<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>3lyly0 | Technical Research Archive</title><description>Technical investigations, browser exploitation, vulnerability research, and systems reverse engineering.</description><link>https://www.3lyly0.dev/</link><language>en-us</language><lastBuildDate>Thu, 24 Sep 2026 00:00:00 GMT</lastBuildDate><atom:link href="https://www.3lyly0.dev/rss.xml" rel="self" type="application/rss+xml"/><item><title>SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It</title><link>https://www.3lyly0.dev/research/sha256-sha384-type-confusion-oob-write-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/sha256-sha384-type-confusion-oob-write-explained/</guid><description>From 15 out-of-bounds bytes to full root and a walk out of a chroot jail: a technical teardown of a Linux kernel exploit chain that starts with a size mix-up between SHA-256 and SHA-384 inside a custom crypto module, travels through MSG_COPY, pipe_buffer, and struct page, and ends with a data-only write into cred followed by swapping task-&gt;fs for init_fs.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>linux-kernel</category><category>exploit-development</category><category>heap-exploitation</category><category>type-confusion</category><category>privilege-escalation</category></item><item><title>SafeStack Bypass Explained: The Vault Is Solid, the Ledger Isn&apos;t</title><link>https://www.3lyly0.dev/research/safestack-bypass/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/safestack-bypass/</guid><description>SafeStack splits your stack so a buffer overflow can only smash the half nobody misses. Solid plan, except the pointer that defines where the smashable half lives is stored in TLS, and TLS was sitting right next to the overflow. This is the story of how one bad memory layout took down a shadow stack, a canary, and a homemade CFI check in a single chain.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>Binary Exploitation</category><category>Memory Safety</category><category>SafeStack</category><category>Mitigation Bypass</category><category>Exploit Development</category></item><item><title>MQTT Debug Topic Leaks Explained: When Your Device Keeps a Diary Anyone Can Read</title><link>https://www.3lyly0.dev/research/mqtt-debug-topic-leaks-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/mqtt-debug-topic-leaks-explained/</guid><description>A retained MQTT debug topic is the IoT equivalent of leaving the master key on a public noticeboard that never gets cleaned. Here is how firmware analysis, weak broker credentials, and one forgotten retain flag turn a thermostat into a leaky vault.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>MQTT</category><category>IoT</category><category>Firmware Analysis</category><category>Retained Messages</category><category>Weak Credentials</category></item><item><title>Side-Channel ECDSA Explained: When Your Division Algorithm Can&apos;t Keep a Secret</title><link>https://www.3lyly0.dev/research/side-channel-ecdsa-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/side-channel-ecdsa-explained/</guid><description>How a custom binary modular division implementation leaks the ECDSA nonce through traced function calls, and how an attacker can recover the private key from the execution trace alone.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>cryptography</category><category>ecdsa</category><category>side-channel</category><category>binary-gcd</category><category>key-recovery</category></item><item><title>Non-Transitive Comparators Explained: When Sorting Quietly Walks Off the Array</title><link>https://www.3lyly0.dev/research/non-transitive-comparators/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/non-transitive-comparators/</guid><description>A comparison function that looks innocent can turn qsort into an out-of-bounds write primitive. This article breaks down how integer overflow in comparators breaks the assumptions of insertion sort, forces the slow path with a memory limit, and opens a full chain from stack corruption to code execution.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><category>Memory Corruption</category><category>Integer Overflow</category><category>qsort</category><category>Binary Exploitation</category><category>Comparators</category></item><item><title>Browser Session Hijacking Explained: When the Cookie Walks Out the Front Door</title><link>https://www.3lyly0.dev/research/browser-session-hijacking-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/browser-session-hijacking-explained/</guid><description>You spent money on MFA, zero-trust policies, and password managers. Then a friendly-looking extension quietly copied your live session tokens out of Chrome&apos;s LevelDB and left. This write-up shows how the theft works, how the artifacts survive on disk, and why the browser itself became the weakest link.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><category>DFIR</category><category>Session Hijacking</category><category>Malicious Extensions</category><category>LevelDB</category><category>Browser Forensics</category></item><item><title>Hybrid Mobile Reward Check Explained: When Four Handoffs Still Mean Yes</title><link>https://www.3lyly0.dev/research/hybrid-mobile-reward-check-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/hybrid-mobile-reward-check-explained/</guid><description>A cross-platform mobile app splits its reward check across managed code and a tiny native helper, with mixing passes, a bytecode runner, and anti-debug on top. None of that moves the decision off the phone. Here is how to map the chain, port the transforms, and drive the native exports in order.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><category>Reverse Engineering</category><category>Mobile RE</category><category>Android</category><category>Native Code</category><category>Client-Side Trust</category></item><item><title>Heap Metadata Corruption Explained: When One Byte Starts Rewriting the Rules</title><link>https://www.3lyly0.dev/research/blinded-heap-exploitation/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/blinded-heap-exploitation/</guid><description>A practical deep dive into turning a one-byte heap write into controlled memory corruption on modern glibc. We will walk from the bug itself to allocator metadata, dynamic linking structures, and a deterministic final code-execution primitive.