Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
awesome-list — 사이버 보안 지향 awesome 리스트 | Kitploit
도구/GitHubGitHub/0xor0ne/awesome-list
Vulnerability AnalysisExploitationReverse EngineeringMalware AnalysisCTFBinary AnalysisPapers & ResearchLearning & EducationCurated Resources
GitHub0xor0ne/awesome-list

awesome-list

사이버 보안 지향 awesome 리스트

3.9k413261일 전Kitploit 검토 완료
저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Awesome Cybersecurity List

사이버 보안에 초점을 맞춘 멋진 블로그 글, 분석 글, 논문들을 개인적으로 모아둔 컬렉션입니다.

사이버 보안 관련 도구에 대해 더 깊이 알고 싶다면, 별도의 Cybersecurity Tools 목록을 확인하세요.

목차

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2014
  • 2011
  • 기타
  • 다른 목록들

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [Part 1][1241]
    • [Part 2][1242]
    • [Part 3][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes"][1307]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["How LLMs Actually Work"][1308]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • "Sleeping Beauty"
    • ["Putting Adaptix to Bed with Crystal Palace"][1309]
    • ["CFG, CET, and Stack Spoofing"][1310]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]
  • 2025- ["20년 동안 해독되지 않은 파일 형식"][1202]

    • ["Starlink 사용자 단말기 첫 인상"][1084]
    • ["퍼지 탈출 - 하이퍼바이저 취약점 연구 이야기"][1151]
    • ["Android ITW DNG 익스플로잇 분석"][1231]
    • ["블링큰라이트의 현대적 이야기"][1200]
    • ["리눅스 커널 페이지 할당자 퀵 다이브"][1098]
    • ["io_uring pbuf 취약점 시리즈"][1083]
    • ["리눅스 커널의 eBPF 투어: 관측성, 보안 및 네트워킹"][1181]
    • ["리눅스 커널에서 7년 된 취약점을 우연히 발견하다"][1021]
    • ["필요한 건 MCP뿐 - LLM이 DEF CON CTF 결승 챌린지를 해결하다"][1142]
    • ["리눅스 커널 TLS 서브시스템의 1-day 취약점 분석"][1174]
    • ["iOS 커널 패닉 로그 분석"][1037]
    • ["Android: Scudo"][1070]
    • ["신뢰 사슬의 또 다른 균열: (또 하나의) 보안 부팅 우회 발견"][1240]
    • ["NRF52832에서 APPROTECT 우회"][1139]
    • ["APT28 팬텀 넷 복셀 작전"][1171]
    • ["GenAI 애플리케이션과 LLM 공격하기 – 때로는 정중하게 요청하기만 하면 됩니다!"][1132]
    • ["주의, 고전압: Rockwell Automation PowerMonitor 1000의 공격 표면 탐구"][1106]
    • ["1바이트로 Steam Deck의 오버로드 되기"][1044]
    • "BPFDoor"
      • ["파트 1 - 과거"][1101]
      • ["파트 2 - 현재"][1102]
    • ["속도로 xloader 이기기: 역공학을 위한 힘의 증폭기로서의 생성형 AI"][1189]
    • ["키 파생 모범 사례"][1023]
    • ["Binder 퍼징"][1146]
    • ["iOS 18을 뚫고 나가기"][1038]
    • ["블루투스 헤드폰 재킹: Airoha RACE 취약점 전체 공개"][1254]
    • ["침해로의 부팅: Windows SecureBoot의 원격 공격 표면 사냥"][1138]
    • ["부트로더에서 Iris까지: 하드웨어 지갑의 보안 해체"][1199]
    • ["디스어셈블리 깨기 — 리눅스 프로그램의 심볼 해석을 악용한 라이브러리 호출 난독화"][1125]
    • ["Brother (MFC-J1010DW) 해킹: 겉보기엔 순진한 프린터의 세 가지 보안 결함"][1196]
    • ["Beestation 해킹: Pwn2Own 2025 익스플로잇 여정 내부"][1217]
    • ["음속 장벽 깨기 파트 I: Mach 메시지로 CoreAudio 퍼징"][1039]
    • ["깨진 신뢰: 수정된 Supermicro BMC 버그가 두 가지 새로운 취약점으로 새 생명을 얻다"][1179]
    • ["버그 테이머: 제한된 힙 오버플로를 완전한 VMware 탈출로 전환"][1209]
    • ["로그에 묻히다. 20년 된 NTFS 취약점 익스플로잇"][1124]
    • ["자동 TPM2 잠금 해제 시스템에서 디스크 암호화 우회"][1018]
    • ["CVE-2025-0072로 MTE 우회"][1105]
    • ["콜백 지옥: 콜백, 테일콜, 프록시 프레임을 악용한 스택 난독화"][1222]
    • ["사례 연구: macOS IONVMeFamily 드라이버 서비스 거부 문제 분석"][1040]
    • ["사례 연구: IOMobileFramebuffer NULL 포인터 역참조"][1041]
    • ["현재 아이슬란드 가정용 라우터 6종 에뮬레이션의 도전과 함정"][1107]
    • ["CimFS: 메모리에서 충돌, SYSTEM 찾기 (커널 에디션)"][1061]
    • ["리눅스 커널의 제어 흐름 하이재킹"][1114]
    • ["데이터 포인터를 통한 제어 흐름 하이재킹"][1085]
    • ["corCTF 2025 - corphone"][1168]
    • ["Pixel 8 해킹: 문서화되지 않은 DSP를 악용한 MTE 우회"][1212]
    • ["크로스 캐시 공격 치트시트"][1006]
    • ["CVE-2023-52927 - 잊힌 Syzkaller 리포트를 kCTF 익스플로잇으로 전환"][1118]
    • ["CVE-2024-30088 Windows 커널 공략 @ Pwn2Own Vancouver 2024 (Xbox 포함)"][1149]
    • ["CVE-2024-53141: Netfilter Ipset의 OOB 쓰기 취약점"][1065]
    • ["CVE-2025-23016 - FASTCGI 라이브러리 익스플로잇"][1086]
    • ["CVE-2025-37752 두 바이트의 광기: 0x0000으로 262636 바이트 아웃오브바운드 쓰기로 리눅스 커널 공략"][1076]
    • ["CVE-2025-38001 모든 Google kernelCTF 인스턴스와 Debian 12를 0-Day로 익스플로잇하여 $82k 획득: RBTree 가족 드라마"][1163]
    • ["CVE-2025-6554: (토끼) 굴"][1188]
    • ["KGDB를 통한 Pixel 8 커널 디버깅"][1123]
    • ["AST를 이용한 난독화된 NodeJS 멀웨어의 문자열 난독화 무력화"][1068]
    • ["Ruzzing의 거부: Windows 커널의 Rust"][1185]
    • ["더티 페이지플래그: 리눅스에서 PTE 익스플로잇 재조명"][1166]
    • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
    • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
    • ["바이너리 디스어셈블링: 선형 스윕과 재귀적 순회"][1019]
    • ["macOS 'AppleProcessHub' 스틸러 해부: 다단계 공격의 기술적 분석"][1047]
    • ["피싱하지 마, 실망시키지 마: FIDO 인증 다운그레이드"][1155]
    • ["EL3로 승격된 권한: Google WiFi Pro를 루트에서 EL3까지 글리칭"][1121]
    • ["QEMU에서 iPhone 에뮬레이션"][1051]
    • ["끝없는 익스플로잇: 아홉 번 타격당한 macOS 취약점의 사가"][1052]
    • ["익스플로잇 개발: Windows의 커널 모드 섀도 스택 조사"][1211]
    • ["AIxCC Nginx 버그 익스플로잇: 파트 I"][1035]
    • ["익스플로잇 워크스루와 기법 - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
    • ["QEMU의 13년 된 버그 익스플로잇"][1218]
    • ["더티 페이지테이블 기법을 통한 CVE-2024-0582 익스플로잇"][1081]
    • ["Samsung S23에서 CVE-2025-21479 익스플로잇"][1184]
    • ["실제 환경에서 Retbleed 익스플로잇"][1141]
    • ["Pwn2Own Ireland 2024에서 Synology TC500 익스플로잇"][1122]
    • ["TP-Link AX10 라우터의 제로데이(CVE-2025–9961) 취약점 익스플로잇"][1164]
    • ["Heroes of Might and Magic V 익스플로잇"][1119]
    • ["GrapheneOS 보안 할당자 탐구: 강화된 Malloc"][1167]
    • ["힙 익스플로잇 메커니즘 탐구: House of Force 기법 이해"][1029]
    • ["이터널 턱스: N-Day에서 리눅스 커널 KSMBD 0-클릭 RCE 익스플로잇 제작"][1172]
    • ["Synology 암호화 아카이브 추출 - Pwn2Own Ireland 2024"][1152]
    • ["거짓 주입: 물리학, 오해, 그리고 이상한 기계 이야기"][1120]
    • ["빠르고 결함 있는 - KGSL 폴트 처리의 Use After Free"][1182]
    • ["FiberGateway GR241AG - 전체 익스플로잇 체인"][1097]
    • ["Apple의 USB 제한 모드 우회(CVE-2025-24200) 첫 분석"][1058]
    • ["FLOP: 거짓 로드 출력 예측을 통한 Apple M3 CPU 해킹"][1059]
    • ["가상 메모리의 기초"][1162]
    • ["Chrome 렌더러 코드 실행에서 MSG_OOB를 통한 커널까지"][1153]
    • ["게임 해킹 - Valve Anti-Cheat (VAC)"][1074]
    • ["컨트롤러 속 유령: Supermicro BMC 펌웨어 검증 악용"][1215]
    • ["5초 만에 사라짐: WARN_ON이 10분을 훔친 방법"][1103]
    • ["Google CTF 2025 예선 라이트업"][1131]
    • ["에뮬레이션된 행성 해킹: Planet WGS-804HPT 산업용 스위치 취약점 사냥"][1031]
    • "XBox 360 하이퍼바이저 해킹"
      • [파트 1][1109]
      • [파트 2][1110]
    • ["Sonoff 스마트 홈 IoT 기기 해킹 - 추출, 수정, 부팅, 가로채기, 복제!"][1129]
    • ["Nokia Beacon 1 라우터 해킹: UART, 명령 주입, Qiling을 이용한 비밀번호 생성"][1198]
    • ["HITCON CTF 2025 -- calc"][1145]
    • ["WSC 역공학으로 휴가를 망친 방법"][1077]
    • ["o3를 사용하여 리눅스 커널 SMB 구현의 원격 제로데이 취약점 CVE-2025-37899를 찾은 방법"][1090]
    • ["얼마나 더 피를 흘려야 하는가? - Citrix NetScaler 메모리 노출 (CitrixBleed 2 CVE-2025-5777)"][1115]
    • "Hydroph0bia (CVE-2025-4275)"
      • ["Insyde H2O 기반 UEFI 호환 펌웨어의 사소한 SecureBoot 우회"][1143]
      • ["Insyde H2O 기반 UEFI 호환 펌웨어의 사소한 SecureBoot 우회 그 이상"][1144]
      • ["Insyde H2O 기반 UEFI 호환 펌웨어의 수정된 SecureBoot 우회"][1108]
    • ["메모리 내성 검사와 역공학을 위한 하이퍼바이저"][1099]
    • ["커널 익스플로잇 기법: (페이지) 테이블 뒤집기"][1100]
    • ["Kernel-hack-drill과 리눅스 커널에서 CVE-2024-50264를 익스플로잇하는 새로운 접근법"][1180]
    • ["Riot Vanguard의 디스패치 테이블 후크 내부"][1073]
    • ["Flutter에서 HTTPS 통신 가로채기: Frida로 풀 하드코어 모드 가기"][1079]
    • "iOS 17: 새로운 버전, 새로운 약어":
      • [파트 1][1042]
      • [파트 2][1043]
    • ["kASLR 내부 구조와 진화"][1095]
    • ["Kernel-Hack-Drill: 리눅스 커널 익스플로잇 개발 환경"][1082]
    • ["KernelSnitch: 커널 데이터 구조에 대한 사이드 채널 공격"][1005]
    • ksmbd (doyensec):
      • ["ksmbd 취약점 연구"][1033]
      • ["퍼징 개선과 취약점 발견"][1175]
      • ["CVE-2025-37947 익스플로잇"][1176]
    • ["예산 내 레이저 결함 주입: RP2350 에디션"][1017]
    • ["마지막 장벽 붕괴, 또는 Intel 보안 퓨즈용 퓨즈 암호화 키의 침해"][1072]
    • ["요리해 드릴게요, 취약점 하나: Thermomix TM5 익스플로잇"][1137]
    • ["바이너리 리프팅, 파트 0: VMProtect와 Themida 디버추얼라이징: 그냥 플래트닝인가?"][1147]
    • ["초보자를 위한 리눅스 커널 익스플로잇"][1113]
    • ["리눅스 커널 Hfsplus 슬랩 아웃오브바운드 쓰기"][1066]
    • ["루트킷 탐지를 위한 리눅스 커널 Rust 모듈"][1026]
    • ["Llama의 역설 - Llama.cpp 깊이 파헤치기와 Llama.cpp의 힙 미로 익스플로잇: 힙 오버플로에서 원격 코드 실행까지"][1011]
    • ["LunoBotnet: 모듈식 DDoS와 크립토재킹 기능을 갖춘 자가 치유 리눅스 봇넷"][1177]
    • ["Mali-cious Intent: GPU 취약점 익스플로잇 (CVE-2022-22706 / CVE-2021-39793)"][1050]
    • ["멀웨어가 다시 무료 패스를 받았다!"][1221]
    • ["MCTF 2025 - 라이트업 Sec Mem - Pwn"][1080]
    • ["mediatek? media-rekt가 더 어울리지, 그렇지."][1220]
    • ["Mindshare: Binary Ninja API를 사용한 잠재적 Use-after-free 취약점 탐지"][1069]
    • ["현대 (커널) 저단편화 힙 익스플로잇"][1127]
    • ["내 에뮬레이션이 달까지 간다... 거짓 깃발 전까지"][1094]
    • ["NASA cFS 버전 Aquila 소프트웨어 취약점 평가"][1056]
    • ["펌웨어 덤핑을 위한 nRF51 RBPCONF 우회"][1154]
    • ["Alibaba UC 브라우저의 원클릭 메모리 손상: 패치 갭 V8 취약점을 악용한 데이터 탈취"][1193]
    • ["이런! 커널 스택 use-after-free입니다: NVIDIA GPU 리눅스 드라이버 익스플로잇"][1186]
    • ["침해된 렌더러로부터 ANGLE CopyNativeVertexData의 아웃오브바운드 읽기"][1148]
    • ["v8에서의 Map 익스플로잇 개요"][1075]
    • ["파란색으로 칠하기: 블루투스 스택 공격"][1216]
    • ["$0으로 Google Container-Optimized OS 패치 갭 공격"][1032]
    • ["PatchGuard 내부 구조"][1092]
    • ["PerfektBlue 자동차 산업을 공략하는 범용 원클릭 익스플로잇"][1213]
    • ["Phoenix: 자기 교정 동기화를 통한 DDR5 로우해머 공격"][1170]
    • ["프린트 스캔 해킹: 여러 Brother 기기에서 여러 취약점 식별"][1136]
    • ["프로젝트 레인: L1TF"][1178]
    • ["Pwn2Own 2025: Lexmark의 Postscript 프로세서 공략"][1194]
    • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
    • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
    • ["pyghidra-mcp: 프로젝트 전체, 다중 바이너리 분석을 위한 헤드리스 Ghidra MCP 서버"][1134]
    • ["공유 객체 파일 작성 또는 바이트코드 파일 덮어쓰기를 통한 Python 더티 임의 파일 쓰기에서 RCE까지"][1087]
    • ["Qualcomm DSP 커널 내부 구조"][1135]
    • ["커널의 시계태엽 장치에서 시간과의 경쟁"][1160]
    • [".NET Native AOT 바이너리에서 메타데이터 복구"][1089]
    • ["신뢰할 수 있는 시스템 콜 가로채기"][1010]
    • ["WiFi를 통한 공간 히터 펌웨어 교체"][1020]
    • ["IDA Pro를 이용한 Hanwha 보안 카메라 펌웨어 파일 복호화 역공학"][1093]
    • ["더 나은 블루투스 보안 도구 및 교육을 위한 Realtek RTL8761B* 블루투스 칩 역공학"][1201]
    • ["TP-Link 라우터 취약점 역공학, 발견, 익스플로잇 — CVE-2024–54887"][1013]
    • ["Samsung의 H-Arx 하이퍼바이저 프레임워크 역공학 - 파트 1"][1036]
    • ["QardioArm 역공학"][1048]
    • ["버려진 취약점 되살리기: 제어 메타데이터 필드를 통한 이전에 익스플로잇 불가능했던 리눅스 커널 버그 익스플로잇"][1226]
    • ["modprobe_path 기법 되살리기: search_binary_handler() 패치 극복"][1071]
    • ["신용카드 단말기에서 루트 셸"][1112]
    • ["TP-Link Tapo C200 Rev.5 루팅"][1130]
    • ["ROP으로 RCE까지"][1028]
    • ["PAX 신용카드 결제 기기에서 코드 실행"][1272]
    • ["RV130X 펌웨어 분석"][1025]
    • ["투명성을 통한 보안: RP2350 해킹 챌린지 이야기"][1256]
    • ["smoltalk: 오픈 소스 에이전트의 RCE"][1045]
    • ["Solo: Pixel 6 Pro 이야기 (버그 하나면 충분할 때)"][1128]
    • ["SoK: EMV 비접촉 결제 시스템의 보안"][1088]
    • ["프로그래밍 언어 합성을 통한 데이터 지향 익스플로잇의 건전하고 효율적인 생성"][1034]
    • ["스택 오버플로, 힙 오버플로, 그리고 실존적 공포"][1150]
    • ["리눅스 스냅샷 퍼징의 현황"][1078]
    • ["STM32L05 전압 글리칭"][1111]
    • ["스마트 스피커로 제로파이 셸 스트리밍"][1096]
    • ["Singularity: 현대 스텔스 리눅스 커널 루트킷 깊이 파헤치기"][1228]
    • ["시스템 레지스터 하이재킹: 시스템 레지스터를 시스템에 역이용하여 커널 무결성 침해"][1197]
    • ["리눅스 커널 루트킷의 예술"][1008]
    • ["전자 여권 뒤의 암호학"][1214]
    • "Dirty COW의 진화":
      • [파트 1][1062]
      • [파트 2][1063]
    • ["Ubuntu의 비특권 네임스페이스 제한 우회 여정"][1116]
    • ["TLS NoVerify: 모든 것을 우회"][1165]
    • ["Tp-Link 라우터 심층 연구"][1203]
    • ["근원까지 추적하기 | SPTM 라운드 3"][1046]
    • ["카메라 감시를 축으로 돌리기"][1158]
    • ["매듭 풀기: 가정용 무선 메시 네트워크의 접근 제어 깨기"][1126]
    • ["정보 노출로 이어지는 Can BCM 서브시스템의 Use-After-Free 취약점 (CVE-2023-52922)"][1133]
    • ["VMware Workstation 게스트에서 호스트로 탈출"][1161]
    • ["우리는 ARM 무장했다, 더 이상 ROPpery는 없다"][1016]
    • "Wi-Fi SSID로 MT02 리피터에서 루트 권한을 얻을 때"
      • [파트 1][1156]
      • [파트 2][1157]
    • ["좋은 커널 방어가 나빠질 때: 방어 증폭 TLB 사이드 채널 누출을 통한 안정적이고 신뢰할 수 있는 커널 익스플로잇"][1067]
    • ["Windows arm64 내부 구조: 포인터 인증 해체"][1190]
    • ["Windows 힙 익스플로잇 - 힙 오버플로에서 임의 R/W까지"][1195]
    • "Windows 프로세스 간 통신 표면 너머의 깊이 파헤치기"
      • [파트 1][1204]
      • [파트 2][1205]
      • [파트 3][1206]
      • [파트 4][1207]
      • [파트 5][1208]
    • ["WireTap: DRAM 버스 개입을 통한 서버 SGX 해킹"][1183]
    • ["워크숍: 펌웨어 역공학"][1269]
    • ["Ghidra 프로세서 모듈 작성"][1064]
    • ["Sync 작성, Cron 터뜨리기: DEVCORE의 Synology BeeStation RCE와 새로운 SQLite 주입 RCE 기법 (CVE-2024-50629~50631)"][1247]
    • ["yIKEs (WatchGuard Fireware OS IKEv2 아웃오브바운드 쓰기 CVE-2025-9242)"][1210]
    • ["당신은 이미 우리의 개인 데이터를 가지고 있으니, 우리의 전화 통화도 가져가세요"][1140]
    • ["마이크로코드 해킹의 선과 예술"][1027]
    • ["Zyxel 라우터 취약점 연구 Zyxel DX3301-T0/EX3301-T0"][1227]

