我个人收集的优秀博客文章、技术分析和论文,聚焦于网络安全领域。
如需深入了解网络安全相关工具,请查看专门的 网络安全工具 列表。
["深入探究 macOS 应用程序渗透测试(第 1 部分)"][49]
["深入剖析 Pwn2own Automotive EV 充电器硬件"][537]
["LibAFL 入门研讨会"][826]
["探究 CVE-2023-29360,一个漂亮的逻辑 LPE 漏洞"][260]
["入侵 Google Search Appliance 之旅"][203]
["一种利用基于文件的 DirtyCred 进行容器逃逸的新方法"][201]
["NAS 之痛:利用云连接攻陷你的 NAS:Synology DS920+ 版"][273]
["SoC 探索之旅"][189]
"面向 Windows 完全初学者的 PCIe 实用教程":
["一场 TOCTOU 报告竞赛:Intel SMM 中漏洞碰撞的分析"][255]
["红队队员日记"][156]
["一个关于篡改 EDR 的故事"][293]
["滥用 Liftoff 汇编并高效逃逸 sbx"][677]
["滥用 RCU 回调与 Use-After-Free 读取击败 KASLR"][857]
["滥用未记录功能伪造 PE 节头"][139]
["在 Steam 中实现远程代码执行:Remote Play 协议之旅"][587]
["关于 LeakSanitizer 的一切"][460]
["所有警察都在广播:TETRA 受到审视"][237]
["我最爱的所有追踪工具:eBPF、QEMU、Perfetto,以及我构建的更多新工具"][513]
["对一起在野 iOS Safari WebContent 到 GPU 进程漏洞利用的分析"][392]
["栈欺骗入门"][580]
["人类操控勒索软件中合法工具滥用分析"][4]
"Citrix ADC 和 NetScaler Gateway 中 CVE-2023-3519 的分析":
["VirtualBox CVE-2023-21987 和 CVE-2023-21991 分析"][119]
["分析一个现代在野 Android 漏洞利用"][379]
["分析 NETGEAR 路由器中一个古老的 Netatalk dsi_writeinit 缓冲区溢出漏洞"][326]
"ARM64 逆向与利用" (8ksec)
"攻击 EDR"
["攻击 JS 引擎:理解内存破坏崩溃的基础知识"][720]
["嵌入式 Linux 音频培训"][267]
["使用 Terraform、Nebula、Caddy 和 Cobalt Strike 自动化 C2 基础设施"][300]
["b3typer - bi0sCTF 2022"][554]
["回归未来的平台安全"][97]
["Parallel Desktop 中的 Bash 特权模式漏洞及 MacOS 中的 CDPATH 处理"][100]
["超越容量:Extreme Networks/Aerohive 无线 AP 中的未认证 RCE - CVE-2023-35803"][91]
["盾牌背后:揭开 Scudos 的防御"][8]
["BlackLotus UEFI bootkit:神话被证实"][429]
["使用 Volatility 3 进行 BPF 内存取证"][881]
["破解 Fortinet 固件加密"][233]
["破解代码 - 利用和分析 cls_tcindex 分类器漏洞中的 CVE-2023-1829"][81]
["在 Silicon Labs Gecko 平台上破解安全启动"][262]
["为 macOS 构建自定义 Mach-O 内存加载器"][523]
["为 FortiGate 漏洞 CVE-2023-27997 构建漏洞利用"][475]
["通过 ELF roping 绕过 noexec"][528]
["在用户态绕过 PPL(再次)"][308]
["使用 init_module 绕过 SELinux"][494]
"C101101: D-Link DIR-865L":
["CAN 注入:无钥匙汽车盗窃"][195]
"chonked"
["Chromium V8 堆沙箱中的代码执行"][896]
["Coffee:一个用 Rust 编写的 COFF 加载器"][93]
["参加 Pwn2Own ICS 2022 迈阿密:利用 ICONICS Genesis64 中的零点击远程内存破坏"][397]
["通过 io_uring 征服内存 - CVE-2023-2598 分析"][528]
"用 HEVD 破解 Windows 内核"
["准备计算器:Linux 漏洞利用开发入门"][534]
"定制 Sliver":
["CVE-2023-0179:Linux 内核 nftables 栈缓冲区溢出:PoC 与 writeup"][567]
["CVE-2023-2008 - 分析和利用 udmabuf 驱动中的漏洞"][72]
["CVE-2023-23504:XNU dlil.c 中的堆下写"][543]
["CVE-2023-26258 – ArcServe UDP Backup 中的远程代码执行"][99]
["CVE-2023-36844 及其伙伴:Juniper 设备中的 RCE"][281]
["CVE-2023-38408:OpenSSH 转发 ssh-agent 中的远程代码执行"][186]
["cURL 审计:一个玩笑如何引出重大发现"][459]
["D^ 3CTF2023 d3kcache:从 null 字节跨缓存溢出到无限任意读写"][964]
["Ghidra 调试器课程"][28]
["调试 D-Link:模拟固件与硬件黑客"][290]
["反编译调试"][508]
["OT 网络中的深度横向移动:边界何时不再是边界?"][253]
["定义 Cobalt Strike 反射加载器"][320]