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>Heap Exploitation</category><category>glibc</category><category>Memory Corruption</category><category>Dynamic Linking</category><category>Pwn</category></item><item><title>Obfuscated State Machine Explained: When Your Verifier Turns Into a Maze</title><link>https://www.3lyly0.dev/research/obfuscated-state-machine/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/obfuscated-state-machine/</guid><description>Some binaries do not check a secret with a simple comparison. They turn the input into bits and drive it through a state machine filled with transitions, dictionary lookups, and 256-bit arithmetic constraints. This write-up shows how to reverse that verifier into a graph you can actually solve.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>Reverse Engineering</category><category>Binary Analysis</category><category>Obfuscation</category><category>State Machines</category><category>CTF</category></item><item><title>Arbitrary Pointer Manipulation Explained: When Memory-Safe Code Hands You the Keys</title><link>https://www.3lyly0.dev/research/arbitrary-pointer-manipulation-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/arbitrary-pointer-manipulation-explained/</guid><description>A memory-safe language can prevent whole classes of memory corruption, then leave one perfectly valid pointer in exactly the wrong place. This write-up breaks down how pointer corruption, stale length metadata, and indirect callbacks can turn an innocent note cache into code execution.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>Memory Safety</category><category>Pointer Corruption</category><category>RCE</category><category>Zig</category><category>Binary Exploitation</category></item><item><title>Replacement-String Injection Explained: When `$`` Steals the Template</title><link>https://www.3lyly0.dev/research/replacement-string-injection-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/replacement-string-injection-explained/</guid><description>An escape function can look perfectly safe while JavaScript quietly interprets the replacement string underneath it. Here&apos;s how the bug works, how the XSS chain develops, and why String.replace() makes a terrible template engine.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>XSS</category><category>JavaScript</category><category>CSP</category><category>Template Injection</category><category>Secure Coding</category></item><item><title>Rend Asunder Explained: When the Browser Itself Becomes Your Playground and the Screenshot Is the Only Output Channel</title><link>https://www.3lyly0.dev/research/rend-asunder-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/rend-asunder-explained/</guid><description>Three years circling the same Hacker101 challenge. HeadlessChrome 67, an opaque iframe, an old V8 typer bug, and three flags. I finally broke all of them. This is not a short summary. It is the full map from the moment you open the instance until you read the file from disk, step by step, so anyone can reproduce the entire exploit.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>Browser Exploitation</category><category>V8</category><category>Chrome 67</category><category>Hacker101</category><category>RCE</category><category>SOP Bypass</category><category>WebAssembly</category></item><item><title>Approximate GCD Explained: When Your Secret Prime Hides in Plain Arithmeti</title><link>https://www.3lyly0.dev/research/approximate-gcd-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/approximate-gcd-explained/</guid><description>A homemade encryption scheme hides a giant secret prime inside a pile of noise and multiplication. Turns out a lattice can filter out the noise faster than you can say &apos;I rolled my own crypto.&apos; Here&apos;s the math, the break, and why you should never do this at home.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>Approximate GCD</category><category>Lattice Cryptanalysis</category><category>LLL</category><category>Cryptography</category><category>Homomorphic Encryption</category><category>CTF</category></item><item><title>Predictable Quantum Randomness Explained: When Your Device-Independent Beacon Is Just a Fancy Hash Function</title><link>https://www.3lyly0.dev/research/predictable-quantum-randomness-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/predictable-quantum-randomness-explained/</guid><description>A cold wallet swears its private key came from an unbreakable quantum experiment. The experiment turns out to be pure math running on a public seed. Here is how that works, why it still fails the Bell test in practice, and how to stop treating deterministic code as physics.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate><category>Quantum Cryptography</category><category>Random Number Generators</category><category>Key Generation</category><category>Cryptography</category><category>Device Independence</category><category>Bell Test</category></item><item><title>PRNG Stream Reuse Explained: When Randomness Repeats Itself</title><link>https://www.3lyly0.dev/research/prng-stream-reuse-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/prng-stream-reuse-explained/</guid><description>A random-looking validation flow can collapse when two code paths consume the same PRNG stream. Add an empty-iterator check and silently ignored values, and the whole thing starts behaving less like security and more like a vending machine that gives refunds.