
  • ["New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"][440]
  • ["New Old Bugs in the Linux Kernel"][305]
  • ["Practical Introduction to CodeQL"][1233]
  • ["Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug"]
  • ["Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"][555]
  • ["Recovering a Full PEM Private key when Half of it is Redacted"][96]
  • "Reverse Engineering an Unknown Microcontroller"
  • "Reverse Engineering Bare-Metal Firmware":
    • [Part 1][142]
    • [Part 2][143]
    • [Part 3][144]
  • ["Reverse Engineering Yaesu FT-70D Firmware Encryption"][147]
  • "Syzkaller diving":
    • [Part 1][423]
    • [Part 2][424]
    • [Part 3][425]
  • ["The Art of Exploiting UAF by Ret2bpf in Android Kernel"][595]
  • ["The Oddest Place You Will Ever Find PAC"][306]
  • ["Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"][888]
  • "VMProtect 2"
    • [Part 1][960]
    • [Part 2][961]
  • ["Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"][251]
  • ["ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"][370]
  • ["Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"][780]
  • ["SSHD Injection and Password Harvesting"][230]
  • ["There’s A Hole In Your SoC: Glitching The MediaTek BootROM"][737]
  • ["Weekend Destroyer - RCE in Western Digital PR4100 NAS"][447]
  • ["What're you telling me, Ghidra?"][358]
  • ["parking-game-fuzzer"][1159]
  • ["Practical Cryprography for Developers"][785]
  • [Red-Team-Infrastructure-Wiki][498]
  • ["Reverse Engineering For Everyone!"][399]
  • "Reverse Engineering WiFi on RISC-V BL602"
  • "Rust Atomics and Locks"
  • ["RustRedOps"][686]
  • ["Satellite Hacking Demystified(RTC0007)"][221]
  • [TEE Reversing][263]
  • ["THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"][258]
  • [tmpout.sh][515]: colección de writeups sobre temas de bajo nivel
  • ["Trail of Bits Testing Handbook"][724]
  • [TripleCross][696]
  • [USB-WiFi][329]
  • ["VSS: Beginners Guide to Building a Hardware Hacking Lab"][249]
  • ["WinDBG quick start tutorial"][485]
  • https://idov31.github.io/2022/10/30/lord-of-the-ring0-p3.html
    https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html
    https://idov31.github.io/2023/07/19/lord-of-the-ring0-p5.html
    https://llsoftsec.github.io/llsoftsecbook/
    https://blog.lexfo.fr/sshimpanzee.html
    https://syscalls.mebeim.net/?table=x86/64/x64/v6.5
    https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html
    https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part1.html
    https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part2.html
    https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part3.html
    https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part4.html
    http://courses.cms.caltech.edu/cs124/lectures-wi2016/CS124Lec15.pdf
    https://makefiletutorial.com
    https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html
    http://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html
    https://blog.k3170makan.com/2021/01/linux-kernel-exploitation-0x2.html
    https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger
    https://robocoffee.de/?p=436
    https://www.trustedsec.com/blog/red-vs-blue-kerberos-ticket-times-checksums-and-you
    https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
    https://medium.com/@INTfinitySG/fortinet-series-3-cve-2022-42475-sslvpn-exploit-strategy-2578597f892f
    http://blog.coffinsec.com/research/2022/06/12/orbi-hunting-0-intro-uart.html
    http://blog.coffinsec.com/research/2022/06/19/orbi-hunting-1-soap-api-crashes.html
    http://blog.coffinsec.com/research/2022/07/02/orbi-nday-exploit-cve-2020-27861.html
    https://starlabs.sg/blog/2023/06-the-old-the-new-and-the-bypass-one-clickopen-redirect-to-own-samsung-s22-at-pwn2own-2022/
    https://download.vusec.net/papers/uncontained_sec23.pdf
    https://mccaulay.co.uk/mast1c0re-introduction-exploiting-the-ps4-and-ps5-through-a-gamesave/
    https://mccaulay.co.uk/mast1c0re-part-1-modifying-ps2-game-save-files/
    https://mccaulay.co.uk/mast1c0re-part-2-arbitrary-ps2-code-execution/
    https://mccaulay.co.uk/mast1c0re-part-3-escaping-the-emulator/
    https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/
    https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-1-fuzzing-gegl-with-fuzzuf.html
    https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-2-evaluating-performance.html
