Recent posts
Exploit Writing Part 1: CVE-2023-26818 MacOS TCC Bypass W/ telegram
Writing full exploit for CVE-2023-26818: MacOS TCC Bypass W/ telegram
CVE-2023-26818 Part 2 (Sandbox): MacOS TCC Bypass W/ telegram using DyLib Injection
In 2nd part of the analysis for CVE-2023-26818, We discussing the app sandboxing in MacOS and show how to bypass it. To exploit the vulne...
CVE-2023-26818 Part1: MacOS TCC Bypass with telegram using DyLib Injection
In this analysis we discussing a vulnerability exist in telegram app on MacOS known as CVE-2023-26818.
CVE-2021-38294: Apache Storm Nimbus Command Injection
Command Injection vulnerability that affects Nimbus server in apache storm.
CVE-2021-44521: Apache Cassandra Remote Code Execution
Detailed analysis for Apache Cassandra CVE-2021-44521 Remote Code Execution & Sandbox/Security Bypass.
CVE-2021-45232: Apache APISIX Dashboard Unauthorized Access & Unauth-RCE
Detailed analysis for CVE-2021-45232, an Unauthorized Access vulnerability in apache apisix & how it can be used to achieve RCE.
Exploit Writing: CVE-2022-22733 Privilege Escalation & RCE
Writing Exploit for CVE-2022-22733: Apache ShardingSphere ElasticJob-UI.
CVE-2022-22733: Apache ShardingSphere ElasticJob-UI privilege escalation
Detailed analysis for CVE-2022-22733 a privilege escalation vulnerability through exposure of sensitive data.