    2024- ["1-click Exploit in South Korea's biggest mobile chat app"][965]

    • ["4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"][959]
    • "64 bytes and a ROP chain – A journey through nftables":
      • [Part 1][865]
      • [Part 2][866]
    • "nix libX11: Uncovering and exploiting a 35-year-old vulnerability":
      • [Part 1][703]
      • [Part 2][704]
    • ["A few notes on AWS Nitro Enclaves: Images and attestation"][738]
    • "A first look at Android 14 forensics"
    • ["A "Gau-Hack" from EuskalHack"][893]
    • ["A Journey From sudo iptables To Local Privilege Escalation"][1009]
    • ["A Practical Guide to PrintNightmare in 2024"][709]
    • ["A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "][714]
    • ["A Trip Down Memory Lane"][715]
    • [AArch64 memory and paging][1015]
    • ["An Introduction to Chrome Exploitation - Maglev Edition"][882]
    • ["An unexpected journey into Microsoft Defender's signature World"][876]
    • ["Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"][952]
    • ["Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"][736]
    • ["AES-GCM and breaking it on nonce reuse"][912]
    • ["Analyzing Mutation-Coded - VM Protect and Alcatraz English"][834]
    • ["ARLO: I'M WATCHING YOU"][810]
    • ["ASLRn’t: How memory alignment broke library ASLR"][731]
    • ["Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"][911]
    • ["Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"][852]
    • ["Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"][1173]
    • "Base64 Beyond Encoding"
      • [Part 1][945]
      • [Part 2][946]
    • ["Becoming any Android app via Zygote command injection"][863]
    • ["Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"][895]
    • ["BGGP4: A 420 Byte Self-Replicating UEFI App For x64"][728]
    • ["Binary type inference in Ghidra"][905]
    • ["Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"][803]
    • ["Breaking the Barrier: Post-Barrier Spectre Attacks"][970]
    • ["Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"][987]
    • ["Breaking Down Multipart Parsers: File upload validation bypass"][966]
    • ["Breaking the Flash Encryption Feature of Espressif’s Parts"][589]
    • ["Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"][886]
    • ["Buying Spying Insights into Commercial Surveillance Vendors"][733]
    • ["Bypassing EDRs With EDR-Preloading"][716]
    • ["Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"][920]
    • "Chaining N-days to Compromise All":
      • [Part 1][836]
      • [Part 2][837]
      • [Part 3][838]
      • [Part 4][839]
      • [Part 5][840]
    • ["Check Point - Wrong Check Point (CVE-2024-24919)"][875]
    • ["Code injection on Android without ptrace"][874]
    • "CodeQL zero to hero": [Part 1][858] [Part 2][859] [Part 3][860] [Part 4][1191] [Part 5][1192]
    • ["Commonly Abused Linux Initial Access Techniques and Detection Strategies"][896]
    • ["Compiler Options Hardening Guide for C and C++"][877]
    • ["Continuously fuzzing Python C extensions"][734]
    • ["corCTF 2024: trojan-turtles writeup"][929]
    • ["corMine 1 and 2"][948]
    • ["Cross-Process Spectre Exploitation"][969]
    • ["CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"][861]
    • ["CVE-2022-2586 Writeup"][849]
    • ["CVE-2020-27786 ( Race Condition + Use-After-Free )"][967]
    • ["CVE-2022-4262"][864]
    • ["CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"][1012]
    • ["CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"][697]
    • ["Declawing PUMAKIT"][989]
    • [Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)][1003]
    • ["Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"][699]
    • ["Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"][683]
    • ["Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"][805]
    • ["Diving Deep into F5 Secure Vault"][918]
    • ["DJI - The ART of obfuscation"][705]
    • ["Docker Security – Step-by-Step Hardening (Docker Hardening)"][729]
    • ["Driving forward in Android drivers"][908]
    • ["Emulating RH850 architecture with Unicorn Engine"][853]
    • "Everyday Ghidra: Ghidra Data Types"
      • [Part 1][973]
      • [Part 2][974]
    • ["Exploit detail about CVE-2024-26581"][944]
    • ["Exploring AMD Platform Secure Boot"][701]
    • ["Exploring GNU extensions in the Linux kernel"][878]
    • ["Exploiting Android’s Hardened Memory Allocator"][1030]
    • ["Exploiting Empire C2 Framework"][723]
    • "Exploiting Enterprise Backup Software For Privilege Escalation":
      • [Part 1][906]
      • [Part 2][907]
    • "Exploiting Reversing (ER) series":
      • [Article 01][583]
      • [Article 02][584]
    • ["Exploiting Steam: Usual and Unusual Ways in the CEF Framework"][898]
    • ["Exploring object file formats"][684]
    • ["Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"][735]
    • ["Fault Injection Attacks against the ESP32-C3 and ESP32-C6"][590]
    • ["Fault Injection – Down the Rabbit Hole"][993]
    • "Finding Bugs in Kernel":
      • [Part 1][996]
      • [Part 2][997]
    • ["Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"][883]
    • ["Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"][804]
    • ["From fault injection to RCE"][990]
    • ["From object transition to RCE in the Chrome renderer"][940]
    • ["Fuzzing between the lines in popular barcode software"][968]
    • ["Gaining kernel code execution on an MTE-enabled Pixel 8"][808]
    • ["Ghidra nanoMIPS ISA module"][873]
    • ["Going Native - Malicious Native Applications"][842]
    • ["Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"][674]
    • ["GhostRace: Exploiting and Mitigating Speculative Race Conditions"][802]
    • ["GPUAF - Two ways of Rooting All Qualcomm based Android phones"][994]
    • ["GraphStrike: Anatomy of Offensive Tool Development"][712]
    • ["Hacking a 2014 tablet... in 2024!"][932]
    • ["Hacking a Smart Home Device"][691]
    • ["Hacking Android Games"][949]
    • ["Heap exploitation, glibc internals and nifty tricks"][938]
    • ["HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"][818]
    • ["Hi, My Name is Keyboard"][676]
    • ["Hiding Linux Processes with Bind Mounts"][925]
    • ["How I Also Hacked my Car"][976]
    • ["How to Bypass Golang SSL Verification"][941]
    • ["Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"][995]
    • "Hunting down the HVCI bug in UEFI"
    • "Hunting for Unauthenticated n-days in Asus Routers"
    • "Iconv, Set the Charset to RCE":
      • [Part 1][870]
      • [Part 2][871]
    • ["Java Deserialization Tricks"][815]
    • ["JTAG Hacking with a Raspberry Pi"][851]
    • ["Kuiper Ransomware’s Evolution"][702]
    • ["Inside a New OT/IoT Cyberweapon: IOCONTROL"][1001]
    • ["Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"][692]
    • ["Introduction to Fuzzing Android Native Components"][984]
    • "Learning LLVM":
      • [Part 1][934]
      • [Part 2][935]
    • ["LeftoverLocals: Listening to LLM responses through leaked GPU local memory"][687]
    • "Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"
    • ["Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"][999]
    • "Linux Kernel Exploitation":
      • ["Environment"][922]
      • ["ret2usr"][923]
    • ["Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"][939]
    • "ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs":
      • [Part 1][901]
      • [Part 2][902]
      • [Part 3][903]
    • ["Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"][809]
    • ["Mali GPU Kernel LPE"][786]
    • ["MalpediaFLOSSed"][814]
    • ["Microsoft BitLocker Bypasses are Practical"][718]
    • ["Modern implant design: position independent malware development"][690]
    • ["My new superpower"][688]
    • ["Not the Drones You're Looking For"][825]
    • "Operation triangulation":
      • ["Keychain module analysis"][823]
      • ["audio module analysis"][824]
    • ["OtterRoot: Netfilter Universal Root 1-day"][986]
    • ["Out-of-bounds read & write in the glibc's qsort()"][698]
    • ["PageJack: A Powerful Exploit Technique With Page-Level UAF"][951]
    • ["Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code Pages"][1000]
    • ["Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"][835]
    • ["Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"][983]
    • ["PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"][711]
    • "Playing with libmalloc in 2024"
    • ["Puckungfu 2: Another NETGEAR WAN Command Injection"][730]
    • ["Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"][910]
    • ["Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"][933]
    • ["Pwning browsers like a kernel"][957]
    • "Pwn2Own: WAN-to-LAN Exploit Showcase":
      • ["Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"][950]
      • ["Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"][942]
    • "Pwn2Own Toronto 2023":
      • ["How it all started"][829]
      • ["Exploring the Attack Surface"][830]
      • ["Exploration"][831]
      • ["Memory Corruption Analysis"][832]
      • ["The Exploit"][833]
    • ["Pwning a Brother labelmaker, for fun and interop!"][897]
    • "Pwntools 10x":
      • [Part 1][867]
      • [Part 2][868]
      • [Part 3][869]
    • ["Pygmy Goat"][972]
    • ["Recovering an ECU firmware using disassembler and branches"][921]
    • ["regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"][919]
    • ["Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"][846]
    • ["Retrofitting encrypted firmware is a Bad Idea"][1024]
    • ["Reverse engineering a car key fob signal "][801]
    • ["Reverse Engineering and Dismantling Kekz Headphones"][962]
    • ["Reverse Engineering Protobuf Definitions From Compiled Binaries"][820]
    • ["Reverse engineering the 59-pound printer onboard the Space Shuttle"][943]
    • ["Reverse Engineering the AM335x Boot ROM"][947]
    • ["Reverse Engineering The Stream Deck Plus"][1004]
    • "Ring Around The Regex"
      • [Part 1][955]
      • [Part 2][956]
    • ["RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"][958]
    • ["RomCom exploits Firefox and Windows zero days in the wild"][981]
    • ["ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"][892]
    • ["Route to Safety: Navigating Router Pitfalls"][816]
    • ["Rooting a Hive Camera"][819]
    • ["SAME70 Emulator"][879]
    • "Say Friend and Enter":
      • [Part 1][812]
      • [Part 2][813]
    • ["Samsung NX related posts"][887]
    • ["Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"][975]
    • ["SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"][862]
    • ["SELinux bypasses"][963]
    • ["SLUB Internals for Exploit Developers"][980]
    • ["SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"][937]
    • ["Shell We Assemble?"][689]
    • ["Shellcode evasion using WebAssembly and Rust"][726]
    • "SMM isolation":
      • ["SMI deprivileging (ISRD)"][847]
      • ["Security policy reporting (ISSR)"][848]
    • ["SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"][1049]
    • ["Strengthening the Shield: MTE in Heap Allocators"][596]
    • ["Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"][913]
    • ["The architecture of SAST tools: An explainer for developers"][739]
    • ["The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"][880]
    • ["The Definitive Guide to Linux Process Injection"][971]
    • ["The 'Invisibility Cloak' - Slash-Proc Magic"][924]
    • ["The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"][1007]
    • ["The rev.ng decompiler goes open source + start of the UI closed beta"][694]
    • ["The tale of a GSM Kernel LP"][850]
    • ["The Wild West of Proof of Concept Exploit Code (PoC)"][926]
    • "The Windows Registry Adventure":
      • [Part 1][914]
      • [Part 2][915]
      • [Part 3][916]
    • ["TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"][894]
    • ["Tony Hawk’s Pro Strcpy"][928]
    • ["Toolchain Necromancy: Past Mistakes Haunting ASLR"][732]
    • ["TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"][988]
    • ["TP-Link TDDP Buffer Overflow Vulnerability"][695]
    • ["Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"][787]
    • ["Understanding AddressSanitizer: Better memory safety for your code"][889]
    • ["Understanding Unix Garbage Collection and its Interaction with io_uring"][891]
    • ["Understanding Windows x64 Assembly"][693]
    • ["Using Symbolic Execution to Devirtualise a Virtualised Binary"][936]
    • ["Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"][985]
    • ["VBA: having fun with macros, overwritten pointers & R/W/X memory"][843]
    • ["Vulnerabilities of Realtek SD card reader driver"][1002]
    • ["Why Code Security Matters - Even in Hardened Environments"][953]
    • ["Windows Secure-Launch on Qualcomm devices"][811]
    • ["Windows Sockets: From Registered I/O to SYSTEM Privileges"][998]
    • ["Windows vs Linux Loader Architecture"][844]
    • ["Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"][954]
    • "Writing a Debugger From Scratch"
      • ["Attaching to a Process"][449]
      • ["Register State and Stepping"][450]
      • ["Reading Memory"][451]
      • ["Exports and Private Symbols"][452]
      • ["Breakpoints"][453]
      • ["Stacks"][454]
      • ["Disassembly"][455]
    • ["Writing a system call tracer using eBPF"][931]
    • ["Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"][854]
    • ["x64 Return Address Spoofing"][991]
    • ["x64 Call Stack Spoofing"][992]

