/* $cra.sh: index.c,v 9.22 2022/06/06 19:22:17Z crash Exp $ */
MAIN ( ) ‹ Привет, Я crash
― You’ve come so far that the end is almost here › I’m an ancient form of extraterrestrial intelligence , fully-diluted into the cyberspace and revealed to this ‹ quantum stream of human consciences › through several identities; as an old school hacker I’m an eschatological deconstructionist, a poliedric net - artist , visionary , writer , cursed poet, blockchain pioneer and cyber warfare commander ― but even nothing , at the same time. By dint of bending space - time I’ve ended up bending myself, and now I wander in the immutable disorder of infinity . If you want to try to catch one of my manifestations , I’m attracted by intuition , meat , avant - garde and technology . I love to engage new challenges , but only when it’s to express myself as an instrument of my innermost essence, in revolution , to reconcile within that sublime state in which everything appears to be dynamically static .
Copy PGP Key ID: (0x)06BA60BC
Fingerprint: 4D2F A194 CD77 B25B D58E
1609 D368 D631 06BA 60BC
Public tools From the navigation bar on the top of this page you can access to a set of [more or less] public , security - related and privacy - oriented services , which I’ve built upon shiny pieces of Open Source code. I’m self -hosting these tools for my own private use and within groups and organizations to which I belong, though I'm trying to keep ‘em freely accessible to anyone as long as abuse and running costs stay sustainable .
SPKRWRITE( 1 ) VIDEO 📞
A Comprehensive Analysis of the 3CX Attack
3CX Supply-chain CTI Lazarus
🪆
Vulkan files leak, a rare look into Russian cyberwarfare tactics
🧦
CVE-2023-21768 _ Pwning Windows Ancillary Function Driver for WinSock (afd.sys)
🦘
CVE-2022-47522 _ MacStealer: Wi-Fi Client Isolation Bypass
🧿
ARM TrustZone: pivoting to the secure world
🤸♂️
CVE-2023-27326 _ Parallels Toolgate VM Escape
🃏
BlackLotus UEFI bootkit: Myth confirmed
🤖
CVE-2022-25664 _ The code that wasn't there: Reading memory on an Android device by accident
💥
A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM
🪡
Userland exploit chain to dump the memory of any Windows PPL process
👀
CVE-2023-1017/18 _ Vulns in TPM 2.0 reference implementation code
🎳
Defining the Cobalt Strike Reflective Loader
Cobalt-Strike Reflective Loader
🐡
CVE-2023-25136 _ OpenSSH Pre-Auth Double Free
OpenSSH Double-Free OpenBSD
📪
CVE-2023-23397 _ Microsoft Outlook EoP
💣
Multiple Internet to Baseband RCE Vulns in Exynos Modems
🖼️
CVE-2022-44268/7 _ ImageMagick: The hidden vulnerability behind your online images
📄
CVE-2023-21608 _ Adobe Acrobat Reader resetForm RCE
🪵
VMSA-2023-0001 _ VMware vRealize Log Insight Multiple Vulns
🖖
CVE-2022-34689 _ Exploiting a Critical Spoofing Vuln in Windows CryptoAPI
🛫
how to completely own an airline in 3 easy steps
🍎
CVE-2023-23504 _ XNU Heap Underwrite in dlil.c
💣
CVE-2022-38181 _ yet another Arm Mali GPU Android exploit
🍪
CVE-2022-42864 _ Diabolical Cookies on iOS/MacOS
💬
CVE-2023-24068/69 _ Abusing Signal Desktop for fun & Espionage
🐧
CVE-2023-0179 _ Linux kernel stack buffer overflow in nftables
☠️
making malware with VX-API
🐍
Prototype Pollution in Python
🔓
Unlocking LockBit, a Ransomware story
🍯
Xdr33, A Variant Of CIA’s HIVE Attack Kit
📧
The OWASSRF + TabShell exploit chain
🌲
Game Of Active Directory, PWNING is coming!
