landave’s blog
-
1
Avast Antivirus: Remote Stack Buffer Overflow with Magic Numbers
-
2
Bitdefender: Remote Stack Buffer Overflow via 7z PPMD
-
3
F-Secure Anti-Virus: Arbitrary Free Vulnerability via TNEF
-
4
Bitdefender: Heap Buffer Overflow via 7z LZMA
-
5
7-Zip: Multiple Memory Corruptions via RAR and ZIP
-
6
7-Zip: From Uninitialized Memory to Remote Code Execution
-
7
F-Secure Anti-Virus: Remote Code Execution via Solid RAR Unpacking
-
8
Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions
lcamtuf’s blog
-
1
Boolean algebra with CSS (when you can only set colors)
-
2
A bit more about american fuzzy lop
-
3
Binary fuzzing strategies: what works, what doesn't
-
4
CVE-2014-1564: Uninitialized memory with truncated images in Firefox
-
5
Quick notes about the bash bug, its impact, and the fixes so far
-
6
Bash bug: apply Florian's patch now (CVE-2014-6277 and CVE-2014-6278)
-
7
Bash bug: the other two RCEs, or how we chipped away at the original fix (CVE-2014-6277 and '78)
-
8
Fuzzing random programs without execve()
-
9
Two more browser memory disclosure bugs (CVE-2014-1580 and #19611cz)
-
10
PSA: don't run 'strings' on untrusted files (CVE-2014-8485)
marcograss’ blog
-
1
php 5.6.24 one liner fixed null pointer memory access
-
2
[CVE-2016-6828] Linux kernel tcp related read Use After Free
-
3
A simple bug in Wickr Android I disclosed in 2014
-
4
[CVE-2016-7425] Linux Kernel SCSI arcmsr driver: buffer overflow in arcmsr_iop_message_xfer()
-
5
[CVE-2016-7799/7800/7906] 2 ImageMagick bugs and 1 GraphicsMagick bug
-
6
[NO-CVE] cJSON JSON parser buffer out of bound read
-
7
[CVE-2016-5328/5329] Multiple VMWare Fusion kernel infoleaks (1 in the OS X Host and 1 in the OS X Guest)
-
8
[CVE-2016-4673] Apple CoreGraphics macOS/iOS JPEG memory corruption
-
9
Filetype Classifier with CNN
-
10
squid-cache proxy Out of Bound Write in Gopher
Michael Coppola’s Blog
-
1
NETGEAR unsquashfs.c version 1.3
-
2
DEF CON 20 Presentation
-
3
Anatomy of a SCADA Exploit: Part 2 – From EIP to Shell
-
4
MIT/LL CTF Writeup (Ticket Server)
-
5
Suterusu Rootkit: Inline Kernel Function Hooking on x86 and ARM
-
6
Summercon 2013: Hacking the Withings WS-30
-
7
CSAW CTF 2013 Kernel Exploitation Challenge
-
8
Reverse Engineering a Furby
-
9
CSAW CTF 2015 Kernel Exploitation Challenge
-
10
Google: Stop Burning Counterterrorism Operations
Objective-See’s Blog
-
1
Detecting (Evil) Dylibs
-
2
It's Turtles All The Way Down
-
3
The Mac Malware of 2023
-
4
Analyzing DPRK's SpectralBlur
-
5
Why Join The Navy If You Can Be A Pirate?
-
6
Apple Gets an 'F' for Slicing Apples
-
7
This Meeting Should Have Been an Email
-
8
The Hidden Treasures of Crash Reports
-
9
Restoring Reflective Code Loading on macOS
-
10
The Mac Malware of 2024
Push the Red Button
-
1
Paper and Slides Available for "Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection"
-
2
What I Did on My Summer Vacation
-
3
Virtuoso – Initial Code Release
-
4
Announcing PANDA: A Platform for Architecture-Neutral Dynamic Analysis
-
5
Prebuilt VM for PANDA Now Available
-
6
PANDA, Reproducibility, and Open Science
-
7
Breaking Spotify DRM with PANDA
-
8
PANDA VM Updated
-
9
Replaying Regin in PANDA
-
10
Reproducible Malware Analyses for All