    2023- ["Brute Ratel C4 페이로드 심층 분석"][374]

    • ["macOS 애플리케이션 침투 테스트 심층 분석 (파트 1)"][49]

    • "TPM 기반 BitLocker 드라이브 암호화 심층 분석"

    • ["Pwn2own Automotive EV 충전기 하드웨어 상세 분석"][537]

    • ["LibAFL 입문 워크숍"][826]

    • ["CVE-2023-29360 살펴보기, 아름다운 논리적 LPE 취약점"][260]

    • ["Google Search Appliance 해킹 여정"][203]

    • ["파일 기반 DirtyCred를 이용한 새로운 컨테이너 탈출 기법"][201]

    • ["NAS의 고통: 클라우드 연결성을 악용하여 NAS를 PWN하다: Synology DS920+ 에디션"][273]

    • ["SoC에서의 포트홀링 투어"][189]

    • "Windows 초보자를 위한 PCIe 실전 튜토리얼":

      • [파트 1][806]
      • [파트 2][807]
    • ["TOCTOU 신고 경쟁: Intel SMM에서의 버그 충돌 분석"][255]

    • ["레드팀원의 일기"][156]

    • ["EDR 변조에 관한 이야기"][293]

    • ["Liftoff 어셈블리 악용 및 sbx에서의 효율적인 탈출"][677]

    • ["Use-After-Free 읽기를 통한 RCU 콜백 악용으로 KASLR 무력화"][857]

    • ["문서화되지 않은 기능을 악용한 PE 섹션 헤더 스푸핑"][139]

    • ["Steam에서의 원격 코드 실행 달성: Remote Play 프로토콜 탐험"][587]

    • ["LeakSanitizer 완전 정복"][460]

    • ["모든 경찰이 방송 중: TETRA 심층 분석"][237]

    • ["내가 가장 좋아하는 트레이싱 도구들: eBPF, QEMU, Perfetto, 그리고 내가 만든 새로운 도구들"][513]

    • ["실제 공격에서 발견된 iOS Safari WebContent에서 GPU 프로세스로의 익스플로잇 분석"][392]

    • ["스택 스푸핑 입문"][580]

    • ["인간이 운영하는 랜섬웨어에서 악용된 합법적 도구 분석"][4]

    • "Citrix ADC 및 NetScaler Gateway의 CVE-2023-3519 분석":

      • [파트 1][196]
      • [파트 2][197]
    • ["VirtualBox CVE-2023-21987 및 CVE-2023-21991 분석"][119]

    • ["최신 실제 공격에서 발견된 Android 익스플로잇 분석"][379]

    • ["NETGEAR 라우터에서 오래된 Netatalk dsi_writeinit 버퍼 오버플로 취약점 분석"][326]

    • "ARM64 리버싱 및 익스플로잇" (8ksec)

      • [파트 1][107]
      • [파트 2][108]
      • [파트 3][109]
      • [파트 4][110]
      • [파트 5][111]
      • [파트 6][112]
      • [파트 7][113]
      • [파트 8][388]
      • [파트 9][389]
      • [파트 10][390]
    • "EDR 공격하기"

      • [파트 1][395]
      • [파트 2][396]
    • "웹 관점에서의 IoT 기기 공격"

    • ["JS 엔진 공격: 메모리 손상 크래시 이해를 위한 기초"][720]

    • ["임베디드 Linux 교육이 포함된 오디오"][267]

    • ["Terraform, Nebula, Caddy 및 Cobalt Strike를 이용한 C2 인프라 자동화"][300]

    • ["b3typer - bi0sCTF 2022"][554]

    • ["플랫폼 보안과 함께하는 미래로의 회귀"][97]

    • ["Parallel Desktop의 Bash 권한 모드 취약점과 MacOS의 CDPATH 처리"][100]

    • ["Bee-yond Capacity: Extreme Networks/Aerohive 무선 AP의 인증 없는 RCE - CVE-2023-35803"][91]

    • ["방패 뒤편: Scudos의 방어 체계 해부"][8]

    • ["BlackLotus UEFI 부트킷: 사실로 확인되다"][429]

    • "BLUFFS: 블루투스 순방향 및 미래 비밀성 공격과 방어"

    • ["Volatility 3를 이용한 BPF 메모리 포렌식"][881]

    • ["Fortinet 펌웨어 암호화 깨기"][233]

    • ["코드 깨기 - cls_tcindex 분류기 취약점 CVE-2023-1829 익스플로잇 및 분석"][81]

    • ["Silicon Labs Gecko 플랫폼에서 보안 부팅 깨기"][262]

    • ["macOS용 커스텀 Mach-O 메모리 로더 구축"][523]

    • ["FortiGate 취약점 CVE-2023-27997 익스플로잇 개발"][475]

    • ["elf roping을 통한 noexec 우회"][528]

    • ["유저랜드에서의 PPL 우회 (다시)"][308]

    • ["init_module을 이용한 SELinux 우회"][494]

    • "C101101: D-Link DIR-865L":

      • ["원격 코드 실행 (인증 전)"][599]
      • ["서명되지 않은 펌웨어 업로드로 인한 지속적 백도어 (인증 전)"][600]
      • ["메모리 손상으로 인한 원격 코드 실행 (인증 전)"][601]
    • ["CAN 인젝션: 키리스 자동차 도난"][195]

    • "chonked"

      • ["minidlna 1.3.2 http 청크 파싱 힙 오버플로 (cve-2023-33476) 근본 원인 분석"][193]
      • ["원격 코드 실행을 위한 cve-2023-33476 익스플로잇"][194]
    • ["Chromium V8 힙 샌드박스에서의 코드 실행"][896]

    • ["Coffee: Rust로 만든 COFF 로더"][93]

    • ["Pwn2Own ICS 2022 Miami 참가기: ICONICS Genesis64의 제로 클릭 원격 메모리 손상 익스플로잇"][397]

    • ["io_uring을 통한 메모리 정복 - CVE-2023-2598 분석"][528]

    • "HEVD로 Windows 커널 공략하기"

      • "챕터 0"
      • "챕터 1"
      • "챕터 2"
      • "챕터 3"
      • "챕터 4"
    • ["계산기 띄우기: Linux 익스플로잇 개발 입문"][534]

    • "Sliver 커스터마이징":

      • [파트 1][603]
      • 파트 2
      • 파트 3
    • "CVE-2022-27666: 내 파일, 네 메모리"

    • ["CVE-2023-0179: nftables의 Linux 커널 스택 버퍼 오버플로: PoC 및 분석"][567]

    • ["CVE-2023-2008 - udmabuf 드라이버의 버그 분석 및 익스플로잇"][72]

    • ["CVE-2023-23504: dlil.c의 XNU 힙 언더라이트"][543]

    • ["CVE-2023-26258 – ArcServe UDP Backup의 원격 코드 실행"][99]

    • ["CVE-2023-36844 그리고 친구들: Juniper 기기의 RCE"][281]

    • ["CVE-2023-38408: OpenSSH의 포워딩된 ssh-agent에서의 원격 코드 실행"][186]

    • ["cURL 감사: 농담이 중대한 발견으로 이어진 이야기"][459]

    • ["D^ 3CTF2023 d3kcache: null-byte 크로스 캐시 오버플로에서 무한 임의 읽기 및 쓰기까지"][964]

    • ["Ghidra 디버거 클래스"][28]

    • ["D-Link 디버깅: 펌웨어 에뮬레이션과 하드웨어 해킹"][290]

    • ["디컴파일 디버깅"][508]

    • ["OT 네트워크에서의 심층 측면 이동: 언제 경계가 경계가 아닌가?"][253]

    • ["Cobalt Strike 리플렉티브 로더 정의하기"][320]

    • ["비트 연산 이해하기, 친절한 C 튜토리얼"][400]

    • ["Sliver C2 탐지 및 복호화 – 위협 헌터 가이드"][480]

    • ["BPF 필터를 악용하는 BPFDoor 백도어 변종 탐지"][183]

    • ["Dirty Pagetable: Linux 커널을 지배하는 새로운 익스플로잇 기법"][51]

    • ["TCP/IP RCE 취약점 'EvilESP' 분석 및 익스플로잇"][164]

    • ["스마트 컨트랙트 디컴파일 탐구"][204]

    • ["Starlink 사용자 단말기 펌웨어 탐구"][268]

    • "DJI Mavic 3 드론 연구"

      • ["펌웨어 분석"][376]
      • ["취약점 분석"][713]
    • ["드론 보안과 결함 주입 공격"][82]

    • "DualShock4 리버스 엔지니어링":

      • [파트 1][149]
      • [파트 3][150]
      • [파트 3][151]
    • "eBPF: 멀웨어의 새로운 개척지"

    • ["IoT 펌웨어 에뮬레이션 쉽게 하기: 물리적 기기 없이 해킹 시작하기"][47]

    • ["암호화되었다고 인증된 것은 아니다: ShareFile RCE (CVE-2023-24489)"][182]

    • ["ENLBufferPwn (CVE-2022-47949)"][422]

    • ["데이터 전용 익스플로잇으로 Google kCTF 컨테이너 탈출하기"][178]

    • ["제한적인 청크 크기에서의 커널 풀 오버플로 익스플로잇 (CVE-2021-31969)"][827]

    • ["Openfire CVE-2023-32315 익스플로잇"][283]

    • ["Windows CryptoAPI의 치명적 스푸핑 취약점 익스플로잇"][572]

    • ["Windows 유저 모드 프린터 드라이버의 비트맵 처리 결함 익스플로잇"][130]

    • ["컨테이너 탈출을 위한 CVE-2021-3490 익스플로잇"][552]

    • ["Linux 커널에서의 null-dereference 익스플로잇"][148]

    • ["iOS 커널 익스플로잇 프리미티브를 위한 UNIX 파이프 탐구"][514]

    • ["EPF: Evil Packet Filter"][73]

    • ["Bhyve에서 탈출하기"][192]

    • ["ESP32-C3 무선 모험: IoT 종합 가이드"][69]

    • ["Espressif ESP32: 전자기 분석으로 HW AES 깨기"][394]

    • ["Espressif ESP32: 전력 분석으로 HW AES 깨기"][393]

    • ["OpenSSH 샌드박싱과 권한 분리 검토 – 공격 표면 분석"][324]

    • ["읽기 전용 파일 시스템에서 임의 코드 및 실행 파일 실행하기"][52]

    • ["익스플로잇 엔지니어링 – Linux 커널 공격"][146]

    • ["커스텀 TCP 스택을 이용한 원격 힙 오버플로 익스플로잇"][322]

    • ["Hell's Gate 탐구"][594]

    • ["Zig로 Linux 커널 버그 익스플로잇"][597]

    • ["HTTP 파서 불일치 익스플로잇"][391]

    • ["CVE-2023-30799로 MikroTik RouterOS 하드웨어 익스플로잇"][198]

    • ["Jemalloc 'New'에서의 Android 힙 할당 탐구"][7]

    • ["Linux의 새로운 랜덤 Kmalloc 캐시 탐구"][511]

    • "링커 출력에서의 섹션 레이아웃 탐구"

    • "환상적인 루트킷: 그리고 어디서 찾을 수 있는가":

      • [파트 1][275]
      • [파트 2][276]
      • [파트 3][277]
    • ["덜 알려진 C의 트릭, 특이점 및 기능들"][354]

    • ["3000달러를 위한 LOL을 이용한 프로세스 킬러 드라이버 발견 및 익스플로잇"][172]

    • ["Multi-Level IR과 VAST를 이용한 C 코드 버그 찾기"][92]

    • ["정적 분석 도구를 이용한 CPU 사이드 채널용 가젯 찾기"][75]

    • ["과학을 위하여! - EDK II의 평범한 버그를 이용한 재미있는 익스플로잇"][70]

    • ["FortiNAC - 몇 가지 더 많은 RCE"][95]

    • ["Fortinet 시리즈 3 — CVE-2022–42475 SSLVPN 익스플로잇 전략"][32]

    • ["프레임 구성하기: 전송 큐 조작을 통한 Wi-Fi 암호화 우회"][90]

    • ["C와 인라인 어셈블리에서 셸코드까지"][235]

    • "퍼징 팜":

