Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
awesome-list — 面向网络安全的精选列表 | Kitploit
工具/GitHubGitHub/0xor0ne/awesome-list
漏洞分析漏洞利用逆向工程恶意软件分析CTF二进制分析论文与研究学习与教育精选资源
GitHub0xor0ne/awesome-list

awesome-list

面向网络安全的精选列表

查看仓库
3.9k413261天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

优秀网络安全列表

我个人收集的优秀博客文章、技术分析和论文,聚焦于网络安全领域。

如需深入了解网络安全相关工具,请查看专门的 网络安全工具 列表。

目录

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2014
  • 2011
  • 杂项
  • 其他列表

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [第 1 部分][1241]
    • [第 2 部分][1242]
    • [第 3 部分][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes"][1307]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["How LLMs Actually Work"][1308]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • "Sleeping Beauty"
    • ["Putting Adaptix to Bed with Crystal Palace"][1309]
    • ["CFG, CET, and Stack Spoofing"][1310]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]
  • 2025- ["A File Format Uncracked for 20 Years"][1202]

    • ["A First Glimpse of the Starlink User Ternimal"][1084]
    • ["A Fuzzy Escape - A tale of vulnerability research on hypervisors"][1151]
    • ["A look at an Android ITW DNG exploit"][1231]
    • ["A modern tale of blinkenlights"][1200]
    • ["A Quick Dive Into The Linux Kernel Page Allocator"][1098]
    • ["A Series of io_uring pbuf Vulnerabilities"][1083]
    • ["A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"][1181]
    • ["Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"][1021]
    • ["All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"][1142]
    • ["Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"][1174]
    • ["Analyzing IOS Kernel Panic Logs"][1037]
    • ["Android: Scudo"][1070]
    • ["Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"][1240]
    • ["APPROTECT Bypass on NRF52832"][1139]
    • ["APT28 Operation Phantom Net Voxel"][1171]
    • ["Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"][1132]
    • ["Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"][1106]
    • ["Being Overlord on the Steam Deck with 1 Byte"][1044]
    • "BPFDoor"
      • ["Part 1 - The Past"][1101]
      • ["Part 2 - The Present"][1102]
    • ["Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"][1189]
    • ["Best practices for key derivation"][1023]
    • ["Binder Fuzzing"][1146]
    • ["Blasting Past iOS 18"][1038]
    • ["Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"][1254]
    • ["Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"][1138]
    • ["Bootloader to Iris: A Security Teardown of a Hardware Wallet"][1199]
    • ["Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"][1125]
    • ["Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"][1196]
    • ["Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"][1217]
    • ["Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"][1039]
    • ["Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"][1179]
    • ["Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"][1209]
    • ["Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"][1124]
    • ["Bypassing disk encryption on systems with automatic TPM2 unlock"][1018]
    • ["Bypassing MTE with CVE-2025-0072"][1105]
    • ["Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"][1222]
    • ["Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"][1040]
    • ["Case Study: IOMobileFramebuffer NULL Pointer Dereference"][1041]
    • ["Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"][1107]
    • ["CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"][1061]
    • ["Control Flow Hijacking in the Linux Kernel"][1114]
    • ["Control Flow Hijacking via Data Pointers"][1085]
    • ["corCTF 2025 - corphone"][1168]
    • ["Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"][1212]
    • ["Cross Cache Attack CheetSheet"][1006]
    • ["CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"][1118]
    • ["CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"][1149]
    • ["CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"][1065]
    • ["CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"][1086]
    • ["CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"][1076]
    • ["CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"][1163]
    • ["CVE-2025-6554: The (rabbit) Hole"][1188]
    • ["Debugging the Pixel 8 kernel via KGDB"][1123]
    • ["Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"][1068]
    • ["Denial of Ruzzing: Rust in the Windows Kernel"][1185]
    • ["Dirty Pageflags: Revisiting PTE Exploitation in Linux"][1166]
    • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
    • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
    • ["Disassembling a binary: linear sweep and recursive traversal"][1019]
    • ["Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"][1047]
    • ["Don’t Phish-let Me Down: FIDO Authentication Downgrade"][1155]
    • ["EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"][1121]
    • ["Emulating an iPhone in QEMU"][1051]
    • ["Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"][1052]
    • ["Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"][1211]
    • ["Exploitation of AIxCC Nginx bugs: Part I"][1035]
    • ["Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
    • ["Exploiting a 13-years old bug on QEMU"][1218]
    • ["Exploiting CVE-2024-0582 via the Dirty Pagetable Method"][1081]
    • ["Exploiting CVE-2025-21479 on a Samsung S23"][1184]
    • ["Exploiting Retbleed in the real world"][1141]
    • ["Exploiting the Synology TC500 at Pwn2Own Ireland 2024"][1122]
    • ["Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"][1164]
    • ["Exploiting Heroes of Might and Magic V"][1119]
    • ["Exploring Grapheneos Secure Allocator: Hardened Malloc"][1167]
    • ["Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"][1029]
    • ["Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"][1172]
    • ["Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"][1152]
    • ["False Injections: Tales of Physics, Misconceptions and Weird Machines"][1120]
    • ["Fast & Faulty - A Use After Free in KGSL Fault Handling"][1182]
    • ["FiberGateway GR241AG - Full Exploit Chain"][1097]
    • ["First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"][1058]
    • ["FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"][1059]
    • ["Fundamental of Virtual Memory"][1162]
    • ["From Chrome renderer code exec to kernel with MSG_OOB"][1153]
    • ["Game Hacking - Valve Anti-Cheat (VAC)"][1074]
    • ["Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"][1215]
    • ["Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"][1103]
    • ["Google CTF 2025 Quals Writeup"][1131]
    • ["Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"][1031]
    • "Hacking the XBox 360 Hypervisor"
      • [Part 1][1109]
      • [Part 2][1110]
    • ["Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"][1129]
    • ["Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"][1198]
    • ["HITCON CTF 2025 -- calc"][1145]
    • ["How I ruined my vacation by reverse engineering WSC"][1077]
    • ["How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"][1090]
    • ["How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"][1115]
    • "Hydroph0bia (CVE-2025-4275)"
      • ["a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1143]
      • ["a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1144]
      • ["a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1108]
    • ["Hypervisors for Memory Introspection and Reverse Engineering"][1099]
    • ["Kernel Exploitation Techniques: Turning The (Page) Tables"][1100]
    • ["Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"][1180]
    • ["Inside Riot Vanguard's Dispatch Table Hooks"][1073]
    • ["Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"][1079]
    • "iOS 17: New Version, New Acronyms":
      • [Part 1][1042]
      • [Part 2][1043]
    • ["kASLR Internals and Evolution"][1095]
    • ["Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"][1082]
    • ["KernelSnitch: Side-Channel Attacks on Kernel Data Structures"][1005]
    • ksmbd (doyensec):
      • ["ksmbd vulnerability research"][1033]
      • ["Fuzzing Improvements and Vulnerability Discovery"][1175]
      • ["Exploiting CVE-2025-37947"][1176]
    • ["Laser Fault Injection on a Budget: RP2350 Edition"][1017]
    • ["Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"][1072]
    • ["Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"][1137]
    • ["Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"][1147]
    • ["Linux Kernel Exploitation For Beginners"][1113]
    • ["Linux Kernel Hfsplus Slab-out-of-bounds Write"][1066]
    • ["Linux kernel Rust module for rootkit detection"][1026]
    • ["Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution"][1011]
    • ["LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"][1177]
    • ["Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"][1050]
    • ["Malware Just Got Its Free Passes Back!"][1221]
    • ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
    • ["mediatek? more like media-rekt, amirite."][1220]
    • ["Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"][1069]
    • ["Modern (Kernel) Low Fragmentation Heap Exploitation"][1127]
    • ["My Emulation Goes to the Moon... Until False Flag"][1094]
    • ["NASA cFS version Aquila Software Vulnerability Assessment"][1056]
    • ["nRF51 RBPCONF bypass for firmware dumping"][1154]
    • ["One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"][1193]
    • ["Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"][1186]
    • ["Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"][1148]
    • ["Overview of Map Exploitation in v8"][1075]
    • ["Paint it Blue: Attacking the Bluetooth Stack"][1216]
    • ["Patch-Gapping the Google Container-Optimized OS for $0"][1032]
    • ["PatchGuard Internals"][1092]
    • ["PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"][1213]
    • ["Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"][1170]
    • ["Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"][1136]
    • ["Project Rain:L1TF"][1178]
    • ["Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"][1194]
    • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
    • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
    • ["pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"][1134]
    • ["Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"][1087]
    • ["Qualcomm DSP Kernel Internals"][1135]
    • ["Race Against Time in the Kernel’s Clockwork"][1160]
    • ["Recovering Metadata from .NET Native AOT Binaries"][1089]
    • ["Reliable system call interception"][1010]
    • ["Replacing a Space Heater Firmware Over WiFi"][1020]
    • ["Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"][1093]
    • ["Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"][1201]
    • ["Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"][1013]
    • ["Reversing Samsung's H-Arx Hypervisor Framework - Part 1"][1036]
    • ["Reversing the QardioArm"][1048]
    • ["Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields"][1226]
    • ["Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"][1071]
    • ["Root Shell on Credit Card Terminal"][1112]
    • ["Rooting the TP-Link Tapo C200 Rev.5"][1130]
    • ["ROPing our way to RCE"][1028]
    • ["Running code in a PAX Credit Card Payment Machine"][1272]
    • ["RV130X Firmware Analysis"][1025]
    • ["Security through Transparency: Tales from the RP2350 Hacking Challenge"][1256]
    • ["smoltalk: RCE in Open Source Agents"][1045]
    • ["Solo: A Pixel 6 Pro Story (When one bug is all you need)"][1128]
    • ["SoK: Security of EMV Contactless Payment Systems"][1088]
    • ["Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"][1034]
    • ["Stack Overflows, Heap Overflows, and Existential Dread"][1150]
    • ["State of Linux Snapshot Fuzzing"][1078]
    • ["STM32L05 Voltage Glitching"][1111]
    • ["Streaming Zero-Fi Shells to Your Smart Speaker"][1096]
    • ["Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"][1228]
    • ["System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"][1197]
    • ["The Art of Linux Kernel Rootkits"][1008]
    • ["The cryptography behind electronic passports"][1214]
    • "The Evolution of Dirty COW":
      • [Part 1][1062]
      • [Part 2][1063]
    • ["The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"][1116]
    • ["TLS NoVerify: Bypass All The Things"][1165]
    • ["Tp-Link Router Deep Research"][1203]
    • ["Tracing Back to the Source | SPTM Round 3"][1046]
    • ["Turning Camera Surveillance on its Axis"][1158]
    • ["Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"][1126]
    • ["Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"][1133]
    • ["VMware Workstation guest-to-host escape"][1161]
    • ["We are ARMed no more ROPpery Here"][1016]
    • "When a Wi-Fi SSID Gives You Root on an MT02 Repeater"
      • [Part 1][1156]
      • [Part 2][1157]
    • ["When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"][1067]
    • ["Windows arm64 Internals: Deconstructing Pointer Authentication"][1190]
    • ["Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"][1195]
    • "Windows Inter Process Communication A Deep Dive Beyond the Surface"
      • [Part 1][1204]
      • [Part 2][1205]
      • [Part 3][1206]
      • [Part 4][1207]
      • [Part 5][1208]
    • ["WireTap: Breaking Server SGX via DRAM Bus Interposition"][1183]
    • ["Workshop: Firmware Reverse Engineering"][1269]
    • ["Writing a Ghidra processor module"][1064]
    • ["Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique (CVE-2024-50629~50631)"][1247]
    • ["yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"][1210]
    • ["You Already Have Our Personal Data, Take Our Phone Calls Too"][1140]
    • ["Zen and the Art of Microcode Hacking"][1027]
    • ["Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"][1227]

    2024- ["韩国最大移动聊天应用中的一键利用"][965]

