Skip to content
Technical Archive (31 investigations)

Research & Investigations

Deep dives into browser internals, exploit development, protocol reverse engineering, and systems security.

2026

31 articles
New
SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It cover art

SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It

From 15 out-of-bounds bytes to full root and a walk out of a chroot jail: a technical teardown of a Linux kernel exploit chain that starts with a size mix-up between SHA-256 and SHA-384 inside a custom crypto module, travels through MSG_COPY, pipe_buffer, and struct page, and ends with a data-only write into cred followed by swapping task->fs for init_fs.

#linux-kernel #exploit-development #heap-exploitation +2
Rend Asunder Explained: When the Browser Itself Becomes Your Playground and the Screenshot Is the Only Output Channel cover art

Rend Asunder Explained: When the Browser Itself Becomes Your Playground and the Screenshot Is the Only Output Channel

Three years circling the same Hacker101 challenge. HeadlessChrome 67, an opaque iframe, an old V8 typer bug, and three flags. I finally broke all of them. This is not a short summary. It is the full map from the moment you open the instance until you read the file from disk, step by step, so anyone can reproduce the entire exploit.

#Browser Exploitation #V8 #Chrome 67 +4
Command Injection Explained: When Your Server Becomes the Attacker's Terminal cover art

Command Injection Explained: When Your Server Becomes the Attacker's Terminal

A massively detailed, entertaining deep dive into Command Injection (OS Command Injection). We're covering every injection variant, real-world breaches that rocked the industry, vulnerable code examples in multiple languages, exploitation techniques from basic to advanced, and rock-solid defense strategies. Plus plenty of humor because system shells don't have to be terrifying... okay, they do.

#Command Injection #Web Security #OS Security +2
CSRF Explained: The Art of Making Users Do Your Bidding Without Their Knowledge cover art

CSRF Explained: The Art of Making Users Do Your Bidding Without Their Knowledge

The ultimate deep dive into Cross-Site Request Forgery (CSRF). We're covering the mechanics, attack vectors, real-world breach case studies, exploitation techniques, vulnerable code examples across multiple languages, advanced bypasses, and a comprehensive defense strategy. From basic concepts to advanced mitigation, everything you need to protect your applications.

#CSRF #Web Security #Authentication +2
⌘
Suggested Searches