      • ["fuzzuf로 GEGL 퍼징하기"][43]
      • ["퍼저의 성능 평가"][44]
      • ["패치 분석 및 PoC 개발"][45]
      • ["0-day 헌팅 및 익스플로잇 [CVE-2022-24834]"][46]
    • "재미와 패닉을 위한 Golang msgpack 퍼징"

    • ["Maglev 컴파일러의 불완전한 객체 초기화로 Chrome에서 RCE 얻기"][486]

    • "Ghidra" (Craig Young):

      • ["Ghidra로 공유 객체 리버싱 가이드"][121]
      • ["Ghidra 디컴파일러로 간단한 CrackMe 리버싱"][122]
      • ["Ghidra를 이용한 취약점 헌팅"][123]
      • ["Ghidra 리스팅에서 버그 패치하기"][124]
      • ["Ghidra 스크립팅을 이용한 취약점 분석"][125]
    • ["전선 속의 유령, 벽 속의 소닉 - SonicWall과의 모험"][481]

    • ["Google Chrome V8 ArrayShift 경쟁 조건 원격 코드 실행"][530]

    • ["Tapo TC60 카메라 해킹"][350]

    • ["Amazon eero 6 해킹 (파트 1)"][86]

    • ["Brightway 스쿠터 해킹: 사례 연구"][29]

    • ["ICS Historian 해킹: IT에서 OT로의 전환점"][444]

    • ["Nintendo DSi 브라우저 해킹"][456]

    • ["BIOS 비밀번호 우회를 위한 하드웨어 해킹"][5]

    • ["주의! Xdr33, CIA의 HIVE 공격 키트 변종 등장"][443]

    • ["간단한 K-TypeConfusion이 익스플로잇을 만드는 데 3개월이 걸린 이유? [HEVD] - Windows 11 (빌드 22621)"][240]

    • ["Linux는 어떻게 프로세스를 시작하는가"][501]

    • "NAT의 작동 방식":

      • [파트 1][152]
      • [파트 2][153]
      • [파트 3][154]
      • [파트 4][155]
    • "내 차를 해킹한 방법":

      • [파트 1][101]
      • [파트 2][102]
      • [파트 3][103]
      • [파트 4][104]
      • [파트 5][105]
      • [파트 6][106]
    • ["스마트 조명 해킹: CVE-2022-47758 비하인드 스토리"][841]

    • ["Qiling을 이용한 Android 네이티브 라이브러리 에뮬레이션 방법"][482]

    • ["전압 결함 주입 방법"][685]

    • ["Linux 서버 보안 방법"][140]

    • "취약한 커널 드라이버 헌팅"

    • ["Icicle: 그레이박스 펌웨어 퍼징을 위한 재설계된 에뮬레이터"][171]

    • ["Valorant의 Guarded Regions 심층 분석"][141]

    • ["메모리 전용 ELF 실행 (tmpfs 없이)"][355]

    • ["Intel BIOS 권고 – HID 드라이버의 메모리 손상"][257]

    • ["Global Allocator로 할당 가로채기"][79]

    • "Cutter 입문"

    • ["SELinux 소개"][59]

    • "IoT 시리즈":

      • ["사람들은 준비가 되었는가?"][465]
      • ["커널 이미지를 처음부터 빌드하는 방법"][466]
      • ["QEMU에서의 펌웨어 테스트"][467]
      • ["GDB & GHIDRA + 제로데이로 디버깅"][468]
    • ["2023년에 오리지널 Xbox JTAG '해킹'"][244]

    • ["커널 익스플로잇 팩토리"][159]

    • ["가장 맛있는 예제로 Makefile 배우기"][24]

    • ["모든 것을 훔치는 Chrome 확장 프로그램을 만들어보자"][463]

    • ["토끼굴로 들어가 보자 — Golang 프로그램을 동적으로 후킹하는 과제"][387]

      • [파트 1][387]
      • [파트 2][904]
      • [파트 3][930]
    • ["임의 실행(및 권한 상승)을 위한 ssh-keygen 활용"][327]

    • "lexmark 프린터 해킹"

    • [linux-re-101][169]

    • ["Linux 디버깅, 프로파일링 및 트레이싱 교육"][353]

    • "Linux 커널 익스플로잇"

      • ["시작하기 & BOF"][678]
      • ["힙 기법"][679]
      • ["경쟁 조건 + UAF 익스플로잇"][680]
    • "Linux 커널 PWN":

      • ["ret2dir"][899]
      • ["DirtyCred"][900]
    • ["KSMBD 내 Linux 커널 인증 없는 원격 힙 오버플로"][544]

    • ["Linux 커널 교육"][131]

    • ["Linux 멀웨어: 방어 회피 기법"][165]

    • "Linux 레드팀":

      • ["익스플로잇 기법"][222]
      • ["권한 상승 기법"][223]
      • ["지속성 기법"][224]
    • ["Linux 원격 프로세스 인젝션 - (firefox 프로세스에 인젝션하기)"][569]

    • ["Linux 루트킷 해설 – 파트 1: 동적 링커 하이재킹"][60]

    • ["Linux 셸코드 101: 지옥에서 셸까지"][53]

    • ["DJI RM500 스마트 컨트롤러의 로컬 권한 상승"][160]

    • "Lord Of The Ring0":

      • [파트 1][10]
      • [파트 2][11]
      • [파트 3][12]
      • [파트 4][13]
      • [파트 5][14]
    • ["컴파일러 개발자를 위한 저수준 소프트웨어 보안"][15]

    • ["RenderDoc의 LPE와 RCE: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"][202]

    • ["TOCTOU를 다시 위대하게 – X(R)IP"][474]

    • "초보자를 위한 멀웨어 리버스 엔지니어링":

      • [파트 1][128]
      • [파트 2][129]
    • ["로그 AP 없는 중간자 공격: WPA가 ICMP 리다이렉트를 만날 때"][285]

    • "mast1c0re"

      • ["소개 – 게임 세이브를 통한 PS4 및 PS5 익스플로잇"][38]
      • ["파트 1 – PS2 게임 세이브 파일 수정"][39]
      • ["파트 2 – 임의 PS2 코드 실행"][40]
      • ["파트 3 – 에뮬레이터 탈출"][41]
    • ["Mélofée: Panda의 도구 세트에 등장한 Linux 호스트를 겨냥한 새로운 외계 멀웨어"][330]

    • ["Meterpreter vs 현대 EDR"][170]

    • "구현된 MTE":

      • [파트 1][366]
      • [파트 2][367]
    • ["mTLS: 인증서 인증이 잘못되었을 때"][270]

    • ["MSMQ QueueJumper (RCE 취약점): 심층 기술 분석"][177]

    • ["Qualcomm 및 Lenovo ARM 기반 기기의 다중 취약점"][404]

    • "NetGear 시리즈: Netgear R6700V3 circled 바이너리 에뮬레이션":

      • [파트 1][441]
      • [파트 2][442]
    • ["새로운 HiatusRAT 라우터 멀웨어, 은밀하게 피해자 감시"][402]

    • ["No Alloc, No Problem: 프로세스 인젝션을 위한 프로그램 진입점 활용"][1091]

    • ["NVMe: 새로운 취약점 쉽게 만들기"][264]

    • ["nftables 모험: 버그 헌팅과 N-day 익스플로잇 (CVE-2023-31248)"][365]

    • ["잘 알려지지 않은 Windows 파일 형식"][74]

    • ["오래된 버그, 얕은 버그: Pwn2own Vancouver 2023에서 Ubuntu 익스플로잇"][254]

    • ["한 방에 트리플 킬"][700]

    • "OPC UA 심층 분석 시리즈":

      • [파트 1][211]
      • [파트 2][212]
      • [파트 3][213]
      • [파트 4][214]
      • [파트 5][215]
    • ["OpenSSH 인증 전 Double Free CVE-2023-25136 – 분석 및 개념 증명"][42]

    • ["OrBit: Linux 전용 멀웨어 심층 분석"][427]

    • ["OrBit: 실행 흐름의 독특한 하이재킹을 사용하는 새로운 미탐지 Linux 위협"][428]

    • ["P2PInfect: Rust로 작성된 P2P 자기 복제 웜"][206]

    • ["P4wnP1-LTE"][209]

    • ["패치, 충돌, 그리고 루트 셸: Pwn2Own 모험"][278]

    • ["패치 화요일 -> 익스플로잇 수요일: 24시간 만에 WinSock 보조 함수 드라이버 (afd.sys) 공략"][297]

    • ["지속되는 지속성 기법"][299]

    • ["BLE GATT 리버스 엔지니어링 실전 입문: Domyos EL500 해킹"][166]

    • ["prctl anon_vma_name: 재미있는 Linux 커널 힙 스프레이"][184]

    • ["CVE-2022-42475 (Fortinet RCE) PoC 제작"][323]

    • ["의도하지 않은 노출로부터 Android 클립보드 콘텐츠 보호"][448]

    • "피닉스 보호하기: Phoenix Contact HMI의 치명적 취약점 공개"

      • [파트 1][477]
      • [파트 2][478]
      • [파트 3][479]
    • "Python의 프로토타입 오염"

    • ["PSPRAY: 타이밍 사이드 채널 기반 Linux 커널 힙 익스플로잇 기법"][758]

    • ["PyLoose: Python 기반 파일리스 멀웨어가 클라우드 워크로드를 대상으로 크립토마이너 전달"][98]

    • ["PwnAgent: CVE-2023-24749를 이용한 Netgear RAX 라우터의 원클릭 WAN 측 RCE"][318]

    • "Pwnassistant - Home Assistant RCE를 통한 /home 제어"

    • ["남은 패치로 Pixel 6 공략하기"][310]

    • ["tp-link ax1800 wifi 6 라우터 공략: 메모리 손상 취약점 발견 및 익스플로잇"][309]

    • ["잠금과의 경쟁: Android 커널의 스핀락 UAF 익스플로잇"][185]

    • ["Readline 범죄: SUID 로직 버그 익스플로잇"][439]

    • ["레드 vs 블루: Kerberos 티켓 시간, 체크섬, 그리고 당신!"][30]

    • ["Reptar"][527]

    • ["Dyld 메모리 로딩 복원"][522]

    • ["AMLogic A113X TrustZone 익스플로잇 과정 재조명"][77]

    • ["영국 모바일 철도 티켓 리버싱"][551]

    • "Windows 컨테이너 리버싱":

      • [파트 1][821]
      • [파트 2][822]
    • ["RISC-V 바이트: 커스텀 ESP32 부트로더 탐구"][493]

    • ["REUnziP: FaultyUSB로 Huawei 복구 모드 재익스플로잇"][364]

    • ["CVE-2017-11176 재조명"][48]

    • "FiiO M6 루팅":

      • ["'세계 최악의 퍼저'를 이용한 커널 버그 찾기"][499]
      • ["오버플로 버그를 위한 LPE 익스플로잇 작성"][500]
    • ["Xiaomi WiFi 라우터 루팅"][817]

    • ["Rust 바이너리 분석, 기능별로"][231]

    • ["Rust에서 어셈블리까지: Rust의 내부 동작 이해"][134]

    • "Linux를 Rust로 안전하게 만들기":

      • [파트 1][575]
      • [파트 2][576]
      • [파트 3][577]
      • [파트 4][578]
    • ["scudo Hardened Allocator — 비공식 내부 문서"][706]

    • "홈 랩 보안: Frigate 코드 리뷰"

    • "홈 랩 보안: Home Assistant 코드 리뷰"

    • ["SHA-1이 SHAttered되다"][325]

    • ["Shambles: 0-Day 취약점을 발견하는 차세대 IoT 리버스 엔지니어링 도구"][55]

    • ["유령 속의 셸: Ghostscript CVE-2023-28879 분석"][76]

    • ["경계 이동: Apple Safari의 정수 오버플로 익스플로잇"][261]

    • ["자신의 .flags에 발을 쏘기 – Sonos Era 100 탈옥"][531]

    • ["스마트 스피커 소동: Sonos ONE이 비밀을 노래하게 만들기"][504]

    • ["상태 머신 부수기: 웹 경쟁 조건의 진정한 잠재력"][271]

    • ["Linux 페이지 캐시에 대한 SRE 심층 분석"][94]

    • ["Sshimpanzee"][16]

    • ["Insyde 시스템 관리 모드 진입"][256]

    • ["Sudo <= 1.9.12p1 CVE-2023-22809의 Sudoedit 우회"][562]

    • ["THC가 가장 좋아하는 팁, 트릭 & 해킹 (치트 시트)"][31]

    • ["ARM32 스케줄링과 커널 공간/유저 공간 경계"][512]

    • ["퍼징의 예술: 소개"][57]

    • ["퍼징의 예술: Windows 바이너리"][89]

    • ["퍼징의 예술 - LibFuzzer를 이용한 커버리지 기반 퍼징 단계별 가이드"][54]

    • ["Linux 지속성의 예술"][872]

    • ["AFL++를 이용한 퍼징 Blitz 튜토리얼 랩"][303]

    • ["거기 없던 코드: 우연히 Android 기기에서 메모리 읽기"][462]

    • ["카마로를 판 드래곤: 커스텀 라우터 임플란트 분석"][228]

    • ["네트워크 분석에서 리버스 엔지니어링의 중요성"][426]

    • ["Linux 커널 모듈 프로그래밍 가이드"][3]

    • ["세계에서 가장 위험한 코덱: H.264 디코더의 취약점 발견 및 익스플로잇"][284]

    • ["정적 분석에서 제어 흐름 그래프의 역할"][509]

    • ["우리 사이의 침묵하는 스파이: 스마트 인터콤 공격"][331]

    • ["스택 시리즈: X64 스택"][356]

    • ["BlackLotus UEFI 부트킷의 숨겨진 이야기"][205]

    • ["ksmbd 간지럽히기: Linux 커널에서 SMB 퍼징"][386]

    • ["도구 공개: Cartographer"][371]

    • ["완전한 신원 침해: Active Directory 보안에 관한 Microsoft 사고 대응 교훈"][445]

    • ["Xortigate, 또는 CVE-2023-27997 - 소문으로만 돌던 RCE의 실체"][80]

    • ["당신의 그렇지 않은 '홈 오피스' - Pwn2Own에서의 SOHO 해킹"][5]

    • ["Ubuntu Shiftfs: 불균형 언락 익스플로잇 시도"][524]

    • ["RIGOL 오실로스코프의 인증 없는 RCE"][210]

    • ["UNCONTAINED: Linux 커널의 컨테이너 혼란 파헤치기"][37]

    • ["Chrome 확장 프로그램에서의 놀라운 권한 상승 발견"][502]

    • ["HinataBot 파헤치기: Go 기반 위협 심층 분석"][311]

    • ["후드 아래 - IKEA-Sonos Symfonisk 스피커 램프 분해"][180]

    • ["Meterpreter 및 기타 게스트와 함께하는 페이로드의 생애 이해"][315]

    • ["Dirty Pagetable 이해하기 - m0leCon Finals 2023 CTF 라이트업"][591]

    • ["힙 이해하기 - 아름다운 혼돈"][348]

    • ["ksmbd 해방하기: Linux 커널의 원격 익스플로잇 제작"][828]

    • ["ksmbd 해방하기: Linux 커널의 원격 익스플로잇 (ZDI-23-979, ZDI-23-980)"][533]

    • ["무한한 결과: ESP32-V3의 펌웨어 암호화 깨기"][598]