    • ["4 个漏洞利用,1 个 bug:以 4 种不同方式利用 cve-2024-20017"][959]
    • "64 字节与一条 ROP 链——nftables 之旅":
      • [第 1 部分][865]
      • [第 2 部分][866]
    • "nix libX11:揭示并利用一个 35 年前的漏洞":
      • [第 1 部分][703]
      • [第 2 部分][704]
    • ["关于 AWS Nitro Enclaves 的若干笔记:镜像与证明"][738]
    • "Android 14 取证初探"
    • ["来自 EuskalHack 的一次“Gau-Hack”"][893]
    • ["从 sudo iptables 到本地权限提升的旅程"][1009]
    • ["2024 年 PrintNightmare 实用指南"][709]
    • ["技术深度剖析:比较反作弊绕过与 EDR 绕过"][714]
    • ["回忆之旅"][715]
    • [AArch64 内存与分页][1015]
    • ["Chrome 利用入门——Maglev 版"][882]
    • ["一段意想不到的 Microsoft Defender 签名世界之旅"][876]
    • ["CVE-2024-21310 池溢出 Windows 云筛选器驱动程序分析"][952]
    • ["面向恶意软件分析的高级 CyberChef 技巧——详细演练与示例"][736]
    • ["AES-GCM 及基于 nonce 重用的破解"][912]
    • ["分析 Mutation-Coded——VM Protect 与 Alcatraz 英文版"][834]
    • ["ARLO:我在看着你"][810]
    • ["ASLRn't:内存对齐如何破坏了库 ASLR"][731]
    • ["克隆体来袭:利用重复对象属性在 Chrome 渲染器中实现 RCE"][911]
    • ["攻击 Android Binder:CVE-2023-20938 的分析与利用"][852]
    • ["汽车内存保护单元:揭示隐藏的漏洞"][1173]
    • "Base64 不止于编码"
      • [第 1 部分][945]
      • [第 2 部分][946]
    • ["通过 Zygote 命令注入变身任意 Android 应用"][863]
    • ["超越控制:探索用于 Linux 系统数据型攻击的新型文件系统对象"][895]
    • ["BGGP4:一个 420 字节的 x64 自复制 UEFI 应用"][728]
    • ["Ghidra 中的二进制类型推断"][905]
    • ["以 Router TL-WR902AC 为例对 IoT 设备进行黑盒模糊测试"][803]
    • ["打破屏障:屏障后 Spectre 攻击"][970]
    • ["通过红队挑战拆解对抗性机器学习攻击"][987]
    • ["拆解 Multipart 解析器:文件上传验证绕过"][966]
    • ["破解 Espressif 芯片的 Flash 加密功能"][589]
    • ["Bus Pirate 5:硬件黑客的瑞士 ARRRmy 军刀"][886]
    • ["购买间谍活动:深入了解商业监控供应商"][733]
    • ["利用 EDR-Preloading 绕过 EDR"][716]
    • ["字节码剖析:揭开 Factorio 的 Lua 安全缺陷"][920]
    • "串联 N-day 攻陷一切":
      • [第 1 部分][836]
      • [第 2 部分][837]
      • [第 3 部分][838]
      • [第 4 部分][839]
      • [第 5 部分][840]
    • ["Check Point——错误的检查点(CVE-2024-24919)"][875]
    • ["无需 ptrace 的 Android 代码注入"][874]
    • "CodeQL 从零到精通": [第 1 部分][858] [第 2 部分][859] [第 3 部分][860] [第 4 部分][1191] [第 5 部分][1192]
    • ["常见被滥用的 Linux 初始访问技术及检测策略"][896]
    • ["C 和 C++ 编译器选项加固指南"][877]
    • ["持续模糊测试 Python C 扩展"][734]
    • ["corCTF 2024:trojan-turtles 题解"][929]
    • ["corMine 1 和 2"][948]
    • ["跨进程 Spectre 利用"][969]
    • ["CVE-2024-20356:越狱 Cisco 设备以运行 DOOM"][861]
    • ["CVE-2022-2586 题解"][849]
    • ["CVE-2020-27786(竞态条件 + 释放后使用)"][967]
    • ["CVE-2022-4262"][864]
    • ["CVE-2024-5274:V8 解析器中的一个小缺陷导致灾难"][1012]
    • ["CVE-2023-6246:glibc 的 syslog() 中的堆缓冲区溢出"][697]
    • ["拔掉 PUMAKIT 的爪牙"][989]
    • [深入 RCU 竞态条件:TCP-AO UAF 分析(CVE-2024–27394)][1003]
    • ["拒绝快感:用 Flipper Zero 攻击不寻常的 BLE 目标"][699]
    • ["用 Ghidra 去混淆 Android ARM64 字符串:模拟、修补与自动化"][683]
    • ["剖析一个复杂漏洞并在 Ichitaro Word 中实现任意代码执行"][805]
    • ["深入探究 F5 Secure Vault"][918]
    • ["DJI——混淆的艺术"][705]
    • ["Docker 安全——逐步加固(Docker Hardening)"][729]
    • ["在 Android 驱动中一路前行"][908]
    • ["用 Unicorn Engine 模拟 RH850 架构"][853]
    • "日常 Ghidra:Ghidra 数据类型"
      • [第 1 部分][973]
      • [第 2 部分][974]
    • ["CVE-2024-26581 漏洞利用详情"][944]
    • ["探索 AMD 平台安全启动"][701]
    • ["探索 Linux 内核中的 GNU 扩展"][878]
    • ["利用 Android 的加固内存分配器"][1030]
    • ["利用 Empire C2 框架"][723]
    • "利用企业备份软件进行权限提升":
      • [第 1 部分][906]
      • [第 2 部分][907]
    • "漏洞利用与逆向(ER)系列":
      • [文章 01][583]
      • [文章 02][584]
    • ["利用 Steam:CEF 框架中的常见与不常见方式"][898]
    • ["探索目标文件格式"][684]
    • ["从 2021 款 Toyota RAV4 Prime 中提取安全车载通信(SecOC)密钥"][735]
    • ["针对 ESP32-C3 和 ESP32-C6 的故障注入攻击"][590]
    • ["故障注入——掉进兔子洞"][993]
    • "在内核中寻找 Bug":
      • [第 1 部分][996]
      • [第 2 部分][997]
    • ["平线:分析 Pulse Secure 固件并绕过完整性检查"][883]
    • ["翻页:分析 nf_tables 中的一个新 Linux 漏洞及加固利用技术"][804]
    • ["从故障注入到 RCE"][990]
    • ["从对象转换到 Chrome 渲染器中的 RCE"][940]
    • ["在流行条码软件的字里行间进行模糊测试"][968]
    • ["在启用 MTE 的 Pixel 8 上获得内核代码执行"][808]
    • ["Ghidra nanoMIPS ISA 模块"][873]
    • ["走向原生——恶意原生应用"][842]
    • ["Google Chrome V8 CVE-2024-0517 越界写入代码执行"][674]
    • ["GhostRace:利用与缓解推测性竞态条件"][802]
    • ["GPUAF——攻破所有基于 Qualcomm 的 Android 手机的两种方法"][994]
    • ["GraphStrike:攻击性工具开发剖析"][712]
    • ["在 2024 年入侵一台 2014 年的平板电脑!"][932]
    • ["入侵一台智能家居设备"][691]
    • ["入侵 Android 游戏"][949]
    • ["堆利用、glibc 内部机制与巧妙技巧"][938]
    • ["HEAP HEAP HOORAY——揭示 GLIBC 堆溢出漏洞(CVE-2023–6246)"][818]
    • ["嗨,我的名字是键盘"][676]
    • ["用 Bind Mounts 隐藏 Linux 进程"][925]
    • ["我又是如何入侵我的车的"][976]
    • ["如何绕过 Golang SSL 验证"][941]
    • ["用 KASAN 在 Linux 内核中猎捕 Bug:如何使用及其好处?"][995]
    • "追猎 UEFI 中的 HVCI 漏洞"
    • "在 Asus 路由器中猎捕未认证的 n-day"
    • "Iconv,将字符集设为 RCE":
      • [第 1 部分][870]
      • [第 2 部分][871]
    • ["Java 反序列化技巧"][815]
    • ["用树莓派进行 JTAG 黑客攻击"][851]
    • ["Kuiper 勒索软件的演变"][702]
    • ["深入一款新型 OT/IoT 网络武器:IOCONTROL"][1001]
    • ["深入 LogoFAIL PoC:从整数溢出到任意代码执行"][692]
    • ["Android 原生组件模糊测试入门"][984]
    • "学习 LLVM":
      • [第 1 部分][934]
      • [第 2 部分][935]
    • ["LeftoverLocals:通过泄露的 GPU 本地内存监听 LLM 响应"][687]
    • "利用 Binary Ninja IL 逆向自定义 ISA:破解“金罐”37C3"
    • ["Linux 内核攻击面:超越 IOCTL。DMA-BUF"][999]
    • "Linux 内核利用":
      • ["环境"][922]
      • ["ret2usr"][923]
    • ["听着:Sonos 空中远程内核利用与隐蔽窃听——BlackHat USA 2024 白皮书"][939]
    • "ManageEngine ADAudit——逆向 Windows RPC 以发现 CVE":
      • [第 1 部分][901]
      • [第 2 部分][902]
      • [第 3 部分][903]
    • ["留意补丁差距:利用 Ubuntu 中的 io_uring 漏洞"][809]
    • ["Mali GPU 内核本地权限提升"][786]
    • ["MalpediaFLOSSed"][814]
    • ["Microsoft BitLocker 绕过是可行的"][718]
    • ["现代植入物设计:位置无关的恶意软件开发"][690]
    • ["我的新超能力"][688]
    • ["不是你要找的无人机"][825]
    • "三角测量行动":
      • ["Keychain 模块分析"][823]
      • ["音频模块分析"][824]
    • ["OtterRoot:Netfilter 通用 Root 1-day"][986]
    • ["glibc 的 qsort() 中的越界读取与写入"][698]
    • ["PageJack:一种利用页级 UAF 的强大漏洞利用技术"][951]
    • ["面向页编程:用不可写代码页颠覆商用操作系统内核的控制流完整性"][1000]
    • ["补丁星期二差异分析:CVE-2024-20696——Windows Libarchive RCE"][835]
    • ["在 Linux 内核中固定用户空间页:探索 get_user_pages、pin_user_pages 与页表遍历"][983]
    • ["PixieFail:Tianocore 的 EDK II IPv6 网络栈中的九个漏洞"][711]
    • "2024 年玩转 libmalloc"
    • ["Puckungfu 2:另一个 NETGEAR WAN 命令注入"][730]
    • ["在 Musl 堆上举铁——在 Alpine mallocng 堆上对 CVE-2022-24834 的真实世界利用"][910]
    • ["Pwn2Own Automotive 2024:入侵 ChargePoint Home Flex(及其云……)"][933]
    • ["像内核一样攻破浏览器"][957]
    • "Pwn2Own:WAN 到 LAN 漏洞利用展示":
      • ["Pwn2Own:WAN 到 LAN 漏洞利用展示,第 1 部分"][950]
      • ["Pwn2Own:从 WAN 转向 LAN 攻击 Synology BC500 IP 摄像头,第 2 部分"][942]
    • "Pwn2Own Toronto 2023":
      • ["一切是如何开始的"][829]
      • ["探索攻击面"][830]
      • ["探索"][831]
      • ["内存破坏分析"][832]
      • ["漏洞利用"][833]
    • ["攻破一台 Brother 标签打印机,为了乐趣与互操作性!"][897]
    • "Pwntools 10x":
      • [第 1 部分][867]
      • [第 2 部分][868]
      • [第 3 部分][869]
    • ["Pygmy Goat"][972]
    • ["用反汇编器和分支恢复 ECU 固件"][921]
    • ["regreSSHion:基于 glibc 的 Linux 系统上 OpenSSH 服务器中的 RCE(CVE-2024-6387)"][919]
    • ["用 Python 中的 Capstone 反汇编器与 Unicorn 解析栈字符串"][846]
    • ["改造加密固件是个坏主意"][1024]
    • ["逆向一台汽车钥匙遥控信号"][801]
    • ["逆向工程与拆解 Kekz 耳机"][962]
    • ["从编译后的二进制文件中逆向 Protobuf 定义"][820]
    • ["逆向航天飞机上那台 59 磅重的打印机"][943]
    • ["逆向 AM335x 启动 ROM"][947]
    • ["逆向 Stream Deck Plus"][1004]
    • "环绕正则表达式"
      • [第 1 部分][955]
      • [第 2 部分][956]
    • ["RISCVuzz:通过差异化硬件模糊测试发现架构级 CPU 漏洞"][958]
    • ["RomCom 在野利用 Firefox 和 Windows 零日漏洞"][981]
    • ["从零开始 ROP 路由器:逐步实现 Tenda Ac8v4 Mips 0day 流控制 ROP -> RCE"][892]
    • ["通往安全之路:避开路由器陷阱"][816]
    • ["攻破一台 Hive 摄像头"][819]
    • ["SAME70 模拟器"][879]
    • "说声朋友,就进来吧":
      • [第 1 部分][812]
      • [第 2 部分][813]
    • ["Samsung NX 相关文章"][887]
    • ["Scavy:自动发现 Linux 内核中用于权限提升的内存破坏目标"][975]
    • ["SECGlitcher(第 1 部分)——在 STM32 微控制器上可复现的电压毛刺"][862]
    • ["SELinux 绕过"][963]
    • ["面向漏洞利用开发者的 SLUB 内部机制"][980]
    • ["SLUBStick:通过 Linux 内核中实用的软件跨缓存攻击实现任意内存写入"][937]
    • ["我们汇编吗?"][689]
    • ["使用 WebAssembly 和 Rust 进行 Shellcode 规避"][726]
    • "SMM 隔离":
      • ["SMI 降权(ISRD)"][847]
      • ["安全策略报告(ISSR)"][848]
    • ["SoK:“up”在哪里?!关于 Arm Cortex-M 系统安全性的全面(自底向上)研究"][1049]
    • ["强化护盾:堆分配器中的 MTE"][596]
    • ["更进一步:理解 Linux 内核利用中的页喷射"][913]
    • ["SAST 工具的架构:面向开发者的解释"][739]
    • ["UEFI 的黑暗面:跨芯片利用技术深度剖析"][880]
    • ["Linux 进程注入权威指南"][971]
    • ["“隐形斗篷”——斜杠 Proc 魔法"][924]
    • ["Qualcomm DSP 驱动——意外挖掘出一个漏洞利用"][1007]
    • ["rev.ng 反编译器开源 + UI 封闭测试启动"][694]
    • ["一个 GSM 内核本地权限提升的故事"][850]
    • ["概念验证漏洞利用代码(PoC)的狂野西部"][926]
    • "Windows 注册表冒险":
      • [第 1 部分][914]
      • [第 2 部分][915]
      • [第 3 部分][916]
    • ["TIKTAG:用推测执行攻破 ARM 的内存标记扩展"][894]
    • ["Tony Hawk 的 Pro Strcpy"][928]
    • ["工具链死灵术:困扰 ASLR 的过往错误"][732]
    • ["TP-Link 固件解密 C210 V2 云摄像头引导加载程序"][988]
    • ["TP-Link TDDP 缓冲区溢出漏洞"][695]
    • ["两个字节足矣:利用 CVE-2024-21762 实现 FortiGate RCE"][787]
    • ["理解 AddressSanitizer:让你的代码拥有更好的内存安全"][889]
    • ["理解 Unix 垃圾回收及其与 io_uring 的交互"][891]
    • ["理解 Windows x64 汇编"][693]
    • ["使用符号执行去虚拟化一个虚拟化二进制文件"][936]
    • ["利用跨 CPU 分配攻击禁用抢占的 Linux 内核"][985]
    • ["VBA:玩转宏、被覆写的指针与 R/W/X 内存"][843]
    • ["Realtek SD 卡读卡器驱动的漏洞"][1002]
    • ["为什么代码安全很重要——即使在加固环境中"][953]
    • ["Qualcomm 设备上的 Windows Secure-Launch"][811]
    • ["Windows Sockets:从注册 I/O 到 SYSTEM 权限"][998]
    • ["Windows 与 Linux 加载器架构"][844]
    • ["Windows Wi-Fi 驱动 RCE 漏洞——CVE-2024-30078"][954]
    • "从零编写调试器"
      • ["附加到进程"][449]
      • ["寄存器状态与单步执行"][450]
      • ["读取内存"][451]
      • ["导出与私有符号"][452]
      • ["断点"][453]
      • ["栈"][454]
      • ["反汇编"][455]
    • ["用 eBPF 编写系统调用跟踪器"][931]
    • ["你的 NVMe 被 Syz 了:用 Syzkaller 模糊测试 Linux 的 NVMe-oF/TCP 驱动"][854]
    • ["x64 返回地址欺骗"][991]
    • ["x64 调用栈欺骗"][992]

    2023- ["深入探究 Brute Ratel C4 Payloads"][374]

    • ["深入探究 macOS 应用程序渗透测试(第 1 部分)"][49]

