41554 blogs · [ { "id": "01a0e6d6-6d89-7370-9014-96d1c7de2361", "title": "Virtualizor: The Login Parameter That Skips the Login", "url": "https://chocapikk.com/posts/2026/virtualizor-billing-hook-unauthenticated-root-rce/", "published_at": "2026-09-25T00:00:00+00:00" }, { "id": "01a08d26-efeb-7307-b67e-2d9423709693", "title": "FileRun: Four More Ways to Run Your Files", "url": "https://chocapikk.com/posts/2026/filerun-delegated-admin-sql-to-object-injection-rce/", "published_at": "2026-09-10T00:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3362929d", "title": "Inside BitAIM+: Reverse Engineering a Commercial Carrom Pool Cheat", "url": "https://chocapikk.com/posts/2026/bitaim-carrom-pool-cheat-reverse-engineering/", "published_at": "2026-09-05T18:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3415a2f0", "title": "FileRun: When Your File Manager Runs Your Files", "url": "https://chocapikk.com/posts/2026/filerun-thumbnail-command-injection-rce/", "published_at": "2026-08-14T00:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3422dbe5", "title": "Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys", "url": "https://chocapikk.com/posts/2026/aimy-captcha-less-form-guard-object-injection/", "published_at": "2026-07-31T00:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3476e2f7", "title": "Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists", "url": "https://chocapikk.com/posts/2026/monstaftp-ssrf-ipv6-blocklist-bypass/", "published_at": "2026-07-14T00:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e34e4410a", "title": "NVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in Inference API", "url": "https://chocapikk.com/posts/2026/gen3c-pickle-rce/", "published_at": "2026-07-06T00:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e35e3c094", "title": "FOSSBilling: One Missing throw - From Auth Bypass to Unauthenticated RCE", "url": "https://chocapikk.com/posts/2026/fossbilling-unauth-rce/", "published_at": "2026-07-05T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e36992cb8", "title": "CVE-2026-29514: NetBox Jinja2 Sandbox Bypass to RCE via RenderTemplateMixin environment_params", "url": "https://chocapikk.com/posts/2026/netbox-export-template-rce/", "published_at": "2026-04-30T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e375d2a5b", "title": "Unauthenticated RCE in OpenCATS via Installer Config Injection", "url": "https://chocapikk.com/posts/2026/opencats-installer-rce/", "published_at": "2026-04-27T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e37fa460d", "title": "CVE-2026-26210: ktransformers Unauthenticated RCE via Pickle Deserialization in ZMQ Scheduler", "url": "https://chocapikk.com/posts/2026/ktransformers-pickle-rce/", "published_at": "2026-04-22T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e380b8796", "title": "CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer", "url": "https://chocapikk.com/posts/2026/lerobot-pickle-rce/", "published_at": "2026-04-22T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e382de472", "title": "Microsoft tensorwatch: Local Code Execution via Pickle Deserialization in ZMQ Listener", "url": "https://chocapikk.com/posts/2026/tensorwatch-pickle-rce/", "published_at": "2026-04-22T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e383a61e1", "title": "Instagram's 'Seen' Is a Lie — And They're About to Charge You for the Proof", "url": "https://chocapikk.com/posts/2026/instagram-seen-is-a-lie/", "published_at": "2026-04-17T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e38fe1bea", "title": "How to Start Contributing to Metasploit: Field Notes from 68 Modules", "url": "https://chocapikk.com/posts/2026/contributing-to-metasploit/", "published_at": "2026-04-16T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e39153d3a", "title": "Your .swp Files Are Telling on You: A Git Forensics Guide", "url": "https://chocapikk.com/posts/2026/swap-files-in-git/", "published_at": "2026-04-15T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e39505538", "title": "CeWL Is Dead. Here's What Replaces It.", "url": "https://chocapikk.com/posts/2026/cewlai-ai-powered-wordlist-generator/", "published_at": "2026-04-13T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e396e5c62", "title": "Xboard / V2Board: Magic Link Token Leak - Unauthenticated Account Takeover", "url": "https://chocapikk.com/posts/2026/xboard-v2board-account-takeover/", "published_at": "2026-04-08T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3a098b74", "title": "Dumping PostgreSQL Without Credentials: Heap File Parsing for Offensive Security", "url": "https://chocapikk.com/posts/2026/dumping-postgresql-without-credentials/", "published_at": "2026-04-06T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3a8723aa", "title": "Windfall: From Path Traversal to RCE in Nextcloud Flow & Windmill", "url": "https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/", "published_at": "2026-04-06T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3ad8e488", "title": "From Zero to Exploit Dev: What Actually