Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
awesome-list — Cybersecurity oriented awesome list | Kitploit
Herramientas/GitHubGitHub/0xor0ne/awesome-list
Vulnerability AnalysisExploitationReverse EngineeringMalware AnalysisCTFBinary AnalysisPapers & ResearchLearning & EducationCurated Resources
GitHub0xor0ne/awesome-list

awesome-list

Cybersecurity oriented awesome list

3.9k413hace 3 díasRevisado por Kitploit
Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Awesome Cybersecurity List

My personal collection of awesome blog posts, write-ups, and papers focusing on cybersecurity.

For a deeper dive into cybersecurity-related tools, check out the dedicated Cybersecurity Tools list.

Outline

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2014
  • 2011
  • Misc
  • Other Lists

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [Part 1][1241]
    • [Part 2][1242]
    • [Part 3][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
Descargar herramienta
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]
  • 2025

    • ["A File Format Uncracked for 20 Years"][1202]
    • ["A First Glimpse of the Starlink User Ternimal"][1084]
    • ["A Fuzzy Escape - A tale of vulnerability research on hypervisors"][1151]
    • ["A look at an Android ITW DNG exploit"][1231]
    • ["A modern tale of blinkenlights"][1200]
    • ["A Quick Dive Into The Linux Kernel Page Allocator"][1098]
    • ["A Series of io_uring pbuf Vulnerabilities"][1083]
    • ["A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"][1181]
    • ["Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"][1021]
    • ["All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"][1142]
    • ["Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"][1174]
    • ["Analyzing IOS Kernel Panic Logs"][1037]
    • ["Android: Scudo"][1070]
    • ["Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"][1240]
    • ["APPROTECT Bypass on NRF52832"][1139]
    • ["APT28 Operation Phantom Net Voxel"][1171]
    • ["Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"][1132]
    • ["Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"][1106]
    • ["Being Overlord on the Steam Deck with 1 Byte"][1044]
    • "BPFDoor"
      • ["Part 1 - The Past"][1101]
      • ["Part 2 - The Present"][1102]
    • ["Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"][1189]
    • ["Best practices for key derivation"][1023]
    • ["Binder Fuzzing"][1146]
    • ["Blasting Past iOS 18"][1038]
    • ["Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"][1254]
    • ["Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"][1138]
    • ["Bootloader to Iris: A Security Teardown of a Hardware Wallet"][1199]
    • ["Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"][1125]
    • ["Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"][1196]
    • ["Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"][1217]
    • ["Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"][1039]
    • ["Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"][1179]
    • ["Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"][1209]
    • ["Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"][1124]
    • ["Bypassing disk encryption on systems with automatic TPM2 unlock"][1018]
    • ["Bypassing MTE with CVE-2025-0072"][1105]
    • ["Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"][1222]
    • ["Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"][1040]
    • ["Case Study: IOMobileFramebuffer NULL Pointer Dereference"][1041]
    • ["Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"][1107]
    • ["CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"][1061]
    • ["Control Flow Hijacking in the Linux Kernel"][1114]
    • ["Control Flow Hijacking via Data Pointers"][1085]
    • ["corCTF 2025 - corphone"][1168]
    • ["Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"][1212]
    • ["Cross Cache Attack CheetSheet"][1006]
    • ["CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"][1118]
    • ["CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"][1149]
    • ["CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"][1065]
    • ["CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"][1086]
    • ["CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"][1076]
    • ["CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"][1163]
    • ["CVE-2025-6554: The (rabbit) Hole"][1188]
    • ["Debugging the Pixel 8 kernel via KGDB"][1123]
    • ["Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"][1068]
    • ["Denial of Ruzzing: Rust in the Windows Kernel"][1185]
    • ["Dirty Pageflags: Revisiting PTE Exploitation in Linux"][1166]
    • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
    • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
    • ["Disassembling a binary: linear sweep and recursive traversal"][1019]
    • ["Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"][1047]
    • ["Don’t Phish-let Me Down: FIDO Authentication Downgrade"][1155]
    • ["EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"][1121]
    • ["Emulating an iPhone in QEMU"][1051]
    • ["Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"][1052]
    • ["Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"][1211]
    • ["Exploitation of AIxCC Nginx bugs: Part I"][1035]
    • ["Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
    • ["Exploiting a 13-years old bug on QEMU"][1218]
    • ["Exploiting CVE-2024-0582 via the Dirty Pagetable Method"][1081]
    • ["Exploiting CVE-2025-21479 on a Samsung S23"][1184]
    • ["Exploiting Retbleed in the real world"][1141]
    • ["Exploiting the Synology TC500 at Pwn2Own Ireland 2024"][1122]
    • ["Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"][1164]
    • ["Exploiting Heroes of Might and Magic V"][1119]
    • ["Exploring Grapheneos Secure Allocator: Hardened Malloc"][1167]
    • ["Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"][1029]
    • ["Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"][1172]
    • ["Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"][1152]
    • ["False Injections: Tales of Physics, Misconceptions and Weird Machines"][1120]
    • ["Fast & Faulty - A Use After Free in KGSL Fault Handling"][1182]
    • ["FiberGateway GR241AG - Full Exploit Chain"][1097]
    • ["First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"][1058]
    • ["FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"][1059]
    • ["Fundamental of Virtual Memory"][1162]
    • ["From Chrome renderer code exec to kernel with MSG_OOB"][1153]
    • ["Game Hacking - Valve Anti-Cheat (VAC)"][1074]
    • ["Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"][1215]
    • ["Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"][1103]
    • ["Google CTF 2025 Quals Writeup"][1131]
    • ["Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"][1031]
    • "Hacking the XBox 360 Hypervisor"
      • [Part 1][1109]
      • [Part 2][1110]
    • ["Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"][1129]
    • ["Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"][1198]
    • ["HITCON CTF 2025 -- calc"][1145]
    • ["How I ruined my vacation by reverse engineering WSC"][1077]
    • ["How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"][1090]
    • ["How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"][1115]
    • "Hydroph0bia (CVE-2025-4275)"
      • ["a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1143]
      • ["a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1144]
      • ["a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1108]
    • ["Hypervisors for Memory Introspection and Reverse Engineering"][1099]
    • ["Kernel Exploitation Techniques: Turning The (Page) Tables"][1100]
    • ["Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"][1180]
    • ["Inside Riot Vanguard's Dispatch Table Hooks"][1073]
    • ["Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"][1079]
    • "iOS 17: New Version, New Acronyms":
      • [Part 1][1042]
      • [Part 2][1043]
    • ["kASLR Internals and Evolution"][1095]
    • ["Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"][1082]
    • ["KernelSnitch: Side-Channel Attacks on Kernel Data Structures"][1005]
    • ksmbd (doyensec):
      • ["ksmbd vulnerability research"][1033]
      • ["Fuzzing Improvements and Vulnerability Discovery"][1175]
      • ["Exploiting CVE-2025-37947"][1176]
    • ["Laser Fault Injection on a Budget: RP2350 Edition"][1017]
    • ["Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"][1072]
    • ["Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"][1137]
    • ["Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"][1147]
    • ["Linux Kernel Exploitation For Beginners"][1113]
    • ["Linux Kernel Hfsplus Slab-out-of-bounds Write"][1066]
    • ["Linux kernel Rust module for rootkit detection"][1026]
    • ["Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution"][1011]
    • ["LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"][1177]
    • ["Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"][1050]
    • ["Malware Just Got Its Free Passes Back!"][1221]
    • ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
    • ["mediatek? more like media-rekt, amirite."][1220]
    • ["Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"][1069]
    • ["Modern (Kernel) Low Fragmentation Heap Exploitation"][1127]
    • ["My Emulation Goes to the Moon... Until False Flag"][1094]
    • ["NASA cFS version Aquila Software Vulnerability Assessment"][1056]
    • ["nRF51 RBPCONF bypass for firmware dumping"][1154]
    • ["One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"][1193]
    • ["Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"][1186]
    • ["Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"][1148]
    • ["Overview of Map Exploitation in v8"][1075]
    • ["Paint it Blue: Attacking the Bluetooth Stack"][1216]
    • ["Patch-Gapping the Google Container-Optimized OS for $0"][1032]
    • ["PatchGuard Internals"][1092]
    • ["PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"][1213]
    • ["Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"][1170]
    • ["Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"][1136]
    • ["Project Rain:L1TF"][1178]
    • ["Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"][1194]
    • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
    • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
    • ["pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"][1134]
    • ["Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"][1087]
    • ["Qualcomm DSP Kernel Internals"][1135]
    • ["Race Against Time in the Kernel’s Clockwork"][1160]
    • ["Recovering Metadata from .NET Native AOT Binaries"][1089]
    • ["Reliable system call interception"][1010]
    • ["Replacing a Space Heater Firmware Over WiFi"][1020]
    • ["Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"][1093]
    • ["Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"][1201]
    • ["Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"][1013]
    • ["Reversing Samsung's H-Arx Hypervisor Framework - Part 1"][1036]
    • ["Reversing the QardioArm"][1048]
    • ["Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields"][1226]
    • ["Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"][1071]
    • ["Root Shell on Credit Card Terminal"][1112]
    • ["Rooting the TP-Link Tapo C200 Rev.5"][1130]
    • ["ROPing our way to RCE"][1028]
    • ["Running code in a PAX Credit Card Payment Machine"][1272]
    • ["RV130X Firmware Analysis"][1025]
    • ["Security through Transparency: Tales from the RP2350 Hacking Challenge"][1256]
    • ["smoltalk: RCE in Open Source Agents"][1045]
    • ["Solo: A Pixel 6 Pro Story (When one bug is all you need)"][1128]
    • ["SoK: Security of EMV Contactless Payment Systems"][1088]
    • ["Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"][1034]
    • ["Stack Overflows, Heap Overflows, and Existential Dread"][1150]
    • ["State of Linux Snapshot Fuzzing"][1078]
    • ["STM32L05 Voltage Glitching"][1111]
    • ["Streaming Zero-Fi Shells to Your Smart Speaker"][1096]
    • ["Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"][1228]
    • ["System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"][1197]
    • ["The Art of Linux Kernel Rootkits"][1008]
    • ["The cryptography behind electronic passports"][1214]
    • "The Evolution of Dirty COW":
      • [Part 1][1062]
      • [Part 2][1063]
    • ["The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"][1116]
    • ["TLS NoVerify: Bypass All The Things"][1165]
    • ["Tp-Link Router Deep Research"][1203]
    • ["Tracing Back to the Source | SPTM Round 3"][1046]
    • ["Turning Camera Surveillance on its Axis"][1158]
    • ["Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"][1126]
    • ["Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"][1133]
    • ["VMware Workstation guest-to-host escape"][1161]
    • ["We are ARMed no more ROPpery Here"][1016]
    • "When a Wi-Fi SSID Gives You Root on an MT02 Repeater"
      • [Part 1][1156]
      • [Part 2][1157]
    • ["When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"][1067]
    • ["Windows arm64 Internals: Deconstructing Pointer Authentication"][1190]
    • ["Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"][1195]
    • "Windows Inter Process Communication A Deep Dive Beyond the Surface"
      • [Part 1][1204]
      • [Part 2][1205]
      • [Part 3][1206]
      • [Part 4][1207]
      • [Part 5][1208]
    • ["WireTap: Breaking Server SGX via DRAM Bus Interposition"][1183]
    • ["Workshop: Firmware Reverse Engineering"][1269]
    • ["Writing a Ghidra processor module"][1064]
    • ["Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique (CVE-2024-50629~50631)"][1247]
    • ["yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"][1210]
    • ["You Already Have Our Personal Data, Take Our Phone Calls Too"][1140]
    • ["Zen and the Art of Microcode Hacking"][1027]
    • ["Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"][1227]