    • "深入探究基于 TPM 的 BitLocker 驱动器加密"

    • ["深入剖析 Pwn2own Automotive EV 充电器硬件"][537]

    • ["LibAFL 入门研讨会"][826]

    • ["探究 CVE-2023-29360,一个漂亮的逻辑 LPE 漏洞"][260]

    • ["入侵 Google Search Appliance 之旅"][203]

    • ["一种利用基于文件的 DirtyCred 进行容器逃逸的新方法"][201]

    • ["NAS 之痛:利用云连接攻陷你的 NAS:Synology DS920+ 版"][273]

    • ["SoC 探索之旅"][189]

    • "面向 Windows 完全初学者的 PCIe 实用教程":

      • [第 1 部分][806]
      • [第 2 部分][807]
    • ["一场 TOCTOU 报告竞赛:Intel SMM 中漏洞碰撞的分析"][255]

    • ["红队队员日记"][156]

    • ["一个关于篡改 EDR 的故事"][293]

    • ["滥用 Liftoff 汇编并高效逃逸 sbx"][677]

    • ["滥用 RCU 回调与 Use-After-Free 读取击败 KASLR"][857]

    • ["滥用未记录功能伪造 PE 节头"][139]

    • ["在 Steam 中实现远程代码执行:Remote Play 协议之旅"][587]

    • ["关于 LeakSanitizer 的一切"][460]

    • ["所有警察都在广播:TETRA 受到审视"][237]

    • ["我最爱的所有追踪工具:eBPF、QEMU、Perfetto,以及我构建的更多新工具"][513]

    • ["对一起在野 iOS Safari WebContent 到 GPU 进程漏洞利用的分析"][392]

    • ["栈欺骗入门"][580]

    • ["人类操控勒索软件中合法工具滥用分析"][4]

    • "Citrix ADC 和 NetScaler Gateway 中 CVE-2023-3519 的分析":

      • [第 1 部分][196]
      • [第 2 部分][197]
    • ["VirtualBox CVE-2023-21987 和 CVE-2023-21991 分析"][119]

    • ["分析一个现代在野 Android 漏洞利用"][379]

    • ["分析 NETGEAR 路由器中一个古老的 Netatalk dsi_writeinit 缓冲区溢出漏洞"][326]

    • "ARM64 逆向与利用" (8ksec)

      • [第 1 部分][107]
      • [第 2 部分][108]
      • [第 3 部分][109]
      • [第 4 部分][110]
      • [第 5 部分][111]
      • [第 6 部分][112]
      • [第 7 部分][113]
      • [第 8 部分][388]
      • [第 9 部分][389]
      • [第 10 部分][390]
    • "攻击 EDR"

      • [第 1 部分][395]
      • [第 2 部分][396]
    • "从 Web 视角攻击 IoT 设备"

    • ["攻击 JS 引擎:理解内存破坏崩溃的基础知识"][720]

    • ["嵌入式 Linux 音频培训"][267]

    • ["使用 Terraform、Nebula、Caddy 和 Cobalt Strike 自动化 C2 基础设施"][300]

    • ["b3typer - bi0sCTF 2022"][554]

    • ["回归未来的平台安全"][97]

    • ["Parallel Desktop 中的 Bash 特权模式漏洞及 MacOS 中的 CDPATH 处理"][100]

    • ["超越容量:Extreme Networks/Aerohive 无线 AP 中的未认证 RCE - CVE-2023-35803"][91]

    • ["盾牌背后:揭开 Scudos 的防御"][8]

    • ["BlackLotus UEFI bootkit:神话被证实"][429]

    • "BLUFFS:蓝牙前向与未来保密性攻击及防御"

    • ["使用 Volatility 3 进行 BPF 内存取证"][881]

    • ["破解 Fortinet 固件加密"][233]

    • ["破解代码 - 利用和分析 cls_tcindex 分类器漏洞中的 CVE-2023-1829"][81]

    • ["在 Silicon Labs Gecko 平台上破解安全启动"][262]

    • ["为 macOS 构建自定义 Mach-O 内存加载器"][523]

    • ["为 FortiGate 漏洞 CVE-2023-27997 构建漏洞利用"][475]

    • ["通过 ELF roping 绕过 noexec"][528]

    • ["在用户态绕过 PPL(再次)"][308]

    • ["使用 init_module 绕过 SELinux"][494]

    • "C101101: D-Link DIR-865L":

      • ["远程代码执行(预认证)"][599]
      • ["未签名固件上传导致持久后门(预认证)"][600]
      • ["内存破坏导致远程代码执行(预认证)"][601]
    • ["CAN 注入:无钥匙汽车盗窃"][195]

    • "chonked"

      • ["minidlna 1.3.2 http chunk 解析堆溢出(cve-2023-33476)根因分析"][193]
      • ["利用 cve-2023-33476 实现远程代码执行"][194]
    • ["Chromium V8 堆沙箱中的代码执行"][896]

    • ["Coffee:一个用 Rust 编写的 COFF 加载器"][93]

    • ["参加 Pwn2Own ICS 2022 迈阿密:利用 ICONICS Genesis64 中的零点击远程内存破坏"][397]

    • ["通过 io_uring 征服内存 - CVE-2023-2598 分析"][528]

    • "用 HEVD 破解 Windows 内核"

      • "第 0 章"
      • "第 1 章"
      • "第 2 章"
      • "第 3 章"
      • "第 4 章"
    • ["准备计算器:Linux 漏洞利用开发入门"][534]

    • "定制 Sliver":

      • [第 1 部分][603]
      • 第 2 部分
      • 第 3 部分
    • "CVE-2022-27666:我的文件你的内存"

    • ["CVE-2023-0179:Linux 内核 nftables 栈缓冲区溢出:PoC 与 writeup"][567]

    • ["CVE-2023-2008 - 分析和利用 udmabuf 驱动中的漏洞"][72]

    • ["CVE-2023-23504:XNU dlil.c 中的堆下写"][543]

    • ["CVE-2023-26258 – ArcServe UDP Backup 中的远程代码执行"][99]

    • ["CVE-2023-36844 及其伙伴:Juniper 设备中的 RCE"][281]

    • ["CVE-2023-38408:OpenSSH 转发 ssh-agent 中的远程代码执行"][186]

    • ["cURL 审计:一个玩笑如何引出重大发现"][459]

    • ["D^ 3CTF2023 d3kcache:从 null 字节跨缓存溢出到无限任意读写"][964]

    • ["Ghidra 调试器课程"][28]

    • ["调试 D-Link:模拟固件与硬件黑客"][290]

    • ["反编译调试"][508]

    • ["OT 网络中的深度横向移动:边界何时不再是边界?"][253]

    • ["定义 Cobalt Strike 反射加载器"][320]

    • ["揭秘位运算,一篇温和的 C 教程"][400]

    • ["检测和解密 Sliver C2 – 威胁猎手指南"][480]

    • ["检测滥用 BPF 过滤器的 BPFDoor 后门变种"][183]

    • ["Dirty Pagetable:一种统治 Linux 内核的新型利用技术"][51]

    • ["剖析和利用 TCP/IP RCE 漏洞“EvilESP”"][164]

    • ["深入智能合约反编译"][204]

    • ["深入 Starlink 用户终端固件"][268]

    • "DJI Mavic 3 无人机研究"

      • ["固件分析"][376]
      • ["漏洞分析"][713]
    • ["无人机安全与故障注入攻击"][82]

    • "DualShock4 逆向工程":

      • [第 1 部分][149]
      • [第 3 部分][150]
      • [第 3 部分][151]
    • "eBPF:恶意软件的新前沿"

    • ["轻松模拟 IoT 固件:无需物理设备即可开始黑客"][47]

    • ["加密并不意味着认证:ShareFile RCE (CVE-2023-24489)"][182]

    • ["ENLBufferPwn (CVE-2022-47949)"][422]

    • ["用纯数据漏洞利用逃逸 Google kCTF 容器"][178]

    • ["利用受限 chunk 大小的内核池溢出(CVE-2021-31969)"][827]

    • ["Openfire CVE-2023-32315 的利用"][283]

    • ["利用 Windows CryptoAPI 中的严重欺骗漏洞"][572]

    • ["利用 Windows 用户模式打印机驱动中位图处理的缺陷"][130]

    • ["利用 CVE-2021-3490 进行容器逃逸"][552]

    • ["利用 Linux 内核中的空指针解引用"][148]

    • ["探索用于 iOS 内核漏洞利用原语的 UNIX 管道"][514]

    • ["EPF:邪恶包过滤器"][73]

    • ["从 Bhyve 逃逸"][192]

    • ["ESP32-C3 无线冒险 IoT 综合指南"][69]

    • ["Espressif ESP32:用电磁分析破解硬件 AES"][394]

    • ["Espressif ESP32:用功耗分析破解硬件 AES"][393]

    • ["审视 OpenSSH 沙箱与权限分离 – 攻击面分析"][324]

    • ["在只读文件系统中执行任意代码与可执行文件"][52]

    • ["漏洞利用工程 – 攻击 Linux 内核"][146]

    • ["用自定义 TCP 栈利用远程堆溢出"][322]

    • ["探索地狱之门"][594]

    • ["用 Zig 利用 Linux 内核中的漏洞"][597]

    • ["利用 HTTP 解析器不一致性"][391]

    • ["利用 CVE-2023-30799 攻击 MikroTik RouterOS 硬件"][198]

    • ["探索 Jemalloc 'New' 中的 Android 堆分配"][7]

    • ["探索 Linux 新的随机 Kmalloc 缓存"][511]

    • "探索链接器输出中的节布局"

    • "神奇的 Rootkit:以及在哪里找到它们":

      • [第 1 部分][275]
      • [第 2 部分][276]
      • [第 3 部分][277]
    • ["C 语言中鲜为人知的技巧、怪癖和特性"][354]

    • ["用 LOL 寻找和利用进程杀手驱动赚取 3000 美元"][172]

    • ["用多级 IR 和 VAST 发现 C 代码中的漏洞"][92]

    • ["用静态分析工具寻找 CPU 侧信道的小工具"][75]

    • ["为了科学!- 利用 EDK II 中一个不起眼的漏洞进行有趣的利用"][70]

    • ["FortiNAC - 再多几个 RCE"][95]

    • ["Fortinet 系列 3 — CVE-2022–42475 SSLVPN 利用策略"][32]

    • ["构造帧:通过操纵发送队列绕过 Wi-Fi 加密"][90]

    • ["从 C 语言、内联汇编到 shellcode"][235]

    • "Fuzzing Farm":

      • ["用 fuzzuf 对 GEGL 进行模糊测试"][43]
      • ["评估模糊测试器的性能"][44]
      • ["补丁分析与 PoC 开发"][45]
      • ["猎捕和利用 0-day [CVE-2022-24834]"][46]
    • "为乐趣和 panic 对 Golang msgpack 进行模糊测试"

    • ["利用 Maglev 编译器中不完整的对象初始化在 Chrome 中获取 RCE"][486]

    • "Ghidra" (Craig Young):

      • ["用 Ghidra 逆向共享对象指南"][121]
      • ["用 Ghidra 反编译器逆向一个简单的 CrackMe"][122]
      • ["用 Ghidra 进行漏洞狩猎"][123]
      • ["从 Ghidra 清单修补漏洞"][124]
      • ["用 Ghidra 脚本进行漏洞分析"][125]
    • ["线中之鬼,墙中之索尼克 - SonicWall 冒险"][481]

    • ["Google Chrome V8 ArrayShift 竞态条件远程代码执行"][530]

    • ["黑客 Tapo TC60 摄像头"][350]

    • ["黑客 Amazon eero 6(第 1 部分)"][86]

    • ["黑客 Brightway 滑板车:案例研究"][29]

    • ["黑客 ICS 历史数据库:从 IT 到 OT 的支点"][444]

    • ["黑客 Nintendo DSi 浏览器"][456]

    • ["绕过 BIOS 密码的硬件黑客"][5]

    • ["注意!Xdr33,CIA HIVE 攻击工具包的一个变种出现"][443]

    • ["一个简单的 K-TypeConfusion 如何花了我 3 个月才创建出漏洞利用?[HEVD] - Windows 11(build 22621)"][240]

    • ["Linux 如何启动一个进程"][501]

    • "NAT 如何工作":

      • [第 1 部分][152]
      • [第 2 部分][153]
      • [第 3 部分][154]
      • [第 4 部分][155]
    • "我如何黑客我的汽车":

      • [第 1 部分][101]
      • [第 2 部分][102]
      • [第 3 部分][103]
      • [第 4 部分][104]
      • [第 5 部分][105]
      • [第 6 部分][106]
    • ["我如何黑客智能灯:CVE-2022-47758 背后的故事"][841]

    • ["如何使用 Qiling 模拟 Android 原生库"][482]

    • ["如何进行电压故障注入"][685]

    • ["如何保护 Linux 服务器"][140]

    • "猎捕易受攻击的内核驱动"

    • ["Icicle:为灰盒固件模糊测试重新设计的模拟器"][171]

    • ["深入分析 Valorant 的 Guarded Regions"][141]

    • ["仅内存 ELF 执行(不使用 tmpfs)"][355]

    • ["Intel BIOS 公告 – HID 驱动中的内存破坏"][257]

    • ["用全局分配器拦截分配"][79]

    • "Cutter 入门"

    • ["SELinux 简介"][59]

    • "IoT 系列":

      • ["人们准备好了吗?"][465]
      • ["如何从零构建内核镜像"][466]
      • ["QEMU 中的固件测试"][467]
      • ["用 GDB 和 GHIDRA 调试 + 零日"][468]
    • ["2023 年对初代 Xbox 进行 JTAG‘黑客’"][244]

    • ["内核漏洞利用工厂"][159]

    • ["用最美味的示例学习 Makefile"][24]

    • ["让我们构建一个窃取一切的 Chrome 扩展"][463]

    • ["让我们进入兔子洞 — 动态 hook Golang 程序的挑战"][387]

      • [第 1 部分][387]
      • [第 2 部分][904]
      • [第 3 部分][930]
    • ["利用 ssh-keygen 实现任意执行(及权限提升)"][327]

    • "lexmark 打印机 haxx"

    • [linux-re-101][169]

    • ["Linux 调试、性能分析和追踪培训"][353]

    • "Linux 内核利用"

      • ["入门与 BOF"][678]
      • ["堆技术"][679]
      • ["利用竞态条件 + UAF"][680]
    • "Linux 内核 PWN":

