Listening into the Ether
What did the firewall say when it felt defeated?
Unmasking Spoofed Stagers: Header Forensics & Attribution
The paradox at the heart of email-based attacks is this: modern authentication systems—SPF, DKIM, DMARC, ARC—were designed to prevent exactly this kind of forgery, yet a sophisticated attacker can still spoof an email from someone's own address and have it pass every cryptographic check.
Info Leak Cisco ASA - v 9.18
he LINA `kprintf` function contains a use-after-free vulnerability when processing malformed SNMP queries. Error messages logged via `kprintf` reference freed memory structures, allowing:
1. Information disclosure via heap spray
2. ASLR bypass by leaking libc addresses
3. Selective overwrite of freed heap chunks
4. Arbitrary code execution via corrupted function pointers
Huawei EchoLife ONT Tools Windows Exe
From unsanitized command inputs to process injection vulnerabilities in Huawei’s Admin Tool, it has it all!
Cisco ASA HTTP CGI Parameter Heap Overflow
Crimson and Clover: Lina’s Pre-Auth Over and Over, yeahhhhh….What a beautiful feeling. Pre-Auth, Over and Over
SSH Pre-Authentication RCE
Cisco ASA LINA SNMP OID Injection RCE Exploit
Oh the places we go, Oh the lattices we Explore!
Architecture-Agnostic Vulnerability Research: Linear Lattice Predicate Detection Across CPU Architectures
Offense informing Defense, nah, we just say “..!— We Ball!”
Post-Quantum Cryptography and The Riddler Chat Application
Engineering a Renaissance, one APK at a time
Building an Android Fuzzer: Studying Android Internals Through Binder IPC
Secure Onion Routing for SMBs: The Short Brief
Instead of sending traffic directly from your office to the cloud, geographic routing intentionally routes it through multiple independent intermediaries in different countries.
The Post Quantum Era
The Post Quantum Era