    https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-3-patch-analysis-and-poc.html
    https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-4-hunting-and-exploiting-0.html
    https://boschko.ca/qemu-emulating-firmware/
    https://labs.bluefrostsecurity.de/revisiting-cve-2017-11176
    https://www.cyberark.com/resources/threat-research-blog/a-deep-dive-into-penetration-testing-of-macos-applications-part-1
    https://research.nccgroup.com/wp-content/uploads/episerver-images/assets/ad04beb697a64e3ea20579e5bf604b4e/ad04beb697a64e3ea20579e5bf604b4e.pdf
    https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html
    https://labs.withsecure.com/publications/executing-arbitrary-code-executables-in-read-only-filesystems
    https://axcheron.github.io/linux-shellcode-101-from-hell-to-shell/
    https://aviii.hashnode.dev/the-art-of-fuzzing-a-step-by-step-guide-to-coverage-guided-fuzzing-with-libfuzzer
    https://boschko.ca/shambles/
    https://en.hackndo.com/ntlm-relay/
    https://bushido-sec.com/index.php/2023/06/19/the-art-of-fuzzing/
    https://offsec.almond.consulting/windows-msiexec-eop-cve-2020-0911.html
    https://github.blog/2023-07-05-introduction-to-selinux/
    https://www.wiz.io/blog/linux-rootkits-explained-part-1-dynamic-linker-hijacking
    https://cutesmilee.github.io/kernel/linux/android/2022/02/17/cve-2019-2215_writeup.html
    https://whiterose-infosec.super.site/mjsxj09cm-recovering-firmware-and-backdooring
    http://blog.coffinsec.com/nday/2022/08/04/CVE-2022-1215-libinput-fmt-canary-leak.html
    https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/
    https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/
    https://pberba.github.io/security/2022/01/30/linux-threat-hunting-for-persistence-systemd-timers-cron/
    https://pberba.github.io/security/2022/02/06/linux-threat-hunting-for-persistence-initialization-scripts-and-shell-configuration/
    https://pberba.github.io/security/2022/02/07/linux-threat-hunting-for-persistence-systemd-generators/
    https://www.espressif.com/sites/default/files/documentation/ESP32-C3%20Wireless%20Adventure.pdf
    https://blog.quarkslab.com/for-science-using-an-unimpressive-bug-in-edk-ii-to-do-some-fun-exploitation.html
    https://airbus-seclab.github.io/AFLplusplus-blogpost/
    https://labs.bluefrostsecurity.de/blog/cve-2023-2008.html
    https://cs.brown.edu/~vpk/papers/epf.atc23.pdf
    https://remyhax.xyz/posts/obscure-win-files/
    https://github.com/google/security-research/tree/master/pocs/cpus/spectre-gadgets
    https://offsec.almond.consulting/ghostscript-cve-2023-28879.html
    https://boredpentester.com/retreading-the-amlogic-a113x-trustzone-exploit-process/
    https://haxx.in/posts/dumping-the-amlogic-a113x-bootrom/
    https://bd103.github.io/blog/2023-06-27-global-allocators
    https://labs.watchtowr.com/xortigate-or-cve-2023-27997/
    https://starlabs.sg/blog/2023/06-breaking-the-code-exploiting-and-examining-cve-2023-1829-in-cls_tcindex-classifier-vulnerability/
    https://act-on.ioactive.com/acton/attachment/34793/f-b1aa96d0-bd78-4518-bae3-2889aae340de/1/-/-/-/-/DroneSec-GGonzalez.pdf
    https://lkmidas.github.io/posts/20210123-linux-kernel-pwn-part-1/
    https://lkmidas.github.io/posts/20210128-linux-kernel-pwn-part-2/
    https://lkmidas.github.io/posts/20210205-linux-kernel-pwn-part-3/
    https://markuta.com/eero-6-hacking-part-1/
    https://riverloopsecurity.com/blog/2020/03/hw-101-emmc/
    https://dangerouspayload.com/2018/10/24/emmc-data-recovery-from-damaged-smartphone/
    https://bushido-sec.com/index.php/2023/06/25/the-art-of-fuzzing-windows-binaries/
    https://papers.mathyvanhoef.com/usenix2023-wifi.pdf
    https://research.aurainfosec.io/pentest/bee-yond-capacity/
    https://blog.trailofbits.com/2023/06/15/finding-bugs-with-mlir-and-vast/
    https://labs.hakaioffsec.com/coffee-a-coff-loader-made-in-rust/
    https://biriukov.dev/docs/page-cache/0-linux-page-cache-for-sre/
    https://frycos.github.io/vulns4free/2023/06/18/fortinac.html
    https://blog.cryptohack.org/twitter-secrets
    https://labs.ioactive.com/2023/06/back-to-future-with-platform-security.html
    https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads
    https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/
    https://www.zerodayinitiative.com/blog/2023/4/5/bash-privileged-mode-vulnerabilities-in-parallels-desktop-and-cdpath-handling-in-macos
    https://programmingwithstyle.com/posts/howihackedmycar/