      • ["ret2dir"][899]
      • ["DirtyCred"][900]
    • ["Linux 内核 KSMBD 中的未认证远程堆溢出"][544]

    • ["Linux 内核教学"][131]

    • ["Linux 恶意软件:防御规避技术"][165]

    • "Linux 红队":

      • ["利用技术"][222]
      • ["权限提升技术"][223]
      • ["持久化技术"][224]
    • ["Linux 远程进程注入 -(注入到 firefox 进程)"][569]

    • ["Linux rootkit 解析 – 第 1 部分:动态链接器劫持"][60]

    • ["Linux Shellcode 101:从地狱到 Shell"][53]

    • ["DJI RM500 智能控制器上的本地权限提升"][160]

    • "指环王0":

      • [第 1 部分][10]
      • [第 2 部分][11]
      • [第 3 部分][12]
      • [第 4 部分][13]
      • [第 5 部分][14]
    • ["面向编译器开发者的低级软件安全"][15]

    • ["RenderDoc 中的 LPE 和 RCE:CVE-2023-33865、CVE-2023-33864、CVE-2023-33863"][202]

    • ["让 TOCTOU 再次伟大 – X(R)IP"][474]

    • "面向初学者的恶意软件逆向工程":

      • [第 1 部分][128]
      • [第 2 部分][129]
    • ["无恶意 AP 的中间人攻击:当 WPA 遇上 ICMP 重定向"][285]

    • "mast1c0re"

      • ["简介 – 通过游戏存档利用 PS4 和 PS5"][38]
      • ["第 1 部分 – 修改 PS2 游戏存档文件"][39]
      • ["第 2 部分 – 任意 PS2 代码执行"][40]
      • ["第 3 部分 – 逃逸模拟器"][41]
    • ["Mélofée:Panda 工具集中针对 Linux 主机的新外星恶意软件"][330]

    • ["Meterpreter 对现代 EDR"][170]

    • "MTE 的实现":

      • [第 1 部分][366]
      • [第 2 部分][367]
    • ["mTLS:当证书认证做错时"][270]

    • ["MSMQ QueueJumper(RCE 漏洞):深入技术分析"][177]

    • ["Qualcomm 和 Lenovo ARM 设备中的多个漏洞"][404]

    • "NetGear 系列:模拟 Netgear R6700V3 circled 二进制":

      • [第 1 部分][441]
      • [第 2 部分][442]
    • ["新的 HiatusRAT 路由器恶意软件秘密监视受害者"][402]

    • ["无分配,无问题:利用程序入口点进行进程注入"][1091]

    • ["NVMe:新漏洞变得简单"][264]

    • ["nftables 冒险:漏洞狩猎与 N-day 利用(CVE-2023-31248)"][365]

    • ["晦涩的 Windows 文件类型"][74]

    • ["旧漏洞,浅漏洞:在 Pwn2own Vancouver 2023 上利用 Ubuntu"][254]

    • ["一枪三杀"][700]

    • "OPC UA 深入探究系列":

      • [第 1 部分][211]
      • [第 2 部分][212]
      • [第 3 部分][213]
      • [第 4 部分][214]
      • [第 5 部分][215]
    • ["OpenSSH 预认证双重释放 CVE-2023-25136 – Writeup 与概念验证"][42]

    • ["OrBit:一个 Linux 专用恶意软件的高级分析"][427]

    • ["OrBit:新的未被检测到的 Linux 威胁使用独特的执行流劫持"][428]

    • ["P2PInfect:Rusty 点对点自我复制蠕虫"][206]

    • ["P4wnP1-LTE"][209]

    • ["补丁、碰撞和 Root Shell:一次 Pwn2Own 冒险"][278]

    • ["补丁星期二 -> 星期三利用:24 小时内攻陷 Windows WinSock 辅助功能驱动(afd.sys)"][297]

    • ["持久化的持久化技术"][299]

    • ["BLE GATT 逆向工程实用入门:黑客 Domyos EL500"][166]

    • ["prctl anon_vma_name:一个有趣的 Linux 内核堆喷射"][184]

    • ["为 CVE-2022-42475(Fortinet RCE)制作 POC"][323]

    • ["保护 Android 剪贴板内容免遭意外暴露"][448]

    • "保护凤凰:揭示 Phoenix Contact HMI 中的严重漏洞"

      • [第 1 部分][477]
      • [第 2 部分][478]
      • [第 3 部分][479]
    • "Python 中的原型污染"

    • ["PSPRAY:基于时序侧信道的 Linux 内核堆利用技术"][758]

    • ["PyLoose:基于 Python 的无文件恶意软件针对云工作负载投递加密货币挖矿程序"][98]

    • ["PwnAgent:Netgear RAX 路由器中一键 WAN 侧 RCE,CVE-2023-24749"][318]

    • "Pwnassistant - 通过 Home Assistant RCE 控制 /home"

    • ["用一个遗留补丁攻陷 Pixel 6"][310]

    • ["攻陷 tp-link ax1800 wifi 6 路由器:发现并利用一个内存破坏漏洞"][309]

    • ["与锁赛跑:利用 Android 内核中的自旋锁 UAF"][185]

    • ["Readline 犯罪:利用一个 SUID 逻辑漏洞"][439]

    • ["红队对蓝队:Kerberos 票据时间、校验和与你!"][30]

    • ["Reptar"][527]

    • ["恢复 Dyld 内存加载"][522]

    • ["重访 AMLogic A113X TrustZone 漏洞利用过程"][77]

    • ["逆向英国移动铁路票"][551]

    • "逆向 Windows 容器":

      • [第 1 部分][821]
      • [第 2 部分][822]
    • ["RISC-V 字节:探索自定义 ESP32 Bootloader"][493]

    • ["REUnziP:用 FaultyUSB 重新利用华为恢复模式"][364]

    • ["重访 CVE-2017-11176"][48]

    • "Root FiiO M6":

      • ["用“世界上最差的模糊测试器”寻找内核漏洞"][499]
      • ["为我们的溢出漏洞编写 LPE 漏洞利用"][500]
    • ["Root 小米 WiFi 路由器"][817]

    • ["Rust 二进制分析,逐特性"][231]

    • ["Rust 到汇编:理解 Rust 的内部工作原理"][134]

    • "为 Linux 防锈":

      • [第 1 部分][575]
      • [第 2 部分][576]
      • [第 3 部分][577]
      • [第 4 部分][578]
    • ["scudo 加固分配器 — 非官方内部文档"][706]

    • "保护我们的家庭实验室:Frigate 代码审查"

    • "保护我们的家庭实验室:Home Assistant 代码审查"

    • ["SHA-1 被 SHAttered"][325]

    • ["Shambles:下一代 IoT 逆向工程工具,用于发现 0-Day 漏洞"][55]

    • ["幽灵中的 Shell:Ghostscript CVE-2023-28879 writeup"][76]

    • ["移动边界:利用 Apple Safari 中的整数溢出"][261]

    • ["向自己的 .flags 开枪 – 越狱 Sonos Era 100"][531]

    • ["智能音箱恶作剧:让 Sonos ONE 唱出它的秘密"][504]

    • ["粉碎状态机:Web 竞态条件的真正潜力"][271]

    • ["SRE 深入探究 Linux Page Cache"][94]

    • ["Sshimpanzee"][16]

    • ["步入 Insyde 系统管理模式"][256]

    • ["Sudo <= 1.9.12p1 中的 Sudoedit 绕过 CVE-2023-22809"][562]

    • ["THC 最爱的技巧、窍门与黑客(速查表)"][31]

    • ["ARM32 调度与内核空间/用户空间边界"][512]

    • ["模糊测试的艺术:简介"][57]

    • ["模糊测试的艺术:Windows 二进制"][89]

    • ["模糊测试的艺术 - 使用 LibFuzzer 进行覆盖率引导模糊测试的分步指南"][54]

    • ["Linux 持久化艺术"][872]

    • ["AFL++ 模糊测试 Blitz 教程实验室"][303]

    • ["不存在的代码:意外读取 Android 设备内存"][462]

    • ["卖掉他科迈罗的龙:分析自定义路由器植入物"][228]

    • ["逆向工程在网络分析中的重要性"][426]

    • ["Linux 内核模块编程指南"][3]

    • ["世界上最危险的编解码器:发现和利用 H.264 解码器中的漏洞"][284]

    • ["控制流图在静态分析中的作用"][509]

    • ["我们中间的沉默间谍:智能对讲机攻击"][331]

    • ["栈系列:X64 栈"][356]

    • ["BlackLotus UEFI Bootkit 的不为人知的故事"][205]

    • ["逗弄 ksmbd:在 Linux 内核中模糊测试 SMB"][386]

    • ["工具发布:Cartographer"][371]

    • ["完全身份泄露:Microsoft 事件响应关于保护 Active Directory 的教训"][445]

    • ["Xortigate,或 CVE-2023-27997 - 传闻中的 RCE 真相"][80]

    • ["你不太“家庭办公” - Pwn2Own 上的 SOHO 黑客"][5]

    • ["Ubuntu Shiftfs:不平衡解锁利用尝试"][524]

    • ["RIGOL 示波器上的未认证 RCE"][210]

    • ["UNCONTAINED:揭示 Linux 内核中的容器混淆"][37]

    • ["揭示来自 Chrome 扩展的疯狂权限提升"][502]

    • ["揭示 HinataBot:深入探究一个基于 Go 的威胁"][311]

    • ["引擎盖下 - 拆解 IKEA-Sonos Symfonisk 音箱灯"][180]

    • ["理解 Payload 的生命周期,以 Meterpreter 及其他客人为例"][315]

    • ["理解 Dirty Pagetable - m0leCon 决赛 2023 CTF Writeup"][591]

    • ["理解堆 - 一个美丽的混乱"][348]

    • ["释放 ksmbd:打造 Linux 内核的远程漏洞利用"][828]

    • ["释放 ksmbd:Linux 内核的远程利用(ZDI-23-979、ZDI-23-980)"][533]

    • ["无限结果:破解 ESP32-V3 固件加密"][598]

    • "揭示 ESP32 的秘密":

      • "创建一个开源 MAC 层"
      • "逆向工程 RX"
    • "Web 黑客对汽车行业:Ferrari、BMW、Rolls Royce、Porsche 等中的严重漏洞"

    • ["什么是 Loader Lock?"][845]

    • ["Windows Installer 任意内容操纵权限提升(CVE-2020-0911)"][58]

    • ["Windows Installer EOP(CVE-2023-21800)"][314]

    • ["用 C 和 ASM 编写你自己的 RDI /sRDI 加载器"][307]

    • ["Zenbleed"][207]

    • ["零努力私钥泄露:滥用 SSH-Agent 进行横向移动"][248]## 2022

    • "A journey into IoT":

      • ["芯片识别、BUSSide 和 I2C"][294]
      • ["发现组件和端口"][295]
      • ["固件转储与分析"][296]
      • ["无线电通信"][681]
      • ["内部通信"][682]
    • ["A Kernel Hacker Meets Fuchsia OS"][710]

    • "A Technical Analysis of Pegasus for Android":

      • [第 1 部分][564]
      • [第 2 部分][565]
      • [第 3 部分][566]
    • ["ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"][747]

    • ["An In-Depth Look at the ICE-V Wireless FPGA Development Board"][779]

    • "ARM 64 Assembly Series":

      • ["基本定义与寄存器"][408]
      • ["偏移与寻址模式"][409]
      • ["加载与存储"][410]
      • ["分支"][411]
      • ["数据处理(第 1 部分)"][412]
      • ["数据处理(第 2 部分)"][413]
      • ["选择与循环"][414]
      • ["子程序"][415]
    • ["Attacking the Android kernel using the Qualcomm TrustZone"][885]

    • ["Attacking Titan M with Only One Byte"][259]

    • ["Avoiding Detection with Shellcode Mutator"][432]

    • "BasicFUN Series":

      • "硬件分析 / SPI Flash 提取"
      • "逆向工程固件 / 重新刷写 SPI Flash"
      • "通过 I2C I/O 扩展器转储并行 Flash"
      • "I2C 嗅探、EEPROM 提取与并行 Flash 提取"
    • ["Basics for Binary Exploitation"][749]

    • ["Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"][238]

    • ["BrokenPrint: A Netgear stack overflow"][782]

    • "Bypassing software update package encryption ":

      • ["提取 Lexmark MC3224i 打印机固件"][190]
      • ["利用 Lexmark MC3224i 打印机"][191]
    • ["Bypassing vtable Check in glibc File Structures"][208]

    • ["Blind Exploits to Rule Watchguard Firewalls"][173]

    • ["BPFDoor - An Evasive Linux Backdoor Technical Analysis"][292]

    • ["Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"][917]

    • "Chrome Browser Exploitation":

      • [第 1 部分][1053]
      • [第 2 部分][1054]
      • [第 3 部分][1055]
    • ["Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"][556]

    • ["CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"][759]

    • ["Corrupting memory without memory corruption"][762]

    • ["Creating a Rootkit to Learn C"][719]

    • ["CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"][377]

    • ["[CVE-2022-1786] A Journey To The Dawn"][401]

    • ["CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"][168]

    • ["CVE-2022-27666: Exploit esp6 modules in Linux kernel"][532]

    • ["CVE-2022-29582 An io_uring vulnerability"][495]

    • ["Deconstructing and Exploiting CVE-2020-6418"][778]

    • ["DirtyCred Remastered: how to turn an UAF into Privilege Escalation"][167]

    • "Disclosing information with a side-channel in Django"

    • ["Dumping the Amlogic A113X Bootrom"][78]

    • ["Dynamic analysis of firmware components in IoT devices"][250]

    • ["Embedded Systems Security and TrustZone"][145]

    • ["Emulate Until You Make it"][748]

    • ["EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"][473]

    • ["Expanding the Dragon: Adding an ISA to Ghidra"][542]

    • ["Exploiting: Buffer overflow in Xiongmai DVRs"][742]

    • ["Exploiting CSN.1 Bugs in MediaTek Basebands"][272]

    • ["exploiting CVE-2019-2215"][61]

    • "Exploiting CVE-2022-42703 - Bringing back the stack attack"

    • ["Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"][707]

    • "Exploring the Hidden Attack Surface of OEM IoT Devices"

    • ["Firmware key extraction by gaining EL3"][316]

    • ["Fortigate - Authentication Bypass Lead to Full Device Takeover"][291]

