
Lista awesome orientata alla cybersecurity
La mia raccolta personale di fantastici blog post, write-up e paper incentrati sulla cybersecurity.
Per un approfondimento sugli strumenti legati alla cybersecurity, dai un'occhiata alla lista dedicata Cybersecurity Tools.
["A Deep Dive into Penetration Testing of macOS Applications (Part 1)"][49]
["A Detailed Look at Pwn2own Automotive EV Charger Hardware"][537]
["A LibAFL Introductory Workshop"][826]
["A look at CVE-2023-29360, a beautiful logical LPE vuln"][260]
["A Journey Into Hacking Google Search Appliance"][203]
["A new method for container escape using file-based DirtyCred"][201]
["A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"][273]
["A Potholing Tour in a SoC"][189]
"A Practical Tutorial on PCIe for Total Beginners on Windows":
["A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"][255]
["A Red-Teamer diaries"][156]
["A story about tampering EDRs"][293]
["Abusing Liftoff assembly and efficiently escaping from sbx"][677]
["Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"][857]
["Abusing undocumented features to spoof PE section headers"][139]
["Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"][587]
["All about LeakSanitizer"][460]
["All cops are broadcasting: TETRA under scrutiny"][237]
["All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"][513]
["An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit"][392]
["An Introduction into Stack Spoofing"][580]
["Analysis on legit tools abused in human operated ransomware"][4]
"Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway":
["Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"][119]
["Analyzing a Modern In-the-wild Android Exploit"][379]
["Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"][326]
"ARM64 Reversing And Exploitation" (8ksec)
"Attacking an EDR"
["Attacking JS engines: Fundamentals for understanding memory corruption crashes"][720]
["Audio with embedded Linux training"][267]
["Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"][300]
["b3typer - bi0sCTF 2022"][554]
["Back to the Future with Platform Security"][97]
["Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"][100]
["Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"][91]
["Behind the Shield: Unmasking Scudos's Defenses"][8]
["BlackLotus UEFI bootkit: Myth confirmed"][429]
"BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"
["BPF Memory Forensics with Volatility 3"][881]
["Breaking Fortinet Firmware Encryption"][233]
["Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"][81]
["Breaking Secure Boot on the Silicon Labs Gecko platform"][262]
["Building a Custom Mach-O Memory Loader for macOS"][523]
["Building an Exploit for FortiGate Vulnerability CVE-2023-27997"][475]
["Bypassing a noexec by elf roping"][528]
["Bypassing PPL in Userland (again)"][308]
["Bypassing SELinux with init_module"][494]
"C101101: D-Link DIR-865L":
["CAN Injection: keyless car theft"][195]
"chonked"
["Code Execution in Chromium’s V8 Heap Sandbox"][896]
["Coffee: A COFF loader made in Rust"][93]
["Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"][397]
["Conquering the memory through io_uring - Analysis of CVE-2023-2598"][528]
"Cracking Windows Kernel with HEVD"
["Cueing up a calculator: an introduction to exploit development on Linux"][534]
"Customizing Sliver":
["CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"][567]
["CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"][72]
["CVE-2023-23504: XNU Heap Underwrite in dlil.c"][543]
["CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"][99]
["CVE-2023-36844 And Friends: RCE In Juniper Devices"][281]
["CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"][186]
["cURL audit: How a joke led to significant findings"][459]
["D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."][964]
["Debugger Ghidra Class"][28]
["Debugging D-Link: Emulating firmware and hacking hardware"][290]
["Decompilation Debugging"][508]
["Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"][253]
["Defining the cobalt strike reflective loader"][320]
["Demystifying bitwise operations, a gentle C tutorial"][400]
["Detecting and decrypting Sliver C2 – a threat hunter’s guide"][480]
["Detecting BPFDoor Backdoor Variants Abusing BPF Filters"][183]
["Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"][51]
["Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"][164]
["Diving Into Smart Contract Decompilation"][204]
["Diving into Starlink's User Terminal Firmware"][268]
"DJI Mavic 3 Drone Research"
["Drone Security and Fault Injection Attacks"][82]
"DualShock4 Reverse Engineering":
["Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"][47]
["Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"][182]
["ENLBufferPwn (CVE-2022-47949)"][422]
["Escaping the Google kCTF Container with a Data-Only Exploit"][178]
["Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"][827]
["Exploitation of Openfire CVE-2023-32315"][283]
["Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"][572]
["Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"][130]
["Exploiting CVE-2021-3490 for Container Escapes"][552]
["Exploiting null-dereferences in the Linux kernel"][148]
["Exploring UNIX pipes for iOS kernel exploit primitives"][514]