["揭秘位运算,一篇温和的 C 教程"][400]
["检测和解密 Sliver C2 – 威胁猎手指南"][480]
["检测滥用 BPF 过滤器的 BPFDoor 后门变种"][183]
["Dirty Pagetable:一种统治 Linux 内核的新型利用技术"][51]
["剖析和利用 TCP/IP RCE 漏洞“EvilESP”"][164]
["深入智能合约反编译"][204]
["深入 Starlink 用户终端固件"][268]
"DJI Mavic 3 无人机研究"
["无人机安全与故障注入攻击"][82]
"DualShock4 逆向工程":
["轻松模拟 IoT 固件:无需物理设备即可开始黑客"][47]
["加密并不意味着认证:ShareFile RCE (CVE-2023-24489)"][182]
["ENLBufferPwn (CVE-2022-47949)"][422]
["用纯数据漏洞利用逃逸 Google kCTF 容器"][178]
["利用受限 chunk 大小的内核池溢出(CVE-2021-31969)"][827]
["Openfire CVE-2023-32315 的利用"][283]
["利用 Windows CryptoAPI 中的严重欺骗漏洞"][572]
["利用 Windows 用户模式打印机驱动中位图处理的缺陷"][130]
["利用 CVE-2021-3490 进行容器逃逸"][552]
["利用 Linux 内核中的空指针解引用"][148]
["探索用于 iOS 内核漏洞利用原语的 UNIX 管道"][514]
["EPF:邪恶包过滤器"][73]
["从 Bhyve 逃逸"][192]
["ESP32-C3 无线冒险 IoT 综合指南"][69]
["Espressif ESP32:用电磁分析破解硬件 AES"][394]
["Espressif ESP32:用功耗分析破解硬件 AES"][393]
["审视 OpenSSH 沙箱与权限分离 – 攻击面分析"][324]
["在只读文件系统中执行任意代码与可执行文件"][52]
["漏洞利用工程 – 攻击 Linux 内核"][146]
["用自定义 TCP 栈利用远程堆溢出"][322]
["探索地狱之门"][594]
["用 Zig 利用 Linux 内核中的漏洞"][597]
["利用 HTTP 解析器不一致性"][391]
["利用 CVE-2023-30799 攻击 MikroTik RouterOS 硬件"][198]
["探索 Jemalloc 'New' 中的 Android 堆分配"][7]
["探索 Linux 新的随机 Kmalloc 缓存"][511]
"神奇的 Rootkit:以及在哪里找到它们":
["C 语言中鲜为人知的技巧、怪癖和特性"][354]
["用 LOL 寻找和利用进程杀手驱动赚取 3000 美元"][172]
["用多级 IR 和 VAST 发现 C 代码中的漏洞"][92]
["用静态分析工具寻找 CPU 侧信道的小工具"][75]
["为了科学!- 利用 EDK II 中一个不起眼的漏洞进行有趣的利用"][70]
["FortiNAC - 再多几个 RCE"][95]
["Fortinet 系列 3 — CVE-2022–42475 SSLVPN 利用策略"][32]
["构造帧:通过操纵发送队列绕过 Wi-Fi 加密"][90]
["从 C 语言、内联汇编到 shellcode"][235]
"Fuzzing Farm":
["利用 Maglev 编译器中不完整的对象初始化在 Chrome 中获取 RCE"][486]
"Ghidra" (Craig Young):
["线中之鬼,墙中之索尼克 - SonicWall 冒险"][481]
["Google Chrome V8 ArrayShift 竞态条件远程代码执行"][530]
["黑客 Tapo TC60 摄像头"][350]
["黑客 Amazon eero 6(第 1 部分)"][86]
["黑客 Brightway 滑板车:案例研究"][29]
["黑客 ICS 历史数据库:从 IT 到 OT 的支点"][444]
["黑客 Nintendo DSi 浏览器"][456]
["绕过 BIOS 密码的硬件黑客"][5]
["注意!Xdr33,CIA HIVE 攻击工具包的一个变种出现"][443]
["一个简单的 K-TypeConfusion 如何花了我 3 个月才创建出漏洞利用?[HEVD] - Windows 11(build 22621)"][240]
["Linux 如何启动一个进程"][501]
"NAT 如何工作":
"我如何黑客我的汽车":
["我如何黑客智能灯:CVE-2022-47758 背后的故事"][841]
["如何使用 Qiling 模拟 Android 原生库"][482]
["如何进行电压故障注入"][685]
["如何保护 Linux 服务器"][140]
["Icicle:为灰盒固件模糊测试重新设计的模拟器"][171]
["深入分析 Valorant 的 Guarded Regions"][141]
["仅内存 ELF 执行(不使用 tmpfs)"][355]
["Intel BIOS 公告 – HID 驱动中的内存破坏"][257]
["用全局分配器拦截分配"][79]
["SELinux 简介"][59]
"IoT 系列":
["2023 年对初代 Xbox 进行 JTAG‘黑客’"][244]
["内核漏洞利用工厂"][159]
["用最美味的示例学习 Makefile"][24]
["让我们构建一个窃取一切的 Chrome 扩展"][463]
["让我们进入兔子洞 — 动态 hook Golang 程序的挑战"][387]
["利用 ssh-keygen 实现任意执行(及权限提升)"][327]
[linux-re-101][169]
["Linux 调试、性能分析和追踪培训"][353]