    https://programmingwithstyle.com/posts/howihackedmycarpart2/
    https://programmingwithstyle.com/posts/howihackedmycarpart3/
    https://programmingwithstyle.com/posts/howihackedmycarpart4/
    https://programmingwithstyle.com/posts/howihackedmycarpart5/
    https://programmingwithstyle.com/posts/myhackedcarisdoomed/
    https://8ksec.io/arm64-reversing-and-exploitation-part-1-arm-instruction-set-simple-heap-overflow/
    https://8ksec.io/arm64-reversing-and-exploitation-part-2-use-after-free/
    https://8ksec.io/arm64-reversing-and-exploitation-part-3-a-simple-rop-chain/
    https://8ksec.io/arm64-reversing-and-exploitation-part-4-using-mprotect-to-bypass-nx-protection-8ksec-blogs/
    https://8ksec.io/arm64-reversing-and-exploitation-part-5-writing-shellcode-8ksec-blogs/
    https://8ksec.io/arm64-reversing-and-exploitation-part-6-exploiting-an-uninitialized-stack-variable-vulnerability/
    https://8ksec.io/arm64-reversing-and-exploitation-part-7-bypassing-aslr-and-nx/
    http://jcjc-dev.com/2016/04/08/reversing-huawei-router-1-find-uart/
    https://jcjc-dev.com/2016/04/29/reversing-huawei-router-2-scouting-firmware/
    https://jcjc-dev.com/2016/05/23/reversing-huawei-3-sniffing/
    https://jcjc-dev.com/2016/06/08/reversing-huawei-4-dumping-flash/
    https://jcjc-dev.com/2016/12/14/reversing-huawei-5-reversing-firmware/
    https://qriousec.github.io/post/vbox-pwn2own-2023/
    https://margin.re/2022/06/pulling-mikrotik-into-the-limelight/
    https://medium.com/@cy1337/a-guide-to-reversing-shared-objects-with-ghidra-cec83d5031e6
    https://medium.com/@cy1337/reversing-a-simple-crackme-with-ghidra-decompiler-5dd1b1c3c0ba
    https://medium.com/@cy1337/vulnerability-hunting-with-ghidra-fb3fc53470ba
    https://medium.com/@cy1337/patching-a-bug-from-a-ghidra-listing-8496e529224a
    https://medium.com/@cy1337/vulnerability-analysis-with-ghidra-scripting-ccf416cfa56d
    https://boschko.ca/glinet-router/
    https://boschko.ca/tenda_ac1200_router/
    https://intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
    https://intezer.com/blog/incident-response/malware-reverse-engineering-for-beginners-part-2/
    https://www.zerodayinitiative.com/blog/2023/8/1/exploiting-a-flaw-in-bitmap-handling-in-windows-user-mode-printer-drivers
    https://linux-kernel-labs.github.io/refs/heads/master/index.html
    https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/
    https://blog.syss.com/posts/hacking-usb-flash-drives-part-2/
    https://eventhelix.com/rust/
    https://intezer.com/blog/research/executable-linkable-format-101-part1-sections-segments/
    https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-2-symbols/
    https://intezer.com/blog/malware-analysis/executable-and-linkable-format-101-part-3-relocations/
    https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-4-dynamic-linking/
    https://secret.club/2023/06/05/spoof-pe-sections.html
    https://github.com/imthenachoman/How-To-Secure-A-Linux-Server
    https://reversing.info/posts/guardedregions/
    https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef
    https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef
    https://medium.com/geekculture/reverse-engineering-bare-metal-firmware-part-3-analyzing-arm-assembly-and-exploiting-3b2dbe219f19
    https://embeddedsecurity.io
    https://research.nccgroup.com/2023/05/23/offensivecon-2023-exploit-engineering-attacking-the-linux-kernel/
    https://landaire.net/reversing-yaesu-firmware-encryption/
    https://googleprojectzero.blogspot.com/2023/01/exploiting-null-dereferences-in-linux.html
    https://blog.the.al/2023/01/01/ds4-reverse-engineering.html
    https://blog.the.al/2023/01/02/ds4-reverse-engineering-part-2.html
    https://blog.the.al/2023/01/03/ds4-reverse-engineering-part-3.html
    https://educatedguesswork.org/posts/nat-part-1/
    https://educatedguesswork.org/posts/nat-part-2/
    https://educatedguesswork.org/posts/nat-part-3/
    https://educatedguesswork.org/posts/nat-part-4/
    https://github.com/ihebski/A-Red-Teamer-diaries
    https://blog.quarkslab.com/digging-into-linux-namespaces-part-1.html
    https://blog.quarkslab.com/digging-into-linux-namespaces-part-2.html
    https://github.com/bsauce/kernel-exploit-factory
    https://icanhack.nl/blog/dji-rm500-privilege-escalation/
    https://blog.zapb.de/stm32f1-exceptional-failure/
    https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/
