This is Part 1 in a 4 part series about my process hunting for vulnerabilities in a network auditing tool (used to protect networks by detecting and fixing security holes) and fully exploiting one of the vulnerabilities I found.
There is an insanely cool, simple and elegant way to calculate Fibonacci numbers in assembly using only 2 opcodes!
Failed patches are a norm in our industry, unfortunately. I had to examine the patch for my CVE-2019-12181 vulnerability to see if it was secure.
I found a stable privilege escalation 0day in the Serv-U FTP Server through command injection. This is how I found and exploited it.
I often take breaks from vulnerability hunting, and occasionally I find myself doing some really random things.
For example, I stumbled across this poster and decided to make a version of my own. I wanted to make one that is slightly more offensive so that it can be gifted to a good friend. Here is the final result.