    2024

    • ["1-click Exploit in South Korea's biggest mobile chat app"][965]
    • ["4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"][959]
    • "64 bytes and a ROP chain – A journey through nftables":
      • [Part 1][865]
      • [Part 2][866]
    • "nix libX11: Uncovering and exploiting a 35-year-old vulnerability":
      • [Part 1][703]
      • [Part 2][704]
    • ["A few notes on AWS Nitro Enclaves: Images and attestation"][738]
    • "A first look at Android 14 forensics"
    • ["A "Gau-Hack" from EuskalHack"][893]
    • ["A Journey From sudo iptables To Local Privilege Escalation"][1009]
    • ["A Practical Guide to PrintNightmare in 2024"][709]
    • ["A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "][714]
    • ["A Trip Down Memory Lane"][715]
    • [AArch64 memory and paging][1015]
    • ["An Introduction to Chrome Exploitation - Maglev Edition"][882]
    • ["An unexpected journey into Microsoft Defender's signature World"][876]
    • ["Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"][952]
    • ["Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"][736]
    • ["AES-GCM and breaking it on nonce reuse"][912]
    • ["Analyzing Mutation-Coded - VM Protect and Alcatraz English"][834]
    • ["ARLO: I'M WATCHING YOU"][810]
    • ["ASLRn’t: How memory alignment broke library ASLR"][731]
    • ["Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"][911]
    • ["Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"][852]
    • ["Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"][1173]
    • "Base64 Beyond Encoding"
      • [Part 1][945]
      • [Part 2][946]
    • ["Becoming any Android app via Zygote command injection"][863]
    • ["Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"][895]
    • ["BGGP4: A 420 Byte Self-Replicating UEFI App For x64"][728]
    • ["Binary type inference in Ghidra"][905]
    • ["Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"][803]
    • ["Breaking the Barrier: Post-Barrier Spectre Attacks"][970]
    • ["Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"][987]
    • ["Breaking Down Multipart Parsers: File upload validation bypass"][966]
    • "Breaking the Flash Encryption Feature of Espressif’s Parts"
    • ["Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"][886]
    • ["Buying Spying Insights into Commercial Surveillance Vendors"][733]
    • ["Bypassing EDRs With EDR-Preloading"][716]
    • ["Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"][920]
    • "Chaining N-days to Compromise All":
      • [Part 1][836]
      • [Part 2][837]
      • [Part 3][838]
      • [Part 4][839]
      • [Part 5][840]
    • ["Check Point - Wrong Check Point (CVE-2024-24919)"][875]
    • ["Code injection on Android without ptrace"][874]
    • "CodeQL zero to hero": [Part 1][858] [Part 2][859] [Part 3][860] [Part 4][1191] [Part 5][1192]
    • ["Commonly Abused Linux Initial Access Techniques and Detection Strategies"][896]
    • ["Compiler Options Hardening Guide for C and C++"][877]
    • ["Continuously fuzzing Python C extensions"][734]
    • ["corCTF 2024: trojan-turtles writeup"][929]
    • ["corMine 1 and 2"][948]
    • ["Cross-Process Spectre Exploitation"][969]
    • ["CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"][861]
    • ["CVE-2022-2586 Writeup"][849]
    • ["CVE-2020-27786 ( Race Condition + Use-After-Free )"][967]
    • ["CVE-2022-4262"][864]
    • ["CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"][1012]
    • ["CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"][697]
    • ["Declawing PUMAKIT"][989]
    • [Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)][1003]
    • ["Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"][699]
    • ["Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"][683]
    • ["Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"][805]
    • ["Diving Deep into F5 Secure Vault"][918]
    • ["DJI - The ART of obfuscation"][705]
    • ["Docker Security – Step-by-Step Hardening (Docker Hardening)"][729]
    • ["Driving forward in Android drivers"][908]
    • ["Emulating RH850 architecture with Unicorn Engine"][853]
    • "Everyday Ghidra: Ghidra Data Types"
      • [Part 1][973]
      • [Part 2][974]
    • ["Exploit detail about CVE-2024-26581"][944]
    • ["Exploring AMD Platform Secure Boot"][701]
    • ["Exploring GNU extensions in the Linux kernel"][878]
    • ["Exploiting Android’s Hardened Memory Allocator"][1030]
    • ["Exploiting Empire C2 Framework"][723]
    • "Exploiting Enterprise Backup Software For Privilege Escalation":
      • [Part 1][906]
      • [Part 2][907]
    • "Exploiting Reversing (ER) series":
      • Article 01
      • Article 02
    • ["Exploiting Steam: Usual and Unusual Ways in the CEF Framework"][898]
    • ["Exploring object file formats"][684]
    • ["Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"][735]
    • "Fault Injection Attacks against the ESP32-C3 and ESP32-C6"
    • ["Fault Injection – Down the Rabbit Hole"][993]
    • "Finding Bugs in Kernel":
      • [Part 1][996]
      • [Part 2][997]
    • ["Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"][883]
    • ["Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"][804]
    • ["From fault injection to RCE"][990]
    • ["From object transition to RCE in the Chrome renderer"][940]
    • ["Fuzzing between the lines in popular barcode software"][968]
    • ["Gaining kernel code execution on an MTE-enabled Pixel 8"][808]
    • ["Ghidra nanoMIPS ISA module"][873]
    • ["Going Native - Malicious Native Applications"][842]
    • "Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"
    • ["GhostRace: Exploiting and Mitigating Speculative Race Conditions"][802]
    • ["GPUAF - Two ways of Rooting All Qualcomm based Android phones"][994]
    • ["GraphStrike: Anatomy of Offensive Tool Development"][712]
    • ["Hacking a 2014 tablet... in 2024!"][932]
    • ["Hacking a Smart Home Device"][691]
    • ["Hacking Android Games"][949]
    • ["Heap exploitation, glibc internals and nifty tricks"][938]
    • ["HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"][818]
    • "Hi, My Name is Keyboard"
    • ["Hiding Linux Processes with Bind Mounts"][925]
    • ["How I Also Hacked my Car"][976]
    • ["How to Bypass Golang SSL Verification"][941]
    • ["Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"][995]
    • "Hunting down the HVCI bug in UEFI"
    • "Hunting for Unauthenticated n-days in Asus Routers"
    • "Iconv, Set the Charset to RCE":
      • [Part 1][870]
      • [Part 2][871]
    • ["Java Deserialization Tricks"][815]
    • ["JTAG Hacking with a Raspberry Pi"][851]
    • ["Kuiper Ransomware’s Evolution"][702]
    • ["Inside a New OT/IoT Cyberweapon: IOCONTROL"][1001]