Worked", "url": "https://chocapikk.com/posts/2026/from-zero-to-exploit-dev/", "published_at": "2026-04-03T08:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3bb9885a", "title": "How I Added PTY Support to Busybox Shells (When Everyone Said It Was Impossible)", "url": "https://chocapikk.com/posts/2026/pwncat-busybox-pty/", "published_at": "2026-04-01T21:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3c38f286", "title": "Reverse Engineering the ITE 8910 Keyboard RGB Protocol for OpenRGB", "url": "https://chocapikk.com/posts/2026/reverse-engineering-ite8910-keyboard-rgb/", "published_at": "2026-03-26T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3c5d9860", "title": "OmniGen2: Unauthenticated RCE via Pickle Deserialization in BAAI's Reward Server", "url": "https://chocapikk.com/posts/2026/omnigen2-pickle-rce/", "published_at": "2026-03-17T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3c7488be", "title": "sglang: Unauthenticated RCE via Pickle Deserialization in ZMQ Transport (Disaggregated Serving)", "url": "https://chocapikk.com/posts/2026/sglang-pickle-rce/", "published_at": "2026-03-17T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3cb9b28c", "title": "openDCIM: From SQL Injection to RCE via Config Poisoning", "url": "https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/", "published_at": "2026-02-26T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3d1daa1a", "title": "CVE-2026-27743 through CVE-2026-27747: Five Vulnerabilities in SPIP Plugins", "url": "https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/", "published_at": "2026-02-24T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3d75cef7", "title": "CVE-2025-71243: AI-Assisted Reversal of SPIP Saisies RCE in 30 Minutes", "url": "https://chocapikk.com/posts/2026/spip-saisies-rce/", "published_at": "2026-02-18T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3e2e534b", "title": "MajorDoMo Revisited: What I Missed in 2023", "url": "https://chocapikk.com/posts/2026/majordomo-revisited/", "published_at": "2026-02-17T23:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3e7c4842", "title": "Android's AccessibilityService: A Single Toggle to Total Device Control", "url": "https://chocapikk.com/posts/2026/android-a11y-god-mode/", "published_at": "2026-02-15T01:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3ed3eb21", "title": "LightLLM: Unauthenticated RCE via Pickle Deserialization in WebSocket Endpoints", "url": "https://chocapikk.com/posts/2026/lightllm-pickle-rce/", "published_at": "2026-02-11T01:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3f77a170", "title": "manga-image-translator: Unauthenticated RCE via Pickle Deserialization with Nonce Bypass", "url": "https://chocapikk.com/posts/2026/manga-image-translator-pickle-rce/", "published_at": "2026-02-10T23:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e3ff174ed", "title": "How Internet Scanners Actually Work: The 'Passive' Scanning Myth", "url": "https://chocapikk.com/posts/2026/how-internet-scanners-work/", "published_at": "2026-02-08T01:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e40577102", "title": "From Zero to Shell: Hunting Critical Vulnerabilities in AVideo", "url": "https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/", "published_at": "2025-12-18T22:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4061cc71", "title": "Streama Path Traversal + SSRF: Chaining Vulnerabilities for Arbitrary File Write", "url": "https://chocapikk.com/posts/2025/streama-path-traversal-ssrf/", "published_at": "2025-12-18T16:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e40e9422d", "title": "Setting Up Giscus: An Ad-Free Alternative to Disqus for Blog Comments", "url": "https://chocapikk.com/posts/2025/setting-up-giscus-comments/", "published_at": "2025-11-14T12:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e416fddc4", "title": "When a Wi-Fi SSID Gives You Root on an MT02 Repeater – Part 2", "url": "https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root-part-two/", "published_at": "2025-08-06T12:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e41985773", "title": "When a Wi-Fi SSID Gives You Root on an MT02 Repeater", "url": "https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root/", "published_at": "2025-08-03T12:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e428fda48", "title": "Multiple Vulnerabilities in Xorcom CompletePBX 5.2.35: RCE, File Disclosure and XSS", "url": "https://chocapikk.com/posts/2025/completepbx/", "published_at": "2025-06-22T02:04:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e437fbccc", "title": "Patchstack WCEU CTF – Open Contributions", "url": "https://chocapikk.com/posts/2025/patchstack-open-contributions/", "published_at": "2025-06-05T19:30:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4459e8bd", "title": "Helping Friends Learn Cybersecurity: Lessons from Teaching Beginners", "url": "https://chocapikk.com/posts/2025/helping-friends-cybersecurity/", "published_at": "2025-05-23T12:30:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e454ac381", "title": "Vembu