    • "Fourchain":

      • ["序幕"][765]
      • ["漏洞"][766]
      • ["沙箱"][767]
    • ["Fuzzing ping(8) … and finding a 24 year old bug"][751]

    • "Hacking Bluetooth to Brew Coffee from Github Actions":

      • [第 1 部分][752]
      • [第 2 部分][753]
      • [第 3 部分][754]
    • "Hackign More Secure Portable Storage Devices"

    • ["How did I approach making linux LKM rootkit, “reveng_rtkit” ?"][884]

    • ["How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"][266]

    • ["Huawei Security Hypervisor Vulnerability"][435]

    • "Hunting for Persistence in Linux"

      • [第 1 部分][64]
      • [第 2 部分][65]
      • [第 3 部分][66]
      • [第 4 部分][67]
      • [第 5 部分][68]
    • "Hacking Some More Secure USB Flash Drives":

      • [第 1 部分][132]
      • [第 2 部分][133]
    • ["Learning eBPF exploitation"][768]

    • "Intro to Embedded RE":

      • ["工具与系列"][351]
      • ["UART 发现与通过 UBoot 提取固件"][352]
    • "Introduction to x64 Linux Binary Exploitation":

      • 第 1 部分
      • 第 2 部分
      • 第 3 部分
      • 第 4 部分
      • 第 5 部分
    • ["io_uring - new code, new bugs, and a new exploit technique"][978]

    • ["Linux Hardening Guide"][349]

    • ["Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"][269]

    • ["Linux Kernel Exploit (CVE-2022–32250) with mqueue"][242]

    • "Linux SLUB Allocator Internals and Debugging":

      • [第 1 部分][359]
      • [第 2 部分][360]
      • [第 3 部分][361]
      • [第 4 部分][362]
    • ["Linternals: Introducing Memory Allocators & The Page Allocator"][516]

    • ["Linternals: The Slab Allocator"][517]

    • ["Linux kernel heap feng shui in 2022"][535]

    • ["Looking for Remote Code Execution bugs in the Linux kernel"][503]

    • ["Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"][319]

    • ["MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"][777]

    • ["Missing Manuals - io_uring worker pool"][265]

    • ["Modifying Embedded Filesystems in ARM Linux zImages"][775]

    • "Netgear Orbi":

      • ["orbi hunting 0x0: introduction, uart access, recon"][33]
      • ["orbi hunting 0x1: crashes in soap-api"][34]
      • ["nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"][35]
    • ["nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"][63]

    • ["NFC Relay Attack on Tesla Model Y"][574]

    • ["Nightmare: One Byte to ROP // Deep Dive Edition"][582]

    • ["Overview of GLIBC heap exploitation techniques"][239]

    • "Parsing TFTP in Rust"

    • ["Patching, Instrumenting & Debugging Linux Kernel Modules"][483]

    • "PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"

    • ["pipe_buffer arbitrary read write"][282]

    • "Pixel 6 Bootloader"

      • ["启动过程"][286]
      • ["模拟、ROP"][287]
      • ["漏洞利用"][288]
    • ["Port knocking from the scratch"][227]

    • ["Pulling MikroTik into the Limelight"][120]

    • ["Racing against the clock -- hitting a tiny kernel race window"][492]

    • ["Replicating CVEs with KLEE"][763]

    • ["Reversing C++, Qt based applications using Ghidra"][586]

    • ["Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"][406]

    • ["Replicant: Reproducing a Fault Injection "][675]

    • ["Researching Xiaomi’s Tee to Get to Chinese Money"][274]

    • "Reversing embedded device bootloader (U-Boot)":

      • [第 1 部分][162]
      • [第 2 部分][163]
    • ["Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"][368]

    • "Reverse engineering an EV charger"

    • "Reverse Engineering Dark Souls 3":

      • "连接"
      • "数据包"
      • "密钥交换"
      • "可靠 UDP"
    • ["Reverse engineering integrity checks in Black Ops 3"][220]

    • ["Reverse engineering thermal printers"][245]

    • ["Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"][491]

    • ["SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"][484]

    • ["Shedding Light on Huawei's Security Hypervisor"][434]

    • ["Shikitega - New stealthy malware targeting Linux"][438]

    • ["side channels: power analysis"][380]

    • ["side channels: using the chipwhisperer"][381]

    • ["SIM Hijacking"][579]

    • ["Spoofing Call Stacks To Confuse EDRs"][431]

    • ["SROP Exploitation with radare2"][770]

    • ["Stealing the Bitlocker key from a TPM"][505]

    • ["Stranger Strings: An exploitable flaw in SQLite"][588]

    • "Survey of security mitigations and architectures, December 2022"

    • ["Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"][461]

    • ["Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"][226]

    • ["The Dirty Pipe Vulnerability"][321]

    • ["The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"][772]

    • ["The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"][36]

    • ["TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)"][751]

    • "The toddler’s introduction to Heap exploitation":

      • ["第 1 部分"][339]
      • ["第 2 部分"][340]
      • ["溢出"][341]
      • ["Use After Free 与 Double free"][342]
      • ["FastBin Dup to Stack"][343]
      • ["FastBin Dup Consolidate"][344]
      • ["Unsafe Unlink"][345]
      • ["House of Spirit"][346]
      • ["House of Lore"][347]
    • ["TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"][553]

    • ["Tracing and Manipulating with DynamoRIO"][750]

    • ["Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"][312]

    • ["Turning Google smart speakers into wiretaps for $100k"][18]

    • "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"

    • ["Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"][126]

    • "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security":

      • [第 1 部分][496]
      • [第 2 部分][497]
    • ["Vulnerability Details for CVE-2022-41218"][563]

    • ["Vulnerabilities in Tenda's W15Ev2 AC1200 Router"][127]

    • "When an N-Day turns into a 0day"

    • ["WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"][764]

    • ["Write a Linux firewall from scratch based on Netfilter"][313]

    • ["Yet another bug into Netfilter"][457]

    • "Xiongmai IoT Exploitation"

    • "Zyxel authentication bypass patch analysis (CVE-2022-0342)"

    2021

    • "A dive into the PE file format":
      • ["简介"][332]
      • ["DOS 头、DOS 存根与 Rich 头"][333]
      • ["NT 头"][334]
      • ["数据目录、节头与节"][335]
      • ["导入(导入目录表、ILT、IAT)"][336]
      • ["PE 基址重定位"][337]
      • ["编写 PE 解析器"][338]
    • ["A Nerve-Racking Bug Collision in Samsung's NPU Driver"][855]
    • "A Practical Approach to Attacking IoT Embedded Designs":
      • [第 1 部分][721]
      • [第 2 部分][722]
    • ["Attacking Samsung RKP"][909]
    • ["Automatic unpacking with Qiling framework"][558]
    • ["BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"][755]
    • ["Breaking 64 bit aslr on Linux x86-64"][234]
    • ["Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"][375]
    • ["Complete Guide to Stack Buffer Overflow (OSCP Preparation)"][317]
    • ["CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"][561]
    • ["CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."][179]
    • ["CVE-2021-22555: Turning \x00\x00 into 10000$"][977]
    • ["Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"][756]
    • "Digging into Linux namespaces":
      • [第 1 部分][157]
      • [第 2 部分][158]
    • ["Exploiting crash handlers: LPE on Ubuntu"][760]
    • "Extending Ghidra Part 1: Setting up a Development Environment"
    • ["Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"][252]
    • "Fuzzing101 with LibAFL":
      • ["Fuzzing Xpdf"][468]
      • ["第 I 部分的性能改进"][469]
      • ["Fuzzing libexif"][470]
    • ["Getting to know memblock"][771]
    • "Ghidra 101":
      • ["光标文本高亮"][416]
      • ["切片高亮"][417]
      • ["解码栈字符串"][418]
      • ["加载 Windows 符号(PDB 文件)"][419]
      • ["在 Ghidra 中创建结构体"][420]
      • ["在 Ghidra 10.x 中加载 Windows 符号(PDB 文件)"][421]
    • ["GRCON 2021 - Capture the Signal"][403]
    • "Hacking the Furbo Dog Camera":
      • [第 1 部分][744]
      • [第 2 部分][745]
      • [第 3 部分][746]
    • ["How AUTOSLAB Changes the Memory Unsafety Game"][536]
    • "Learning Linux Kernel Exploitation":
      • [第 1 部分][83]
      • [第 2 部分][84]
      • [第 3 部分][85]
    • "LinkSys EA6100 AC1200":
      • [第 1 部分][740]
      • [第 1 部分][741]
    • "Linux Internals: How /proc/self/mem writes to unwritable memory"
    • "Linux Kernel Exploitation":
      • ["使用 QEMU 调试内核"][25]
      • ["在内核中粉碎栈溢出"][26]
      • ["通过栈溢出控制 RIP 并提升权限"][27]
    • "Live Debugging Techniques for the Linux Kernel"
      • [第 1 部分][470]
      • [第 2 部分][471]
      • [第 3 部分][472]
    • "Malware development (0xPat)"
      • [第 1 部分][792]
      • [第 2 部分][793]
      • [第 3 部分][794]
      • [第 4 部分][795]
      • [第 5 部分][796]
      • [第 6 部分][797]
      • [第 7 部分][798]
      • [第 8 部分][799]
      • [第 9 部分][800]
    • ["mooosl"][602]
    • ["My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"][560]
    • ["New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"][440]
    • ["New Old Bugs in the Linux Kernel"][305]
    • ["Practical Introduction to CodeQL"][1233]
    • ["Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug"]
    • ["Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"][555]
    • ["Recovering a Full PEM Private key when Half of it is Redacted"][96]
    • "Reverse Engineering an Unknown Microcontroller"
    • "Reverse Engineering Bare-Metal Firmware":
      • [第 1 部分][142]
      • [第 2 部分][143]
      • [第 3 部分][144]
    • ["Reverse Engineering Yaesu FT-70D Firmware Encryption"][147]
    • "Syzkaller diving":
      • [第 1 部分][423]
      • [第 2 部分][424]
      • [第 3 部分][425]
    • ["The Art of Exploiting UAF by Ret2bpf in Android Kernel"][595]
    • ["The Oddest Place You Will Ever Find PAC"][306]
    • ["Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"][888]
    • "VMProtect 2"
      • [第 1 部分][960]
      • [第 2 部分][961]
    • ["Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"][251]

    2020

    • "A Deep Dive Into Samsung's TrustZone"
      • [第 1 部分][487]
      • [第 2 部分][488]
      • [第 3 部分][489]
    • ["An iOS hacker tries Android"][856]
    • "BGET Explained Binary Heap Exploitation on OP-TEE":
      • [第 1 部分][187]
      • [第 2 部分][188]
    • ["BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"][372]
    • ["Building a Basic C2"][1057]
    • ["CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"][890]
    • ["CVE-2020-16040 Analysis & Exploitation"][725]
    • "Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"
    • "Espressif ESP32: Bypassing Secure Boot using EMFI"
    • "Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"
    • "Espressif ESP32: Controlling PC during Secure Boot"
    • ["Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"][430]
    • ["Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"][161]
    • ["Flashback Connects - Cisco RV340 SSL VPN RCE"][525]
    • "Hardware Debugging for Reverse Engineers":
      • "SWD、OpenOCD 与 Xbox One 控制器"
      • "TAG、SSD 与固件提取"Manipulating AES Traffic
    • ["Hardware Hacking 101: Identifying and Dumping eMMC Flash"][87]
    • ["House of Muney - Leakless Heap Exploitation Technique"][181]
    • ["Learning to Decapsulate Integrated Circuits Using Acid Deposition"][727]
    • ["Loading Dynamic Libraries on Mac"][458]
    • ["Minesweeper - TP-Link Archer C7 LAN RCE"][446]
    • ["My Methods To Achieve Persistence In Linux Systems"][247]
    • "nRF52 Debug Resurrection":
      • [第 1 部分][279]
      • [第 2 部分][280]
    • ["NTLM Relay"][56]
    • "Patch Diffing a Cisco RV110W Firmware Update"
      • [第 1 部分][506]
      • [第 2 部分][507]
    • ["Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"][783]
    • ["ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"][370]
    • ["Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"][780]
    • ["SSHD Injection and Password Harvesting"][230]
    • ["There’s A Hole In Your SoC: Glitching The MediaTek BootROM"][737]
    • ["Weekend Destroyer - RCE in Western Digital PR4100 NAS"][447]
    • ["What're you telling me, Ghidra?"][358]

    2019

    • ["Breaking out of Docker via runC – Explaining CVE-2019-5736"][369]
    • "Executable and Linkable Format 101":
      • ["节与段"][135]
      • ["符号"][136]
      • ["重定位"][137]
      • ["动态链接"][138]
    • ["Exploiting Qualcomm WLAN and Modem Over the Air"][773]
    • ["Hacking microcontroller firmware through a USB"][243]
    • ["Hardening Secure Boot on Embedded Devices for Hostile Environments"][175]
    • ["How to Weaponize the Yubikey"][743]
    • ["Pew Pew Pew: Designing Secure Boot Securely"][176]
    • ["Pwn the ESP32 crypto-core"][757]
    • ["Pwn the ESP32 Secure Boot"][289]
    • ["Reverse Engineering Architecture And Pinout of Custom Asics"][398]
    • ["Reverse-engineering Broadcom wireless chipsets"][200]
    • "Reverse Engineering of a Not-so-Secure IoT Device"
    • "Virtualization Internals":
      • [第 1 部分][216]
      • [第 2 部分][217]
      • [第 3 部分][218]
      • [第 4 部分][219]

    2018

    • ["A Deep dive into (implicit) Thread Local Storage"][581]
    • ["A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"][464]
    • "ARM Exploitation":
      • ["面向返回编程"][788]
      • ["环境搭建与工具"][789]
      • ["绕过 DEP - 执行 system()"][790]
      • ["绕过 DEP - 执行 mprotect()"][791]
    • "CVE-2017-11176: A step-by-step Linux Kernel exploitation":
      • [第 1 部分][19]
      • [第 2 部分][20]
      • [第 3 部分][21]
      • [第 4 部分][22]
    • ["eMMC Data Recovery from Damaged Smartphone"][88]
    • ["Kinibi TEE: Trusted Application Exploitation"][781]
    • ["My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"][302]
    • ["Reverse Engineering BLE Devices"][761]
    • "Reversing ESP8266 Firmware":
      • [第 1 部分][545]
      • [第 2 部分][546]
      • [第 3 部分][547]
      • [第 4 部分][548]
      • [第 5 部分][549]
      • [第 6 部分][550]
    • "Vectorized Emulation":[438]
      • ["以每秒 2 万亿条指令的速度进行硬件加速污点跟踪"][382]
      • ["MMU 设计"][383]