    • ["Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"][692]
    • ["Introduction to Fuzzing Android Native Components"][984]
    • "Learning LLVM":
      • [Part 1][934]
      • [Part 2][935]
    • ["LeftoverLocals: Listening to LLM responses through leaked GPU local memory"][687]
    • "Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"
    • ["Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"][999]
    • "Linux Kernel Exploitation":
      • ["Environment"][922]
      • ["ret2usr"][923]
    • ["Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"][939]
    • "ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs":
      • [Part 1][901]
      • [Part 2][902]
      • [Part 3][903]
    • ["Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"][809]
    • ["Mali GPU Kernel LPE"][786]
    • ["MalpediaFLOSSed"][814]
    • ["Microsoft BitLocker Bypasses are Practical"][718]
    • ["Modern implant design: position independent malware development"][690]
    • ["My new superpower"][688]
    • ["Not the Drones You're Looking For"][825]
    • "Operation triangulation":
      • ["Keychain module analysis"][823]
      • ["audio module analysis"][824]
    • ["OtterRoot: Netfilter Universal Root 1-day"][986]
    • ["Out-of-bounds read & write in the glibc's qsort()"][698]
    • ["PageJack: A Powerful Exploit Technique With Page-Level UAF"][951]
    • ["Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code Pages"][1000]
    • ["Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"][835]
    • ["Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"][983]
    • ["PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"][711]
    • "Playing with libmalloc in 2024"
    • ["Puckungfu 2: Another NETGEAR WAN Command Injection"][730]
    • ["Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"][910]
    • ["Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"][933]
    • ["Pwning browsers like a kernel"][957]
    • "Pwn2Own: WAN-to-LAN Exploit Showcase":
      • ["Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"][950]
      • ["Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"][942]
    • "Pwn2Own Toronto 2023":
      • ["How it all started"][829]
      • ["Exploring the Attack Surface"][830]
      • ["Exploration"][831]
      • ["Memory Corruption Analysis"][832]
      • ["The Exploit"][833]
    • ["Pwning a Brother labelmaker, for fun and interop!"][897]
    • "Pwntools 10x":
      • [Part 1][867]
      • [Part 2][868]
      • [Part 3][869]
    • ["Pygmy Goat"][972]
    • ["Recovering an ECU firmware using disassembler and branches"][921]
    • ["regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"][919]
    • ["Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"][846]
    • ["Retrofitting encrypted firmware is a Bad Idea"][1024]
    • ["Reverse engineering a car key fob signal "][801]
    • ["Reverse Engineering and Dismantling Kekz Headphones"][962]
    • ["Reverse Engineering Protobuf Definitions From Compiled Binaries"][820]
    • ["Reverse engineering the 59-pound printer onboard the Space Shuttle"][943]
    • ["Reverse Engineering the AM335x Boot ROM"][947]
    • ["Reverse Engineering The Stream Deck Plus"][1004]
    • "Ring Around The Regex"
      • [Part 1][955]
      • [Part 2][956]
    • ["RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"][958]
    • ["RomCom exploits Firefox and Windows zero days in the wild"][981]
    • ["ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"][892]
    • ["Route to Safety: Navigating Router Pitfalls"][816]
    • ["Rooting a Hive Camera"][819]
    • ["SAME70 Emulator"][879]
    • "Say Friend and Enter":
      • [Part 1][812]
      • [Part 2][813]
    • ["Samsung NX related posts"][887]
    • ["Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"][975]
    • ["SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"][862]
    • ["SELinux bypasses"][963]
    • ["SLUB Internals for Exploit Developers"][980]
    • ["SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"][937]
    • ["Shell We Assemble?"][689]
    • ["Shellcode evasion using WebAssembly and Rust"][726]
    • "SMM isolation":
      • ["SMI deprivileging (ISRD)"][847]
      • ["Security policy reporting (ISSR)"][848]
    • ["SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"][1049]
    • "Strengthening the Shield: MTE in Heap Allocators"
    • ["Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"][913]
    • ["The architecture of SAST tools: An explainer for developers"][739]
    • ["The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"][880]
    • ["The Definitive Guide to Linux Process Injection"][971]
    • ["The 'Invisibility Cloak' - Slash-Proc Magic"][924]
    • ["The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"][1007]
    • ["The rev.ng decompiler goes open source + start of the UI closed beta"][694]
    • ["The tale of a GSM Kernel LP"][850]
    • ["The Wild West of Proof of Concept Exploit Code (PoC)"][926]
    • "The Windows Registry Adventure":
      • [Part 1][914]
      • [Part 2][915]
      • [Part 3][916]
    • ["TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"][894]
    • ["Tony Hawk’s Pro Strcpy"][928]
    • ["Toolchain Necromancy: Past Mistakes Haunting ASLR"][732]
    • ["TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"][988]
    • ["TP-Link TDDP Buffer Overflow Vulnerability"][695]
    • ["Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"][787]
    • ["Understanding AddressSanitizer: Better memory safety for your code"][889]
    • ["Understanding Unix Garbage Collection and its Interaction with io_uring"][891]
    • ["Understanding Windows x64 Assembly"][693]
    • ["Using Symbolic Execution to Devirtualise a Virtualised Binary"][936]
    • ["Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"][985]
    • ["VBA: having fun with macros, overwritten pointers & R/W/X memory"][843]
    • ["Vulnerabilities of Realtek SD card reader driver"][1002]
    • ["Why Code Security Matters - Even in Hardened Environments"][953]
    • ["Windows Secure-Launch on Qualcomm devices"][811]
    • ["Windows Sockets: From Registered I/O to SYSTEM Privileges"][998]
    • ["Windows vs Linux Loader Architecture"][844]
    • ["Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"][954]
    • "Writing a Debugger From Scratch"
      • "Attaching to a Process"
      • "Register State and Stepping"
      • "Reading Memory"
      • "Exports and Private Symbols"
      • "Breakpoints"
      • "Stacks"
      • "Disassembly"
    • ["Writing a system call tracer using eBPF"][931]
    • ["Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"][854]
    • ["x64 Return Address Spoofing"][991]
    • ["x64 Call Stack Spoofing"][992]