    • "ESP32의 비밀 공개":

      • "오픈소스 MAC 계층 만들기"
      • "RX 리버스 엔지니어링"
    • "웹 해커 vs 자동차 산업: Ferrari, BMW, Rolls Royce, Porsche 등의 치명적 취약점"

    • ["Loader Lock이란 무엇인가?"][845]

    • ["Windows Installer 임의 콘텐츠 조작 권한 상승 (CVE-2020-0911)"][58]

    • ["Windows Installer EOP (CVE-2023-21800)"][314]

    • ["C와 ASM을 이용한 자체 RDI /sRDI 로더 작성"][307]

    • ["Zenbleed"][207]

    • ["노력 없는 개인 키 침해: 측면 이동을 위한 SSH-Agent 악용"][248]## 2022

    • "A journey into IoT":

      • ["Chip identification, BUSSide, and I2C"][294]
      • ["Discover components and ports"][295]
      • ["Firmware dump and analysis"][296]
      • ["Radio communications"][681]
      • ["Internal communications"][682]
    • ["A Kernel Hacker Meets Fuchsia OS"][710]

    • "A Technical Analysis of Pegasus for Android":

      • [part 1][564]
      • [Part 2][565]
      • [Part 3][566]
    • ["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]

    • ["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]

    • "ARM 64 Assembly Series":

      • ["Basic definitions and registers"][408]
      • ["Offset and Addressing modes"][409]
      • ["Load and Store"][410]
      • ["Branch"][411]
      • ["Data Processing (Part 1)"][412]
      • ["Data Processing (Part 2)"][413]
      • ["selections and loops"][414]
      • ["Subroutines"][415]
    • ["Attacking the Android kernel using the Qualcomm TrustZone"][885]

    • ["Attacking Titan M with Only One Byte"][259]

    • ["Avoiding Detection with Shellcode Mutator"][432]

    • "BasicFUN Series":

      • "Hardware Analysis / SPI Flash Extraction"
      • "Reverse Engineering Firmware / Reflashing SPI Flash"
      • "Dumping Parallel Flash via I2C I/O Expanders"
      • "I2C Sniffing, EEPROM Extraction and Parallel Flash Extraction"
    • ["Basics for Binary Exploitation"][749]

    • ["Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"][238]

    • ["BrokenPrint: A Netgear stack overflow"][782]

    • "Bypassing software update package encryption ":

      • ["Extracting the Lexmark MC3224i printer firmware"][190]
      • ["Exploiting the Lexmark MC3224i printer"][191]
    • ["Bypassing vtable Check in glibc File Structures"][208]

    • ["Blind Exploits to Rule Watchguard Firewalls"][173]

    • ["BPFDoor - An Evasive Linux Backdoor Technical Analysis"][292]

    • ["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]

    • "Chrome Browser Exploitation":

      • [Part 1][1053]
      • [Part 2][1054]
      • [Part 3][1055]
    • ["Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"][556]

    • ["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]

    • ["Corrupting memory without memory corruption"][762]

    • ["Creating a Rootkit to Learn C"][719]

    • ["CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"][377]

    • ["[CVE-2022-1786] A Journey To The Dawn"][401]

    • ["CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"][168]

    • ["CVE-2022-27666: Exploit esp6 modules in Linux kernel"][532]

    • ["CVE-2022-29582 An io_uring vulnerability"][495]

    • ["Deconstructing and Exploiting CVE-2020-6418"][778]

    • ["DirtyCred Remastered: how to turn an UAF into Privilege Escalation"][167]

    • "Disclosing information with a side-channel in Django"

    • ["Dumping the Amlogic A113X Bootrom"][78]

    • ["Dynamic analysis of firmware components in IoT devices"][250]

    • ["Embedded Systems Security and TrustZone"][145]

    • ["Emulate Until You Make it"][748]

    • ["EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"][473]

    • ["Expanding the Dragon: Adding an ISA to Ghidra"][542]

    • ["Exploiting: Buffer overflow in Xiongmai DVRs"][742]

    • ["Exploiting CSN.1 Bugs in MediaTek Basebands"][272]

    • ["exploiting CVE-2019-2215"][61]

    • "Exploiting CVE-2022-42703 - Bringing back the stack attack"

    • ["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]

    • "Exploring the Hidden Attack Surface of OEM IoT Devices"

    • ["Firmware key extraction by gaining EL3"][316]

    • ["Fortigate - Authentication Bypass Lead to Full Device Takeover"][291]

    • "Fourchain":

      • ["Prologue"][765]
      • ["Hole"][766]
      • ["Sandbox"][767]
    • ["Fuzzing ping(8) … and finding a 24 year old bug"][751]

    • "Hacking Bluetooth to Brew Coffee from Github Actions":

      • [Part 1][752]
      • [Part 2][753]
      • [Part 3][754]
    • "Hackign More Secure Portable Storage Devices"

    • ["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]

    • ["How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"][266]

    • ["Huawei Security Hypervisor Vulnerability"][435]

    • "Hunting for Persistence in Linux"

      • [Part 1][64]
      • [Part 2][65]
      • [Part 3][66]
      • [Part 4][67]
      • [Part 5][68]
    • "Hacking Some More Secure USB Flash Drives":

      • [Part 1][132]
      • [Part 2][133]
    • ["Learning eBPF exploitation"][768]

    • "Intro to Embedded RE":

      • ["Tools and Series"][351]
      • ["UART Discovery and Firmware Extraction via UBoot"][352]
    • "Introduction to x64 Linux Binary Exploitation":

      • Part 1
      • Part 2
      • Part 3
      • Part 4
      • Part 5
    • ["io_uring - new code, new bugs, and a new exploit technique"][978]

    • ["Linux Hardening Guide"][349]

    • ["Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"][269]

    • ["Linux Kernel Exploit (CVE-2022–32250) with mqueue"][242]

    • "Linux SLUB Allocator Internals and Debugging":

      • [Part 1][359]
      • [Part 2][360]
      • [Part 3][361]
      • [Part 4][362]
    • ["Linternals: Introducing Memory Allocators & The Page Allocator"][516]

    • ["Linternals: The Slab Allocator"][517]

    • ["Linux kernel heap feng shui in 2022"][535]

    • ["Looking for Remote Code Execution bugs in the Linux kernel"][503]

    • ["Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"][319]

    • ["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]

    • ["Missing Manuals - io_uring worker pool"][265]

    • ["Modifying Embedded Filesystems in ARM Linux zImages"][775]

    • "Netgear Orbi":

      • ["orbi hunting 0x0: introduction, uart access, recon"][33]
      • ["orbi hunting 0x1: crashes in soap-api"][34]
      • ["nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"][35]
    • ["nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"][63]

    • ["NFC Relay Attack on Tesla Model Y"][574]

    • ["Nightmare: One Byte to ROP // Deep Dive Edition"][582]

    • ["Overview of GLIBC heap exploitation techniques"][239]

    • "Parsing TFTP in Rust"

    • ["Patching, Instrumenting & Debugging Linux Kernel Modules"][483]

    • "PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"

    • ["pipe_buffer arbitrary read write"][282]

    • "Pixel 6 Bootloader"

      • ["Booting up"][286]
      • ["Emulation, ROP"][287]
      • ["Exploitation"][288]
    • ["Port knocking from the scratch"][227]

    • ["Pulling MikroTik into the Limelight"][120]

    • ["Racing against the clock -- hitting a tiny kernel race window"][492]

    • ["Replicating CVEs with KLEE"][763]

    • ["Reversing C++, Qt based applications using Ghidra"][586]

    • ["Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"][406]

    • ["Replicant: Reproducing a Fault Injection "][675]

    • ["Researching Xiaomi’s Tee to Get to Chinese Money"][274]

    • "Reversing embedded device bootloader (U-Boot)":

      • [Part 1][162]
      • [Part 2][163]
    • ["Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"][368]

    • "Reverse engineering an EV charger"

    • "Reverse Engineering Dark Souls 3":

      • "Connection"
      • "Packets"
      • "Key Exchange"
      • "Reliable UDP"
    • ["Reverse engineering integrity checks in Black Ops 3"][220]

    • ["Reverse engineering thermal printers"][245]

    • ["Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"][491]

    • ["SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"][484]

    • ["Shedding Light on Huawei's Security Hypervisor"][434]

    • ["Shikitega - New stealthy malware targeting Linux"][438]

    • ["side channels: power analysis"][380]

    • ["side channels: using the chipwhisperer"][381]

    • ["SIM Hijacking"][579]

    • ["Spoofing Call Stacks To Confuse EDRs"][431]

    • ["SROP Exploitation with radare2"][770]

    • ["Stealing the Bitlocker key from a TPM"][505]

    • ["Stranger Strings: An exploitable flaw in SQLite"][588]

    • "Survey of security mitigations and architectures, December 2022"

    • ["Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"][461]

    • ["Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"][226]

    • ["The Dirty Pipe Vulnerability"][321]

    • ["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]

    • ["The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"][36]

    • ["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]

    • "The toddler’s introduction to Heap exploitation":

      • ["Part 1"][339]
      • ["Part 2"][340]
      • ["Overflows"][341]
      • ["Use After Free & Double free"][342]
      • ["FastBin Dup to Stack"][343]
      • ["FastBin Dup Consolidate"][344]
      • ["Unsafe Unlink"][345]
      • ["House of Spirit"][346]
      • ["House of Lore"][347]
    • ["TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"][553]

    • ["Tracing and Manipulating with DynamoRIO"][750]

    • ["Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"][312]

    • ["Turning Google smart speakers into wiretaps for $100k"][18]

    • "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"

    • ["Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"][126]

    • "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":

      • [Part 1][496]
      • [Part 2][497]
    • ["Vulnerability Details for CVE-2022-41218"][563]

    • ["Vulnerabilities in Tenda's W15Ev2 AC1200 Router"][127]

    • "When an N-Day turns into a 0day"

    • ["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]

    • ["Write a Linux firewall from scratch based on Netfilter"][313]

    • ["Yet another bug into Netfilter"][457]

    • "Xiongmai IoT Exploitation"

    • "Zyxel authentication bypass patch analysis (CVE-2022-0342)"

    2021

    • "A dive into the PE file format":
      • ["Introduction"][332]
      • ["DOS Header, DOS Stub and Rich Header"][333]
      • ["NT Headers"][334]
      • ["Data Directories, Section Headers and Sections"][335]
      • ["Imports (Import Direcory Table, ILT, IAT)"][336]
      • ["PE Base Relocations"][337]
      • ["Writing a PE Parser"][338]
    • ["A Nerve-Racking Bug Collision in Samsung's NPU Driver"][855]
    • "A Practical Approach to Attacking IoT Embedded Designs":
      • [Part 1][721]
      • [Part 2][722]
    • ["Attacking Samsung RKP"][909]
    • ["Automatic unpacking with Qiling framework"][558]
    • ["BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"][755]
    • ["Breaking 64 bit aslr on Linux x86-64"][234]
    • ["Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"][375]
    • ["Complete Guide to Stack Buffer Overflow (OSCP Preparation)"][317]
    • ["CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"][561]
    • ["CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."][179]
    • ["CVE-2021-22555: Turning \x00\x00 into 10000$"][977]
    • ["Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"][756]
    • "Digging into Linux namespaces":
      • [Part 1][157]
      • [Part 2][158]
    • ["Exploiting crash handlers: LPE on Ubuntu"][760]
    • "Extending Ghidra Part 1: Setting up a Development Environment"
    • ["Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"][252]
    • "Fuzzing101 with LibAFL":
      • ["Fuzzing Xpdf"][468]
      • ["Speed Improvements to Part I"][469]
      • ["Fuzzing libexif"][470]
    • ["Getting to know memblock"][771]
    • "Ghidra 101":
      • ["Cursor Text Highlighting"][416]
      • ["Slice Highlighting"][417]
      • ["Decoding Stack Strings"][418]
      • ["Loading Windows Symbols (PDB files)"][419]
      • ["Creating Structures in Ghidra"][420]
      • ["Loading Windows Symbols (PDB files) in Ghidra 10.x"][421]
    • ["GRCON 2021 - Capture the Signal"][403]
    • "Hacking the Furbo Dog Camera":
      • [Part 1][744]
      • [Part 2][745]
      • [Part 3][746]
    • ["How AUTOSLAB Changes the Memory Unsafety Game"][536]
    • "Learning Linux Kernel Exploitation":
      • [Part 1][83]
      • [Part 2][84]
      • [Part 3][85]
    • "LinkSys EA6100 AC1200":
      • [Part 1][740]
      • [Part 1][741]
    • "Linux Internals: How /proc/self/mem writes to unwritable memory"
    • "Linux Kernel Exploitation":
      • ["Debugging the Kernel with QEMU"][25]
      • ["Smashing Stack Overflows in the Kernel"][26]
      • ["Controlling RIP and Escalating privileges via Stack Overflow"][27]
    • "Live Debugging Techniques for the Linux Kernel"
      • [Part 1][470]
      • [Part 2][471]
      • [Part 3][472]
    • "Malware development (0xPat)"
      • [Part 1][792]
      • [Part 2][793]
      • [Part 3][794]
      • [Part 4][795]
      • [Part 5][796]
      • [Part 6][797]
      • [Part 7][798]
      • [Part 8][799]
      • [Part 9][800]
    • ["mooosl"][602]
    • ["My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"][560]
    • ["New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"][440]
    • ["New Old Bugs in the Linux Kernel"][305]
    • ["Practical Introduction to CodeQL"][1233]
    • ["Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug"]
    • ["Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"][555]
    • ["Recovering a Full PEM Private key when Half of it is Redacted"][96]
    • "Reverse Engineering an Unknown Microcontroller"
    • "Reverse Engineering Bare-Metal Firmware":
      • [Part 1][142]
      • [Part 2][143]
      • [Part 3][144]
    • ["Reverse Engineering Yaesu FT-70D Firmware Encryption"][147]
    • "Syzkaller diving":
      • [Part 1][423]
      • [Part 2][424]
      • [Part 3][425]
    • ["The Art of Exploiting UAF by Ret2bpf in Android Kernel"][595]
    • ["The Oddest Place You Will Ever Find PAC"][306]
    • ["Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"][888]
    • "VMProtect 2"
      • [Part 1][960]
      • [Part 2][961]
    • ["Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"][251]

