|
You are here |
www.jaybosamiya.com | ||
| | | | |
faraz.faith
|
|
| | | | | ||
| | | | |
y4y.space
|
|
| | | | | Some Background Info CVE-2021-38001 is reported on TianFu Cup 2021. This bug exploits a type confusion issue happened in V8's inline cache and can result in remote code execution. In my last V8 pwn blog, I analyzed and reproduced CVE-2020-6507. Its root cause is an OOB read/write issue happened in V8's JIT phase. But to... | |
| | | | |
roundofthree.github.io
|
|
| | | | | This blog post will analyse the exploitability of the temporal safety vulnerabilities in Nginx AIxCC. AIxCC is a DARPA competition to find vulnerabilities in codebases using AI. The competitors are not looking for 0-days but rather intentionally added vulnerabilities in existing codebases. One of them was Nginx in the semifinals, which already took place. In this blog post, I will have a different focus on whether these added vulnerabilities can be exploited to achieve more than just crashes. | |
| | | | |
jnsgr.uk
|
|
| | | A short blog post explaining how I replaced a proprietary wireless temperature monitor for my hot tub, with a simple ESP32 based micro-controller and a cheap bluetooth pool thermometer, all linked up with Home Assistant. | ||