"Linux 内核利用"
"Linux 内核 PWN":
["Linux 内核 KSMBD 中的未认证远程堆溢出"][544]
["Linux 内核教学"][131]
["Linux 恶意软件:防御规避技术"][165]
"Linux 红队":
["Linux 远程进程注入 -(注入到 firefox 进程)"][569]
["Linux rootkit 解析 – 第 1 部分:动态链接器劫持"][60]
["Linux Shellcode 101:从地狱到 Shell"][53]
["DJI RM500 智能控制器上的本地权限提升"][160]
"指环王0":
["面向编译器开发者的低级软件安全"][15]
["RenderDoc 中的 LPE 和 RCE:CVE-2023-33865、CVE-2023-33864、CVE-2023-33863"][202]
["让 TOCTOU 再次伟大 – X(R)IP"][474]
"面向初学者的恶意软件逆向工程":
["无恶意 AP 的中间人攻击:当 WPA 遇上 ICMP 重定向"][285]
"mast1c0re"
["Mélofée:Panda 工具集中针对 Linux 主机的新外星恶意软件"][330]
["Meterpreter 对现代 EDR"][170]
"MTE 的实现":
["mTLS:当证书认证做错时"][270]
["MSMQ QueueJumper(RCE 漏洞):深入技术分析"][177]
["Qualcomm 和 Lenovo ARM 设备中的多个漏洞"][404]
"NetGear 系列:模拟 Netgear R6700V3 circled 二进制":
["新的 HiatusRAT 路由器恶意软件秘密监视受害者"][402]
["无分配,无问题:利用程序入口点进行进程注入"][1091]
["NVMe:新漏洞变得简单"][264]
["nftables 冒险:漏洞狩猎与 N-day 利用(CVE-2023-31248)"][365]
["晦涩的 Windows 文件类型"][74]
["旧漏洞,浅漏洞:在 Pwn2own Vancouver 2023 上利用 Ubuntu"][254]
["一枪三杀"][700]
"OPC UA 深入探究系列":
["OpenSSH 预认证双重释放 CVE-2023-25136 – Writeup 与概念验证"][42]
["OrBit:一个 Linux 专用恶意软件的高级分析"][427]
["OrBit:新的未被检测到的 Linux 威胁使用独特的执行流劫持"][428]
["P2PInfect:Rusty 点对点自我复制蠕虫"][206]
["P4wnP1-LTE"][209]
["补丁、碰撞和 Root Shell:一次 Pwn2Own 冒险"][278]
["补丁星期二 -> 星期三利用:24 小时内攻陷 Windows WinSock 辅助功能驱动(afd.sys)"][297]
["持久化的持久化技术"][299]
["BLE GATT 逆向工程实用入门:黑客 Domyos EL500"][166]
["prctl anon_vma_name:一个有趣的 Linux 内核堆喷射"][184]
["为 CVE-2022-42475(Fortinet RCE)制作 POC"][323]
["保护 Android 剪贴板内容免遭意外暴露"][448]
"保护凤凰:揭示 Phoenix Contact HMI 中的严重漏洞"
["PSPRAY:基于时序侧信道的 Linux 内核堆利用技术"][758]
["PyLoose:基于 Python 的无文件恶意软件针对云工作负载投递加密货币挖矿程序"][98]
["PwnAgent:Netgear RAX 路由器中一键 WAN 侧 RCE,CVE-2023-24749"][318]
["用一个遗留补丁攻陷 Pixel 6"][310]
["攻陷 tp-link ax1800 wifi 6 路由器:发现并利用一个内存破坏漏洞"][309]
["与锁赛跑:利用 Android 内核中的自旋锁 UAF"][185]
["Readline 犯罪:利用一个 SUID 逻辑漏洞"][439]
["红队对蓝队:Kerberos 票据时间、校验和与你!"][30]
["Reptar"][527]
["恢复 Dyld 内存加载"][522]
["重访 AMLogic A113X TrustZone 漏洞利用过程"][77]
["逆向英国移动铁路票"][551]
"逆向 Windows 容器":
["RISC-V 字节:探索自定义 ESP32 Bootloader"][493]
["REUnziP:用 FaultyUSB 重新利用华为恢复模式"][364]
["重访 CVE-2017-11176"][48]
"Root FiiO M6":
["Root 小米 WiFi 路由器"][817]
["Rust 二进制分析,逐特性"][231]
["Rust 到汇编:理解 Rust 的内部工作原理"][134]
"为 Linux 防锈":
["scudo 加固分配器 — 非官方内部文档"][706]
["SHA-1 被 SHAttered"][325]
["Shambles:下一代 IoT 逆向工程工具,用于发现 0-Day 漏洞"][55]
["幽灵中的 Shell:Ghostscript CVE-2023-28879 writeup"][76]
["移动边界:利用 Apple Safari 中的整数溢出"][261]
["向自己的 .flags 开枪 – 越狱 Sonos Era 100"][531]
["智能音箱恶作剧:让 Sonos ONE 唱出它的秘密"][504]
["粉碎状态机:Web 竞态条件的真正潜力"][271]
["SRE 深入探究 Linux Page Cache"][94]
["Sshimpanzee"][16]
["步入 Insyde 系统管理模式"][256]