["EPF: Evil Packet Filter"][73]
["Escaping from Bhyve"][192]
["ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"][69]
["Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"][394]
["Espressif ESP32: Breaking HW AES with Power Analysis"][393]
["Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"][324]
["Executing Arbitrary Code & Executables in Read-Only FileSystems"][52]
["Exploit Engineering – Attacking the Linux Kernel"][146]
["Exploiting a Remote Heap Overflow with a Custom TCP Stack"][322]
["Exploring Hell's Gate"][594]
["Exploiting a bug in the Linux kernel with Zig"][597]
["Exploiting HTTP Parsers Inconsistencies"][391]
["Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"][198]
["Exploring Android Heap Allocations in Jemalloc 'New'"][7]
["Exploring Linux's New Random Kmalloc Caches"][511]
"Fantastic Rootkits: And Where To Find Them":
["Few lesser known tricks, quirks and features of C"][354]
["Finding and exploiting process killer drivers with LOL for 3000$"][172]
["Finding bugs in C code with Multi-Level IR and VAST"][92]
["Finding Gadgets for CPU Side-Channels with Static Analysis Tools"][75]
["For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"][70]
["FortiNAC - Just a few more RCEs"][95]
["Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"][32]
["Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"][90]
["From C, with inline assembly, to shellcode"][235]
"Fuzzing Farm":
["Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"][486]
"Ghidra" (Craig Young):
["Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"][481]
["Google Chrome V8 ArrayShift Race Condition Remote Code Execution"][530]
["Hacking a Tapo TC60 Camera"][350]
["Hacking Amazon's eero 6 (part 1)"][86]
["Hacking Brightway scooters: A case study"][29]
["Hacking ICS Historians: The Pivot Point from IT to OT"][444]
["Hacking the Nintendo DSi Browser"][456]
["Hardware Hacking to Bypass BIOS Passwords"][5]
["Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"][443]
["How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"][240]
["How does Linux start a process"][501]
"How NATs Work":
"How I Hacked my Car":
["How I hacked smart lights: the story behind CVE-2022-47758"][841]
["How to Emulate Android Native Libraries Using Qiling"][482]
["How to Voltage Fault Injection"][685]
["How To Secure A Linux Server"][140]
["Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"][171]
["In-depth analysis on Valorant’s Guarded Regions"][141]
["In-Memory-Only ELF Execution (Without tmpfs)"][355]
["Intel BIOS Advisory – Memory Corruption in HID Drivers "][257]
["Intercepting Allocations with the Global Allocator"][79]
["Introduction to SELinux"][59]
"IoT Series":
["JTAG 'Hacking' the Original Xbox in 2023"][244]
["Kernel Exploit Factory"][159]
["Learn Makefiles With the tastiest examples"][24]
["Let's build a Chrome extension that steals everything"][463]
["Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"][387]
["Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"][327]
[linux-re-101][169]
["Linux debugging, profiling and tracing training"][353]
"Linux Kernel Exploitation"
"Linux Kernel PWN":
["Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"][544]
["Linux Kernel Teaching"][131]
["Linux Malware: Defense Evasion Techniques"][165]
"Linux Red Team":
["Linux Remote Process Injection - (Injecting into a firefox process)"][569]
["Linux rootkits explained – Part 1: Dynamic linker hijacking"][60]
["Linux Shellcode 101: From Hell to Shell"][53]
["Local Privilege Escalation on the DJI RM500 Smart Controller"][160]
"Lord Of The Ring0":
["Low-Level Software Security for Compiler Developers"][15]
["LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"][202]
["Making TOCTOU Great again – X(R)IP"][474]
"Malware Reverse Engineering for Beginners":
["Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"][285]
"mast1c0re"
["Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"][330]
["Meterpreter vs Modern EDR(s)"][170]
"MTE As Implemented":
["mTLS: When certificate authentication is done wrong"][270]
["MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"][177]
["Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"][404]
"NetGear Series: Emulating Netgear R6700V3 circled binary ":
["New HiatusRAT Router Malware Covertly Spies On Victims"][402]
["No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"][1091]
["NVMe: New Vulnerabilities Made Easy"][264]
["nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"][365]
["Obscure Windows File Types"][74]
["Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"][254]
["One shot, Triple kill"][700]
"OPC UA Deep Dive Series":
["OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"][42]
["OrBit: advanced analysis of a Linux dedicated malware"][427]
["OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"][428]
["P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"][206]
["P4wnP1-LTE"][209]
["Patches, Collisions, and Root Shells: A Pwn2Own Adventure"][278]
["Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"][297]
["Persistence Techniques That Persist"][299]
["Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"][166]
["prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"][184]
["Producing a POC for CVE-2022-42475 (Fortinet RCE)"][323]