    https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.2/
    https://securityintelligence.com/x-force/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/
    https://mutur4.github.io/posts/linux-malware-development/edr/
    https://jcjc-dev.com/2023/03/19/reversing-domyos-el500-elliptical/
    https://exploiter.dev/blog/2022/CVE-2022-2602.html
    https://blog.hacktivesecurity.com/index.php/2022/12/21/cve-2022-2602-dirtycred-file-exploitation-applied-on-an-io_uring-uaf/
    https://github.com/michalmalik/linux-re-101
    https://redops.at/en/blog/meterpreter-vs-modern-edrs-in-2023
    https://arxiv.org/pdf/2301.13346.pdf
    https://alice.climent-pommeret.red/posts/process-killer-driver/
    https://web.archive.org/web/20230628130110/https://www.ambionics.io/blog/hacking-watchguard-firewalls
    https://raelize.com/upload/research/2016/2016_BlackHat-EU_Bypassing-Secure-Boot-Using-Fault-Injection_NT-AS.pdf
    https://raelize.com/upload/research/2019/2019_BlueHat-IL_Hardening-Secure-Boot-on-Embedded-Devices-for-Hostile-Environments_NT-AS-CM.pdf
    https://raelize.com/upload//research/2019/2019_Designing-Secure-Boot-Securely_NT-AS.pdf
    https://securityintelligence.com/x-force/msmq-queuejumper-rce-vulnerability-technical-analysis/
    https://h0mbre.github.io/kCTF_Data_Only_Exploit/
    https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
    https://starlabs.sg/blog/2023/08-ikea-sonos-symfonisk-speaker-lamp-teardown/
    https://maxwelldulin.com/BlogPost/House-of-Muney-Heap-Exploitation
    https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
    https://www.trendmicro.com/en_ph/research/23/g/detecting-bpfdoor-backdoor-variants-abusing-bpf-filters.html
    https://starlabs.sg/blog/2023/07-prctl-anon_vma_name-an-amusing-heap-spray/
    https://0xkol.github.io/assets/files/Racing_Against_the_Lock__Exploiting_Spinlock_UAF_in_the_Android_Kernel.pdf
    https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt
    https://phi1010.github.io/2020-09-14-bget-exploitation/
    https://phi1010.github.io/2020-11-02-bget-exploitation-2/
    https://eshard.com/posts/sca-attacks-on-armv8
    https://research.nccgroup.com/2022/02/17/bypassing-software-update-package-encryption-extracting-the-lexmark-mc3224i-printer-firmware-part-1/
    https://research.nccgroup.com/2022/02/18/analyzing-a-pjl-directory-traversal-vulnerability-exploiting-the-lexmark-mc3224i-printer-part-2/
    https://www.synacktiv.com/publications/escaping-from-bhyve.html
    http://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html
    http://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html
    https://kentindell.github.io/2023/04/03/can-injection/
    https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/
    https://blog.assetnote.io/2023/07/24/citrix-rce-part-2-cve-2023-3519/
    https://vulncheck.com/blog/mikrotik-foisted-revisited
    http://tukan.farm/2016/07/27/munmap-madness/
    https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
    https://starlabs.sg/blog/2023/07-a-new-method-for-container-escape-using-file-based-dirtycred/
    https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt
    https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/
    https://jbecker.dev/research/diving-into-decompilation
    https://binarly.io/posts/The_Untold_Story_of_the_BlackLotus_UEFI_Bootkit/index.html
    https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/
    http://lock.cmpxchg8b.com/zenbleed.html
    https://blog.kylebot.net/2022/10/22/angry-FSROP/
    https://sensepost.com/blog/2023/p4wnp1-lte/
    https://tortel.li/post/insecure-scope/
    https://claroty.com/team82/research/opc-ua-deep-dive-history-of-the-opc-ua-protocol
    https://claroty.com/team82/research/opc-deep-dive-part-2-what-is-opc-ua
    https://claroty.com/team82/research/opc-ua-deep-dive-part-3-exploring-the-opc-ua-protocol
    https://claroty.com/team82/research/opc-ua-deep-dive-series-part-4-targeting-core-opc-ua-components
    https://claroty.com/team82/research/opc-ua-deep-dive-series-part-5-inside-team82-s-research-methodology
    https://docs.saferwall.com/blog/virtualization-internals-part-1-intro-to-virtualization/
    https://docs.saferwall.com/blog/virtualization-internals-part-2-vmware-and-virtualization-using-binary-translation/
    https://docs.saferwall.com/blog/virtualization-internals-part-3-xen-and-paravirtualization/
    https://docs.saferwall.com/blog/virtualization-internals-part-4-qemu/