    2023

    • "A Deep Dive Into Brute Ratel C4 Payloads"
    • "A Deep Dive into Penetration Testing of macOS Applications (Part 1)"
    • "A Deep Dive into TPM-based BitLocker Drive Encryption"
    • "A Detailed Look at Pwn2own Automotive EV Charger Hardware"
    • ["A LibAFL Introductory Workshop"][826]
    • "A look at CVE-2023-29360, a beautiful logical LPE vuln"
    • "A Journey Into Hacking Google Search Appliance"
    • "A new method for container escape using file-based DirtyCred"
    • "A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"
    • "A Potholing Tour in a SoC"
    • "A Practical Tutorial on PCIe for Total Beginners on Windows":
      • [Part 1][806]
      • [Part 2][807]
    • "A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"
    • "A Red-Teamer diaries"
    • "A story about tampering EDRs"
    • ["Abusing Liftoff assembly and efficiently escaping from sbx"][677]
    • ["Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"][857]
    • "Abusing undocumented features to spoof PE section headers"
    • "Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"
    • "All about LeakSanitizer"
    • "All cops are broadcasting: TETRA under scrutiny"
    • "All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"
    • "An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit"
    • "An Introduction into Stack Spoofing"
    • "Analysis on legit tools abused in human operated ransomware"
    • "Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway":
      • Part 1
      • Part 2
    • "Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"
    • "Analyzing a Modern In-the-wild Android Exploit"
    • "Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"
    • "ARM64 Reversing And Exploitation" (8ksec)
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
      • Part 7
      • Part 8
      • Part 9
      • Part 10
    • "Attacking an EDR"
      • Part 1
      • Part 2
    • "Attacking IoT Devices from Web Perspective"
    • ["Attacking JS engines: Fundamentals for understanding memory corruption crashes"][720]
    • "Audio with embedded Linux training"
    • "Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"
    • "b3typer - bi0sCTF 2022"
    • "Back to the Future with Platform Security"
    • "Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"
    • "Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"
    • "Behind the Shield: Unmasking Scudos's Defenses"
    • "BlackLotus UEFI bootkit: Myth confirmed"
    • "BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"
    • ["BPF Memory Forensics with Volatility 3"][881]
    • "Breaking Fortinet Firmware Encryption"
    • "Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"
    • "Breaking Secure Boot on the Silicon Labs Gecko platform"
    • "Building a Custom Mach-O Memory Loader for macOS"
    • "Building an Exploit for FortiGate Vulnerability CVE-2023-27997"
    • "Bypassing a noexec by elf roping"
    • "Bypassing PPL in Userland (again)"
    • "Bypassing SELinux with init_module"
    • "C101101: D-Link DIR-865L":
      • "Remote Code Execution (pre-auth)"
      • "Unsigned firmware upload lead to persistent backdoor (pre-auth)"
      • "Memory corruptions lead to Remote Code Execution (pre-auth)"
    • "CAN Injection: keyless car theft"
    • "chonked"
      • "minidlna 1.3.2 http chunk parsing heap overflow (cve-2023-33476) root cause analysis"
      • "exploiting cve-2023-33476 for remote code execution"
    • ["Code Execution in Chromium’s V8 Heap Sandbox"][896]
    • "Coffee: A COFF loader made in Rust"
    • "Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"
    • "Conquering the memory through io_uring - Analysis of CVE-2023-2598"
    • "Cracking Windows Kernel with HEVD"
      • "Chapter 0"
      • "Chapter 1"
      • "Chapter 2"
      • "Chapter 3"
      • "Chapter 4"
    • "Cueing up a calculator: an introduction to exploit development on Linux"
    • "Customizing Sliver":
      • Part 1
      • Part 2
      • Part 3
    • "CVE-2022-27666: My file your memory"
    • "CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"
    • "CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"
    • "CVE-2023-23504: XNU Heap Underwrite in dlil.c"
    • "CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"
    • "CVE-2023-36844 And Friends: RCE In Juniper Devices"
    • "CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"
    • "cURL audit: How a joke led to significant findings"
    • ["D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."][964]
    • "Debugger Ghidra Class"
    • "Debugging D-Link: Emulating firmware and hacking hardware"
    • "Decompilation Debugging"
    • "Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"
    • "Defining the cobalt strike reflective loader"
    • "Demystifying bitwise operations, a gentle C tutorial"
    • "Detecting and decrypting Sliver C2 – a threat hunter’s guide"
    • "Detecting BPFDoor Backdoor Variants Abusing BPF Filters"
    • "Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"
    • "Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"
    • "Diving Into Smart Contract Decompilation"
    • "Diving into Starlink's User Terminal Firmware"
    • "DJI Mavic 3 Drone Research"
      • "Firmware Analysis"
      • ["Vulnerability Analysis"][713]
    • "Drone Security and Fault Injection Attacks"
    • "DualShock4 Reverse Engineering":
      • Part 1
      • Part 3
      • Part 3
    • "eBPF: A new frontier for malware"
    • "Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"
    • "Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"
    • "ENLBufferPwn (CVE-2022-47949)"
    • "Escaping the Google kCTF Container with a Data-Only Exploit"
    • ["Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"][827]
    • "Exploitation of Openfire CVE-2023-32315"
    • "Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"
    • "Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"
    • "Exploiting CVE-2021-3490 for Container Escapes"
    • "Exploiting null-dereferences in the Linux kernel"
    • "Exploring UNIX pipes for iOS kernel exploit primitives"
    • "EPF: Evil Packet Filter"
    • "Escaping from Bhyve"
    • "ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"
    • "Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"
    • "Espressif ESP32: Breaking HW AES with Power Analysis"
    • "Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"
    • "Executing Arbitrary Code & Executables in Read-Only FileSystems"
    • "Exploit Engineering – Attacking the Linux Kernel"
    • "Exploiting a Remote Heap Overflow with a Custom TCP Stack"
    • "Exploring Hell's Gate"
    • "Exploiting a bug in the Linux kernel with Zig"
    • "Exploiting HTTP Parsers Inconsistencies"
    • "Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"
    • "Exploring Android Heap Allocations in Jemalloc 'New'"
    • "Exploring Linux's New Random Kmalloc Caches"
    • "Exploring the section layout in linker output"
    • "Fantastic Rootkits: And Where To Find Them":
      • Part 1
      • Part 2
      • Part 3
    • "Few lesser known tricks, quirks and features of C"
    • "Finding and exploiting process killer drivers with LOL for 3000$"
    • "Finding bugs in C code with Multi-Level IR and VAST"
    • "Finding Gadgets for CPU Side-Channels with Static Analysis Tools"
    • "For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"
    • "FortiNAC - Just a few more RCEs"
    • "Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"
    • "Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"
    • "From C, with inline assembly, to shellcode"
    • "Fuzzing Farm":
      • "Fuzzing GEGL with fuzzuf"
      • "Evaluating Performance of Fuzzer"
      • "Patch Analysis and PoC Development"
      • "Hunting and Exploiting 0-day [CVE-2022-24834]"
    • "Fuzzing Golang msgpack for fun and panic"
    • "Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"
    • "Ghidra" (Craig Young):
      • "A Guide to Reversing Shared Objects with Ghidra"
      • "Reversing a Simple CrackMe with Ghidra Decompiler"
      • "Vulnerability Hunting with Ghidra"
      • "Patching a Bug from a Ghidra Listing"
      • "Vulnerability Analysis with Ghidra Scripting"
    • "Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"
    • "Google Chrome V8 ArrayShift Race Condition Remote Code Execution"
    • "Hacking a Tapo TC60 Camera"
    • "Hacking Amazon's eero 6 (part 1)"
    • "Hacking Brightway scooters: A case study"
    • "Hacking ICS Historians: The Pivot Point from IT to OT"
    • "Hacking the Nintendo DSi Browser"
    • "Hardware Hacking to Bypass BIOS Passwords"
    • "Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"
    • "How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"
    • "How does Linux start a process"
    • "How NATs Work":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "How I Hacked my Car":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