["Sudo <= 1.9.12p1 中的 Sudoedit 绕过 CVE-2023-22809"][562]
["THC 最爱的技巧、窍门与黑客(速查表)"][31]
["ARM32 调度与内核空间/用户空间边界"][512]
["模糊测试的艺术:简介"][57]
["模糊测试的艺术:Windows 二进制"][89]
["模糊测试的艺术 - 使用 LibFuzzer 进行覆盖率引导模糊测试的分步指南"][54]
["Linux 持久化艺术"][872]
["AFL++ 模糊测试 Blitz 教程实验室"][303]
["不存在的代码:意外读取 Android 设备内存"][462]
["卖掉他科迈罗的龙:分析自定义路由器植入物"][228]
["逆向工程在网络分析中的重要性"][426]
["Linux 内核模块编程指南"][3]
["世界上最危险的编解码器:发现和利用 H.264 解码器中的漏洞"][284]
["控制流图在静态分析中的作用"][509]
["我们中间的沉默间谍:智能对讲机攻击"][331]
["栈系列:X64 栈"][356]
["BlackLotus UEFI Bootkit 的不为人知的故事"][205]
["逗弄 ksmbd:在 Linux 内核中模糊测试 SMB"][386]
["工具发布:Cartographer"][371]
["完全身份泄露:Microsoft 事件响应关于保护 Active Directory 的教训"][445]
["Xortigate,或 CVE-2023-27997 - 传闻中的 RCE 真相"][80]
["你不太“家庭办公” - Pwn2Own 上的 SOHO 黑客"][5]
["Ubuntu Shiftfs:不平衡解锁利用尝试"][524]
["RIGOL 示波器上的未认证 RCE"][210]
["UNCONTAINED:揭示 Linux 内核中的容器混淆"][37]
["揭示来自 Chrome 扩展的疯狂权限提升"][502]
["揭示 HinataBot:深入探究一个基于 Go 的威胁"][311]
["引擎盖下 - 拆解 IKEA-Sonos Symfonisk 音箱灯"][180]
["理解 Payload 的生命周期,以 Meterpreter 及其他客人为例"][315]
["理解 Dirty Pagetable - m0leCon 决赛 2023 CTF Writeup"][591]
["理解堆 - 一个美丽的混乱"][348]
["释放 ksmbd:打造 Linux 内核的远程漏洞利用"][828]
["释放 ksmbd:Linux 内核的远程利用(ZDI-23-979、ZDI-23-980)"][533]
["无限结果:破解 ESP32-V3 固件加密"][598]
"揭示 ESP32 的秘密":
["什么是 Loader Lock?"][845]
["Windows Installer 任意内容操纵权限提升(CVE-2020-0911)"][58]
["Windows Installer EOP(CVE-2023-21800)"][314]
["用 C 和 ASM 编写你自己的 RDI /sRDI 加载器"][307]
["Zenbleed"][207]
["零努力私钥泄露:滥用 SSH-Agent 进行横向移动"][248]## 2022
"A journey into IoT":
["A Kernel Hacker Meets Fuchsia OS"][710]
"A Technical Analysis of Pegasus for Android":
["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]
["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]
"ARM 64 Assembly Series":
["Attacking the Android kernel using the Qualcomm TrustZone"][885]
["Attacking Titan M with Only One Byte"][259]
["Avoiding Detection with Shellcode Mutator"][432]
"BasicFUN Series":
["Basics for Binary Exploitation"][749]
["Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"][238]
["BrokenPrint: A Netgear stack overflow"][782]
"Bypassing software update package encryption ":
["Bypassing vtable Check in glibc File Structures"][208]
["Blind Exploits to Rule Watchguard Firewalls"][173]
["BPFDoor - An Evasive Linux Backdoor Technical Analysis"][292]
["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]
"Chrome Browser Exploitation":
["Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"][556]
["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]
["Corrupting memory without memory corruption"][762]
["Creating a Rootkit to Learn C"][719]
["CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"][377]
["[CVE-2022-1786] A Journey To The Dawn"][401]
["CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"][168]
["CVE-2022-27666: Exploit esp6 modules in Linux kernel"][532]
["CVE-2022-29582 An io_uring vulnerability"][495]
["Deconstructing and Exploiting CVE-2020-6418"][778]
["DirtyCred Remastered: how to turn an UAF into Privilege Escalation"][167]
["Dumping the Amlogic A113X Bootrom"][78]
["Dynamic analysis of firmware components in IoT devices"][250]
["Embedded Systems Security and TrustZone"][145]
["Emulate Until You Make it"][748]
["EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"][473]
["Expanding the Dragon: Adding an ISA to Ghidra"][542]
["Exploiting: Buffer overflow in Xiongmai DVRs"][742]
["Exploiting CSN.1 Bugs in MediaTek Basebands"][272]
["exploiting CVE-2019-2215"][61]
"Exploiting CVE-2022-42703 - Bringing back the stack attack"
["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]
["Firmware key extraction by gaining EL3"][316]
["Fortigate - Authentication Bypass Lead to Full Device Takeover"][291]
"Fourchain":
["Fuzzing ping(8) … and finding a 24 year old bug"][751]
"Hacking Bluetooth to Brew Coffee from Github Actions":
["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]
["How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"][266]
["Huawei Security Hypervisor Vulnerability"][435]
"Hunting for Persistence in Linux"
"Hacking Some More Secure USB Flash Drives":
["Learning eBPF exploitation"][768]
"Intro to Embedded RE":
"Introduction to x64 Linux Binary Exploitation":
["io_uring - new code, new bugs, and a new exploit technique"][978]
["Linux Hardening Guide"][349]
["Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"][269]
["Linux Kernel Exploit (CVE-2022–32250) with mqueue"][242]
"Linux SLUB Allocator Internals and Debugging":
["Linternals: Introducing Memory Allocators & The Page Allocator"][516]
["Linternals: The Slab Allocator"][517]
["Linux kernel heap feng shui in 2022"][535]
["Looking for Remote Code Execution bugs in the Linux kernel"][503]
["Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"][319]
["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]
["Missing Manuals - io_uring worker pool"][265]
["Modifying Embedded Filesystems in ARM Linux zImages"][775]
"Netgear Orbi":
["nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"][63]
["NFC Relay Attack on Tesla Model Y"][574]
["Nightmare: One Byte to ROP // Deep Dive Edition"][582]
["Overview of GLIBC heap exploitation techniques"][239]
["Patching, Instrumenting & Debugging Linux Kernel Modules"][483]
"PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"
["pipe_buffer arbitrary read write"][282]
"Pixel 6 Bootloader"
["Port knocking from the scratch"][227]
["Pulling MikroTik into the Limelight"][120]
["Racing against the clock -- hitting a tiny kernel race window"][492]
["Replicating CVEs with KLEE"][763]
["Reversing C++, Qt based applications using Ghidra"][586]
["Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"][406]
["Replicant: Reproducing a Fault Injection "][675]
["Researching Xiaomi’s Tee to Get to Chinese Money"][274]
"Reversing embedded device bootloader (U-Boot)":
["Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"][368]
"Reverse Engineering Dark Souls 3":
["Reverse engineering integrity checks in Black Ops 3"][220]
["Reverse engineering thermal printers"][245]
["Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"][491]
["SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"][484]
["Shedding Light on Huawei's Security Hypervisor"][434]
["Shikitega - New stealthy malware targeting Linux"][438]
["side channels: power analysis"][380]
["side channels: using the chipwhisperer"][381]
["SIM Hijacking"][579]
["Spoofing Call Stacks To Confuse EDRs"][431]
["SROP Exploitation with radare2"][770]
["Stealing the Bitlocker key from a TPM"][505]
["Stranger Strings: An exploitable flaw in SQLite"][588]
"Survey of security mitigations and architectures, December 2022"
["Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"][461]
["Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"][226]
["The Dirty Pipe Vulnerability"][321]
["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]
["The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"][36]
["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]
"The toddler’s introduction to Heap exploitation":
["TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"][553]
["Tracing and Manipulating with DynamoRIO"][750]
["Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"][312]
["Turning Google smart speakers into wiretaps for $100k"][18]
"UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"
["Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"][126]
"Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":
["Vulnerability Details for CVE-2022-41218"][563]
["Vulnerabilities in Tenda's W15Ev2 AC1200 Router"][127]
["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]
["Write a Linux firewall from scratch based on Netfilter"][313]
["Yet another bug into Netfilter"][457]
"Zyxel authentication bypass patch analysis (CVE-2022-0342)"