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>PRNG</category><category>Python</category><category>Logic Bugs</category><category>Input Validation</category><category>Oracle Attack</category><category>CTF</category></item><item><title>Client-Side Password Validation Explained: When Your Password Checker Builds Its Own Tiny CPU</title><link>https://www.3lyly0.dev/research/client-side-password-validation-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/client-side-password-validation-explained/</guid><description>A password checker can look wonderfully complicated, decrypt code at runtime, and even run a custom virtual machine. That still does not make the secret unbreakable. Here is how to pull the VM apart, recover its instructions, and reverse the final checks.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>Reverse Engineering</category><category>Virtual Machine</category><category>Obfuscation</category><category>Binary Analysis</category><category>Password Validation</category><category>GD</category></item><item><title>Encrypted C2 Loader Explained: Correlating PCAP, Memory, and a Hidden Stage</title><link>https://www.3lyly0.dev/research/encrypted-c2-loader-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/encrypted-c2-loader-explained/</guid><description>This challenge started with exactly two artifacts: `capture.pcapng` and `DbgInfo.DMP`. From there, the investigation moved through C2 decryption, screenshot and binary recovery, and reverse engineering of a loader that hid an encrypted in-memory stage.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Reverse Engineering</category><category>Forensics</category><category>PCAP</category><category>Shellcode</category><category>Windows</category><category>Malware Analysis</category></item><item><title>Insecure OPC-UA Write Access Explained: When the Safety Interlock Is Just a Boolean</title><link>https://www.3lyly0.dev/research/insecure-opc-ua-write-access-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/insecure-opc-ua-write-access-explained/</guid><description>OPC-UA is supposed to be the grown-up industrial protocol. Hand it a self-signed certificate and a writable safety node, and it becomes a remote kill switch. Here is how that happens and how to stop it.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>OPC-UA</category><category>ICS</category><category>SCADA</category><category>Industrial Control</category><category>Write Access</category></item><item><title>RF Protocol Reverse Engineering Explained: When the Airwaves Leak the Keys</title><link>https://www.3lyly0.dev/research/rf-protocol-reverse-engineering-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/rf-protocol-reverse-engineering-explained/</guid><description>A proprietary wireless security protocol looked solid on paper. Then someone opened the packets, fixed the CRC, and discovered that self-addressed commands plus one wrong transmission parameter were all that stood between locked sensors and open doors.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>RF</category><category>Protocol Reverse Engineering</category><category>CRC</category><category>Wireless Security</category><category>Hardware Hacking</category></item><item><title>Flutter App Reverse Engineering Explained: When the Crypto Is Just Fancy Wrapping Paper</title><link>https://www.3lyly0.dev/research/flutter-app-reverse-engineering-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/flutter-app-reverse-engineering-explained/</guid><description>A full walkthrough of pulling a Flutter banking app apart, recovering its custom RSA+AES API protocol from the Dart AOT snapshot, and talking to the backend like the real client. Spoiler: encrypting the wire does not mean the server checks who owns the account.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>Flutter</category><category>Mobile RE</category><category>Dart AOT</category><category>API Security</category><category>Cryptography</category></item><item><title>PHP Extension Heap Overflow Explained: When Metadata Owns the Allocator</title><link>https://www.3lyly0.dev/research/php-extension-heap-overflow-explained-when-metadata-owns-the-allocator/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/php-extension-heap-overflow-explained-when-metadata-owns-the-allocator/</guid><description>A custom PHP extension that parses image metadata with a fixed-size buffer and classic strcpy can hand the entire process to an attacker. Pair it with a loose file reader and you get ASLR bypass plus reliable RCE.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>Heap Overflow</category><category>PHP Extensions</category><category>Zend Allocator</category><category>LFI</category><category>RCE</category><category>Memory Corruption</category></item><item><title>UPnP Command Injection Explained: When Your Gateway Trusts the Network Too Much</title><link>https://www.3lyly0.dev/research/upnp-command-injection-explained/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/upnp-command-injection-explained/</guid><description>UPnP was supposed to make devices play nice automatically. Instead it often hands attackers a SOAP endpoint, a password, and a shell. Here&apos;s how a diagnostic service turns into remote code execution.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>UPnP</category><category>Command Injection</category><category>IoT</category><category>Router Security</category><category>SOAP</category></item><item><title>Insecure Deserialization Explained: When Your Data Comes Back to Bite You</title><link>https://www.3lyly0.dev/research/insecure-deserialization/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/insecure-deserialization/</guid><description>A deep dive into insecure deserialization vulnerabilities, from Java gadgets to PHP object injection. Learn how attackers weaponize your own data formats, real breaches that made headlines, vulnerable examples, exploitation chains, and rock‑solid defenses. With jokes. Of course.</description><pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate><category>Insecure Deserialization</category><category>Web Security</category><category>Serialization</category><category>OWASP</category><category>Application Security</category></item><item><title>Broken Authentication Explained: When Logins Leak Like a Sieve</title><link>https://www.3lyly0.dev/research/broken-authentication/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/broken-authentication/</guid><description>An exhaustive, witty walkthrough of authentication failures: weak passwords, flawed reset flows, session fixation, MFA bypass, and more. Learn from real breaches, vulnerable code samples, and defense checklists that&apos;ll harden your login system without hurting UX.