["Protecting Android clipboard content from unintended exposure"][448]
"Protecting the Phoenix: Unveiling Critical Vulnerabilities in Phoenix Contact HMI"
["PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"][758]
["PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"][98]
["PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"][318]
"Pwnassistant - Controlling /home's via a Home Assistant RCE"
["Pwning Pixel 6 with a leftover patch"][310]
["Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"][309]
["Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"][185]
["Readline crime: exploiting a SUID logic bug"][439]
["Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"][30]
["Reptar"][527]
["Restoring Dyld Memory Loading"][522]
["Retreading The AMLogic A113X TrustZone Exploit Process"][77]
["Reversing UK mobile rail tickets"][551]
"Reversing Windows Container":
["RISC-V Bytes: Exploring a Custom ESP32 Bootloader"][493]
["REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"][364]
["Revisiting CVE-2017-11176"][48]
"Rooting the FiiO M6":
["Rooting Xiaomi WiFi Routers"][817]
["Rust Binary Analysis, Feature by Feature"][231]
["Rust to Assembly: Understanding the Inner Workings of Rust"][134]
"Rustproofing Linux":
["scudo Hardened Allocator — Unofficial Internals Documentation"][706]
["SHA-1 gets SHAttered"][325]
["Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"][55]
["Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"][76]
["Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"][261]
["Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"][531]
["Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"][504]
["Smashing the state machine: the true potential of web race conditions"][271]
["SRE deep dive into Linux Page Cache"][94]
["Sshimpanzee"][16]
["Stepping Insyde System Management Mode"][256]
["Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"][562]
["THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"][31]
["The ARM32 Scheduling and Kernelspace/Userspace Boundary"][512]
["The art of Fuzzing: Introduction"][57]
["The art of fuzzing: Windows Binaries"][89]
["The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"][54]
["The Art Of Linux Persistence"][872]
["The Blitz Tutorial Lab on Fuzzing with AFL++"][303]
["The code that wasn’t there: Reading memory on an Android device by accident"][462]
["The Dragon Who Sold His camaro: Analyzing Custom Router Implant"][228]
["The Importance of Reverse Engineering in Network Analysis"][426]
["The Linux Kernel Module Programming Guide"][3]
["The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"][284]
["The Role of the Control Flow Graph in Static Analysis"][509]
["The Silent Spy Among Us: Smart Intercom Attacks"][331]
["The Stack Series: The X64 Stack"][356]
["The Untold Story of the BlackLotus UEFI Bootkit"][205]
["Tickling ksmbd: fuzzing SMB in the Linux kernel"][386]
["Tool Release: Cartographer"][371]
["Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"][445]
["Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"][80]
["Your not so "Home Office" - SOHO Hacking at Pwn2Own"][5]
["Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"][524]
["Unauthenticated RCE on a RIGOL oscilloscope"][210]
["UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"][37]
["Uncovering a crazy privilege escalation from Chrome extensions"][502]
["Uncovering HinataBot: A Deep Dive into a Go-Based Threat"][311]
["Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"][180]
["Understanding a Payload’s Life Featuring Meterpreter & Other Guests "][315]
["Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"][591]
["Understanding the Heap - a beautiful mess"][348]
["Unleashing ksmbd: crafting remote exploits of the Linux kernel"][828]
["Unleashing ksmbd: remote exploitation of the Linux kernel (ZDI-23-979, ZDI-23-980)"][533]
["Unlimited Results: Breaking Firmware Encryption of ESP32-V3"][598]
"Unveiling secrets of the ESP32":
["What is Loader Lock?"][845]
["Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"][58]
["Windows Installer EOP (CVE-2023-21800)"][314]
["Writing your own RDI /sRDI loader using C and ASM"][307]
["Zenbleed"][207]
["Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"][248]## 2022
"A journey into IoT":
["A Kernel Hacker Meets Fuchsia OS"][710]
"A Technical Analysis of Pegasus for Android":
["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]
["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]
"ARM 64 Assembly Series":
["Attacking the Android kernel using the Qualcomm TrustZone"][885]
["Attacking Titan M with Only One Byte"][259]
["Avoiding Detection with Shellcode Mutator"][432]
"BasicFUN Series":
["Basics for Binary Exploitation"][749]
["Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"][238]
["BrokenPrint: A Netgear stack overflow"][782]
"Bypassing software update package encryption ":
["Bypassing vtable Check in glibc File Structures"][208]
["Blind Exploits to Rule Watchguard Firewalls"][173]
["BPFDoor - An Evasive Linux Backdoor Technical Analysis"][292]
["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]
"Chrome Browser Exploitation":
["Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"][556]
["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]
