Lexfo’s security blog
-
1
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
-
2
CVE-2016-9838 - Joomla! Account Takeover & Remote Code Execution
-
3
Grails PDF Plugin XXE
-
4
Drupal 7.x Services module unserialize() to RCE
-
5
TYPO3 News module SQL Injection
-
6
Oracle PeopleSoft Remote Code Execution: Blind XXE to SYSTEM Shell
-
7
PHP Generic Gadget Chains: Exploiting unserialize in unknown environments
-
8
PrestaShop 1.6 Privilege Escalation
-
9
CVE-2017-11176: A step-by-step Linux Kernel exploitation (part 1/4)
-
10
CVE-2017-11176: A step-by-step Linux Kernel exploitation (part 2/4)
SkullSecurity
-
1
BSidesSF 2024 Writeups: Turing Complete (Reversing / exploitation)
-
2
goto-zero: An extended intro to solving stack overflow CTF challenges
-
3
BSidesSF 2025: bug-me (hard reversing challenge)
-
4
BSidesSF 2025: accan and drago-daction: pwn your own memory
-
5
BSidesSF 2025: 101 Challenges
-
6
BSidesSF 2025: Miscellaneous challenges
-
7
BSidesSF 2026: miscellaneous challenges (if-it-leads, gitfab, jengacrypt)
-
8
BSidesSF 2026: nameme - a DNS-based pwn challenge
-
9
BSidesSF 2026: read(write(call))me - progressive pwn challenges
-
10
BSidesSF 2026: rugdoctor - a broken JIT compiler pwn challenge
博客园_Ox9A82
-
1
plaidctf-2016 Pwn试题小结 - Ox9A82
-
2
Grinder搭建小记与Nduja(这次不待续了) - Ox9A82
-
3
《Look Mom, I don’t use Shellcode》议题解析 - Ox9A82
-
4
【OOB】MSHTML!CPasteCommand::ConvertBitmaptoPng heap-based buffer overflow学习 - Ox9A82
-
5
CVE-2010-0249 IE8 UAF漏洞分析 - Ox9A82
-
6
Smashing The Browser:From Vulnerability Discovery To Exploit学习记录 - Ox9A82
-
7
ZCTF-2017 比赛总结 - Ox9A82
-
8
一个浏览器Fuzzing框架的学习 - Ox9A82
-
9
BCTF2017 BabyUse - Ox9A82
-
10
Hitcon 2016 Pwn赛题学习 - Ox9A82
小刀志
-
1
从 PE 到 PKCS#7:深入理解 Windows PE 数字签名机制
-
2
对 UAF 漏洞 CVE-2016-0167 的分析和利用
-
3
从 CVE-2016-0165 说起:分析、利用和检测(上)
-
4
恶意样本对抗栈回溯检测机制的套路浅析
-
5
从 PE 文件资源表中提取文件的版本信息
-
6
在 64 位 Windows 操作系统中的内核特权级别提升
-
7
从 CVE-2016-0165 说起:分析、利用和检测(下)
-
8
通过对比 5 月补丁分析 win32k 空指针解引用漏洞
-
9
对 UAF 漏洞 CVE-2015-2546 的分析和利用
-
10
通过 Windows 用户模式回调实施的内核攻击
Exploit Monday
-
1
Welcome!
-
2
Leveraging format string vulnerabilities to interrogate Win32 process memory
-
3
Post-mortem Analysis of a Use-After-Free Vulnerability (CVE-2011-1260)
-
4
Cool kids pop a programmer's calc in their demos
-
5
Integrating WinDbg and IDA for Improved Code Flow Analysis
-
6
Targeted Heap Spraying – 0x0c0c0c0c is a Thing of the Past
-
7
Dropping Executables with Powershell
-
8
Stealth Alternate Data Streams and Other ADS Weirdness
Low-cost hardware and free softw
-
1
Kali linux – setup
-
2
GNU Radio and Gqrx – setup
-
3
Airprobe – setup
-
4
ARFCN tool, Kalibrate tool and others – setup
-
5
Get Kc key and TMSI number!
-
6
Advanced/hidden menus – Android system
-
7
ADB install – Android system
-
8
Custom ROM install – Android system
-
9
PiAware software – Installation on the RPi
-
10
Kali Linux and Numix Customization!
pentest-n00b
-
1
2012 in review
-
2
Installing Metasploit Framework GIT version
-
3
Finding Exposed Http(s) Admin Pages
-
4
Update to Metasploit Framework v4.10.1-dev – Changes needed.
-
5
Weaponised Interactive PowerShell Session With Metasploit
-
6
HTTP Security Headers Script
-
7
PoshC2 – Powershell C2
-
8
PowerShell PSRemoting Pwnage
-
9
PoshC2 – New Payloads, New Folder Layout
-
10
Simple Bypass for PowerShell Constrained Language Mode
VUSec
-
1
Much ado about RIDL
-
2
RIDL Second in CSAW’19 Best applied Research
-
3
Harry King Wins bachelor Thesis Prize
-
4
Trrespass: Rowhammer in the news (again)
-
5
Cristiano Giuffrida WINS VMWare Early Career Faculty Grant
-
6
TRRespass wins best paper Award at Security & privacy
-
7
Pietro Frigo Wins Qualcomm Innovation fellowship
-
8
VUSec wins HAck@Sec
-
9
TRRespass wins Pwnie Award
-
10
Awards Catch-UP!