    • ["How I hacked smart lights: the story behind CVE-2022-47758"][841]
    • "How to Emulate Android Native Libraries Using Qiling"
    • ["How to Voltage Fault Injection"][685]
    • "How To Secure A Linux Server"
    • "Hunting Vulnerable Kernel Drivers"
    • "Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"
    • "In-depth analysis on Valorant’s Guarded Regions"
    • "In-Memory-Only ELF Execution (Without tmpfs)"
    • "Intel BIOS Advisory – Memory Corruption in HID Drivers "
    • "Intercepting Allocations with the Global Allocator"
    • "Intro to Cutter"
    • "Introduction to SELinux"
    • "IoT Series":
      • "Are People Ready to go?"
      • "How To Build Kernel Image From Scratch"
      • "Firmware testing in QEMU"
      • "Debugging with GDB & GHIDRA + Zero-day"
    • "JTAG 'Hacking' the Original Xbox in 2023"
    • "Kernel Exploit Factory"
    • "Learn Makefiles With the tastiest examples"
    • "Let's build a Chrome extension that steals everything"
    • "Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"
      • Part 1
      • [Part 2][904]
      • [Part 3][930]
    • "Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"
    • "lexmark printer haxx"
    • linux-re-101
    • "Linux debugging, profiling and tracing training"
    • "Linux Kernel Exploitation"
      • ["Getting started & BOF"][678]
      • ["Heap techniques"][679]
      • ["Exploiting race-condition + UAF"][680]
    • "Linux Kernel PWN":
      • ["ret2dir"][899]
      • ["DirtyCred"][900]
    • "Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"
    • "Linux Kernel Teaching"
    • "Linux Malware: Defense Evasion Techniques"
    • "Linux Red Team":
      • "Exploitation Techniques"
      • "Privilege Escalation Techniques"
      • "Persistence Techniques"
    • "Linux Remote Process Injection - (Injecting into a firefox process)"
    • "Linux rootkits explained – Part 1: Dynamic linker hijacking"
    • "Linux Shellcode 101: From Hell to Shell"
    • "Local Privilege Escalation on the DJI RM500 Smart Controller"
    • "Lord Of The Ring0":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "Low-Level Software Security for Compiler Developers"
    • "LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"
    • "Making TOCTOU Great again – X(R)IP"
    • "Malware Reverse Engineering for Beginners":
      • Part 1
      • Part 2
    • "Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"
    • "mast1c0re"
      • "Introduction – Exploiting the PS4 and PS5 through a game save"
      • "Part 1 – Modifying PS2 game save files"
      • "Part 2 – Arbitrary PS2 code execution"
      • "Part 3 – Escaping the emulator"
    • "Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"
    • "Meterpreter vs Modern EDR(s)"
    • "MTE As Implemented":
      • Part 1
      • Part 2
    • "mTLS: When certificate authentication is done wrong"
    • "MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"
    • "Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"
    • "NetGear Series: Emulating Netgear R6700V3 circled binary ":
      • Part 1
      • Part 2
    • "New HiatusRAT Router Malware Covertly Spies On Victims"
    • ["No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"][1091]
    • "NVMe: New Vulnerabilities Made Easy"
    • "nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"
    • "Obscure Windows File Types"
    • "Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"
    • ["One shot, Triple kill"][700]
    • "OPC UA Deep Dive Series":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"
    • "OrBit: advanced analysis of a Linux dedicated malware"
    • "OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"
    • "P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"
    • "P4wnP1-LTE"
    • "Patches, Collisions, and Root Shells: A Pwn2Own Adventure"
    • "Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"
    • "Persistence Techniques That Persist"
    • "Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"
    • "prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"
    • "Producing a POC for CVE-2022-42475 (Fortinet RCE)"
    • "Protecting Android clipboard content from unintended exposure"
    • "Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI"
      • Part 1
      • Part 2
      • Part 3
    • "Prototype Pollution in Python"
    • ["PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"][758]
    • "PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"
    • "PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"
    • "Pwnassistant - Controlling /home's via a Home Assistant RCE"
    • "Pwning Pixel 6 with a leftover patch"
    • "Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"
    • "Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"
    • "Readline crime: exploiting a SUID logic bug"
    • "Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"
    • "Reptar"
    • "Restoring Dyld Memory Loading"
    • "Retreading The AMLogic A113X TrustZone Exploit Process"
    • "Reversing UK mobile rail tickets"
    • "Reversing Windows Container":
      • [Part 1][821]
      • [Part 2][822]
    • "RISC-V Bytes: Exploring a Custom ESP32 Bootloader"
    • "REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"
    • "Revisiting CVE-2017-11176"
    • "Rooting the FiiO M6":
      • "Using the "World's Worst Fuzzer" To Find A Kernel Bug"
      • "Writing an LPE Exploit For Our Overflow Bug"
    • ["Rooting Xiaomi WiFi Routers"][817]
    • "Rust Binary Analysis, Feature by Feature"
    • "Rust to Assembly: Understanding the Inner Workings of Rust"
    • "Rustproofing Linux":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • ["scudo Hardened Allocator — Unofficial Internals Documentation"][706]
    • "Securing our home labs: Frigate code review"
    • "Securing our home labs: Home Assistant code review"
    • "SHA-1 gets SHAttered"
    • "Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"
    • "Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"
    • "Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"
    • "Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"
    • "Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"
    • "Smashing the state machine: the true potential of web race conditions"
    • "SRE deep dive into Linux Page Cache"
    • "Sshimpanzee"
    • "Stepping Insyde System Management Mode"
    • "Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"
    • "THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"
    • "The ARM32 Scheduling and Kernelspace/Userspace Boundary"
    • "The art of Fuzzing: Introduction"
    • "The art of fuzzing: Windows Binaries"
    • "The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"
    • ["The Art Of Linux Persistence"][872]
    • "The Blitz Tutorial Lab on Fuzzing with AFL++"
    • "The code that wasn’t there: Reading memory on an Android device by accident"
    • "The Dragon Who Sold His camaro: Analyzing Custom Router Implant"
    • "The Importance of Reverse Engineering in Network Analysis"
    • "The Linux Kernel Module Programming Guide"
    • "The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"
    • "The Role of the Control Flow Graph in Static Analysis"
    • "The Silent Spy Among Us: Smart Intercom Attacks"
    • "The Stack Series: The X64 Stack"
    • "The Untold Story of the BlackLotus UEFI Bootkit"
    • "Tickling ksmbd: fuzzing SMB in the Linux kernel"
    • "Tool Release: Cartographer"
    • "Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"
    • "Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"
    • "Your not so "Home Office" - SOHO Hacking at Pwn2Own"
    • "Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"
    • "Unauthenticated RCE on a RIGOL oscilloscope"
    • "UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"
    • "Uncovering a crazy privilege escalation from Chrome extensions"
    • "Uncovering HinataBot: A Deep Dive into a Go-Based Threat"
    • "Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"
    • "Understanding a Payload’s Life Featuring Meterpreter & Other Guests "
    • "Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"
    • "Understanding the Heap - a beautiful mess"
    • ["Unleashing ksmbd: crafting remote exploits of the Linux kernel"][828]
    • "Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)"
    • "Unlimited Results: Breaking Firmware Encryption of ESP32-V3"
    • "Unveiling secrets of the ESP32":
      • "creating an open-source MAC Layer"
      • "reverse engineering RX"
    • "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More"
    • ["What is Loader Lock?"][845]
    • "Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"
    • "Windows Installer EOP (CVE-2023-21800)"
    • "Writing your own RDI /sRDI loader using C and ASM"
    • "Zenbleed"
    • "Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"