    https://web.archive.org/web/20230522230748/https://momo5502.com/posts/2022-11-17-reverse-engineering-integrity-checks-in-black-ops-3/
    https://redteamrecipe.com/Satellite-Hacking-Demystified/
    https://www.linode.com/docs/guides/linux-red-team-exploitation-techniques/
    https://www.linode.com/docs/guides/linux-red-team-privilege-escalation-techniques/
    https://www.linode.com/docs/guides/linux-red-team-persistence-techniques/
    https://makelinux.github.io/kernel/map/
    https://xcellerator.github.io/posts/tetsuji/
    https://antonio-cooler.gitbook.io/coolervoid-tavern/port-knocking-from-the-scratch
    https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/
    https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
    https://jm33.me/sshd-injection-and-password-harvesting.html
    https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/
    https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger
    https://bishopfox.com/blog/breaking-fortinet-firmware-encryption
    https://github.com/nick0ve/how-to-bypass-aslr-on-linux-x86_64
    https://steve-s.gitbook.io/0xtriboulet/just-malicious/from-c-with-inline-assembly-to-shellcode
    https://github.com/tothi/pwn-hisilicon-dvr/tree/42d8325e68fdb075fe27df8a269932f9fa9601a6
    https://uploads-ssl.webflow.com/64a2900ed5e9bb672af9b2ed/64d42fcc2e3fdcf3d323f3d9_All_cops_are_broadcasting_TETRA_under_scrutiny.pdf
    https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html
    https://0x434b.dev/overview-of-glibc-heap-exploitation-techniques/
    https://wafzsucks.medium.com/how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f
    https://ad2001.gitbook.io/a-noobs-guide-to-arm-exploitation/
    https://blog.theori.io/linux-kernel-exploit-cve-2022-32250-with-mqueue-a8468f32aab5
    https://securelist.com/hacking-microcontroller-firmware-through-a-usb/89919/
    https://blog.ret2.io/2023/08/09/jtag-hacking-the-original-xbox-2023/
    https://wes4m.io/posts/epson_rev/
    https://0xax.gitbooks.io/linux-insides/content/
    https://flaviu.io/advanced-persistent-threat/
    https://grahamhelton.com/blog/ssh_agent/
    https://voidstarsec.com/hw-hacking-lab/vss-lab-guide%5D
    https://ics-cert.kaspersky.com/publications/reports/2022/07/06/dynamic-analysis-of-firmware-components-in-iot-devices/
    https://syst3mfailure.io/wall-of-perdition/
    https://www.willsroot.io/2021/08/corctf-2021-fire-of-salvation-writeup.html
    https://www.forescout.com/resources/l1-lateral-movement-reportg
    https://www.synacktiv.com/en/publications/old-bug-shallow-bug-exploiting-ubuntu-at-pwn2own-vancouver-2023
    https://research.nccgroup.com/2023/03/15/a-race-to-report-a-toctou-analysis-of-a-bug-collision-in-intel-smm/
    https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/
    https://research.nccgroup.com/2023/08/08/intel-bios-advisory-memory-corruption-in-hid-drivers/
    https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
    https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html
    https://big5-sec.github.io/posts/CVE-2023-29360-analysis/
    https://blog.exodusintel.com/2023/07/20/shifting-boundaries-exploiting-an-integer-overflow-in-apple-safari/
    https://blog.quarkslab.com/breaking-secure-boot-on-the-silicon-labs-gecko-platform.html
    https://github.com/enovella/TEE-reversing
    https://www.cyberark.com/resources/all-blog-posts/nvme-new-vulnerabilities-made-easy
    https://blog.cloudflare.com/missing-manuals-io_uring-worker-pool/
    https://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/
    https://bootlin.com/doc/training/audio/audio-slides.pdf
    https://blog.quarkslab.com//starlink.html
    https://blog.exodusintel.com/2022/12/19/linux-kernel-exploiting-a-netfilter-use-after-free-in-kmalloc-cg/
    https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/
    https://portswigger.net/research/smashing-the-state-machine
    https://labs.taszk.io/articles/post/mtk_baseband_csn1_exploitation/
    https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition
    https://research.checkpoint.com/2022/researching-xiaomis-tee/
    https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-1
    https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-2
    https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-3-arm-edition
    https://www.sonarsource.com/blog/patches-collisions-and-root-shells-a-pwn2own-adventure/
