2022-07-18 Analyze .NET deserialization: TypeConfuseDelegate gadget chain with BinaryFormatter .net,c#, deserialization research IntroductionTypeConfuseDelegate is a gadget chain take advantage of SortedSet class calls the comparator class to sort w
2022-06-06 CVE-2022-26134: A look into bypass isSafeExpression check in Confluence Preauth RCE 0day, cve-2022-26134 research Reference https://pulsesecurity.co.nz/articles/EL-Injection-WAF-Bypass https://www.rapid7.com/blog/post/2022/06/02/activ
2022-04-22 WSO2 Carbon Server: Pre-auth RCE bug ( CVE-2022-29464) 0day, cve-2022-29464 research IntroductionCVE-2022-29464 is a simple and critical vulnerability reported by Orange Tsai, the vulnerability is a pre-au
2022-03-25 Analyze Java deserialization: CommonsCollections2 gadget chain ( part 2 ) java, deserialization research Introduction - CommonsCollections2 gadget chain analysisTo continue part 1, we will analyze CommonsCollections2 gadget c
2022-01-19 Analyze Java deserialization: CommonsCollections5 gadget chain ( part 1 ) java, deserialization research IntroductionMost of people have heard about Java deserialization apocalypse. There are great tools out there for hunting
2021-12-11 Apache Log4j RCE 0day: CVE-2021-44228 0day, log4j, cve-2021-44228 research Reference: https://www.lunasec.io/docs/blog/log4j-zero-day/ https://www.veracode.com/blog/research/exploiting-jndi-inje
2021-09-27 DownUnder CTF 2021 - Attacking AES ECB mode - Break Me challenge Crypto research IntroductionDownUnder CTF was an awesome event, I enjoyed it a lot. Unfortunately I’m not Australian so I cannot join a
2021-09-01 A look into CVE-2021-26084 Confluence RCE CVE-2021-26084, Web Security research OGNL Injection on Confluence Twitter is always the best place to keep up-to-date with the newest CVE or exploit. CVE-202
2021-08-16 My journey to reproduce the Proxyshell exploit chain (reported by Orange Tsai) research ProxyShell Microsoft ExchangeReference: The original talk is from Orange Tsai: https://i.blackhat.com/USA21/Wednesday-