Research & writeups
Vulnerability research, exploit development and the occasional side quest.
-
QQPlayer 3.9 Heap Overflow: Matroska Exploitation
QQPlayerAnalysis of a heap overflow vulnerability in QQPlayer 3.9 discovered through WinAFL fuzzing of .webm files, exploiting Matroska container parsing flaws.
6 min read memory-corruptionfuzzingexploit-development -
VLC 2.2.6 Stack Overflow: ActiveX Plugin Exploitation
VLC VLC Media PlayerAnalysis of a stack overflow vulnerability in VLC Media Player 2.2.6 discovered through .vob file fuzzing, exploitable via Internet Explorer ActiveX plugin.
6 min read memory-corruptionfuzzingexploit-development -
Mercury Browser Intent Hijacking: Android File Manager RCE
Mercury BrowserCritical intent hijacking vulnerability in Mercury Browser for Android enabling arbitrary file upload and code execution through file manager abuse.
5 min read rcemobilevulnerability-research -
Audacious 3.8/3.9 Stack Overflow: Deep Dive Analysis
AudaciousIn-depth analysis of a critical stack overflow vulnerability in Audacious Player, discovered through fuzzing .aac files with advanced exploitation techniques.
6 min read memory-corruptionfuzzingexploit-development -
Frameshock: A Modular Penetration Testing Framework
Deep dive into Frameshock, a modular penetration testing framework with Shodan integration, multi-target management, and advanced payloads.
8 min read red-teamexploit-development -
License Plate OSINT: Argentina Vehicle Registry
How I reverse-engineered Argentina's license plate system to track down a hit-and-run driver using client-side JavaScript vulnerabilities.
8 min read osintweb-securityreverse-engineering -
Shellshock QMAIL Exploitation: SMTP Injection Attack
CVE-2014-6271 qmailAdvanced exploitation of CVE-2014-6271 (Shellshock) through QMAIL SMTP servers via MAIL FROM header injection for remote code execution.
5 min read rceexploit-development