    https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
    https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass-part-2/
    https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
    https://www.interruptlabs.co.uk/articles/pipe-buffer
    https://vulncheck.com/blog/openfire-cve-2023-32315
    https://wrv.github.io/h26forge.pdf
    https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf
    https://eshard.com/posts/pixel6_bootloader
    https://eshard.com/posts/pixel6bootloader-2
    https://eshard.com/posts/pixel6_bootloader_3
    https://limitedresults.com/2019/09/pwn-the-esp32-secure-boot/
    https://www.greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware
    https://labs.hakaioffsec.com/fortigate-authentication-bypass/
    https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
    https://redops.at/blog/a-story-about-tampering-edrs
    https://security.human[421
    https://www.tripwire.com/state-of-security/ghidra-101-loading-windows-symbols-pdb-files-in-ghidra-10-x
    https://github.com/PabloMK7/ENLBufferPwn
    https://f0rm2l1n.github.io/2021-02-02-syzkaller-diving-01/
    https://f0rm2l1n.github.io/2021-02-04-syzkaller-diving-02/
    https://f0rm2l1n.github.io/2021-02-10-syzkaller-diving-03/
    https://www.nozominetworks.com/blog/the-importance-of-reverse-engineering-in-network-analysis
    https://www.stormshield.com/news/orbit-analysis-of-a-linux-dedicated-malware/
    https://intezer.com/blog/research/orbit-new-undetected-linux-threat/
    https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
    https://sandflysecurity.com/blog/detecting-linux-memfd-create-fileless-malware-with-command-line-forensics/
    https://labs.withsecure.com/publications/spoofing-call-stacks-to-confuse-edrs
    https://labs.nettitude.com/blog/shellcode-source-mutations/
    https://rollingpwn.github.io/BLE-Relay-Aattck/
    https://blog.impalabs.com/2212_huawei-security-hypervisor.html
    https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html
    https://protectedmo.de/brute.html
    https://github.com/mikeryan/ice9-bluetooth-sniffer
    https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
    https://blog.trailofbits.com/2023/02/16/suid-logic-bug-linux-readline/
    https://intezer.com/blog/malware-analysis/new-linux-backdoor-redxor-likely-operated-by-chinese-nation-state-actor/
    https://medium.com/@INTfinitySG/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2
    https://medium.com/@INTfinitySG/1-2-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-2-cf1571493117
    https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/
    https://claroty.com/team82/research/hacking-ics-historians-the-pivot-point-from-it-to-ot
    https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/total-identity-compromise-microsoft-incident-response-lessons-on/ba-p/3753391
    https://www.flashback.sh/blog/minesweeper-tplink-archer-lan-rce
    https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce
    https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-1/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-2/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-3/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-4/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-5/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-6/
    https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-7/
    https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser
    https://www.randorisec.fr/yet-another-bug-netfilter/
    http://clarkkromenaker.com/post/library-dynamic-loading-mac/
    https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/
    https://maskray.me/blog/2023-02-12-all-about-leak-sanitizer
    https://intezer.com/blog/research/new-linux-threat-symbiote/
    https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/
    https://mattfrisbie.substack.com/p/spy-chrome-extension
    https://modexp.wordpress.com/2018/10/30/arm64-assembly/?ref=0xor0ne.xyz
    https://www.artresilia.com/iot-series-i-are-people-ready-to-go/
    https://www.artresilia.com/iot-series-ii-how-to-build-kernel-image-from-scratch/
    https://www.artresilia.com/iot-series-iii-firmware-testing-in-qemu/
    https://www.artresilia.com/iot-series-iv-debugging-with-gdb-ghidra-zero-day/
    https://mutur4.github.io/posts/remote-process-injection/
    https://blogs.oracle.com/linux/post/live-kernel-debugging-1
    https://blogs.oracle.com/linux/post/live-kernel-debugging-2
