Binary Analysis:
Brief description | Label | |
---|---|---|
GDBleed | Dynamic-Static binary instrumentation framework on top of GDB | gdb, python, binary analysis |
narly.js | narly.js - print binary protections with Windbg JS (/SafeSEH, /GS, ASLR, etc.) | windbg, javascript |
windbg-code-tracing | binary code tracing with windbg python API | windbg, python, binary analysis |
Linux-kernel-forensics-scripts | Scripts i made to perform binary analysis and forensic tasks | gdb, python, linux, r2 |
OSED_scripts | Scripts developed for OSED exam preparation | OSED, python |
IDC_OSED_scripts | IDC plugins to support OSED exam preparation | IDC, IDA |
scheappes.py | heap memory inspection | python, ptmalloc2 |
Vulnerability research & exploit development:
Brief description | Label | |
---|---|---|
Stuff_and_POCs | Containing vulnerabilities I've discovered and maybe CVE | vulnerability research, exploit |
CVE-2020-36109-POC | poc of CVE-2020-36109 | router, asus, DoS |
CVE-2021-20294-POC | poc of CVE-2021-20294 | readelf, overflow |
BFS Ekoparty 2022 challenge | BFS 2022 ekoparty windows challenge writeup | windows, ctf, exploit |
coccinelle_exercises | variant analysis with coccinelle | coccinelle, linux |
CVE-2018-14714-POC | poc of CVE-2018-14714 | asus, rce |
IoT_toolbox | IoT rudimentary tools | iot, tools |
CVE-2023-35086-POC | poc of CVE-2023-35086-POC | router, asus, DoS |
Web3 security:
Brief description | Label | |
---|---|---|
smart_contract_auditor_tool | Tool for doing security checks on smart contracts | slither, solidity, python |
Audits | Smart contract audits that i have done | code audit, solidity |
solidity_CVE-2021-42574-POC | POC of CVE-2021-42574 for solidity and solc compiler | solidity |
Notes & cheatsheets:
Brief description | Label | |
---|---|---|
Becoming a Vulnerability Researcher roadmap: my personal experience | roadmap | vulnerability research |
The Art of Software Security Assessment notes | notes | software analysis |
The Linux Programming Interface notes | notes | C, linux |
"Reverse Engineering 3201: Symbolic Analysis" class notes | notes | python, symbolic execution |
GDB extra tips memo | notes | gdb |
C/C++ and inline assembly notes | notes | c |
Roadmap to learn fuzzing | roadmap | fuzzing |
roadmap to variant analysis | roadmap | software analysis |
roadmap_network-infrastructure_pen_testing.md | roadmap | penetration testing |
roadmap_web_hacking_wapt.md | roadmap | wapt |
roadmap_windows_exploit.md | roadmap | ctf, windows, exploit |
IDAPython cheatsheet | cheatsheet | ida, python |
Radare2 cheatsheet | cheatsheet | r2 |