    2017

    • ["Escalating Privileges in Linux using Fault Injection"][774]
    • ["Hardware hacking tutorial: Dumping and reversing firmware"][557]
    • ["HiSilicon DVR hack"][236]
    • ["How I Reverse Engineered and Exploited a Smart Massager"][301]
    • "Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"
    • ["Linux ptrace introduction AKA injecting into sshd for fun"][229]
    • "Over The Air":
      • ["利用 Broadcom 的 Wi-Fi 协议栈(第 1 部分)"][539]
      • ["利用 Broadcom 的 Wi-Fi 协议栈(第 2 部分)"][540]
      • ["利用 Apple 设备上的 Wi-Fi 协议栈"][541]

    2016

    • ["Bypassing Secure Boot using Fault Injection"][174]
    • ["munmap madness"][199]
    • ["Implementation of Signal Handling"][23]
    • "Practical Reverse Engineering"
      • ["深入固件"][114]
      • ["侦察固件"][115]
      • ["跟踪数据"][116]
      • ["转储 Flash"][117]
      • ["深入固件"][118]
    • ["Understanding and Hardening Linux Containers"][50]

    2014

    • ["ret2dir: Rethinking Kernel Isolation"][384]

    2011

    • ["共享库的加载时重定位"][592]
    • ["共享库中的位置无关代码(PIC)"][593]

    杂项- 0xtriboulet

    • ["A Noobs Guide to ARM Exploitation"][241]
    • ["Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent fuzzing"][71]
    • ["Advanced Compilers: The Self-Guided Online Course"][298]
    • ["Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"][559]
    • ["Android Kernel Exploitation"][571]
    • [Anti-Debug Tricks][585]
    • ["ARM TrustZone: pivoting to the secure world"][304]
    • ["ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"][927]
    • [Awesome binary parsing][769]
    • [Awesome Executable Packing][717]
    • [Awesome Industrial Protocols][510]
    • ["Brute Ratel - Scandinavian Defence"][436]
    • Comprehensive Rust
    • [cryptopals][1022]
    • [CVE North Stars][708]
    • ["Debugger Ghidra Class"][232]
    • [DhavalKapil/heap-exploitation][363]
    • [Diffing Portal][378]
    • [exploit_mitigations][526]
    • ["fenrir"][1169]
    • [Ghidriff - Ghidra Binary Diffing Engine][490]
    • ["Grand Theft Auto A peek of BLE relay attack"][433]
    • ["Hands-on Firmware Extraction, Exploration, and Emulation"][979]
    • [ice9-bluetooth-sniffer][437]
    • "图解连接":
      • [dtls][519]
      • [quic][518]
      • [tls 1.2][521]
      • [tls 1.3][520]
    • "嵌入式 Linux 加密入门"
      • ["嵌入式 Linux 开发者加密入门"][0]
      • ["对称密钥加密实践方法"][1]
      • ["实践中的非对称密钥加密与数字签名"][2]
    • ["恶意软件分析与逆向工程入门"][407]
    • ["内核地址空间布局去随机化"][529]
    • ["内核漏洞利用配方笔记"][776]
    • ["基于激光的语音可控系统音频注入"][328]
    • [Linux 内核 CVE][385]
    • ["Linux 内核漏洞利用开发"][573]
    • ["Linux 内核地图"][225]
    • ["Linux 内幕"][246]
    • ["Linux 权限提升"][982]
    • ["Linux 系统调用参考"][17]
    • ["Lytro 解锁 - 让糟糕的相机稍微好一点"][373]
    • ["最小化 Rust 二进制大小"][476]
    • ["mjsxj09cm 固件恢复与后门植入"][62]
    • ["攻击性安全 (0xtriboulet)"][405]
    • ["在 Raspberry Pi 上用 Rust 进行操作系统开发教程"][357]
    • ["parking-game-fuzzer"][1159]
    • ["开发者实用密码学"][785]
    • [Red-Team-Infrastructure-Wiki][498]
    • ["面向所有人的逆向工程!"][399]
    • "在 RISC-V BL602 上逆向 WiFi"
    • "Rust 原子操作与锁"
    • ["RustRedOps"][686]
    • ["卫星黑客揭秘(RTC0007)"][221]
    • [TEE 逆向][263]
    • ["THC 最爱的技巧、窍门与黑客方法(速查表)"][258]
    • [tmpout.sh][515]: 底层技术文章合集
    • ["Trail of Bits 测试手册"][724]
    • [TripleCross][696]
    • [USB-WiFi][329]
    • ["VSS:构建硬件黑客实验室初学者指南"][249]
    • ["WinDBG 快速入门教程"][485]

