Freat - writing a game hacking birdfeeder for fun and...fun24 February 2026·3924 words·19 minsFrida Game-Hacking GodotCan we mash together frida, Python and Godot to write an ugly CheatEngine clone and learn more about game hacking?
Modding and distributing mobile apps with frida23 October 2025·1713 words·9 minsFrida MobileWalkthrough of how to embed frida scripts in apps to distribute proper mods. Supports frida 17+.
A journey from `sudo` iptables to local privilege escalation ↗ ↖20 September 2024External Linux PrivescYou’ve landed on a network appliance and you need those fancy privileges? Don’t worry, I’ve got your back!
AlcaWASM challenge writeup - Pwning an in-browser Lua interpreter12 September 2024·4521 words·22 minsWriteup Pwn Wasm LuaGamedevs of the world, unite! Your favourite language is in danger – the l33t wrongdoers have figured out how to BYOB (Bring Your Own Bytecode) and pwn the Lua v5.4 interpreter!
Element Android CVE-2024-26131, CVE-2024-26132 - Never take intents from strangers ↗ ↖18 April 2024External 0day AndroidWild trips with intent redirections to compromise an end-to-end encrypted messaging chat.
Hunting for (Un?)authenticated n-days in Asus routers ↗ ↖30 January 2024External Nday PwnFirmware analysis, reverse engineering and binary exploitation shenanigans on Asus routers.
CVE-2023-33466 - Exploiting healthcare servers with polyglot files ↗ ↖23 October 2023External NdayN-day exploit for Orthanc. Now featuring polyglot files!
IceCTF 2018 - Twitter writeup15 September 2018·698 words·4 minsPwn CtfYou can play 8-bit emulators if you want, but isn’t it pwning them more fun?
IceCTF 2018 - Fermat string writeup14 September 2018·1483 words·7 minsPwn CtfHow much space do you need to exploit a format string?
GSoC 2018 - Final report10 August 2018·687 words·4 minsCoding GsocRecap of my experience in the Google Summer of Code with mitmproxy
GSoC week 3....4 - Passing the exam7 June 2018·668 words·4 minsCoding GsocWeek 3 and 4 of hacking at mitmproxy for the Google Summer of Code
GSoC week 2 - The quest for performances23 May 2018·677 words·4 minsCoding GsocWeek 2 of hacking at mitmproxy with the Google Summer of Code
GSoC week 1 - Staging15 May 2018·803 words·4 minsCoding GsocWeek 1 of hacking at mitmproxy with the Google Summer of Code