Posts on exploit-development
9 posts tagged exploit-development.
-
WebKit CVE-2016-4622: Array.slice Memory Disclosure
CVE-2016-4622 Apple WebKitComprehensive analysis and exploitation of the WebKit JavaScript Core vulnerability that enables memory disclosure through Array.slice manipulation
7 min read browser-exploitationmemory-corruptionexploit-development -
D-Link DIR600 Remote Code Execution Exploit Chain
D-Link DIR-600Complete exploit chain for D-Link DIR600 routers using CSRF, authentication bypass, and RCE to achieve persistent backdoor access via single HTTP link.
5 min read rcecsrffirmware -
CVE-2019-9194: elFinder Command Injection 1-Day Exploit
CVE-2019-9194 elFinderAnalysis and exploitation of CVE-2019-9194, a command injection vulnerability in elFinder, from discovery to functional exploit development.
6 min read rceweb-securityexploit-development -
CVE-2019-14670 - LimeSurvey TCPDF RCE via PHAR File
CVE-2019-14670 LimeSurveyRemote code execution in LimeSurvey < 3.17 through TCPDF PHAR deserialization attack, exploiting queXML PDF export functionality.
4 min read rceweb-securityexploit-development -
QQPlayer 3.9 Heap Overflow: Matroska Exploitation
QQPlayerAnalysis of a heap overflow vulnerability in QQPlayer 3.9 discovered through WinAFL fuzzing of .webm files, exploiting Matroska container parsing flaws.
6 min read memory-corruptionfuzzingexploit-development -
VLC 2.2.6 Stack Overflow: ActiveX Plugin Exploitation
VLC VLC Media PlayerAnalysis of a stack overflow vulnerability in VLC Media Player 2.2.6 discovered through .vob file fuzzing, exploitable via Internet Explorer ActiveX plugin.
6 min read memory-corruptionfuzzingexploit-development -
Audacious 3.8/3.9 Stack Overflow: Deep Dive Analysis
AudaciousIn-depth analysis of a critical stack overflow vulnerability in Audacious Player, discovered through fuzzing .aac files with advanced exploitation techniques.
6 min read memory-corruptionfuzzingexploit-development -
Frameshock: A Modular Penetration Testing Framework
Deep dive into Frameshock, a modular penetration testing framework with Shodan integration, multi-target management, and advanced payloads.
8 min read red-teamexploit-development -
Shellshock QMAIL Exploitation: SMTP Injection Attack
CVE-2014-6271 qmailAdvanced exploitation of CVE-2014-6271 (Shellshock) through QMAIL SMTP servers via MAIL FROM header injection for remote code execution.
5 min read rceexploit-development