PHP Bugs
-
1
Rockstar Games: Ticket Trick Attack allows access to Rockstar Games' workspaces
-
2
[$3000] 8x8: connect.8x8.com: Deserialization Vulnerability in Automation Builder via Jint→Newtonsoft serializer coercion (TypeNameHandling)
-
3
[$1337] 8x8: connect.8x8.com: Automation Builder - Input Validation Issue in Workflow Step Outputs
-
4
curl: 07: GnuTLS 0-RTT early data bypasses file-backed public-key pin verification
-
5
curl: CVE-2026-18924: HTTP/2 server push UAF
-
6
Weblate: SSRF via URL Parser Differential in `normalize_request_url` (wlc)
-
7
curl: CVE-2026-80256: wcurl backslash bypass
-
8
curl: 06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses
-
9
curl: 41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body
-
10
curl: 33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231)
老罗的Android之旅
-
1
Chromium网页滑动和捏合手势处理过程分析
-
2
Chromium分发输入事件给WebKit处理的过程分析
-
3
Chromium视频标签<video>简要介绍和学习计划
-
4
Chromium为视频标签<video>创建播放器的过程分析
-
5
Chromium为视频标签<video>渲染视频画面的过程分析
-
6
Chromium为视频标签<video>全屏播放的过程分析
-
7
Chromium扩展(Extension)机制简要介绍和学习计划
-
8
Chromium扩展(Extension)加载过程分析
-
9
Chromium扩展(Extension)的页面(Page)加载过程分析
-
10
Chromium扩展(Extension)的Content Script加载过程分析
I hack, therefore I am
-
1
Linux/x86 Execve Python Interpreter with a Python Program Passed in as String Shellcode
-
2
Decoderless Shellcode Encoding
-
3
Modulation and Data Loss Prevention (DLP) Solutions
-
4
Automated Static Malware Analysis with Pythonect
-
5
Fuzzing Like A Boss with Pythonect
-
6
Scraping LinkedIn Public Profiles for Fun and Profit
-
7
Password Policy: You Are Doing It Wrong (When 2^56 Becomes 2^42)
-
8
Hackersh 0.1 Release Announcement
-
9
Pythonect Has New Graphs, Documentation, Tutorial, and More!
-
10
I See Your True ECHO_REQUEST Patterns (Pinging Data Away)
The Fuzzing Project
-
1
Use after free in my_login() function of DBD::mysql (Perl module)
-
2
Fun with Bignums: Crashing MatrixSSL and more
-
3
Multiple vulnerabilities in RPM – and a rant
-
4
Out of bounds heap bugs in glib, heap buffer overflow in gnome-session
-
5
Update on MatrixSSL miscalculation (CVE-2016-8671, incomplete fix for CVE-2016-6887)
-
6
Fuzzing Irssi with Perl Scripts
-
7
htpasswDoS: Local Denial of Service via Apache httpd password hashes
-
8
Diving into Control Flow Integrity
-
9
exiv2: multiple memory safety issues
-
10
Six year old PDF loop bug affects most major implementations
Cатсн²² (in)sесuяitу / ChrisJohn
-
1
[DeepSec 2014] Advanced Powershell Threat: Lethal Client Side Attacks using Powershell
-
2
All good things must come to an end
-
3
Taking out the Eurotrash
-
4
[LHS Microcast] Interview w/ Jen Ellis
-
5
[LHS Microcast] DeepSec 2015
-
6
[DeepSec 2015] Can societies manage the SIGINT monster?
-
7
[DeepSec 2015] Hacking Cookies in Modern Web Applications and Browsers
-
8
[DeepSec 2015]How to Break XML Encryption – Automatically
-
9
[DeepSec 2015] File Format Fuzzing in Android – Giving a Stagefright to the Android Installer
-
10
[DeepSec 2015]50 Shades of WAF
Black-Hole’s Blog
-
1
XSS principles, dissected
-
2
Automated CSRF detection
-
3
Automated CSRF detection (part 2)
-
4
Notes on bypassing WAFs (Web Application Firewalls)
-
5
How to log in to Thunder under Debian
-
6
Browser plugin attack vectors
-
7
Company Wi-Fi security
-
8
Automated XSS intranet invasion
-
9
Some ideas based on URLProtocol attacks
-
10
pm2 configuration for Vue+Koa
w00tsec
-
1
Hello world
-
2
SIMET Box Firmware Analysis: Embedded Device Hacking & Forensics
-
3
Analyzing and Running binaries from Firmware Images - Part 1
-
4
Unpacking Firmware Images from Cable Modems
-
5
Binwally: Directory tree diff tool using Fuzzy Hashing
-
6
Analyzing Malware for Embedded Devices: TheMoon Worm
-
7
Wildcard DNS, Content Poisoning, XSS and Certificate Pinning
-
8
Foxit PDF Reader Stored XSS
-
9
Hacking Asus RT-AC66U and Preparing for SOHOpelesslyBroken CTF
-
10
Scan the Internet & Screenshot All the Things