    https://blogs.oracle.com/linux/post/live-kernel-debugging-3
    https://www.willsroot.io/2022/12/entrybleed.html
    https://onekey.com/blog/making-toctou-great-again-xrip/?ref=0xor0ne.xyz
    https://bishopfox.com/blog/building-exploit-fortigate-vulnerability-cve-2023-27997
    https://github.com/johnthagen/min-sized-rust
    https://www.nozominetworks.com/blog/14-vulnerabilities-discovered-in-phoenix-contact-hmis
    https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-2
    https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-3
    https://www.immersivelabs.com/blog/detecting-and-decrypting-sliver-c2-a-threat-hunters-guide/
    https://labs.watchtowr.com/ghost-in-the-wire-sonic-in-the-wall/
    https://www.appknox.com/security/how-to-emulate-android-native-libraries-using-qiling
    https://sam4k.com/patching-instrumenting-debugging-linux-kernel-modules/
    https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/
    http://codemachine.com/articles/windbg_quickstart.html
    https://github.blog/2023-10-17-getting-rce-in-chrome-with-incomplete-object-initialization-in-the-maglev-compiler/?ref=0xor0ne.xyz
    https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f
    https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f
    https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html
    https://github.com/clearbluejar/ghidriff
    https://www.willsroot.io/2022/08/reviving-exploits-against-cred-struct.html
    https://googleprojectzero.blogspot.com/2022/03/racing-against-clock-hitting-tiny.html
    https://danielmangum.com/posts/risc-v-bytes-exploring-custom-esp32-bootloader/
    https://seanpesce.blogspot.com/2023/05/bypassing-selinux-with-initmodule.html
    https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/
    https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part-
    https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part-2
    https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
    https://stigward.github.io/posts/fiio-m6-kernel-bug/
    https://stigward.github.io/posts/fiio-m6-exploit/
    https://iq.thc.org/how-does-linux-start-a-process
    https://0x44.xyz/blog/cve-2023-4369/
    https://xairy.io/articles/syzkaller-external-network
    http://conference.hitb.org/files/hitbsecconf2023ams/materials/D2T1%20-%20Smart%20Speaker%20Shenanigans%20-%20Making%20the%20SONOS%20One%20Sing%20Its%20Secrets%20-%20Peter%20Geissler.pdf
    https://astralvx.com/stealing-the-bitlocker-key-from-a-tpm/
    https://quentinkaiser.be/exploitdev/2020/09/23/ghetto-patch-diffing-cisco/
    https://quentinkaiser.be/exploitdev/2020/10/01/patch-diffing-cisco-rv110/?ref=0xor0ne.xyz
    https://clearbluejar.github.io/posts/decompilation-debugging-pretending-all-binaries-come-with-source-code/
    https://nicolo.dev/en/blog/role-control-flow-graph-static-analysis/
    https://github.com/Orange-Cyberdefense/awesome-industrial-protocols
    https://sam4k.com/exploring-linux-random-kmalloc-caches/
    https://people.kernel.org/linusw/the-arm32-scheduling-and-kernelspace-userspace-boundary
    https://thume.ca/2023/12/02/tracing-methods/
    https://www.corellium.com/blog/exploring-unix-pipes-for-ios-kernel-exploit-primitives
    https://tmpout.sh
    https://sam4k.com/linternals-memory-allocators-part-1/
    https://sam4k.com/linternals-memory-allocators-0x02/
    https://quic.xargs.org
    https://dtls.xargs.org
    https://tls13.xargs.org
    https://tls12.xargs.org
    https://blog.xpnsec.com/restoring-dyld-memory-loading/
    https://blog.xpnsec.com/building-a-mach-o-memory-loader-part-1/
    https://www.synacktiv.com/sites/default/files/2023-11/ubuntu_shiftfs.pdf
    https://www.flashback.sh/blog/flashback-connects-cisco-rv340-ssl-vpn-rce
    https://github.com/nccgroup/exploit_mitigations?ref=0xor0ne.xyz
    https://lock.cmpxchg8b.com/reptar.html
    https://anatomic.rip/cve-2023-2598/
    https://github.com/bcoles/kasld
    https://blog.exodusintel.com/2023/05/16/google-chrome-v8-arrayshift-race-condition-remote-code-execution/
    https://research.nccgroup.com/2023/12/04/shooting-yourself-in-the-flags-jailbreaking-the-sonos-era-100/
    https://etenal.me/archives/1825
    https://pwning.tech/ksmbd/
    https://github.blog/2023-12-06-cueing-up-a-calculator-an-introduction-to-exploit-development-on-linux/
    https://duasynt.com/blog/linux-kernel-heap-feng-shui-2022
    https://grsecurity.net/how_autoslab_changes_the_memory_unsafety_game