    2022

    • "A journey into IoT":
      • "Chip identification, BUSSide, and I2C"
      • "Discover components and ports"
      • "Firmware dump and analysis"
      • ["Radio communications"][681]
      • ["Internal communications"][682]
    • ["A Kernel Hacker Meets Fuchsia OS"][710]
    • "A Technical Analysis of Pegasus for Android":
      • part 1
      • Part 2
      • Part 3
    • ["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]
    • ["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]
    • "ARM 64 Assembly Series":
      • "Basic definitions and registers"
      • "Offset and Addressing modes"
      • "Load and Store"
      • "Branch"
      • "Data Processing (Part 1)"
      • "Data Processing (Part 2)"
      • "selections and loops"
      • "Subroutines"
    • ["Attacking the Android kernel using the Qualcomm TrustZone"][885]
    • "Attacking Titan M with Only One Byte"
    • "Avoiding Detection with Shellcode Mutator"
    • "BasicFUN Series":
      • "Hardware Analysis / SPI Flash Extraction"
      • "Reverse Engineering Firmware / Reflashing SPI Flash"
      • "Dumping Parallel Flash via I2C I/O Expanders"
      • "I2C Sniffing, EEPROM Extraction and Parallel Flash Extraction"
    • ["Basics for Binary Exploitation"][749]
    • "Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"
    • ["BrokenPrint: A Netgear stack overflow"][782]
    • "Bypassing software update package encryption ":
      • "Extracting the Lexmark MC3224i printer firmware"
      • "Exploiting the Lexmark MC3224i printer"
    • "Bypassing vtable Check in glibc File Structures"
    • "Blind Exploits to Rule Watchguard Firewalls"
    • "BPFDoor - An Evasive Linux Backdoor Technical Analysis"
    • ["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]
    • "Chrome Browser Exploitation":
      • [Part 1][1053]
      • [Part 2][1054]
      • [Part 3][1055]
    • "Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"
    • ["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]
    • ["Corrupting memory without memory corruption"][762]
    • ["Creating a Rootkit to Learn C"][719]
    • "CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"
    • "[CVE-2022-1786] A Journey To The Dawn"
    • "CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"
    • "CVE-2022-27666: Exploit esp6 modules in Linux kernel"
    • "CVE-2022-29582 An io_uring vulnerability"
    • ["Deconstructing and Exploiting CVE-2020-6418"][778]
    • "DirtyCred Remastered: how to turn an UAF into Privilege Escalation"
    • "Disclosing information with a side-channel in Django"
    • "Dumping the Amlogic A113X Bootrom"
    • "Dynamic analysis of firmware components in IoT devices"
    • "Embedded Systems Security and TrustZone"
    • ["Emulate Until You Make it"][748]
    • "EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"
    • "Expanding the Dragon: Adding an ISA to Ghidra"
    • ["Exploiting: Buffer overflow in Xiongmai DVRs"][742]
    • "Exploiting CSN.1 Bugs in MediaTek Basebands"
    • "exploiting CVE-2019-2215"
    • "Exploiting CVE-2022-42703 - Bringing back the stack attack"
    • ["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]
    • "Exploring the Hidden Attack Surface of OEM IoT Devices"
    • "Firmware key extraction by gaining EL3"
    • "Fortigate - Authentication Bypass Lead to Full Device Takeover"
    • "Fourchain":
      • ["Prologue"][765]
      • ["Hole"][766]
      • ["Sandbox"][767]
    • ["Fuzzing ping(8) … and finding a 24 year old bug"][751]
    • "Hacking Bluetooth to Brew Coffee from Github Actions":
      • [Part 1][752]
      • [Part 2][753]
      • [Part 3][754]
    • "Hackign More Secure Portable Storage Devices"
    • ["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]
    • "How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"
    • "Huawei Security Hypervisor Vulnerability"
    • "Hunting for Persistence in Linux"
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • "Hacking Some More Secure USB Flash Drives":
      • Part 1
      • Part 2
    • ["Learning eBPF exploitation"][768]
    • "Intro to Embedded RE":
      • "Tools and Series"
      • "UART Discovery and Firmware Extraction via UBoot"
    • "Introduction to x64 Linux Binary Exploitation":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • ["io_uring - new code, new bugs, and a new exploit technique"][978]
    • "Linux Hardening Guide"
    • "Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"
    • "Linux Kernel Exploit (CVE-2022–32250) with mqueue"
    • "Linux SLUB Allocator Internals and Debugging":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "Linternals: Introducing Memory Allocators & The Page Allocator"
    • "Linternals: The Slab Allocator"
    • "Linux kernel heap feng shui in 2022"
    • "Looking for Remote Code Execution bugs in the Linux kernel"
    • "Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"
    • ["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]
    • "Missing Manuals - io_uring worker pool"
    • ["Modifying Embedded Filesystems in ARM Linux zImages"][775]
    • "Netgear Orbi":
      • "orbi hunting 0x0: introduction, uart access, recon"
      • "orbi hunting 0x1: crashes in soap-api"
      • "nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"
    • "nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"
    • "NFC Relay Attack on Tesla Model Y"
    • "Nightmare: One Byte to ROP // Deep Dive Edition"
    • "Overview of GLIBC heap exploitation techniques"
    • "Parsing TFTP in Rust"
    • "Patching, Instrumenting & Debugging Linux Kernel Modules"
    • "PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"
    • "pipe_buffer arbitrary read write"
    • "Pixel 6 Bootloader"
      • "Booting up"
      • "Emulation, ROP"
      • "Exploitation"
    • "Port knocking from the scratch"
    • "Pulling MikroTik into the Limelight"
    • "Racing against the clock -- hitting a tiny kernel race window"
    • ["Replicating CVEs with KLEE"][763]
    • "Reversing C++, Qt based applications using Ghidra"
    • "Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"
    • "Replicant: Reproducing a Fault Injection "
    • "Researching Xiaomi’s Tee to Get to Chinese Money"
    • "Reversing embedded device bootloader (U-Boot)":
      • Part 1
      • Part 2
    • "Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"
    • "Reverse engineering an EV charger"
    • "Reverse Engineering Dark Souls 3":
      • "Connection"
      • "Packets"
      • "Key Exchange"
      • "Reliable UDP"
    • "Reverse engineering integrity checks in Black Ops 3"
    • "Reverse engineering thermal printers"
    • "Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"
    • "SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"
    • "Shedding Light on Huawei's Security Hypervisor"
    • "Shikitega - New stealthy malware targeting Linux"
    • "side channels: power analysis"
    • "side channels: using the chipwhisperer"
    • "SIM Hijacking"
    • "Spoofing Call Stacks To Confuse EDRs"
    • ["SROP Exploitation with radare2"][770]
    • "Stealing the Bitlocker key from a TPM"
    • "Stranger Strings: An exploitable flaw in SQLite"
    • "Survey of security mitigations and architectures, December 2022"
    • "Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"
    • "Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"
    • "The Dirty Pipe Vulnerability"
    • ["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]
    • "The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"
    • ["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]
    • "The toddler’s introduction to Heap exploitation":
      • "Part 1"
      • "Part 2"
      • "Overflows"
      • "Use After Free & Double free"
      • "FastBin Dup to Stack"
      • "FastBin Dup Consolidate"
      • "Unsafe Unlink"
      • "House of Spirit"
      • "House of Lore"
    • "TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"
    • ["Tracing and Manipulating with DynamoRIO"][750]
    • "Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"
    • "Turning Google smart speakers into wiretaps for $100k"
    • "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"
    • "Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"
    • "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":
      • Part 1
      • Part 2
    • "Vulnerability Details for CVE-2022-41218"
    • "Vulnerabilities in Tenda's W15Ev2 AC1200 Router"
    • "When an N-Day turns into a 0day"
    • ["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]
    • "Write a Linux firewall from scratch based on Netfilter"
    • "Yet another bug into Netfilter"
    • "Xiongmai IoT Exploitation"
    • "Zyxel authentication bypass patch analysis (CVE-2022-0342)"