    2020

    • "A Deep Dive Into Samsung's TrustZone"
      • [Part 1][487]
      • [Part 2][488]
      • [Part 3][489]
    • ["An iOS hacker tries Android"][856]
    • "BGET Explained Binary Heap Exploitation on OP-TEE":
      • [Part 1][187]
      • [Part 2][188]
    • ["BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"][372]
    • ["Building a Basic C2"][1057]
    • ["CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"][890]
    • ["CVE-2020-16040 Analysis & Exploitation"][725]
    • "Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"
    • "Espressif ESP32: Bypassing Secure Boot using EMFI"
    • "Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"
    • "Espressif ESP32: Controlling PC during Secure Boot"
    • ["Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"][430]
    • ["Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"][161]
    • ["Flashback Connects - Cisco RV340 SSL VPN RCE"][525]
    • "Hardware Debugging for Reverse Engineers":
      • "SWD, OpenOCD and Xbox One Controllers"
      • "TAG, SSDs and Firmware Extraction"Manipulating AES Traffic
    • ["Hardware Hacking 101: Identifying and Dumping eMMC Flash"][87]
    • ["House of Muney - Leakless Heap Exploitation Technique"][181]
    • ["Learning to Decapsulate Integrated Circuits Using Acid Deposition"][727]
    • ["Loading Dynamic Libraries on Mac"][458]
    • ["Minesweeper - TP-Link Archer C7 LAN RCE"][446]
    • ["My Methods To Achieve Persistence In Linux Systems"][247]
    • "nRF52 Debug Resurrection":
      • [Part 1][279]
      • [Part 2][280]
    • ["NTLM Relay"][56]
    • "Patch Diffing a Cisco RV110W Firmware Update"
      • [Part 1][506]
      • [Part 2][507]
    • ["Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"][783]
    • ["ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"][370]
    • ["Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"][780]
    • ["SSHD Injection and Password Harvesting"][230]
    • ["There’s A Hole In Your SoC: Glitching The MediaTek BootROM"][737]
    • ["Weekend Destroyer - RCE in Western Digital PR4100 NAS"][447]
    • ["What're you telling me, Ghidra?"][358]

    2019

    • ["Breaking out of Docker via runC – Explaining CVE-2019-5736"][369]
    • "Executable and Linkable Format 101":
      • ["Sections and Segments"][135]
      • ["Symbols"][136]
      • ["Relocations"][137]
      • ["Dynamic Linking"][138]
    • ["Exploiting Qualcomm WLAN and Modem Over the Air"][773]
    • ["Hacking microcontroller firmware through a USB"][243]
    • ["Hardening Secure Boot on Embedded Devices for Hostile Environments"][175]
    • ["How to Weaponize the Yubikey"][743]
    • ["Pew Pew Pew: Designing Secure Boot Securely"][176]
    • ["Pwn the ESP32 crypto-core"][757]
    • ["Pwn the ESP32 Secure Boot"][289]
    • ["Reverse Engineering Architecture And Pinout of Custom Asics"][398]
    • ["Reverse-engineering Broadcom wireless chipsets"][200]
    • "Reverse Engineering of a Not-so-Secure IoT Device"
    • "Virtualization Internals":
      • [Part 1][216]
      • [Part 2][217]
      • [Part 3][218]
      • [Part 4][219]

    2018

    • ["A Deep dive into (implicit) Thread Local Storage"][581]
    • ["A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"][464]
    • "ARM Exploitation":
      • ["Return oriented Programming"][788]
      • ["Setup and Tools"][789]
      • ["Defeating DEP - execute system()"][790]
      • ["Defeating DEP - executing mprotect()"][791]
    • "CVE-2017-11176: A step-by-step Linux Kernel exploitation":
      • [Part 1][19]
      • [Part 2][20]
      • [Part 3][21]
      • [Part 4][22]
    • ["eMMC Data Recovery from Damaged Smartphone"][88]
    • ["Kinibi TEE: Trusted Application Exploitation"][781]
    • ["My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"][302]
    • ["Reverse Engineering BLE Devices"][761]
    • "Reversing ESP8266 Firmware":
      • [Part 1][545]
      • [Part 2][546]
      • [Part 3][547]
      • [Part 4][548]
      • [Part 5][549]
      • [Part 6][550]
    • "Vectorized Emulation":[438]
      • ["Hardware accelerated taint tracking at 2 trillion instructions per second"][382]
      • ["MMU Design"][383]

    2017

    • ["Escalating Privileges in Linux using Fault Injection"][774]
    • ["Hardware hacking tutorial: Dumping and reversing firmware"][557]
    • ["HiSilicon DVR hack"][236]
    • ["How I Reverse Engineered and Exploited a Smart Massager"][301]
    • "Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"
    • ["Linux ptrace introduction AKA injecting into sshd for fun"][229]
    • "Over The Air":
      • ["Exploiting Broadcom’s Wi-Fi Stack (Part 1)"][539]
      • ["Exploiting Broadcom’s Wi-Fi Stack (Part 2)"][540]
      • ["Exploiting The Wi-Fi Stack on Apple Devices"][541]

    2016

    • ["Bypassing Secure Boot using Fault Injection"][174]
    • ["munmap madness"][199]
    • ["Implementation of Signal Handling"][23]
    • "Practical Reverse Engineering"
      • ["Digging Through the Firmware"][114]
      • ["Scouting the Firmware"][115]
      • ["Following the Data"][116]
      • ["Dumping the Flash"][117]
      • ["Digging Through the Firmware"][118]
    • ["Understanding and Hardening Linux Containers"][50]

    2014

    • ["ret2dir: Rethinking Kernel Isolation"][384]

    2011

    • ["Load-time relocation of shared libraries"][592]
    • ["Position Independent Code (PIC) in shared libraries"][593]

    Misc- 0xtriboulet

    • ["A Noobs Guide to ARM Exploitation"][241]
    • ["Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent fuzzing"][71]
    • ["Advanced Compilers: The Self-Guided Online Course"][298]
    • ["Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"][559]
    • ["Android Kernel Exploitation"][571]
    • [Anti-Debug Tricks][585]
    • ["ARM TrustZone: pivoting to the secure world"][304]
    • ["ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"][927]
    • [Awesome binary parsing][769]
    • [Awesome Executable Packing][717]
    • [Awesome Industrial Protocols][510]
    • ["Brute Ratel - Scandinavian Defence"][436]
    • Comprehensive Rust
    • [cryptopals][1022]
    • [CVE North Stars][708]
    • ["Debugger Ghidra Class"][232]
    • [DhavalKapil/heap-exploitation][363]
    • [Diffing Portal][378]
    • [exploit_mitigations][526]
    • ["fenrir"][1169]
    • [Ghidriff - Ghidra Binary Diffing Engine][490]
    • ["Grand Theft Auto A peek of BLE relay attack"][433]
    • ["Hands-on Firmware Extraction, Exploration, and Emulation"][979]
    • [ice9-bluetooth-sniffer][437]
    • "Illustrated Connections":
      • [dtls][519]
      • [quic][518]
      • [tls 1.2][521]
      • [tls 1.3][520]
    • "Introduction to encryption for embedded Linux"
      • ["Introduction to encryption for embedded Linux developers"][0]
      • ["A hands-on approach to symmetric-key encryption"][1]
      • ["Asymmetric-Key Encryption and Digital Signatures in Practice"][2]
    • ["Introduction to Malware Analysis and Reverse Engineering"][407]
    • ["Kernel Address Space Layout Derandomization"][529]
    • ["Kernel Exploit Recipes Notebook"][776]
    • ["Laser-Based Audio Injection on Voice-Controllable Systems"][328]
    • [Linux Kernel CVEs][385]
    • ["Linux kernel exploit development"][573]
    • ["Linux Kernel map"][225]
    • ["Linux Insides"][246]
    • ["Linux Privilege Escalation"][982]
    • ["Linux Syscalls Reference"][17]
    • ["Lytro Unlock - Making a bad camera slightly better"][373]
    • ["Minimizing Rust Binary Size"][476]
    • ["mjsxj09cm Recovering Firmware And Backdooring"][62]
    • ["Offensive security (0xtriboulet)"][405]
    • ["Operating System development tutorials in Rust on the Raspberry Pi"][357]
    • ["parking-game-fuzzer"][1159]
    • ["Practical Cryprography for Developers"][785]
    • [Red-Team-Infrastructure-Wiki][498]
    • ["Reverse Engineering For Everyone!"][399]
    • "Reverse Engineering WiFi on RISC-V BL602"
    • "Rust Atomics and Locks"
    • ["RustRedOps"][686]
    • ["Satellite Hacking Demystified(RTC0007)"][221]
    • [TEE Reversing][263]
    • ["THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"][258]
    • [tmpout.sh][515]: 저수준 관련 글 모음
    • ["Trail of Bits Testing Handbook"][724]
    • [TripleCross][696]
    • [USB-WiFi][329]
    • ["VSS: Beginners Guide to Building a Hardware Hacking Lab"][249]
    • ["WinDBG quick start tutorial"][485]