    https://www.zerodayinitiative.com/blog/2023/11/28/a-detailed-look-at-pwn2own-automotive-ev-charger-hardware
    https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html
    https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html
    https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html
    https://trenchant.io/expanding-the-dragon-adding-an-isa-to-ghidra/
    https://adamdoupe.com/blog/2023/01/23/cve-2023-23504-xnu-heap-underwrite-in-dlil-dot-c/
    https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/
    https://boredpentester.com/reversing-esp8266-firmware-part-1/
    https://boredpentester.com/reversing-esp8266-firmware-part-2/
    https://boredpentester.com/reversing-esp8266-firmware-part-3/
    https://boredpentester.com/reversing-esp8266-firmware-part-4/
    https://boredpentester.com/reversing-esp8266-firmware-part-5/
    https://boredpentester.com/reversing-esp8266-firmware-part-6/
    https://eta.st/2023/01/31/rail-tickets.html
    https://www.crowdstrike.com/blog/exploiting-cve-2021-3490-for-container-escapes/
    https://www.hacefresko.com/posts/tp-link-tapo-c200-unauthenticated-rce
    https://blog.bi0s.in/2023/01/23/Pwn/bi0sCTF22-b3typer/
    https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html
    https://doar-e.github.io/blog/2022/03/26/competing-in-pwn2own-2021-austin-icarus-at-the-zenith/
    https://ivanorsolic.github.io/post/hardwarehacking1/
    https://kernemporium.github.io/posts/unpacking/
    https://www.archcloudlabs.com/projects/loadlibrary-analysis/
    https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9
    https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi
    https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf
    https://github.com/V4bel/CVE-2022-41218
    https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-1/
    https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/
    https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-3/
    https://seclists.org/oss-sec/2023/q1/20
    https://epi052.gitlab.io/notes-to-self/blog/2021-11-07-fuzzing-101-with-libafl-part-1.5/
    https://cloudfuzz.github.io/android-kernel-exploitation/
    https://www.akamai.com/blog/security-research/exploiting-critical-spoofing-vulnerability-microsoft-cryptoapi
    https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development?s=09
    https://act-on.ioactive.com/acton/attachment/34793/f-6460b49e-1afe-41c3-8f73-17dc14916847/1/-/-/-/-/NFC-relay-TESlA_JRoriguez.pdf
    https://research.nccgroup.com/2023/02/06/rustproofing-linux-part-1-4-leaking-addresses/
    https://research.nccgroup.com/2023/02/08/rustproofing-linux-part-2-4-race-conditions/
    https://research.nccgroup.com/2023/02/14/rustproofing-linux-part-3-4-integer-overflows/
    https://research.nccgroup.com/2023/02/16/rustproofing-linux-part-4-4-shared-memory/
    https://sensepost.com/blog/2022/sim-hijacking/
    https://dtsec.us/2023-09-15-StackSpoofin/
    https://chao-tic.github.io/blog/2018/12/25/tls
    https://hackmd.io/@pepsipu/ry-SK44pt?s=09
    https://exploitreversing.files.wordpress.com/2023/04/exploit_reversing_01-1.pdf
    https://exploitreversing.files.wordpress.com/2024/01/exploit_reversing_02.pdf
    https://anti-debug.checkpoint.com
    https://ktln2.org/reversing-c++-qt-applications-using-ghidra/
    https://blog.thalium.re/posts/achieving-remote-code-execution-in-steam-remote-play/
    https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/
    https://courk.cc/breaking-flash-encryption-of-espressif-parts
    https://courk.cc/esp32-c3-c6-fault-injection
    https://ptr-yudai.hatenablog.com/entry/2023/12/08/093606
    https://eli.thegreenplace.net/2011/08/25/load-time-relocation-of-shared-libraries/
    https://eli.thegreenplace.net/2011/11/03/position-independent-code-pic-in-shared-libraries/
    https://redops.at/en/blog/exploring-hells-gate
    https://i.blackhat.com/EU-21/Wednesday/EU-21-Jin-The-Art-of-Exploiting-UAF-by-Ret2bpf-in-Android-Kernel-wp.pdf
    https://www.darknavy.org/blog/strengthening_the_shield_mte_in_memory_allocators/
    https://richiejp.com/linux-kernel-exploit-tls_context-uaf
    https://eprint.iacr.org/2023/090.pdf
    https://therealcoiffeur.com/c101011.html
    https://therealcoiffeur.com/c101100.html
    https://therealcoiffeur.com/c101101.html
    https://blog.kylebot.net/2021/05/08/DEFCON-2021-Quals-mooosl/
    https://security.humanativaspa.it/customizing-sliver-part-1/