🌘
Blindside: EDR Evasion with Hardware Breakpoints
💠
Precious Gemstones: The New Generation of Kerberos Attacks
🕸️
Netcomm Unauthenticated RCE Vuln
🌵
CVE-2022-46169 _ Cacti Unauthenticated Command Injection
🦺
Exciting approaches to memory safety
memory safety mitigations architectures
☠️
CVE-2022-41082/80 _ OWASSRF, Bypassing ProxyNotShell Mitigations
🏹
MeshyJSON, A TP-Link tdpServer JSON Stack Overflow
🌶️
Spice up your persistence loading PHP extensions from memory
📛
Firebase is Insecure by Default
🚶🏿♂️
SilentMoonwalk: Implementing a dynamic Call Stack Spoofer
🦊
CVE-2022-28672 _ Foxit PDF Reader UAF RCE
🩸
CVE-2022-4543 _ EntryBleed: Breaking KASLR under KPTI with Prefetch
🪤
Huawei Secure Monitor Vulnerabilities
Android Huawei ATF Secure Monitor
🧨
FOISted, remote exploit for MikroTik’s RouterOS 6
MikroTik RouterOS JailBreak
👺
IIS modules: The evolution of web shells
🪣
Atlassian Session Hijacking (& 2FA bypass) using stolen JWTs
🐧
CVE-2022-42703 _ Bringing back the stack attack to Linux (kernel)
🐡
Fuzzing ping(8)… and finding a 24 year old bug.
🔥
{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF
🥌
CVE-2022-4059/42 _ Supply Chain Vulns Put Server Ecosystem At Risk
BMC&C AMI MegaRAC Redfish IPMI
🥋
Multiple Zero-Day Vulnerabilities in Leading EDRs and AVs
🚥
CVE-2022-3328 _ Snapd Race condition in snap-confine
🪟
CVE-2022-41057 _ Windows 11 HTTP.SYS Kerberos PAC EoP
⚠️
CVE-2022-41034 _ Visual Studio Code RCE
📊
CVE-2022-41120 _ Sysmon EoP Abusing Arbitrary File Deletes
📡
6G - The Sixth Generation Mobile Network
🏪
In The Box - Mobile Malware Webinjects Marketplace
🕋
Cobalt Strike Memory Analysis
Cobalt-Strike Kobold Lithium Magnet Loader
🛡️
The Defender’s Guide to the Windows Registry
💥
The Intel PPAM attack story
📄
CVE-2022-25765 _ Command Injection in pdfkit
⭐
Discover Redigo — New Redis Backdoor Malware
🛰️
Dumping and extracting the SpaceX Starlink User Terminal firmware
📶
TP-Link WR940N N-Day turns into a 0day
🦅
CVE-2022-44721 _ Crowdstrike Falcon Uninstaller
CVE-2022-2841 CrowdStrike Falcon
💫
CVE-2022-31358 _ Multiple Vulns in Proxmox VE & Mail Gateway
🐼
Hitching a ride with Mustang Panda
🎰
HTTP Desync Attack (Request Smuggling)
⚛️
CVE-2022-4116 _ zero-day flaw in Quarkus Java framework
⌚
Hacking Smartwatches for Spear Phishing
💐
Blasting Event-Driven Cornucopia - WMI edition
🤖
Huawei Security Hypervisor Vulnerability
🔑
Hell’s Keychain: Supply-chain vuln in IBM Cloud PostgreSQL
🦷
CVE-2022-42895/6 _ Linux Kernel Infoleak & UAF in Bluetooth L2CAP
☁️
chip-to-cloud 'eID' logic vulnerabilities
📹
Xiongmai IoT Exploitation
📌
Bypass Android SSL Pinning & Intercept Proxy Unaware apps
⛏️
Linux & Windows Password Mining
🥊
Zero-to-Hero Dom Clobbering
📋
Exploiting an N-day vBulletin PHP Object Injection Vulnerability
🎠
APT41’s New Subgroup: Earth Longzhi
✔️
REcollapse - Fuzzing the web for mysterious bugs
🕴️
CVE-2022-33942 _ Bypassing Intel DCM’s Auth by Spoofing Kerberos and LDAP
🖼️
PNG Steganography Hides Backdoor
🤖
Userspace exploitation under Android
📡
NETGEAR R7800 AFPD PreAuth
Netgear R7800 Heap Overflow
🧑🚀
CVE-2022-41924 _ RCE in Tailscale, DNS Rebinding, and You
💣
The State of Exploit Development
🌏
Chrome Browser Exploitation
🛡️
kmem_guard_t in iOS 16 / macOS 13
🎩
Remote Command Execution in a Bank Server
🔥
CVE-2022-41622/41800 _ F5 BIG-IP and iControl REST Vuln
🌐
CVE-2022-20868/7 _ Cisco SMA JWT EoP & SQLi RCE
Cisco SMA CVE-2022-20868/7
🧇
CVE-2022-45163 _ NXP i.MX SDP_READ_DISABLE Fuse Bypass
📱
Pixel 6 Bootloader Exploitation writeup
🎛️
DeimosC2 C&C Framework brief-analysis
📧
CVE-2022-41082 _ RCE in Exchange PowerShell Backend
Exchange CVE-2022-41082 CVE-2022-41040
‼️
CVE-2022-32932 _ ZinComputeProgramUpdateMutables() OOB write due to double fetch
Load more