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate><category>Broken Authentication</category><category>Web Security</category><category>OWASP</category><category>Login</category><category>Session Management</category></item><item><title>Path Traversal Explained: The Art of Escaping the Filesystem Prison</title><link>https://www.3lyly0.dev/research/path-traversal/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/path-traversal/</guid><description>A massively detailed, story-driven deep dive into Path Traversal vulnerabilities. From classic ../ tricks to modern cloud, container, zip slip, and symlink abuse. Real-world breaches, vulnerable code in every major language, advanced exploitation chains, and defense strategies that actually work.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate><category>Path Traversal</category><category>Directory Traversal</category><category>Web Security</category><category>OWASP</category><category>File System Security</category><category>Penetration Testing</category></item><item><title>Command Injection Explained: When Your Server Becomes the Attacker&apos;s Terminal</title><link>https://www.3lyly0.dev/research/command-injection/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/command-injection/</guid><description>A massively detailed, entertaining deep dive into Command Injection (OS Command Injection). We&apos;re covering every injection variant, real-world breaches that rocked the industry, vulnerable code examples in multiple languages, exploitation techniques from basic to advanced, and rock-solid defense strategies. Plus plenty of humor because system shells don&apos;t have to be terrifying... okay, they do.</description><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate><category>Command Injection</category><category>Web Security</category><category>OS Security</category><category>OWASP</category><category>Penetration Testing</category></item><item><title>How to Hack an Iranian Nuclear Plant (A Lazy Hacker&apos;s Guide)</title><link>https://www.3lyly0.dev/research/stuxnet-nuclear-hack/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/stuxnet-nuclear-hack/</guid><description>The satirical step-by-step guide nobody asked for, followed by the absolutely wild true story of Stuxnet - the cyber weapon that physically destroyed centrifuges while making the world rethink everything about security. Spoiler: It involves USB sticks, zero-days, and a whole lot of &apos;wait, that actually worked?!&apos;</description><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate><category>Stuxnet</category><category>Cyber Warfare</category><category>SCADA</category><category>Zero-Day</category><category>Industrial Security</category><category>Nation-State Attacks</category></item><item><title>SQL Injection Explained: The Bobby Tables Hall of Fame</title><link>https://www.3lyly0.dev/research/sql-injection/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/sql-injection/</guid><description>A massively detailed, entertaining deep dive into SQL Injection attacks. We&apos;re covering every injection type, real-world breaches that shook the industry, vulnerable code in multiple languages, exploitation techniques from basic to advanced, and bulletproof defense strategies. Plus plenty of jokes because SQL doesn&apos;t have to be boring!</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate><category>SQL Injection</category><category>Web Security</category><category>Database Security</category><category>OWASP</category><category>Penetration Testing</category></item><item><title>CSRF Explained: The Art of Making Users Do Your Bidding Without Their Knowledge</title><link>https://www.3lyly0.dev/research/csrf/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/csrf/</guid><description>The ultimate deep dive into Cross-Site Request Forgery (CSRF). We&apos;re covering the mechanics, attack vectors, real-world breach case studies, exploitation techniques, vulnerable code examples across multiple languages, advanced bypasses, and a comprehensive defense strategy. From basic concepts to advanced mitigation, everything you need to protect your applications.</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate><category>CSRF</category><category>Web Security</category><category>Authentication</category><category>OWASP</category><category>Defensive Security</category></item><item><title>XSS Explained: When Your Website Becomes a Puppet Show</title><link>https://www.3lyly0.dev/research/xss/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/xss/</guid><description>A ridiculously detailed, humor-filled deep dive into Cross-Site Scripting (XSS). We&apos;re talking every flavor of XSS, vulnerable code in all your favorite languages, real-world breaches that made headlines, exploitation techniques, and comprehensive mitigation strategies. Buckle up for a wild ride through the world of malicious scripts!</description><pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate><category>XSS</category><category>Web Security</category><category>JavaScript</category><category>OWASP</category><category>Offensive Security</category></item><item><title>OWASP Top 10: The Wild World of Web App Security Risks!</title><link>https://www.3lyly0.dev/research/owasp-top-ten-2025/</link><guid isPermaLink="true">https://www.3lyly0.dev/research/owasp-top-ten-2025/</guid><description>Buckle up for a super-detailed, hilarious deep dive into the OWASP Top 10. We&apos;re talking explanations that go on forever, code snippets that actually make sense, real-world horror stories, and enough mitigation tips to make your head spin. Oh, and some dad jokes because why not?</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><category>OWASP</category><category>Web Security</category><category>Cybersecurity</category><category>Application Security</category></item></channel></rss>