["Corrupting memory without memory corruption"][762]
["Creating a Rootkit to Learn C"][719]
["CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"][377]
["[CVE-2022-1786] A Journey To The Dawn"][401]
["CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"][168]
["CVE-2022-27666: Exploit esp6 modules in Linux kernel"][532]
["CVE-2022-29582 An io_uring vulnerability"][495]
["Deconstructing and Exploiting CVE-2020-6418"][778]
["DirtyCred Remastered: how to turn an UAF into Privilege Escalation"][167]
["Dumping the Amlogic A113X Bootrom"][78]
["Dynamic analysis of firmware components in IoT devices"][250]
["Embedded Systems Security and TrustZone"][145]
["Emulate Until You Make it"][748]
["EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"][473]
["Expanding the Dragon: Adding an ISA to Ghidra"][542]
["Exploiting: Buffer overflow in Xiongmai DVRs"][742]
["Exploiting CSN.1 Bugs in MediaTek Basebands"][272]
["exploiting CVE-2019-2215"][61]
"Exploiting CVE-2022-42703 - Bringing back the stack attack"
["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]
["Firmware key extraction by gaining EL3"][316]
["Fortigate - Authentication Bypass Lead to Full Device Takeover"][291]
"Fourchain":
["Fuzzing ping(8) … and finding a 24 year old bug"][751]
"Hacking Bluetooth to Brew Coffee from Github Actions":
["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]
["How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"][266]
["Huawei Security Hypervisor Vulnerability"][435]
"Hunting for Persistence in Linux"
"Hacking Some More Secure USB Flash Drives":
["Learning eBPF exploitation"][768]
"Intro to Embedded RE":
"Introduction to x64 Linux Binary Exploitation":
["io_uring - new code, new bugs, and a new exploit technique"][978]
["Linux Hardening Guide"][349]
["Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"][269]
["Linux Kernel Exploit (CVE-2022–32250) with mqueue"][242]
"Linux SLUB Allocator Internals and Debugging":
["Linternals: Introducing Memory Allocators & The Page Allocator"][516]
["Linternals: The Slab Allocator"][517]
["Linux kernel heap feng shui in 2022"][535]
["Looking for Remote Code Execution bugs in the Linux kernel"][503]
["Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"][319]
["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]
["Missing Manuals - io_uring worker pool"][265]
["Modifying Embedded Filesystems in ARM Linux zImages"][775]
"Netgear Orbi":
["nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"][63]
["NFC Relay Attack on Tesla Model Y"][574]
["Nightmare: One Byte to ROP // Deep Dive Edition"][582]
["Overview of GLIBC heap exploitation techniques"][239]
["Patching, Instrumenting & Debugging Linux Kernel Modules"][483]
"PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"
["pipe_buffer arbitrary read write"][282]
"Pixel 6 Bootloader"
["Port knocking from the scratch"][227]
["Pulling MikroTik into the Limelight"][120]
["Racing against the clock -- hitting a tiny kernel race window"][492]
["Replicating CVEs with KLEE"][763]
["Reversing C++, Qt based applications using Ghidra"][586]
["Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"][406]
["Replicant: Reproducing a Fault Injection "][675]
["Researching Xiaomi’s Tee to Get to Chinese Money"][274]
"Reversing embedded device bootloader (U-Boot)":
["Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"][368]
"Reverse Engineering Dark Souls 3":
["Reverse engineering integrity checks in Black Ops 3"][220]
["Reverse engineering thermal printers"][245]
["Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"][491]
["SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"][484]
["Shedding Light on Huawei's Security Hypervisor"][434]
["Shikitega - New stealthy malware targeting Linux"][438]
["side channels: power analysis"][380]
["side channels: using the chipwhisperer"][381]
["SIM Hijacking"][579]
["Spoofing Call Stacks To Confuse EDRs"][431]
["SROP Exploitation with radare2"][770]
["Stealing the Bitlocker key from a TPM"][505]
["Stranger Strings: An exploitable flaw in SQLite"][588]
"Survey of security mitigations and architectures, December 2022"
["Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"][461]
["Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"][226]
["The Dirty Pipe Vulnerability"][321]
["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]
["The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"][36]
["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]
"The toddler’s introduction to Heap exploitation":
["TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"][553]
["Tracing and Manipulating with DynamoRIO"][750]
["Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"][312]
["Turning Google smart speakers into wiretaps for $100k"][18]
"UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"
["Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"][126]
"Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":
["Vulnerability Details for CVE-2022-41218"][563]
["Vulnerabilities in Tenda's W15Ev2 AC1200 Router"][127]
["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]
["Write a Linux firewall from scratch based on Netfilter"][313]
["Yet another bug into Netfilter"][457]
"Zyxel authentication bypass patch analysis (CVE-2022-0342)"