    2021

    • "A dive into the PE file format":
      • "Introduction"
      • "DOS Header, DOS Stub and Rich Header"
      • "NT Headers"
      • "Data Directories, Section Headers and Sections"
      • "Imports (Import Direcory Table, ILT, IAT)"
      • "PE Base Relocations"
      • "Writing a PE Parser"
    • ["A Nerve-Racking Bug Collision in Samsung's NPU Driver"][855]
    • "A Practical Approach to Attacking IoT Embedded Designs":
      • [Part 1][721]
      • [Part 2][722]
    • ["Attacking Samsung RKP"][909]
    • "Automatic unpacking with Qiling framework"
    • ["BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"][755]
    • "Breaking 64 bit aslr on Linux x86-64"
    • "Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"
    • "Complete Guide to Stack Buffer Overflow (OSCP Preparation)"
    • "CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"
    • "CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."
    • ["CVE-2021-22555: Turning \x00\x00 into 10000$"][977]
    • ["Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"][756]
    • "Digging into Linux namespaces":
      • Part 1
      • Part 2
    • ["Exploiting crash handlers: LPE on Ubuntu"][760]
    • "Extending Ghidra Part 1: Setting up a Development Environment"
    • "Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"
    • "Fuzzing101 with LibAFL":
      • "Fuzzing Xpdf"
      • "Speed Improvements to Part I"
      • "Fuzzing libexif"
    • ["Getting to know memblock"][771]
    • "Ghidra 101":
      • "Cursor Text Highlighting"
      • "Slice Highlighting"
      • "Decoding Stack Strings"
      • "Loading Windows Symbols (PDB files)"
      • "Creating Structures in Ghidra"
      • "Loading Windows Symbols (PDB files) in Ghidra 10.x"
    • "GRCON 2021 - Capture the Signal"
    • "Hacking the Furbo Dog Camera":
      • [Part 1][744]
      • [Part 2][745]
      • [Part 3][746]
    • "How AUTOSLAB Changes the Memory Unsafety Game"
    • "Learning Linux Kernel Exploitation":
      • Part 1
      • Part 2
      • Part 3
    • "LinkSys EA6100 AC1200":
      • [Part 1][740]
      • [Part 1][741]
    • "Linux Internals: How /proc/self/mem writes to unwritable memory"
    • "Linux Kernel Exploitation":
      • "Debugging the Kernel with QEMU"
      • "Smashing Stack Overflows in the Kernel"
      • "Controlling RIP and Escalating privileges via Stack Overflow"
    • "Live Debugging Techniques for the Linux Kernel"
      • Part 1
      • Part 2
      • Part 3
    • "Malware development (0xPat)"
      • [Part 1][792]
      • [Part 2][793]
      • [Part 3][794]
      • [Part 4][795]
      • [Part 5][796]
      • [Part 6][797]
      • [Part 7][798]
      • [Part 8][799]
      • [Part 9][800]
    • "mooosl"
    • "My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"
    • "New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"
    • "New Old Bugs in the Linux Kernel"
    • ["Practical Introduction to CodeQL"][1233]
    • ["Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug"]
    • "Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"
    • "Recovering a Full PEM Private key when Half of it is Redacted"
    • "Reverse Engineering an Unknown Microcontroller"
    • "Reverse Engineering Bare-Metal Firmware":
      • Part 1
      • Part 2
      • Part 3
    • "Reverse Engineering Yaesu FT-70D Firmware Encryption"
    • "Syzkaller diving":
      • Part 1
      • Part 2
      • Part 3
    • "The Art of Exploiting UAF by Ret2bpf in Android Kernel"
    • "The Oddest Place You Will Ever Find PAC"
    • ["Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"][888]
    • "VMProtect 2"
      • [Part 1][960]
      • [Part 2][961]
    • "Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"