    其他列表

    • 漏洞利用:致力于二进制漏洞利用领域的资源
    • Linux 内核:致力于 Linux 内核(内部机制)的资源合集
    • 无线:致力于无线技术与安全的资源
    • OT/IoT 安全
    • 红队与攻击性安全[0]: https://sergioprado.blog/introduction-to-encryption-for-embedded-linux-developers/ [1]: https://sergioprado.blog/a-hands-on-approach-to-symmetric-key-encryption/ [2]: https://sergioprado.blog/asymmetric-key-encryption-and-digital-signatures-in-practice/ [3]: https://sysprog21.github.io/lkmpg/ [4]: https://jsac.jpcert.or.jp/archive/2023/pdf/JSAC2023_1_1_yamashige-nakatani-tanaka_en.pdf [5]: http://conference.hitb.org/files/hitbsecconf2023ams/materials/D1T1%20-%20Your%20Not%20So%20Home%20Office%20-%20Soho%20Hacking%20at%20Pwn2Own%20-%20McCaulay%20Hudson%20&%20Alex%20Plaskett.pdf [7]: https://www.synacktiv.com/publications/exploring-android-heap-allocations-in-jemalloc-new [8]: https://www.synacktiv.com/en/publications/behind-the-shield-unmasking-scudos-defenses [10]: https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html [11]: https://idov31.github.io/2022/08/04/lord-of-the-ring0-p2.html [12]: https://idov31.github.io/2022/10/30/lord-of-the-ring0-p3.html [13]: https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html [14]: https://idov31.github.io/2023/07/19/lord-of-the-ring0-p5.html [15]: https://llsoftsec.github.io/llsoftsecbook/ [16]: https://blog.lexfo.fr/sshimpanzee.html [17]: https://syscalls.mebeim.net/?table=x86/64/x64/v6.5 [18]: https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html [19]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part1.html [20]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part2.html [21]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part3.html [22]: https://blog.lexfo.fr/cve-2017-11176-linux-kernel-exploitation-part4.html [23]: http://courses.cms.caltech.edu/cs124/lectures-wi2016/CS124Lec15.pdf [24]: https://makefiletutorial.com [25]: https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html [26]: http://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html [27]: https://blog.k3170makan.com/2021/01/linux-kernel-exploitation-0x2.html [28]: https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger [29]: https://robocoffee.de/?p=436 [30]: https://www.trustedsec.com/blog/red-vs-blue-kerberos-ticket-times-checksums-and-you [31]: https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet [32]: https://medium.com/@INTfinitySG/fortinet-series-3-cve-2022-42475-sslvpn-exploit-strategy-2578597f892f [33]: http://blog.coffinsec.com/research/2022/06/12/orbi-hunting-0-intro-uart.html [34]: http://blog.coffinsec.com/research/2022/06/19/orbi-hunting-1-soap-api-crashes.html [35]: http://blog.coffinsec.com/research/2022/07/02/orbi-nday-exploit-cve-2020-27861.html [36]: https://starlabs.sg/blog/2023/06-the-old-the-new-and-the-bypass-one-clickopen-redirect-to-own-samsung-s22-at-pwn2own-2022/ [37]: https://download.vusec.net/papers/uncontained_sec23.pdf [38]: https://mccaulay.co.uk/mast1c0re-introduction-exploiting-the-ps4-and-ps5-through-a-gamesave/ [39]: https://mccaulay.co.uk/mast1c0re-part-1-modifying-ps2-game-save-files/ [40]: https://mccaulay.co.uk/mast1c0re-part-2-arbitrary-ps2-code-execution/ [41]: https://mccaulay.co.uk/mast1c0re-part-3-escaping-the-emulator/ [42]: https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/ [43]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-1-fuzzing-gegl-with-fuzzuf.html [44]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-2-evaluating-performance.html [45]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-3-patch-analysis-and-poc.html [46]: https://ricercasecurity.blogspot.com/2023/07/fuzzing-farm-4-hunting-and-exploiting-0.html [47]: https://boschko.ca/qemu-emulating-firmware/ [48]: https://labs.bluefrostsecurity.de/revisiting-cve-2017-11176 [49]: https://www.cyberark.com/resources/threat-research-blog/a-deep-dive-into-penetration-testing-of-macos-applications-part-1 [50]: https://research.nccgroup.com/wp-content/uploads/episerver-images/assets/ad04beb697a64e3ea20579e5bf604b4e/ad04beb697a64e3ea20579e5bf604b4e.pdf [51]: https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html [52]: https://labs.withsecure.com/publications/executing-arbitrary-code-executables-in-read-only-filesystems [53]: https://axcheron.github.io/linux-shellcode-101-from-hell-to-shell/ [54]: https://aviii.hashnode.dev/the-art-of-fuzzing-a-step-by-step-guide-to-coverage-guided-fuzzing-with-libfuzzer [55]: https://boschko.ca/shambles/ [56]: https://en.hackndo.com/ntlm-relay/ [57]: https://bushido-sec.com/index.php/2023/06/19/the-art-of-fuzzing/ [58]: https://offsec.almond.consulting/windows-msiexec-eop-cve-2020-0911.html [59]: https://github.blog/2023-07-05-introduction-to-selinux/ [60]: https://www.wiz.io/blog/linux-rootkits-explained-part-1-dynamic-linker-hijacking [61]: https://cutesmilee.github.io/kernel/linux/android/2022/02/17/cve-2019-2215_writeup.html [62]: https://whiterose-infosec.super.site/mjsxj09cm-recovering-firmware-and-backdooring [63]: http://blog.coffinsec.com/nday/2022/08/04/CVE-2022-1215-libinput-fmt-canary-leak.html [64]: https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/ [65]: https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/ [66]: https://pberba.github.io/security/2022/01/30/linux-threat-hunting-for-persistence-systemd-timers-cron/ [67]: https://pberba.github.io/security/2022/02/06/linux-threat-hunting-for-persistence-initialization-scripts-and-shell-configuration/ [68]: https://pberba.github.io/security/2022/02/07/linux-threat-hunting-for-persistence-systemd-generators/ [69]: https://www.espressif.com/sites/default/files/documentation/ESP32-C3%20Wireless%20Adventure.pdf [70]: https://blog.quarkslab.com/for-science-using-an-unimpressive-bug-in-edk-ii-to-do-some-fun-exploitation.html [71]: https://airbus-seclab.github.io/AFLplusplus-blogpost/ [72]: https://labs.bluefrostsecurity.de/blog/cve-2023-2008.html [73]: https://cs.brown.edu/~vpk/papers/epf.atc23.pdf [74]: https://remyhax.xyz/posts/obscure-win-files/ [75]: https://github.com/google/security-research/tree/master/pocs/cpus/spectre-gadgets [76]: https://offsec.almond.consulting/ghostscript-cve-2023-28879.html [77]: https://boredpentester.com/retreading-the-amlogic-a113x-trustzone-exploit-process/ [78]: https://haxx.in/posts/dumping-the-amlogic-a113x-bootrom/ [79]: https://bd103.github.io/blog/2023-06-27-global-allocators [80]: https://labs.watchtowr.com/xortigate-or-cve-2023-27997/ [81]: https://starlabs.sg/blog/2023/06-breaking-the-code-exploiting-and-examining-cve-2023-1829-in-cls_tcindex-classifier-vulnerability/ [82]: https://act-on.ioactive.com/acton/attachment/34793/f-b1aa96d0-bd78-4518-bae3-2889aae340de/1/-/-/-/-/DroneSec-GGonzalez.pdf [83]: https://lkmidas.github.io/posts/20210123-linux-kernel-pwn-part-1/ [84]: https://lkmidas.github.io/posts/20210128-linux-kernel-pwn-part-2/ [85]: https://lkmidas.github.io/posts/20210205-linux-kernel-pwn-part-3/ [86]: https://markuta.com/eero-6-hacking-part-1/ [87]: https://riverloopsecurity.com/blog/2020/03/hw-101-emmc/ [88]: https://dangerouspayload.com/2018/10/24/emmc-data-recovery-from-damaged-smartphone/ [89]: https://bushido-sec.com/index.php/2023/06/25/the-art-of-fuzzing-windows-binaries/ [90]: https://papers.mathyvanhoef.com/usenix2023-wifi.pdf [91]: https://research.aurainfosec.io/pentest/bee-yond-capacity/ [92]: https://blog.trailofbits.com/2023/06/15/finding-bugs-with-mlir-and-vast/ [93]: https://labs.hakaioffsec.com/coffee-a-coff-loader-made-in-rust/ [94]: https://biriukov.dev/docs/page-cache/0-linux-page-cache-for-sre/ [95]: https://frycos.github.io/vulns4free/2023/06/18/fortinac.html [96]: https://blog.cryptohack.org/twitter-secrets [97]: https://labs.ioactive.com/2023/06/back-to-future-with-platform-security.html [98]: https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads [99]: https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/ [100]: https://www.zerodayinitiative.com/blog/2023/4/5/bash-privileged-mode-vulnerabilities-in-parallels-desktop-and-cdpath-handling-in-macos [101]: https://programmingwithstyle.com/posts/howihackedmycar/ [102]: https://programmingwithstyle.com/posts/howihackedmycarpart2/ [103]: https://programmingwithstyle.com/posts/howihackedmycarpart3/ [104]: https://programmingwithstyle.com/posts/howihackedmycarpart4/ [105]: https://programmingwithstyle.com/posts/howihackedmycarpart5/ [106]: https://programmingwithstyle.com/posts/myhackedcarisdoomed/ [107]: https://8ksec.io/arm64-reversing-and-exploitation-part-1-arm-instruction-set-simple-heap-overflow/ [108]: https://8ksec.io/arm64-reversing-and-exploitation-part-2-use-after-free/ [109]: https://8ksec.io/arm64-reversing-and-exploitation-part-3-a-simple-rop-chain/ [110]: https://8ksec.io/arm64-reversing-and-exploitation-part-4-using-mprotect-to-bypass-nx-protection-8ksec-blogs/ [111]: https://8ksec.io/arm64-reversing-and-exploitation-part-5-writing-shellcode-8ksec-blogs/ [112]: https://8ksec.io/arm64-reversing-and-exploitation-part-6-exploiting-an-uninitialized-stack-variable-vulnerability/ [113]: https://8ksec.io/arm64-reversing-and-exploitation-part-7-bypassing-aslr-and-nx/ [114]: http://jcjc-dev.com/2016/04/08/reversing-huawei-router-1-find-uart/ [115]: https://jcjc-dev.com/2016/04/29/reversing-huawei-router-2-scouting-firmware/ [116]: https://jcjc-dev.com/2016/05/23/reversing-huawei-3-sniffing/ [117]: https://jcjc-dev.com/2016/06/08/reversing-huawei-4-dumping-flash/ [118]: https://jcjc-dev.com/2016/12/14/reversing-huawei-5-reversing-firmware/ [119]: https://qriousec.github.io/post/vbox-pwn2own-2023/ [120]: https://margin.re/2022/06/pulling-mikrotik-into-the-limelight/ [121]: https://medium.com/@cy1337/a-guide-to-reversing-shared-objects-with-ghidra-cec83d5031e6 [122]: https://medium.com/@cy1337/reversing-a-simple-crackme-with-ghidra-decompiler-5dd1b1c3c0ba [123]: https://medium.com/@cy1337/vulnerability-hunting-with-ghidra-fb3fc53470ba [124]: https://medium.com/@cy1337/patching-a-bug-from-a-ghidra-listing-8496e529224a [125]: https://medium.com/@cy1337/vulnerability-analysis-with-ghidra-scripting-ccf416cfa56d [126]: https://boschko.ca/glinet-router/ [127]: https://boschko.ca/tenda_ac1200_router/ [128]: https://intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/ [129]: https://intezer.com/blog/incident-response/malware-reverse-engineering-for-beginners-part-2/ [130]: https://www.zerodayinitiative.com/blog/2023/8/1/exploiting-a-flaw-in-bitmap-handling-in-windows-user-mode-printer-drivers [131]: https://linux-kernel-labs.github.io/refs/heads/master/index.html [132]: https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/ [133]: https://blog.syss.com/posts/hacking-usb-flash-drives-part-2/ [134]: https://eventhelix.com/rust/ [135]: https://intezer.com/blog/research/executable-linkable-format-101-part1-sections-segments/ [136]: https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-2-symbols/ [137]: https://intezer.com/blog/malware-analysis/executable-and-linkable-format-101-part-3-relocations/ [138]: https://intezer.com/blog/malware-analysis/executable-linkable-format-101-part-4-dynamic-linking/ [139]: https://secret.club/2023/06/05/spoof-pe-sections.html [140]: https://github.com/imthenachoman/How-To-Secure-A-Linux-Server [141]: https://reversing.info/posts/guardedregions/ [142]: https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef [143]: https://ragnarsecurity.medium.com/reverse-engineering-bare-metal-kernel-images-part-2-6a52a4afa3ef [144]: https://medium.com/geekculture/reverse-engineering-bare-metal-firmware-part-3-analyzing-arm-assembly-and-exploiting-3b2dbe219f19 [145]: https://embeddedsecurity.io [146]: https://research.nccgroup.com/2023/05/23/offensivecon-2023-exploit-engineering-attacking-the-linux-kernel/ [147]: https://landaire.net/reversing-yaesu-firmware-encryption/ [148]: https://googleprojectzero.blogspot.com/2023/01/exploiting-null-dereferences-in-linux.html [149]: https://blog.the.al/2023/01/01/ds4-reverse-engineering.html [150]: https://blog.the.al/2023/01/02/ds4-reverse-engineering-part-2.html [151]: https://blog.the.al/2023/01/03/ds4-reverse-engineering-part-3.html [152]: https://educatedguesswork.org/posts/nat-part-1/ [153]: https://educatedguesswork.org/posts/nat-part-2/ [154]: https://educatedguesswork.org/posts/nat-part-3/ [155]: https://educatedguesswork.org/posts/nat-part-4/ [156]: https://github.com/ihebski/A-Red-Teamer-diaries [157]: https://blog.quarkslab.com/digging-into-linux-namespaces-part-1.html [158]: https://blog.quarkslab.com/digging-into-linux-namespaces-part-2.html [159]: https://github.com/bsauce/kernel-exploit-factory [160]: https://icanhack.nl/blog/dji-rm500-privilege-escalation/ [161]: https://blog.zapb.de/stm32f1-exceptional-failure/ [162]: https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ [163]: https://www.shielder.com/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.2/ [164]: https://securityintelligence.com/x-force/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/ [165]: https://mutur4.github.io/posts/linux-malware-development/edr/ [166]: https://jcjc-dev.com/2023/03/19/reversing-domyos-el500-elliptical/ [167]: https://exploiter.dev/blog/2022/CVE-2022-2602.html [168]: https://blog.hacktivesecurity.com/index.php/2022/12/21/cve-2022-2602-dirtycred-file-exploitation-applied-on-an-io_uring-uaf/ [169]: https://github.com/michalmalik/linux-re-101 [170]: https://redops.at/en/blog/meterpreter-vs-modern-edrs-in-2023 [171]: https://arxiv.org/pdf/2301.13346.pdf [172]: https://alice.climent-pommeret.red/posts/process-killer-driver/ [173]: https://web.archive.org/web/20230628130110/https://www.ambionics.io/blog/hacking-watchguard-firewalls [174]: https://raelize.com/upload/research/2016/2016_BlackHat-EU_Bypassing-Secure-Boot-Using-Fault-Injection_NT-AS.pdf [175]: https://raelize.com/upload/research/2019/2019_BlueHat-IL_Hardening-Secure-Boot-on-Embedded-Devices-for-Hostile-Environments_NT-AS-CM.pdf [176]: https://raelize.com/upload//research/2019/2019_Designing-Secure-Boot-Securely_NT-AS.pdf [177]: https://securityintelligence.com/x-force/msmq-queuejumper-rce-vulnerability-technical-analysis/ [178]: https://h0mbre.github.io/kCTF_Data_Only_Exploit/ [179]: https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a [180]: https://starlabs.sg/blog/2023/08-ikea-sonos-symfonisk-speaker-lamp-teardown/ [181]: https://maxwelldulin.com/BlogPost/House-of-Muney-Heap-Exploitation [182]: https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/ [183]: https://www.trendmicro.com/en_ph/research/23/g/detecting-bpfdoor-backdoor-variants-abusing-bpf-filters.html [184]: https://starlabs.sg/blog/2023/07-prctl-anon_vma_name-an-amusing-heap-spray/ [185]: https://0xkol.github.io/assets/files/Racing_Against_the_Lock__Exploiting_Spinlock_UAF_in_the_Android_Kernel.pdf [186]: https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt [187]: https://phi1010.github.io/2020-09-14-bget-exploitation/ [188]: https://phi1010.github.io/2020-11-02-bget-exploitation-2/ [189]: https://eshard.com/posts/sca-attacks-on-armv8 [190]: https://research.nccgroup.com/2022/02/17/bypassing-software-update-package-encryption-extracting-the-lexmark-mc3224i-printer-firmware-part-1/ [191]: https://research.nccgroup.com/2022/02/18/analyzing-a-pjl-directory-traversal-vulnerability-exploiting-the-lexmark-mc3224i-printer-part-2/ [192]: https://www.synacktiv.com/publications/escaping-from-bhyve.html [193]: http://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html [194]: http://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html [195]: https://kentindell.github.io/2023/04/03/can-injection/ [196]: https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/ [197]: https://blog.assetnote.io/2023/07/24/citrix-rce-part-2-cve-2023-3519/ [198]: https://vulncheck.com/blog/mikrotik-foisted-revisited [199]: http://tukan.farm/2016/07/27/munmap-madness/ [200]: https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html [201]: https://starlabs.sg/blog/2023/07-a-new-method-for-container-escape-using-file-based-dirtycred/ [202]: https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt [203]: https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/ [204]: https://jbecker.dev/research/diving-into-decompilation [205]: https://binarly.io/posts/The_Untold_Story_of_the_BlackLotus_UEFI_Bootkit/index.html [206]: https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/ [207]: http://lock.cmpxchg8b.com/zenbleed.html [208]: https://blog.kylebot.net/2022/10/22/angry-FSROP/ [209]: https://sensepost.com/blog/2023/p4wnp1-lte/ [210]: https://tortel.li/post/insecure-scope/ [211]: https://claroty.com/team82/research/opc-ua-deep-dive-history-of-the-opc-ua-protocol [212]: https://claroty.com/team82/research/opc-deep-dive-part-2-what-is-opc-ua [213]: https://claroty.com/team82/research/opc-ua-deep-dive-part-3-exploring-the-opc-ua-protocol [214]: https://claroty.com/team82/research/opc-ua-deep-dive-series-part-4-targeting-core-opc-ua-components [215]: https://claroty.com/team82/research/opc-ua-deep-dive-series-part-5-inside-team82-s-research-methodology [216]: https://docs.saferwall.com/blog/virtualization-internals-part-1-intro-to-virtualization/ [217]: https://docs.saferwall.com/blog/virtualization-internals-part-2-vmware-and-virtualization-using-binary-translation/ [218]: https://docs.saferwall.com/blog/virtualization-internals-part-3-xen-and-paravirtualization/ [219]: https://docs.saferwall.com/blog/virtualization-internals-part-4-qemu/ [220]: https://web.archive.org/web/20230522230748/https://momo5502.com/posts/2022-11-17-reverse-engineering-integrity-checks-in-black-ops-3/ [221]: https://redteamrecipe.com/Satellite-Hacking-Demystified/ [222]: https://www.linode.com/docs/guides/linux-red-team-exploitation-techniques/ [223]: https://www.linode.com/docs/guides/linux-red-team-privilege-escalation-techniques/ [224]: https://www.linode.com/docs/guides/linux-red-team-persistence-techniques/ [225]: https://makelinux.github.io/kernel/map/ [226]: https://xcellerator.github.io/posts/tetsuji/ [227]: https://antonio-cooler.gitbook.io/coolervoid-tavern/port-knocking-from-the-scratch [228]: https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/ [229]: https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/ [230]: https://jm33.me/sshd-injection-and-password-harvesting.html [231]: https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/ [232]: https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger [233]: https://bishopfox.com/blog/breaking-fortinet-firmware-encryption [234]: https://github.com/nick0ve/how-to-bypass-aslr-on-linux-x86_64 [235]: https://steve-s.gitbook.io/0xtriboulet/just-malicious/from-c-with-inline-assembly-to-shellcode [236]: https://github.com/tothi/pwn-hisilicon-dvr/tree/42d8325e68fdb075fe27df8a269932f9fa9601a6 [237]: https://uploads-ssl.webflow.com/64a2900ed5e9bb672af9b2ed/64d42fcc2e3fdcf3d323f3d9_All_cops_are_broadcasting_TETRA_under_scrutiny.pdf [238]: https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html [239]: https://0x434b.dev/overview-of-glibc-heap-exploitation-techniques/ [240]: https://wafzsucks.medium.com/how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [241]: https://ad2001.gitbook.io/a-noobs-guide-to-arm-exploitation/ [242]: https://blog.theori.io/linux-kernel-exploit-cve-2022-32250-with-mqueue-a8468f32aab5 [243]: https://securelist.com/hacking-microcontroller-firmware-through-a-usb/89919/ [244]: https://blog.ret2.io/2023/08/09/jtag-hacking-the-original-xbox-2023/ [245]: https://wes4m.io/posts/epson_rev/ [246]: https://0xax.gitbooks.io/linux-insides/content/ [247]: https://flaviu.io/advanced-persistent-threat/ [248]: https://grahamhelton.com/blog/ssh_agent/ [249]: https://voidstarsec.com/hw-hacking-lab/vss-lab-guide%5D [250]: https://ics-cert.kaspersky.com/publications/reports/2022/07/06/dynamic-analysis-of-firmware-components-in-iot-devices/ [251]: https://syst3mfailure.io/wall-of-perdition/ [252]: https://www.willsroot.io/2021/08/corctf-2021-fire-of-salvation-writeup.html [253]: https://www.forescout.com/resources/l1-lateral-movement-reportg [254]: https://www.synacktiv.com/en/publications/old-bug-shallow-bug-exploiting-ubuntu-at-pwn2own-vancouver-2023 [255]: https://research.nccgroup.com/2023/03/15/a-race-to-report-a-toctou-analysis-of-a-bug-collision-in-intel-smm/ [256]: https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/ [257]: https://research.nccgroup.com/2023/08/08/intel-bios-advisory-memory-corruption-in-hid-drivers/ [258]: https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet [259]: https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html [260]: https://big5-sec.github.io/posts/CVE-2023-29360-analysis/ [261]: https://blog.exodusintel.com/2023/07/20/shifting-boundaries-exploiting-an-integer-overflow-in-apple-safari/ [262]: https://blog.quarkslab.com/breaking-secure-boot-on-the-silicon-labs-gecko-platform.html [263]: https://github.com/enovella/TEE-reversing [264]: https://www.cyberark.com/resources/all-blog-posts/nvme-new-vulnerabilities-made-easy [265]: https://blog.cloudflare.com/missing-manuals-io_uring-worker-pool/ [266]: https://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/ [267]: https://bootlin.com/doc/training/audio/audio-slides.pdf [268]: https://blog.quarkslab.com//starlink.html [269]: https://blog.exodusintel.com/2022/12/19/linux-kernel-exploiting-a-netfilter-use-after-free-in-kmalloc-cg/ [270]: https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/ [271]: https://portswigger.net/research/smashing-the-state-machine [272]: https://labs.taszk.io/articles/post/mtk_baseband_csn1_exploitation/ [273]: https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition [274]: https://research.checkpoint.com/2022/researching-xiaomis-tee/ [275]: https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-1 [276]: https://www.cyberark.com/resources/all-blog-posts/fantastic-rootkits-and-where-to-find-them-part-2 [277]: https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-3-arm-edition [278]: https://www.sonarsource.com/blog/patches-collisions-and-root-shells-a-pwn2own-adventure/ [279]: https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/ [280]: https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass-part-2/ [281]: https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/ [282]: https://www.interruptlabs.co.uk/articles/pipe-buffer [283]: https://vulncheck.com/blog/openfire-cve-2023-32315 [284]: https://wrv.github.io/h26forge.pdf [285]: https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf [286]: https://eshard.com/posts/pixel6_bootloader [287]: https://eshard.com/posts/pixel6bootloader-2 [288]: https://eshard.com/posts/pixel6_bootloader_3 [289]: https://limitedresults.com/2019/09/pwn-the-esp32-secure-boot/ [290]: https://www.greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware [291]: https://labs.hakaioffsec.com/fortigate-authentication-bypass/ [292]: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/ [293]: https://redops.at/blog/a-story-about-tampering-edrs [294]: https://security.human[421]: https://www.tripwire.com/state-of-security/ghidra-101-loading-windows-symbols-pdb-files-in-ghidra-10-x [422]: https://github.com/PabloMK7/ENLBufferPwn [423]: https://f0rm2l1n.github.io/2021-02-02-syzkaller-diving-01/ [424]: https://f0rm2l1n.github.io/2021-02-04-syzkaller-diving-02/ [425]: https://f0rm2l1n.github.io/2021-02-10-syzkaller-diving-03/ [426]: https://www.nozominetworks.com/blog/the-importance-of-reverse-engineering-in-network-analysis [427]: https://www.stormshield.com/news/orbit-analysis-of-a-linux-dedicated-malware/ [428]: https://intezer.com/blog/research/orbit-new-undetected-linux-threat/ [429]: https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/ [430]: https://sandflysecurity.com/blog/detecting-linux-memfd-create-fileless-malware-with-command-line-forensics/ [431]: https://labs.withsecure.com/publications/spoofing-call-stacks-to-confuse-edrs [432]: https://labs.nettitude.com/blog/shellcode-source-mutations/ [433]: https://rollingpwn.github.io/BLE-Relay-Aattck/ [434]: https://blog.impalabs.com/2212_huawei-security-hypervisor.html [435]: https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html [436]: https://protectedmo.de/brute.html [437]: https://github.com/mikeryan/ice9-bluetooth-sniffer [438]: https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux [439]: https://blog.trailofbits.com/2023/02/16/suid-logic-bug-linux-readline/ [440]: https://intezer.com/blog/malware-analysis/new-linux-backdoor-redxor-likely-operated-by-chinese-nation-state-actor/ [441]: https://medium.com/@INTfinitySG/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2 [442]: https://medium.com/@INTfinitySG/1-2-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-2-cf1571493117 [443]: https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/ [444]: https://claroty.com/team82/research/hacking-ics-historians-the-pivot-point-from-it-to-ot [445]: https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/total-identity-compromise-microsoft-incident-response-lessons-on/ba-p/3753391 [446]: https://www.flashback.sh/blog/minesweeper-tplink-archer-lan-rce [447]: https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce [448]: https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/ [449]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-1/ [450]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-2/ [451]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-3/ [452]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-4/ [453]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-5/ [454]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-6/ [455]: https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-7/ [456]: https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser [457]: https://www.randorisec.fr/yet-another-bug-netfilter/ [458]: http://clarkkromenaker.com/post/library-dynamic-loading-mac/ [459]: https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/ [460]: https://maskray.me/blog/2023-02-12-all-about-leak-sanitizer [461]: https://intezer.com/blog/research/new-linux-threat-symbiote/ [462]: https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/ [463]: https://mattfrisbie.substack.com/p/spy-chrome-extension [464]: https://modexp.wordpress.com/2018/10/30/arm64-assembly/?ref=0xor0ne.xyz [465]: https://www.artresilia.com/iot-series-i-are-people-ready-to-go/ [466]: https://www.artresilia.com/iot-series-ii-how-to-build-kernel-image-from-scratch/ [467]: https://www.artresilia.com/iot-series-iii-firmware-testing-in-qemu/ [468]: https://www.artresilia.com/iot-series-iv-debugging-with-gdb-ghidra-zero-day/ [469]: https://mutur4.github.io/posts/remote-process-injection/ [470]: https://blogs.oracle.com/linux/post/live-kernel-debugging-1 [471]: https://blogs.oracle.com/linux/post/live-kernel-debugging-2 [472]: https://blogs.oracle.com/linux/post/live-kernel-debugging-3 [473]: https://www.willsroot.io/2022/12/entrybleed.html [474]: https://onekey.com/blog/making-toctou-great-again-xrip/?ref=0xor0ne.xyz [475]: https://bishopfox.com/blog/building-exploit-fortigate-vulnerability-cve-2023-27997 [476]: https://github.com/johnthagen/min-sized-rust [477]: https://www.nozominetworks.com/blog/14-vulnerabilities-discovered-in-phoenix-contact-hmis [478]: https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-2 [479]: https://www.nozominetworks.com/blog/protecting-the-phoenix-unveiling-critical-vulnerabilities-in-phoenix-contact-hmi-part-3 [480]: https://www.immersivelabs.com/blog/detecting-and-decrypting-sliver-c2-a-threat-hunters-guide/ [481]: https://labs.watchtowr.com/ghost-in-the-wire-sonic-in-the-wall/ [482]: https://www.appknox.com/security/how-to-emulate-android-native-libraries-using-qiling [483]: https://sam4k.com/patching-instrumenting-debugging-linux-kernel-modules/ [484]: https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/ [485]: http://codemachine.com/articles/windbg_quickstart.html [486]: https://github.blog/2023-10-17-getting-rce-in-chrome-with-incomplete-object-initialization-in-the-maglev-compiler/?ref=0xor0ne.xyz [487]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [488]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f [489]: https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html [490]: https://github.com/clearbluejar/ghidriff [491]: https://www.willsroot.io/2022/08/reviving-exploits-against-cred-struct.html [492]: https://googleprojectzero.blogspot.com/2022/03/racing-against-clock-hitting-tiny.html [493]: https://danielmangum.com/posts/risc-v-bytes-exploring-custom-esp32-bootloader/ [494]: https://seanpesce.blogspot.com/2023/05/bypassing-selinux-with-initmodule.html [495]: https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/ [496]: https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part- [497]: https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part-2 [498]: https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki [499]: https://stigward.github.io/posts/fiio-m6-kernel-bug/ [500]: https://stigward.github.io/posts/fiio-m6-exploit/ [501]: https://iq.thc.org/how-does-linux-start-a-process [502]: https://0x44.xyz/blog/cve-2023-4369/ [503]: https://xairy.io/articles/syzkaller-external-network [504]: http://conference.hitb.org/files/hitbsecconf2023ams/materials/D2T1%20-%20Smart%20Speaker%20Shenanigans%20-%20Making%20the%20SONOS%20One%20Sing%20Its%20Secrets%20-%20Peter%20Geissler.pdf [505]: https://astralvx.com/stealing-the-bitlocker-key-from-a-tpm/ [506]: https://quentinkaiser.be/exploitdev/2020/09/23/ghetto-patch-diffing-cisco/ [507]: https://quentinkaiser.be/exploitdev/2020/10/01/patch-diffing-cisco-rv110/?ref=0xor0ne.xyz [508]: https://clearbluejar.github.io/posts/decompilation-debugging-pretending-all-binaries-come-with-source-code/ [509]: https://nicolo.dev/en/blog/role-control-flow-graph-static-analysis/ [510]: https://github.com/Orange-Cyberdefense/awesome-industrial-protocols [511]: https://sam4k.com/exploring-linux-random-kmalloc-caches/ [512]: https://people.kernel.org/linusw/the-arm32-scheduling-and-kernelspace-userspace-boundary [513]: https://thume.ca/2023/12/02/tracing-methods/ [514]: https://www.corellium.com/blog/exploring-unix-pipes-for-ios-kernel-exploit-primitives [515]: https://tmpout.sh [516]: https://sam4k.com/linternals-memory-allocators-part-1/ [517]: https://sam4k.com/linternals-memory-allocators-0x02/ [518]: https://quic.xargs.org [519]: https://dtls.xargs.org [520]: https://tls13.xargs.org [521]: https://tls12.xargs.org [522]: https://blog.xpnsec.com/restoring-dyld-memory-loading/ [523]: https://blog.xpnsec.com/building-a-mach-o-memory-loader-part-1/ [524]: https://www.synacktiv.com/sites/default/files/2023-11/ubuntu_shiftfs.pdf [525]: https://www.flashback.sh/blog/flashback-connects-cisco-rv340-ssl-vpn-rce [526]: https://github.com/nccgroup/exploit_mitigations?ref=0xor0ne.xyz [527]: https://lock.cmpxchg8b.com/reptar.html [528]: https://anatomic.rip/cve-2023-2598/ [529]: https://github.com/bcoles/kasld [530]: https://blog.exodusintel.com/2023/05/16/google-chrome-v8-arrayshift-race-condition-remote-code-execution/ [531]: https://research.nccgroup.com/2023/12/04/shooting-yourself-in-the-flags-jailbreaking-the-sonos-era-100/ [532]: https://etenal.me/archives/1825 [533]: https://pwning.tech/ksmbd/ [534]: https://github.blog/2023-12-06-cueing-up-a-calculator-an-introduction-to-exploit-development-on-linux/ [535]: https://duasynt.com/blog/linux-kernel-heap-feng-shui-2022 [536]: https://grsecurity.net/how_autoslab_changes_the_memory_unsafety_game [537]: https://www.zerodayinitiative.com/blog/2023/11/28/a-detailed-look-at-pwn2own-automotive-ev-charger-hardware [539]: https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html [540]: https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html [541]: https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html [542]: https://trenchant.io/expanding-the-dragon-adding-an-isa-to-ghidra/ [543]: https://adamdoupe.com/blog/2023/01/23/cve-2023-23504-xnu-heap-underwrite-in-dlil-dot-c/ [544]: https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/ [545]: https://boredpentester.com/reversing-esp8266-firmware-part-1/ [546]: https://boredpentester.com/reversing-esp8266-firmware-part-2/ [547]: https://boredpentester.com/reversing-esp8266-firmware-part-3/ [548]: https://boredpentester.com/reversing-esp8266-firmware-part-4/ [549]: https://boredpentester.com/reversing-esp8266-firmware-part-5/ [550]: https://boredpentester.com/reversing-esp8266-firmware-part-6/ [551]: https://eta.st/2023/01/31/rail-tickets.html [552]: https://www.crowdstrike.com/blog/exploiting-cve-2021-3490-for-container-escapes/ [553]: https://www.hacefresko.com/posts/tp-link-tapo-c200-unauthenticated-rce [554]: https://blog.bi0s.in/2023/01/23/Pwn/bi0sCTF22-b3typer/ [555]: https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html [556]: https://doar-e.github.io/blog/2022/03/26/competing-in-pwn2own-2021-austin-icarus-at-the-zenith/ [557]: https://ivanorsolic.github.io/post/hardwarehacking1/ [558]: https://kernemporium.github.io/posts/unpacking/ [559]: https://www.archcloudlabs.com/projects/loadlibrary-analysis/ [560]: https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9 [561]: https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi [562]: https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf [563]: https://github.com/V4bel/CVE-2022-41218 [564]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-1/ [565]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/ [566]: https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-3/ [567]: https://seclists.org/oss-sec/2023/q1/20 [569]: https://epi052.gitlab.io/notes-to-self/blog/2021-11-07-fuzzing-101-with-libafl-part-1.5/ [571]: https://cloudfuzz.github.io/android-kernel-exploitation/ [572]: https://www.akamai.com/blog/security-research/exploiting-critical-spoofing-vulnerability-microsoft-cryptoapi [573]: https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development?s=09 [574]: https://act-on.ioactive.com/acton/attachment/34793/f-6460b49e-1afe-41c3-8f73-17dc14916847/1/-/-/-/-/NFC-relay-TESlA_JRoriguez.pdf [575]: https://research.nccgroup.com/2023/02/06/rustproofing-linux-part-1-4-leaking-addresses/ [576]: https://research.nccgroup.com/2023/02/08/rustproofing-linux-part-2-4-race-conditions/ [577]: https://research.nccgroup.com/2023/02/14/rustproofing-linux-part-3-4-integer-overflows/ [578]: https://research.nccgroup.com/2023/02/16/rustproofing-linux-part-4-4-shared-memory/ [579]: https://sensepost.com/blog/2022/sim-hijacking/ [580]: https://dtsec.us/2023-09-15-StackSpoofin/ [581]: https://chao-tic.github.io/blog/2018/12/25/tls [582]: https://hackmd.io/@pepsipu/ry-SK44pt?s=09 [583]: https://exploitreversing.files.wordpress.com/2023/04/exploit_reversing_01-1.pdf [584]: https://exploitreversing.files.wordpress.com/2024/01/exploit_reversing_02.pdf [585]: https://anti-debug.checkpoint.com [586]: https://ktln2.org/reversing-c++-qt-applications-using-ghidra/ [587]: https://blog.thalium.re/posts/achieving-remote-code-execution-in-steam-remote-play/ [588]: https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ [589]: https://courk.cc/breaking-flash-encryption-of-espressif-parts [590]: https://courk.cc/esp32-c3-c6-fault-injection [591]: https://ptr-yudai.hatenablog.com/entry/2023/12/08/093606 [592]: https://eli.thegreenplace.net/2011/08/25/load-time-relocation-of-shared-libraries/ [593]: https://eli.thegreenplace.net/2011/11/03/position-independent-code-pic-in-shared-libraries/ [594]: https://redops.at/en/blog/exploring-hells-gate [595]: https://i.blackhat.com/EU-21/Wednesday/EU-21-Jin-The-Art-of-Exploiting-UAF-by-Ret2bpf-in-Android-Kernel-wp.pdf [596]: https://www.darknavy.org/blog/strengthening_the_shield_mte_in_memory_allocators/ [597]: https://richiejp.com/linux-kernel-exploit-tls_context-uaf [598]: https://eprint.iacr.org/2023/090.pdf [599]: https://therealcoiffeur.com/c101011.html [600]: https://therealcoiffeur.com/c101100.html [601]: https://therealcoiffeur.com/c101101.html [602]: https://blog.kylebot.net/2021/05/08/DEFCON-2021-Quals-mooosl/ [603]: https://security.humanativaspa.it/customizing-sliver-part-1/

    阅读更多

    下载工具