phoenhex team
-
1
Pwn2Own 2017: UAF in JSC::CachedCall (WebKit)
-
2
Exploiting an integer overflow with array spreading (WebKit)
-
3
Pwn2Own: Safari sandbox part 1 – Mount yourself a root shell
-
4
Share with care: Exploiting a Firefox UAF with shared array buffers
-
5
Pwn2Own: Safari sandbox part 2 – Wrap your way around to root
-
6
This is fine: Vagrant guests can access the entire host filesystem
-
7
Better slow than sorry – VirtualBox 3D acceleration considered harmful
-
8
Fuzzing Counter-Strike: Global Offensive maps files with AFL
-
9
Exploiting a Safari information leak
-
10
Non JIT Bug, JIT Exploit
pwnaccelerator BLOG
-
1
F5521gw - Firmware Easter Egg
-
2
Self Defense - Patching the Stagefright Patch
-
3
New Blog
-
4
SSHBleed - Initial Analysis
-
5
Hunting For Vulnerabilities in Signal - Part 1
-
6
Hunting For Vulnerabilities in Signal - Part 2
-
7
Hunting For Vulnerabilities in Signal - Part 3
-
8
Vendors, Disclosure, and a bit of WebUSB Madness
The Pwnie Awards
-
1
Clement Lecigne: 0-days hunter world champion
-
2
“Holy fucking bingle, we have the no fly list,”
-
3
Three Lessons From Threema: Analysis of a Secure Messenger
-
4
ClamAV RCE
-
5
URB Excalibur: Slicing Through the Gordian Knot of VMware VM Escapes
-
6
Inside Apple’s Lightning: Jtagging the iPhone for Fuzzing and Profit
-
7
Activation Context Cache Poisoning
-
8
Video-based cryptanalysis: Extracting Cryptographic Keys from Video Footage of a Device’s Power LED
-
9
Clickin’
-
10
CountExposure!
The search for animal 0-day
-
1
The first step
-
2
Fuzzing Apache httpd server with American Fuzzy Lop + persistent mode
-
3
From fuzzing Apache httpd server to CVE-2017-7668 and a $1500 bounty
-
4
Hack.lu - HeapHeaven write-up with radare2 and pwntools (ret2libc)
-
5
Linux Kernel Debugging with VMWare Player Free
-
6
Reviews for OSCP, OSCE, OSEE and Corelan Advanced Training
-
7
Setting up a vulnerable v8 on a Windows System
This is a One Way Ride.
-
1
CVE-2015-1769 分析
-
2
CVE-2015-3864 libstagefright攻击学习
-
3
Iovyroot (CVE-2015-1805) 分析
-
4
Z3 & Capstone 学习
-
5
libstagefright (CVE-2015-1538) 分析
-
6
CVE-2016-3078 PHP ZipArchive Integer Overflow 分析
-
7
Exploiting Futex Bug (a.k.a TowelRoot)
-
8
Porting iovyroot to Samsung Galaxy S5
-
9
What I Learnt From the CVE-2016-8655 Exploit
-
10
ELF Black Magic Collections - Evading from static analysis
xorl %eax, %eax
-
1
Predict 21: Tradecraft Tips for Unusual Recorded Future Uses
-
2
Guide on Offensive Operations for Companies
-
3
Ideas for Software Supply-Chain Attacks Simulation by Red Teams
-
4
The forgotten SUAVEEYEFUL FreeBSD software implant of the EQUATION GROUP
-
5
Why the Equation Group (EQGRP) is NOT the NSA
-
6
BSides Cyprus: Cloud… Just somebody else’s computer
-
7
OSINT: A Summary of SIDEWINDER Operations in 2022
-
8
2022 CTI-EU Talk: Threat Landscape and Defences Against Mobile Surveillance Implants
-
9
Kaspersky SAS ’23
-
10
BSidesBUD 2023: A Deeper Look at the Disrupted Bot Farms in Ukraine
ZecOps Blog
-
1
Jamf protects against ‘pymafka’ malware
-
2
Jamf protects against CrateDepression malware
-
3
‘No likes’ for iPhone phishing campaign on Instagram
-
4
ChromeLoader adware halted from broadcasting by Jamf Protect
-
5
CloudMensis malware stealing your joy? Jamf’s got you covered!
-
6
Fake droids: Your new Android device is actually an old Android 6
-
7
Jamf Threat Labs identifies macOS Archive Utility vulnerability
-
8
Get to know Aftermath: Jamf’s open-source incident response tool
-
9
Jamf Threat Labs analyzes the exploited in-the-wild WebKit vulnerability CVE-2022-42856
-
10
Evasive cryptojacking malware targeting macOS found lurking in pirated applications
Techorganic
-
1
Solving 67k binaries with r2pipe
-
2
Codefest CTF 2017: Rick's Secure Scheme writeup
-
3
DC416 Introduction to 64-bit Linux Exploit Development: vuln03 Solution
-
4
STEM Cyber Challenge 2018: Keygenme
-
5
Wakanda hacking challenge
-
6
Ch4inrulz hacking challenge
-
7
Raven hacking challenge
-
8
The Omega2+ as a network implant
-
9
Cyber Apocalypse CTF 2021 Pwn Solutions
-
10
Thoughts on Zero-Point Security's Red Team Ops course
ADD / XOR / ROL
-
1
Three important steps in my maturation process
-
2
"Why do you work in security instead of something more lasting ?"
-
3
A quick post on Wikipedia-scrubbing and a historical document on binary diffing
-
4
Two small notes on the "malicious use of AI" report
-
5
A bank statement for app activity (and thus personal data)
-
6
Turing completeness, weird machines, Twitter, and muddled terminology
-
7
Rashomon of disclosure
-
8
Before you ship a "security mitigation" ...
-
9
My self-help guide to making sense of a confusing world
-
10
My Twitter-Discussion-Deescalation Policy