    2020

    • "A Deep Dive Into Samsung's TrustZone"
      • Part 1
      • Part 2
      • Part 3
    • ["An iOS hacker tries Android"][856]
    • "BGET Explained Binary Heap Exploitation on OP-TEE":
      • Part 1
      • Part 2
    • "BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"
    • ["Building a Basic C2"][1057]
    • ["CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"][890]
    • ["CVE-2020-16040 Analysis & Exploitation"][725]
    • "Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"
    • "Espressif ESP32: Bypassing Secure Boot using EMFI"
    • "Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"
    • "Espressif ESP32: Controlling PC during Secure Boot"
    • "Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"
    • "Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"
    • "Flashback Connects - Cisco RV340 SSL VPN RCE"
    • "Hardware Debugging for Reverse Engineers":
      • "SWD, OpenOCD and Xbox One Controllers"
      • "TAG, SSDs and Firmware Extraction"Manipulating AES Traffic
    • "Hardware Hacking 101: Identifying and Dumping eMMC Flash"
    • "House of Muney - Leakless Heap Exploitation Technique"
    • ["Learning to Decapsulate Integrated Circuits Using Acid Deposition"][727]
    • "Loading Dynamic Libraries on Mac"
    • "Minesweeper - TP-Link Archer C7 LAN RCE"
    • "My Methods To Achieve Persistence In Linux Systems"
    • "nRF52 Debug Resurrection":
      • Part 1
      • Part 2
    • "NTLM Relay"
    • "Patch Diffing a Cisco RV110W Firmware Update"
      • Part 1
      • Part 2
    • ["Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"][783]
    • "ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"
    • ["Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"][780]
    • "SSHD Injection and Password Harvesting"
    • ["There’s A Hole In Your SoC: Glitching The MediaTek BootROM"][737]
    • "Weekend Destroyer - RCE in Western Digital PR4100 NAS"
    • "What're you telling me, Ghidra?"

    2019

    • "Breaking out of Docker via runC – Explaining CVE-2019-5736"
    • "Executable and Linkable Format 101":
      • "Sections and Segments"
      • "Symbols"
      • "Relocations"
      • "Dynamic Linking"
    • ["Exploiting Qualcomm WLAN and Modem Over the Air"][773]
    • "Hacking microcontroller firmware through a USB"
    • "Hardening Secure Boot on Embedded Devices for Hostile Environments"
    • ["How to Weaponize the Yubikey"][743]
    • "Pew Pew Pew: Designing Secure Boot Securely"
    • ["Pwn the ESP32 crypto-core"][757]
    • "Pwn the ESP32 Secure Boot"
    • "Reverse Engineering Architecture And Pinout of Custom Asics"
    • "Reverse-engineering Broadcom wireless chipsets"
    • "Reverse Engineering of a Not-so-Secure IoT Device"
    • "Virtualization Internals":
      • Part 1
      • Part 2
      • Part 3
      • Part 4

    2018

    • "A Deep dive into (implicit) Thread Local Storage"
    • "A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"
    • "ARM Exploitation":
      • ["Return oriented Programming"][788]
      • ["Setup and Tools"][789]
      • ["Defeating DEP - execute system()"][790]
      • ["Defeating DEP - executing mprotect()"][791]
    • "CVE-2017-11176: A step-by-step Linux Kernel exploitation":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
    • "eMMC Data Recovery from Damaged Smartphone"
    • ["Kinibi TEE: Trusted Application Exploitation"][781]
    • "My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"
    • ["Reverse Engineering BLE Devices"][761]
    • "Reversing ESP8266 Firmware":
      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
      • Part 6
    • "Vectorized Emulation":438
      • "Hardware accelerated taint tracking at 2 trillion instructions per second"
      • "MMU Design"

    2017

    • ["Escalating Privileges in Linux using Fault Injection"][774]
    • "Hardware hacking tutorial: Dumping and reversing firmware"
    • "HiSilicon DVR hack"
    • "How I Reverse Engineered and Exploited a Smart Massager"
    • "Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"
    • "Linux ptrace introduction AKA injecting into sshd for fun"
    • "Over The Air":
      • "Exploiting Broadcom’s Wi-Fi Stack (Part 1)"
      • "Exploiting Broadcom’s Wi-Fi Stack (Part 2)"
      • "Exploiting The Wi-Fi Stack on Apple Devices"

    2016

    • "Bypassing Secure Boot using Fault Injection"
    • "munmap madness"
    • "Implementation of Signal Handling"
    • "Practical Reverse Engineering"
      • "Digging Through the Firmware"
      • "Scouting the Firmware"
      • "Following the Data"
      • "Dumping the Flash"
      • "Digging Through the Firmware"
    • "Understanding and Hardening Linux Containers"

    2014

    • "ret2dir: Rethinking Kernel Isolation"

    2011

    • "Load-time relocation of shared libraries"
    • "Position Independent Code (PIC) in shared libraries"

    Misc

    • 0xtriboulet
    • "A Noobs Guide to ARM Exploitation"
    • "Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent fuzzing"
    • "Advanced Compilers: The Self-Guided Online Course"
    • "Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"
    • "Android Kernel Exploitation"
    • Anti-Debug Tricks
    • "ARM TrustZone: pivoting to the secure world"
    • ["ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"][927]
    • [Awesome binary parsing][769]
    • [Awesome Executable Packing][717]
    • Awesome Industrial Protocols
    • "Brute Ratel - Scandinavian Defence"
    • Comprehensive Rust
    • [cryptopals][1022]
    • [CVE North Stars][708]
    • "Debugger Ghidra Class"
    • DhavalKapil/heap-exploitation
    • Diffing Portal
    • exploit_mitigations
    • ["fenrir"][1169]
    • Ghidriff - Ghidra Binary Diffing Engine
    • "Grand Theft Auto A peek of BLE relay attack"
    • ["Hands-on Firmware Extraction, Exploration, and Emulation"][979]
    • ice9-bluetooth-sniffer
    • "Illustrated Connections":
      • dtls
      • quic
      • tls 1.2
      • tls 1.3
    • "Introduction to encryption for embedded Linux"
      • "Introduction to encryption for embedded Linux developers"
      • "A hands-on approach to symmetric-key encryption"
      • "Asymmetric-Key Encryption and Digital Signatures in Practice"
    • "Introduction to Malware Analysis and Reverse Engineering"
    • "Kernel Address Space Layout Derandomization"
    • ["Kernel Exploit Recipes Notebook"][776]
    • "Laser-Based Audio Injection on Voice-Controllable Systems"
    • Linux Kernel CVEs
    • "Linux kernel exploit development"
    • "Linux Kernel map"
    • "Linux Insides"
    • ["Linux Privilege Escalation"][982]
    • "Linux Syscalls Reference"
    • "Lytro Unlock - Making a bad camera slightly better"
    • "Minimizing Rust Binary Size"
    • "mjsxj09cm Recovering Firmware And Backdooring"
    • "Offensive security (0xtriboulet)"
    • "Operating System development tutorials in Rust on the Raspberry Pi"
    • ["parking-game-fuzzer"][1159]
    • ["Practical Cryprography for Developers"][785]
    • Red-Team-Infrastructure-Wiki
    • "Reverse Engineering For Everyone!"
    • "Reverse Engineering WiFi on RISC-V BL602"
    • "Rust Atomics and Locks"
    • ["RustRedOps"][686]
    • "Satellite Hacking Demystified(RTC0007)"
    • TEE Reversing
    • "THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"
    • tmpout.sh: collection of writeups on low-level stuff
    • ["Trail of Bits Testing Handbook"][724]
    • [TripleCross][696]
    • USB-WiFi
    • "VSS: Beginners Guide to Building a Hardware Hacking Lab"
    • "WinDBG quick start tutorial"

    Other Lists

    • Exploitation: resources dedicated to the world of binary exploitation
    • Linux Kernel: collection of resources dedicated to Linux kernel (internals)
    • Wireless: resources dedicated to wireless technologies and security
    • OT/IoT Security
    • Red Teaming and Offensive Security

    Read more