    기타 목록

    • Exploitation: 바이너리 익스플로잇 분야에 특화된 자료
    • Linux Kernel: Linux 커널 (내부 구조)에 특화된 자료 모음
    • Wireless: 무선 기술 및 보안에 특화된 자료
    • OT/IoT Security
    • Red Teaming and Offensive Security[0]: https://sergioprado.blog/introduction-to-encryption-for-embedded-linux-developers/ [1]: https://sergioprado.blog/a-hands-on-approach-to-symmetric-key-encryption/ [2]: https://sergioprado.blog/asymmetric-key-encryption-and-digital-signatures-in-practice/ [3]: https://sysprog21.github.io/lkmpg/ [4]: https://jsac.jpcert.or.jp/archive/2023/pdf/JSAC2023_1_1_yamashige-nakatani-tanaka_en.pdf [5]: http://conference.hitb.org/files/hitbsecconf2023ams/materials/D1T1%20-%20Your%20Not%20So%20Home%20Office%20-%20Soho%20Hacking%20at%20Pwn2Own%20-%20McCaulay%20Hudson%20&%20Alex%20Plaskett.pdf [7]: https://www.synacktiv.com/publications/exploring-android-heap-allocations-in-jemalloc-new [8]: https://www.synacktiv.com/en/publications/behind-the-shield-unmasking-scudos-defenses [10]: https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html [11]: https://idov31.github.io/2022/08/04/lord-of-the-ring0-p2.html [12]: https://idov31.github.io/2022/10/30/lord-of-the-ring0-p3.html [13]: https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html [14]: https://idov31.github.io/2023/07/19/lord-of-the-ring0-p5.html [15]: https://llsoftsec.github.io/llsoftsecbook/ [16]: https://blog.lexfo.fr/sshimpanzee.html [17]: https://syscalls.mebeim.net/?table=x86/64/x64/v6.5 [18]: https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html [19]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part1.html [20]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part2.html [21]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part3.html [22]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part4.html [23]: http://courses.cms.caltech.edu/cs124/lectures-wi2016/CS124Lec15.pdf [24]: https://makefiletutorial.com [25]: https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html [26]: http://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html [27]: https://blog.k3170makan.com/2021/01/linux-kernel-exploitation-0x2.html [28]: https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger [29]: https://robocoffee.de/?p=436 [30]: https://www.trustedsec.com/blog/red-vs-blue-kerberos-ticket-times-checksums-and-you [31]: https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet [32]: https://medium.com/@INTfinitySG/fortinet-series-3-cve-2022-42475-sslvpn-exploit-strategy-2578597f892f [33]: http://blog.coffinsec.com/research/2022/06/12/orbi-hunting-0-intro-uart.html [34]: http://blog.coffinsec.com/research/2022/06/19/orbi-hunting-1-soap-api-crashes.html [35]: http://blog.coffinsec.com/research/2022/07/02/orbi-nday-exploit-cve-2020-27861.html [36]: https://starlabs.sg/blog/2023/06-the-old-the-new-and-the-bypass-one-clickopen-redirect-to-own-samsung-s22-at-pwn2own-2022/ [37]: https://download.vusec.net/papers/uncontained_sec23.pdf [38]: https://mccaulay.co.uk/mast1c0re-introduction-exploiting-the-ps4-and-ps5-through-a-gamesave/ [39]: https://mccaulay.co.uk/mast1c0re-part-1-modifying-ps2-game-save-files/ [40]: https://mccaulay.co.uk/mast1c0re-part-2-arbitrary-ps2-code-execution/ [41]: https://mccaulay.co.uk/mast1c0re-part-3-escaping-the-emulator/ [42]: https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/ [43]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-1-fuzzing-gegl-with-fuzzuf.html [44]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-2-evaluating-performance.html [45]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-3-patch-analysis-and-poc.html [46]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-4-hunting-and-exploiting-0.html [47]: https://boschko.ca/qemu-emulating-firmware/ [48]: https://labs.bluefrostsecurity.de/revisiting-cve-2017-11176 [49]: https://www.cyberark.com/resources/threat-research-blog/a-deep-dive-into-penetration-testing-of-macos-applications-part-1 [50]: https://research.nccgroup.com/wp-content/uploads/episerver-images/assets/ad04beb697a64e3ea20579e5bf604b4e/ad04beb697a64e3ea20579e5bf604b4e.pdf [51]: https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html [52]: https://labs.withsecure.com/publications/executing-arbitrary-code-executables-in-read-only-filesystems [53]: https://axcheron.github.io/linux-shellcode-101-from-hell-to-shell/ [54]: https://aviii.hashnode.dev/the-art-of-fuzzing-a-step-by-step-guide-to-coverage-guided-fuzzing-with-libfuzzer [55]: https://boschko.ca/shambles/ [56]: https://en.hackndo.com/ntlm-relay/ [57]: https://bushido-sec.com/index.php/2023/06/19/the-art-of-fuzzing/ [58]: https://offsec.almond.consulting/windows-msiexec-eop-cve-2020-0911.html [59]: https://github.blog/2023-07-05-introduction-to-selinux/ [60]: https://www.wiz.io/blog/linux-rootkits-explained-part-1-dynamic-linker-hijacking [61]: https://cutesmilee.github.io/kernel/linux/android/2022/02/17/cve-2019-2215_writeup.html [62]: https://whiterose-infosec.super.site/mjsxj09cm-recovering-firmware-and-backdooring [63]: http://blog.coffinsec.com/nday/2022/08/04/CVE-2022-1215-libinput-fmt-canary-leak.html [64]: https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/ [65]: https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/ [66]: https://pberba.github.io/security/2022/01/30/linux-threat-hunting-for-persistence-systemd-timers-cron/ [67]: https://pberba.github.io/security/2022/02/06/linux-threat-hunting-for-persistence-initialization-scripts-and-shell-configuration/ [68]: https://pberba.github.io/security/2022/02/07/linux-threat-hunting-for-persistence-systemd-generators/ [69]: https://www.espressif.com/sites/default/files/documentation/ESP32-C3%20Wireless%20Adventure.pdf [70]: https://blog.quarkslab.com/for-science-using-an-unimpressive-bug-in-edk-ii-to-do-some-fun-exploitation.html [71]: https://airbus-seclab.github.io/AFLplusplus-blogpost/ [72]: https://labs.bluefrostsecurity.de/blog/cve-2023-2008.html [73]: https://cs.brown.edu/~vpk/papers/epf.atc23.pdf [74]: https://remyhax.xyz/posts/obscure-win-files/ [75]: https://github.com/google/security-research/tree/master/pocs/cpus/spectre-gadgets [76]: https://offsec.almond.consulting/ghostscript-cve-2023-28879.html [77]: https://boredpentester.com/retreading-the-amlogic-a113x-trustzone-exploit-process/ [78]: https://haxx.in/posts/dumping-the-amlogic-a113x-bootrom/ [79]: https://bd103.github.io/blog/2023-06-27-global-allocators [80]: https://labs.watchtowr.com/xortigate-or-cve-2023-27997/ [81]: https://starlabs.sg/blog/2023/06-breaking-the-code-exploiting-and-examining-cve-2023-1829-in-cls_tcindex-classifier-vulnerability/ [82]: https://act-on.ioactive.com/acton/attachment/34793/f-b1aa96d0-bd78-4518-bae3-2889aae340de/1/-/-/-/-/DroneSec-GGonzalez.pdf [83]: https://lkmidas.github.io/posts/20210123-linux-kernel-pwn-part-1/ [84]: https://lkmidas.github.io/posts/20210128-linux-kernel-pwn-part-2/ [85]: https://lkmidas.github.io/posts/20210205-linux-kernel-pwn-part-3/ [86]: https://markuta.com/eero-6-hacking-part-1/ [87]: https://riverloopsecurity.com/blog/2020/03/hw-101-emmc/ [88]: https://dangerouspayload.com/2018/10/24/emmc-data-recovery-from-damaged-smartphone/ [89]: https://bushido-sec.com/index.php/2023/06/25/the-art-of-fuzzing-windows-binaries/ [90]: https://papers.mathyvanhoef.com/usenix2023-wifi.pdf [91]: https://research.aurainfosec.io/pentest/bee-yond-capacity/ [92]: https://blog.trailofbits.com/2023/06/15/finding-bugs-with-mlir-and-vast/ [93]: https://labs.hakaioffsec.com/coffee-a-coff-loader-made-in-rust/ [94]: https://biriukov.dev/docs/page-cache/0-linux-page-cache-for-sre/ [95]: https://frycos.github.io/vulns4free/2023/06/18/fortinac.html [96]: https://blog.cryptohack.org/twitter-secrets [97]: https://labs.ioactive.com/2023/06/back-to-future-with-platform-security.html [98]: https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads [99]: https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/ [100]: https://www.zerodayinitiative.com/blog/2023/4/5/bash-privileged-mode-vulnerabilities-in-parallels-desktop-and-cdpath-handling-in-macos [101]: https://programmingwithstyle.com/posts/howihackedmycar/ [102]: https://programmingwithstyle.com/posts/howihackedmycarpart2/ [103]: https://programmingwithstyle.com/posts/howihackedmycarpart3/ [104]: https://programmingwithstyle.com/posts/howihackedmycarpart4/ [105]: https://programmingwithstyle.com/posts/howihackedmycarpart5/ [106]: https://programmingwithstyle.com/posts/myhackedcarisdoomed/ [107]: https://8ksec.io/arm64-reversing-and-exploitation-part-1-arm-instruction-set-simple-heap-overflow/ [108]: https://8ksec.io/arm64-reversing-and-exploitation-part-2-use-after-free/ [109]: https://8ksec.io/arm64-reversing-and-exploitation-part-3-a-simple-rop-chain/ [110]: https://8ksec.io/arm64-reversing-and-exploitation-part-4-using-mprotect-to-bypass-nx-protection-8ksec-blogs/ [111]: https://8ksec.io/arm64-reversing-and-exploitation-part-5-writing-shellcode-8ksec-blogs/ [112]: https://8ksec.io/arm64-reversing-and-exploitation-part-6-exploiting-an-uninitialized-stack-variable-vulnerability/ [113]: https://8ksec.io/arm64-reversing-and-exploitation-part-7-bypassing-aslr-and-nx/ [114]: http://jcjc-dev.com/2016/04/08/reversing-huawei-router-1-find-uart/ [115]: https://jcjc-dev.com/2016/04/29/reversing-huawei-router-2-scouting-firmware/ [116]: https://jcjc-dev.com/2016/05/23/reversing-huawei-3-sniffing/ [117]: https://jcjc-dev.com/2016/06/08/reversing-huawei-4-dumping-flash/ [118]: https://jcjc-dev.com/2016/12/14/reversing-huawei-5-reversing-firmware/ [119]: https://qriousec.github.io/post/vbox-pwn2own-2023/ [120]: https://margin.re/2022/06/pulling-mikrotik-into-the-limelight/ [121]: https://medium.com/@cy1337/a-guide-to-reversing-shared-objects-with-ghidra-cec83d5031e6 [122]: https://medium.com/@cy1337/reversing-a-simple-crackme-with-ghidra-decompiler-5dd1b1c3c0ba [123]: https://medium.com/@cy1337/vulnerability-hunting-with-ghidra-fb3fc53470ba [124]: https://medium.com/@cy1337/patching-a-bug-from-a-ghidra-listing-8496e529224a [125]: https://medium.com/@cy1337/vulnerability-analysis-with-ghidra-scripting-ccf416cfa56d [126]: https://boschko.ca/glinet-router/ [127]: https://boschko.ca/tenda_ac1200_router/ [128]: https://intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/ [129]: https://intezer.com/blog/incident-response/malware-reverse-engineering-for-beginners-part-2/ [130]: https://www.zerodayinitiative.com/blog/2023/8/1/exploiting-a-flaw-in-bitmap-handling-in-windows-user-mode-printer-drivers [131]: https://linux-kernel-labs.github.io/refs/heads/master/index.html [132]: https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/ [133]: https://blog.syss.com/posts/hacking-usb-flash-drives-part-2/ [134]: https://eventhelix.com/rust/ [135]: https://intezer.com/blog/research/executable-linkable-format-101-part1-sections-segments/ [136]: https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-2-symbols/ [137]: https://intezer.com/blog/malware-analysis/executable-and-linkable-format-101-part-3-relocations/ [138]: https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-4-dynamic-linking/ [139]: https://secret.club/2023/06/05/spoof-pe-sections.html [140]: https://github.com/imthenachoman/How-To-Secure-A-Linux-Server [141]: https://reversing.info/posts/guardedregions/ [142]: https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef [143]: https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef [144]: https://medium.com/geekculture/reverse-engineering-bare-metal-firmware-part-3-analyzing-arm-assembly-and-exploiting-3b2dbe219f19 [145]: https://embeddedsecurity.io [146]: https://research.nccgroup.com/2023/05/23/offensivecon-2023-exploit-engineering-attacking-the-linux-kernel/ [147]: https://landaire.net/reversing-yaesu-firmware-encryption/ [148]: https://googleprojectzero.blogspot.com/2023/01/exploiting-null-dereferences-in-linux.html [149]: https://blog.the.al/2023/01/01/ds4-reverse-engineering.html [150]: https://blog.the.al/2023/01/02/ds4-reverse-engineering-part-2.html [151]: https://blog.the.al/2023/01/03/ds4-reverse-engineering-part-3.html [152]: https://educatedguesswork.org/posts/nat-part-1/ [153]: https://educatedguesswork.org/posts/nat-part-2/ [154]: https://educatedguesswork.org/posts/nat-part-3/ [155]: https://educatedguesswork.org/posts/nat-part-4/ [156]: https://github.com/ihebski/A-Red-Teamer-diaries [157]: https://blog.quarkslab.com/digging-into-linux-namespaces-part-1.html [158]: https://blog.quarkslab.com/digging-into-linux-namespaces-part-2.html [159]: https://github.com/bsauce/kernel-exploit-factory [160]: https://icanhack.nl/blog/dji-rm500-privilege-escalation/ [161]: https://blog.zapb.de/stm32f1-exceptional-failure/ [162]: https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ [163]: https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.2/ [164]: https://securityintelligence.com/x-force/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/ [165]: https://mutur4.github.io/posts/linux-malware-development/edr/ [166]: https://jcjc-dev.com/2023/03/19/reversing-domyos-el500-elliptical/ [167]: https://exploiter.dev/blog/2022/CVE-2022-2602.html [168]: https://blog.hacktivesecurity.com/index.php/2022/12/21/cve-2022-2602-dirtycred-file-exploitation-applied-on-an-io_uring-uaf/ [169]: https://github.com/michalmalik/linux-re-101 [170]: https://redops.at/en/blog/meterpreter-vs-modern-edrs-in-2023 [171]: https://arxiv.org/pdf/2301.13346.pdf [172]: https://alice.climent-pommeret.red/posts/process-killer-driver/ [173]: https://web.archive.org/web/20230628130110/https://www.ambionics.io/blog/hacking-watchguard-firewalls [174]: https://raelize.com/upload/research/2016/2016_BlackHat-EU_Bypassing-Secure-Boot-Using-Fault-Injection_NT-AS.pdf [175]: https://raelize.com/upload/research/2019/2019_BlueHat-IL_Hardening-Secure-Boot-on-Embedded-Devices-for-Hostile-Environments_NT-AS-CM.pdf [176]: https://raelize.com/upload//research/2019/2019_Designing-Secure-Boot-Securely_NT-AS.pdf [177]: https://securityintelligence.com/x-force/msmq-queuejumper-rce-vulnerability-technical-analysis/ [178]: https://h0mbre.github.io/kCTF_Data_Only_Exploit/ [179]: https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a [180]: https://starlabs.sg/blog/2023/08-ikea-sonos-symfonisk-speaker-lamp-teardown/ [181]: https://maxwelldulin.com/BlogPost/House-of-Muney-Heap-Exploitation [182]: https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/ [183]: https://www.trendmicro.com/en_ph/research/23/g/detecting-bpfdoor-backdoor-variants-abusing-bpf-filters.html [184]: https://starlabs.sg/blog/2023/07-prctl-anon_vma_name-an-amusing-heap-spray/ [185]: https://0xkol.github.io/assets/files/Racing_Against_the_Lock__Exploiting_Spinlock_UAF_in_the_Android_Kernel.pdf [186]: https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt [187]: https://phi1010.github.io/2020-09-14-bget-exploitation/ [188]: https://phi1010.github.io/2020-11-02-bget-exploitation-2/ [189]: https://eshard.com/posts/sca-attacks-on-armv8 [190]: https://research.nccgroup.com/2022/02/17/bypassing-software-update-package-encryption-extracting-the-lexmark-mc3224i-printer-firmware-part-1/ [191]: https://research.nccgroup.com/2022/02/18/analyzing-a-pjl-directory-traversal-vulnerability-exploiting-the-lexmark-mc3224i-printer-part-2/ [192]: https://www.synacktiv.com/publications/escaping-from-bhyve.html [193]: http://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html [194]: http://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html [195]: https://kentindell.github.io/2023/04/03/can-injection/ [196]: https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/ [197]: https://blog.assetnote.io/2023/07/24/citrix-rce-part-2-cve-2023-3519/ [198]: https://vulncheck.com/blog/mikrotik-foisted-revisited [199]: http://tukan.farm/2016/07/27/munmap-madness/ [200]: https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html [201]: https://starlabs.sg/blog/2023/07-a-new-method-for-container-escape-using-file-based-dirtycred/ [202]: https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt [203]: https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/ [204]: https://jbecker.dev/research/diving-into-decompilation [205]: https://binarly.io/posts/The_Untold_Story_of_the_BlackLotus_UEFI_Bootkit/index.html [206]: https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/ [207]: http://lock.cmpxchg8b.com/zenbleed.html [208]: https://blog.kylebot.net/2022/10/22/angry-FSROP/ [209]: https://sensepost.com/blog/2023/p4wnp1-lte/ [210]: https://tortel.li/post/insecure-scope/ [211]: https://claroty.com/team82/research/opc-ua-deep-dive-history-of-the-opc-ua-protocol [212]: https://claroty.com/team82/research/opc-deep-dive-part-2-what-is-opc-ua [213]: https://claroty.com/team82/research/opc-ua-deep-dive-part-3-exploring-the-opc-ua-protocol [214]: https://claroty.com/team82/research/opc-ua-deep-dive-series-part-4-targeting-core-opc-ua-components [215]: https://claroty.com/team82/research/opc-ua-deep-dive-series-part-5-inside-team82-s-research-methodology [216]: https://docs.saferwall.com/blog/virtualization-internals-part-1-intro-to-virtualization/ [217]: https://docs.saferwall.com/blog/virtualization-internals-part-2-vmware-and-virtualization-using-binary-translation/ [218]: https://docs.saferwall.com/blog/virtualization-internals-part-3-xen-and-paravirtualization/ [219]: https://docs.saferwall.com/blog/virtualization-internals-part-4-qemu/ [220]: https://web.archive.org/web/20230522230748/https://momo5502.com/posts/2022-11-17-reverse-engineering-integrity-checks-in-black-ops-3/ [221]: https://redteamrecipe.com/Satellite-Hacking-Demystified/ [222]: https://www.linode.com/docs/guides/linux-red-team-exploitation-techniques/ [223]: https://www.linode.com/docs/guides/linux-red-team-privilege-escalation-techniques/ [224]: https://www.linode.com/docs/guides/linux-red-team-persistence-techniques/ [225]: https://makelinux.github.io/kernel/map/ [226]: https://xcellerator.github.io/posts/tetsuji/ [227]: https://antonio-cooler.gitbook.io/coolervoid-tavern/port-knocking-from-the-scratch [228]: https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/ [229]: https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/ [230]: https://jm33.me/sshd-injection-and-password-harvesting.html [231]: https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/ [232]: https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger [233]: https://bishopfox.com/blog/breaking-fortinet-firmware-encryption [234]: https://github.com/nick0ve/how-to-bypass-aslr-on-linux-x86_64 [235]: https://steve-s.gitbook.io/0xtriboulet/just-malicious/from-c-with-inline-assembly-to-shellcode [236]: https://github.com/tothi/pwn-hisilicon-dvr/tree/42d8325e68fdb075fe27df8a269932f9fa9601a6 [237]: https://uploads-ssl.webflow.com/64a2900ed5e9bb672af9b2ed/64d42fcc2e3fdcf3d323f3d9_All_cops_are_broadcasting_TETRA_under_scrutiny.pdf [238]: https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html [239]: https://0x434b.dev/overview-of-glibc-heap-exploitation-techniques/ [240]: https://wafzsucks.medium.com/how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [241]: https://ad2001.gitbook.io/a-noobs-guide-to-arm-exploitation/ [242]: https://blog.theori.io/linux-kernel-exploit-cve-2022-32250-with-mqueue-a8468f32aab5 [243]: https://securelist.com/hacking-microcontroller-firmware-through-a-usb/89919/ [244]: https://blog.ret2.io/2023/08/09/jtag-hacking-the-original-xbox-2023/ [245]: https://wes4m.io/posts/epson_rev/ [246]: https://0xax.gitbooks.io/linux-insides/content/ [247]: https://flaviu.io/advanced-persistent-threat/ [248]: https://grahamhelton.com/blog/ssh_agent/ [249]: https://voidstarsec.com/hw-hacking-lab/vss-lab-guide%5D [250]: https://ics-cert.kaspersky.com/publications/reports/2022/07/06/dynamic-analysis-of-firmware-components-in-iot-devices/ [251]: https://syst3mfailure.io/wall-of-perdition/ [252]: https://www.willsroot.io/2021/08/corctf-2021-fire-of-salvation-writeup.html [253]: https://www.forescout.com/resources/l1-lateral-movement-reportg [254]: https://www.synacktiv.com/en/publications/old-bug-shallow-bug-exploiting-ubuntu-at-pwn2own-vancouver-2023 [255]: https://research.nccgroup.com/2023/03/15/a-race-to-report-a-toctou-analysis-of-a-bug-collision-in-intel-smm/ [256]: https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/ [257]: https://research.nccgroup.com/2023/08/08/intel-bios-advisory-memory-corruption-in-hid-drivers/ [258]: https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet [259]: https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html [260]: https://big5-sec.github.io/posts/CVE-2023-29360-analysis/ [261]: https://blog.exodusintel.com/2023/07/20/shifting-boundaries-exploiting-an-integer-overflow-in-apple-safari/ [262]: https://blog.quarkslab.com/breaking-secure-boot-on-the-silicon-labs-gecko-platform.html [263]: https://github.com/enovella/TEE-reversing [264]: https://www.cyberark.com/resources/all-blog-posts/nvme-new-vulnerabilities-made-easy [265]: https://blog.cloudflare.com/missing-manuals-io_uring-worker-pool/ [266]: https://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/ [267]: https://bootlin.com/doc/training/audio/audio-slides.pdf [268]: https://blog.quarkslab.com//starlink.html [269]: https://blog.exodusintel.com/2022/12/19/linux-kernel-exploiting-a-netfilter-use-after-free-in-kmalloc-cg/ [270]: https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/ [271]: https://portswigger.net/research/smashing-the-state-machine [272]: https://labs.taszk.io/articles/post/mtk_baseband_csn1_exploitation/ [273]: https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition [274]: https://research.checkpoint.com/2022/researching-xiaomis-tee/ [275]: https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-1 [276]: https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-2 [277]: https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-3-arm-edition [278]: https://www.sonarsource.com/blog/patches-collisions-and-root-shells-a-pwn2own-adventure/ [279]: https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/ [280]: https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass-part-2/ [281]: https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/ [282]: https://www.interruptlabs.co.uk/articles/pipe-buffer [283]: https://vulncheck.com/blog/openfire-cve-2023-32315 [284]: https://wrv.github.io/h26forge.pdf [285]: https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf [286]: https://eshard.com/posts/pixel6_bootloader [287]: https://eshard.com/posts/pixel6bootloader-2 [288]: https://eshard.com/posts/pixel6_bootloader_3 [289]: https://limitedresults.com/2019/09/pwn-the-esp32-secure-boot/ [290]: https://www.greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware [291]: https://labs.hakaioffsec.com/fortigate-authentication-bypass/ [292]: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/ [293]: https://redops.at/blog/a-story-about-tampering-edrs [294]: https://security.human[421]: https://www.tripwire.com/state-of-security/ghidra-101-loading-windows-symbols-pdb-files-in-ghidra-10-x [422]: https://github.com/PabloMK7/ENLBufferPwn [423]: https://f0rm2l1n.github.io/2021-02-02-syzkaller-diving-01/ [424]: https://f0rm2l1n.github.io/2021-02-04-syzkaller-diving-02/ [425]: https://f0rm2l1n.github.io/2021-02-10-syzkaller-diving-03/ [426]: https://www.nozominetworks.com/blog/the-importance-of-reverse-engineering-in-network-analysis [427]: https://www.stormshield.com/news/orbit-analysis-of-a-linux-dedicated-malware/ [428]: https://intezer.com/blog/research/orbit-new-undetected-linux-threat/ [429]: https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/ [430]: https://sandflysecurity.com/blog/detecting-linux-memfd-create-fileless-malware-with-command-line-forensics/ [431]: https://labs.withsecure.com/publications/spoofing-call-stacks-to-confuse-edrs [432]: https://labs.nettitude.com/blog/shellcode-source-mutations/ [433]: https://rollingpwn.github.io/BLE-Relay-Aattck/ [434]: https://blog.impalabs.com/2212_huawei-security-hypervisor.html [435]: https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html [436]: https://protectedmo.de/brute.html [437]: https://github.com/mikeryan/ice9-bluetooth-sniffer [438]: https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux [439]: https://blog.trailofbits.com/2023/02/16/suid-logic-bug-linux-readline/ [440]: https://intezer.com/blog/malware-analysis/new-linux-backdoor-redxor-likely-operated-by-chinese-nation-state-actor/ [441]: https://medium.com/@INTfinitySG/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2 [442]: https://medium.com/@INTfinitySG/1-2-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-2-cf1571493117 [443]: https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/ [444]: https://claroty.com/team82/research/hacking-ics-historians-the-pivot-point-from-it-to-ot [445]: https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/total-identity-compromise-microsoft-incident-response-lessons-on/ba-p/3753391 [446]: https://www.flashback.sh/blog/minesweeper-tplink-archer-lan-rce [447]: https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce [448]: https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/ [449]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-1/ [450]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-2/ [451]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-3/ [452]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-4/ [453]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-5/ [454]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-6/ [455]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-7/ [456]: https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser [457]: https://www.randorisec.fr/yet-another-bug-netfilter/ [458]: http://clarkkromenaker.com/post/library-dynamic-loading-mac/ [459]: https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/ [460]: https://maskray.me/blog/2023-02-12-all-about-leak-sanitizer [461]: https://intezer.com/blog/research/new-linux-threat-symbiote/ [462]: https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/ [463]: https://mattfrisbie.substack.com/p/spy-chrome-extension [464]: https://modexp.wordpress.com/2018/10/30/arm64-assembly/?ref=0xor0ne.xyz [465]: https://www.artresilia.com/iot-series-i-are-people-ready-to-go/ [466]: https://www.artresilia.com/iot-series-ii-how-to-build-kernel-image-from-scratch/ [467]: https://www.artresilia.com/iot-series-iii-firmware-testing-in-qemu/ [468]: https://www.artresilia.com/iot-series-iv-debugging-with-gdb-ghidra-zero-day/ [469]: https://mutur4.github.io/posts/remote-process-injection/ [470]: https://blogs.oracle.com/linux/post/live-kernel-debugging-1 [471]: https://blogs.oracle.com/linux/post/live-kernel-debugging-2 [472]: https://blogs.oracle.com/linux/post/live-kernel-debugging-3 [473]: https://www.willsroot.io/2022/12/entrybleed.html [474]: https://onekey.com/blog/making-toctou-great-again-xrip/?ref=0xor0ne.xyz [475]: https://bishopfox.com/blog/building-exploit-fortigate-vulnerability-cve-2023-27997 [476]: https://github.com/johnthagen/min-sized-rust [477]: https://www.nozominetworks.com/blog/14-vulnerabilities-discovered-in-phoenix-contact-hmis [478]: https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-2 [479]: https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-3 [480]: https://www.immersivelabs.com/blog/detecting-and-decrypting-sliver-c2-a-threat-hunters-guide/ [481]: https://labs.watchtowr.com/ghost-in-the-wire-sonic-in-the-wall/ [482]: https://www.appknox.com/security/how-to-emulate-android-native-libraries-using-qiling [483]: https://sam4k.com/patching-instrumenting-debugging-linux-kernel-modules/ [484]: https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/ [485]: http://codemachine.com/articles/windbg_quickstart.html [486]: https://github.blog/2023-10-17-getting-rce-in-chrome-with-incomplete-object-initialization-in-the-maglev-compiler/?ref=0xor0ne.xyz [487]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [488]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [489]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html [490]: https://github.com/clearbluejar/ghidriff [491]: https://www.willsroot.io/2022/08/reviving-exploits-against-cred-struct.html [492]: https://googleprojectzero.blogspot.com/2022/03/racing-against-clock-hitting-tiny.html [493]: https://danielmangum.com/posts/risc-v-bytes-exploring-custom-esp32-bootloader/ [494]: https://seanpesce.blogspot.com/2023/05/bypassing-selinux-with-initmodule.html [495]: https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/ [496]: https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part- [497]: https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part-2 [498]: https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki [499]: https://stigward.github.io/posts/fiio-m6-kernel-bug/ [500]: https://stigward.github.io/posts/fiio-m6-exploit/ [501]: https://iq.thc.org/how-does-linux-start-a-process [502]: https://0x44.xyz/blog/cve-2023-4369/ [503]: https://xairy.io/articles/syzkaller-external-network [504]: http://conference.hitb.org/files/hitbsecconf2023ams/materials/D2T1%20-%20Smart%20Speaker%20Shenanigans%20-%20Making%20the%20SONOS%20One%20Sing%20Its%20Secrets%20-%20Peter%20Geissler.pdf [505]: https://astralvx.com/stealing-the-bitlocker-key-from-a-tpm/ [506]: https://quentinkaiser.be/exploitdev/2020/09/23/ghetto-patch-diffing-cisco/ [507]: https://quentinkaiser.be/exploitdev/2020/10/01/patch-diffing-cisco-rv110/?ref=0xor0ne.xyz [508]: https://clearbluejar.github.io/posts/decompilation-debugging-pretending-all-binaries-come-with-source-code/ [509]: https://nicolo.dev/en/blog/role-control-flow-graph-static-analysis/ [510]: https://github.com/Orange-Cyberdefense/awesome-industrial-protocols [511]: https://sam4k.com/exploring-linux-random-kmalloc-caches/ [512]: https://people.kernel.org/linusw/the-arm32-scheduling-and-kernelspace-userspace-boundary [513]: https://thume.ca/2023/12/02/tracing-methods/ [514]: https://www.corellium.com/blog/exploring-unix-pipes-for-ios-kernel-exploit-primitives [515]: https://tmpout.sh [516]: https://sam4k.com/linternals-memory-allocators-part-1/ [517]: https://sam4k.com/linternals-memory-allocators-0x02/ [518]: https://quic.xargs.org [519]: https://dtls.xargs.org [520]: https://tls13.xargs.org [521]: https://tls12.xargs.org [522]: https://blog.xpnsec.com/restoring-dyld-memory-loading/ [523]: https://blog.xpnsec.com/building-a-mach-o-memory-loader-part-1/ [524]: https://www.synacktiv.com/sites/default/files/2023-11/ubuntu_shiftfs.pdf [525]: https://www.flashback.sh/blog/flashback-connects-cisco-rv340-ssl-vpn-rce [526]: https://github.com/nccgroup/exploit_mitigations?ref=0xor0ne.xyz [527]: https://lock.cmpxchg8b.com/reptar.html [528]: https://anatomic.rip/cve-2023-2598/ [529]: https://github.com/bcoles/kasld [530]: https://blog.exodusintel.com/2023/05/16/google-chrome-v8-arrayshift-race-condition-remote-code-execution/ [531]: https://research.nccgroup.com/2023/12/04/shooting-yourself-in-the-flags-jailbreaking-the-sonos-era-100/ [532]: https://etenal.me/archives/1825 [533]: https://pwning.tech/ksmbd/ [534]: https://github.blog/2023-12-06-cueing-up-a-calculator-an-introduction-to-exploit-development-on-linux/ [535]: https://duasynt.com/blog/linux-kernel-heap-feng-shui-2022 [536]: https://grsecurity.net/how_autoslab_changes_the_memory_unsafety_game [537]: https://www.zerodayinitiative.com/blog/2023/11/28/a-detailed-look-at-pwn2own-automotive-ev-charger-hardware [539]: https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html [540]: https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html [541]: https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html [542]: https://trenchant.io/expanding-the-dragon-adding-an-isa-to-ghidra/ [543]: https://adamdoupe.com/blog/2023/01/23/cve-2023-23504-xnu-heap-underwrite-in-dlil-dot-c/ [544]: https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/ [545]: https://boredpentester.com/reversing-esp8266-firmware-part-1/ [546]: https://boredpentester.com/reversing-esp8266-firmware-part-2/ [547]: https://boredpentester.com/reversing-esp8266-firmware-part-3/ [548]: https://boredpentester.com/reversing-esp8266-firmware-part-4/ [549]: https://boredpentester.com/reversing-esp8266-firmware-part-5/ [550]: https://boredpentester.com/reversing-esp8266-firmware-part-6/ [551]: https://eta.st/2023/01/31/rail-tickets.html [552]: https://www.crowdstrike.com/blog/exploiting-cve-2021-3490-for-container-escapes/ [553]: https://www.hacefresko.com/posts/tp-link-tapo-c200-unauthenticated-rce [554]: https://blog.bi0s.in/2023/01/23/Pwn/bi0sCTF22-b3typer/ [555]: https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html [556]: https://doar-e.github.io/blog/2022/03/26/competing-in-pwn2own-2021-austin-icarus-at-the-zenith/ [557]: https://ivanorsolic.github.io/post/hardwarehacking1/ [558]: https://kernemporium.github.io/posts/unpacking/ [559]: https://www.archcloudlabs.com/projects/loadlibrary-analysis/ [560]: https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9 [561]: https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi [562]: https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf [563]: https://github.com/V4bel/CVE-2022-41218 [564]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-1/ [565]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/ [566]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-3/ [567]: https://seclists.org/oss-sec/2023/q1/20 [569]: https://epi052.gitlab.io/notes-to-self/blog/2021-11-07-fuzzing-101-with-libafl-part-1.5/ [571]: https://cloudfuzz.github.io/android-kernel-exploitation/ [572]: https://www.akamai.com/blog/security-research/exploiting-critical-spoofing-vulnerability-microsoft-cryptoapi [573]: https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development?s=09 [574]: https://act-on.ioactive.com/acton/attachment/34793/f-6460b49e-1afe-41c3-8f73-17dc14916847/1/-/-/-/-/NFC-relay-TESlA_JRoriguez.pdf [575]: https://research.nccgroup.com/2023/02/06/rustproofing-linux-part-1-4-leaking-addresses/ [576]: https://research.nccgroup.com/2023/02/08/rustproofing-linux-part-2-4-race-conditions/ [577]: https://research.nccgroup.com/2023/02/14/rustproofing-linux-part-3-4-integer-overflows/ [578]: https://research.nccgroup.com/2023/02/16/rustproofing-linux-part-4-4-shared-memory/ [579]: https://sensepost.com/blog/2022/sim-hijacking/ [580]: https://dtsec.us/2023-09-15-StackSpoofin/ [581]: https://chao-tic.github.io/blog/2018/12/25/tls [582]: https://hackmd.io/@pepsipu/ry-SK44pt?s=09 [583]: https://exploitreversing.files.wordpress.com/2023/04/exploit_reversing_01-1.pdf [584]: https://exploitreversing.files.wordpress.com/2024/01/exploit_reversing_02.pdf [585]: https://anti-debug.checkpoint.com [586]: https://ktln2.org/reversing-c++-qt-applications-using-ghidra/ [587]: https://blog.thalium.re/posts/achieving-remote-code-execution-in-steam-remote-play/ [588]: https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ [589]: https://courk.cc/breaking-flash-encryption-of-espressif-parts [590]: https://courk.cc/esp32-c3-c6-fault-injection [591]: https://ptr-yudai.hatenablog.com/entry/2023/12/08/093606 [592]: https://eli.thegreenplace.net/2011/08/25/load-time-relocation-of-shared-libraries/ [593]: https://eli.thegreenplace.net/2011/11/03/position-independent-code-pic-in-shared-libraries/ [594]: https://redops.at/en/blog/exploring-hells-gate [595]: https://i.blackhat.com/EU-21/Wednesday/EU-21-Jin-The-Art-of-Exploiting-UAF-by-Ret2bpf-in-Android-Kernel-wp.pdf [596]: https://www.darknavy.org/blog/strengthening_the_shield_mte_in_memory_allocators/ [597]: https://richiejp.com/linux-kernel-exploit-tls_context-uaf [598]: https://eprint.iacr.org/2023/090.pdf [599]: https://therealcoiffeur.com/c101011.html [600]: https://therealcoiffeur.com/c101100.html [601]: https://therealcoiffeur.com/c101101.html [602]: https://blog.kylebot.net/2021/05/08/DEFCON-2021-Quals-mooosl/ [603]: https://security.humanativaspa.it/customizing-sliver-part-1/

    자세히 보기

    도구 다운로드