b1ack0wl / vulnerability-write-ups
This repo contains write ups of vulnerabilities I've found and exploits I've publicly developed.
☆145Updated 2 years ago
Alternatives and similar repositories for vulnerability-write-ups:
Users that are interested in vulnerability-write-ups are comparing it to the libraries listed below
- ☆203Updated 4 months ago
- Leveraging patch diffing to discover new vulnerabilities☆112Updated 5 months ago
- ASLR bypass without infoleak☆159Updated 3 years ago
- Advanced exploits that I wrote for Pwn2Own competitions and other occasions☆167Updated last year
- The resources for glibc Malloc heap exploitation course by Maxwell Dulin and Security Innovation.☆149Updated 4 months ago
- Slides & Hands-on for the reverse engineering workshop☆178Updated 2 years ago
- A tool for firmware cartography☆146Updated 3 months ago
- A structure-aware HTTP fuzzing library☆210Updated 3 months ago
- Leveraging CVEs as North Stars in vulnerability discovery and comprehension.☆64Updated 11 months ago
- A proper well structured documentation for getting started with chrome pwning & v8 pwning☆192Updated 2 years ago
- Fuzzing IoT Devices Using the Router TL-WR902AC as Example☆109Updated last year
- Zenith exploits a memory corruption vulnerability in the NetUSB driver to get remote-code execution on the TP-Link Archer C7 V5 router fo…☆127Updated 2 years ago
- Writeups, PoCs of the bugs I found while preparing for the Pwn2Own Miami 2023 contest targeting UaGateway from the OPC UA Server category…☆60Updated last year
- ☆122Updated last year
- Slides and Material for "SymbolicExecutionDemystified" Presentation @ Insomni'Hack 2022☆100Updated 2 years ago
- A collection of my Ghidra scripts to facilitate reverse engineering and vulnerability research.☆245Updated 4 months ago
- Userland exec PoC to be used as attack vector technique☆81Updated last month
- esoteric☆51Updated 4 years ago
- Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.☆98Updated last month
- ☆118Updated 3 weeks ago
- An automatic Blind ROP exploitation tool☆199Updated last year
- Linux Kernel N-day Exploit/Analysis.☆63Updated 5 months ago
- A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in c…☆120Updated 2 years ago
- ☆115Updated 11 months ago
- ☆70Updated last year
- PASTIS: Collaborative Fuzzing Framework☆162Updated 7 months ago
- Static Binary Instrumentation tool for Windows x64 executables☆198Updated last month
- Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CV…☆216Updated 2 years ago
- rp-bf: A library to bruteforce ROP gadgets by emulating a Windows user-mode crash-dump☆114Updated 10 months ago
- ☆315Updated 9 months ago