BDRSuite: Unauth XSS, Weird Endpoints and Silent Patches (≤ 7.5.0.1)", "url": "https://chocapikk.com/posts/2025/bdrsuite/", "published_at": "2025-04-15T17:00:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4609b7c9", "title": "WPProbe: A Pragmatic Approach to Detecting WordPress Plugins", "url": "https://chocapikk.com/posts/2025/wpprobe/", "published_at": "2025-04-12T19:13:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4644065d", "title": "Two Stored XSS in MagnusBilling: From CTF Curiosity to CVEs", "url": "https://chocapikk.com/posts/2025/magnusbilling/", "published_at": "2025-03-21T16:30:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4708a524", "title": "How I Got Hacked: A Warning about Malicious PoCs", "url": "https://chocapikk.com/posts/2025/s1nk/", "published_at": "2025-02-07T12:35:21+00:00" }, { "id": "01a0875e-f390-7052-8869-132e47d0ab33", "title": "Wikimedia/svgtranslate 2.0.1 Remote Code Execution", "url": "https://chocapikk.com/posts/2024/svgtranslate/", "published_at": "2024-05-23T13:43:51+00:00" }, { "id": "01a0875e-f390-7052-8869-132e48393c3d", "title": "Exploring Mocodo Vulnerabilities: A Compilation of CVEs from 2024", "url": "https://chocapikk.com/posts/2024/mocodo-vulnerabilities/", "published_at": "2024-05-09T11:10:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e48838f1f", "title": "Exploring AVideo Vulnerabilities: A Deep Dive into CVE-2024-31819", "url": "https://chocapikk.com/posts/2024/cve-2024-31819/", "published_at": "2024-04-09T18:35:21+00:00" }, { "id": "01a0875e-f390-7052-8869-132e48d54e34", "title": "Exploring DerbyNet Vulnerabilities: A Compilation of CVEs from 2024", "url": "https://chocapikk.com/posts/2024/derbynet-vulnerabilities/", "published_at": "2024-04-03T18:35:21+00:00" }, { "id": "01a0875e-f390-7052-8869-132e48ef65c4", "title": "CVE-2023-50917", "url": "https://chocapikk.com/posts/2023/cve-2023-50917/", "published_at": "2023-12-18T08:49:15+00:00" }, { "id": "01a0875e-f390-7052-8869-132e490ecc99", "title": "n00bzCTF 2023 - Conditions", "url": "https://chocapikk.com/posts/2023/n00bzctf2023-conditions/", "published_at": "2023-06-11T16:55:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e49958ef4", "title": "n00bzCTF 2023 - EZrev", "url": "https://chocapikk.com/posts/2023/n00bzctf2023-ezrev/", "published_at": "2023-06-11T16:55:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e49c1db32", "title": "n00bzCTF 2023 - MyPin", "url": "https://chocapikk.com/posts/2023/n00bzctf2023-mypin/", "published_at": "2023-06-11T16:55:00+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4a15856c", "title": "tjCTF 2023 - Gish", "url": "https://chocapikk.com/posts/2023/tjctf2023-gish/", "published_at": "2023-05-28T00:02:50+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4ad33713", "title": "FCSC 2023 - Lapin Blanc", "url": "https://chocapikk.com/posts/2023/fcsc2023-lapin-blanc/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4b711396", "title": "FCSC 2023 - UID", "url": "https://chocapikk.com/posts/2023/fcsc2023-uid/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4c2e5815", "title": "FCSC 2023 - Zéro Pointé", "url": "https://chocapikk.com/posts/2023/fcsc2023-zero-pointe/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4c8523d4", "title": "FCSC 2023 - ENISA Flag Store 1/2", "url": "https://chocapikk.com/posts/2023/fcsc2023-enisa-flag-store-1/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4cc8753b", "title": "TamuCTF 2023 - Connect", "url": "https://chocapikk.com/posts/2023/tamuctf2023-connect/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4cf30f55", "title": "TamuCTF 2023 - Gamer Redux", "url": "https://chocapikk.com/posts/2023/tamuctf2023-gamer-redux/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4dda3857", "title": "TamuCTF 2023 - Logical", "url": "https://chocapikk.com/posts/2023/tamuctf2023-logical/", "published_at": "2023-04-30T20:36:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4ea8463c", "title": "CAF 2023 - Babyrev", "url": "https://chocapikk.com/posts/2023/caf2023-babyrev/", "published_at": "2023-04-18T19:02:57+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4ee61691", "title": "CAF 2023 - Tower of Encryption", "url": "https://chocapikk.com/posts/2023/caf2023-tower-of-encryption/", "published_at": "2023-04-18T12:22:07+00:00" }, { "id": "01a0875e-f390-7052-8869-132e4fc27c43", "title": "CAF 2023 - IT Administrator Credentials", "url": "https://chocapikk.com/posts/2023/caf2023-it-administrator-credentials/", "published_at": "2023-04-18T11:42:57+00:00" }, { "id": "01a0875e-f390-7052-8869-132e5010b98b", "title": "CAF 2023 - I Warn You", "url": "https://chocapikk.com/posts/2023/caf2023-i-warn-you/", "published_at": "2023-04-18T10:27:28+00:00" }, { "id": "01a0875e-f390-7052-8869-132e50639745", "title": "CAF 2023 - Baby Hacker Big Brother", "url": "https://chocapikk.com/posts/2023/caf2023-baby-hacker-big-brother/", "published_at": "2023-04-17T17:46:48+00:00" }, { "id": "01a0875e-f390-7052-8869-132e50e18e1f", "title": "IDOR Vulnerability: Explanation, Exploitation, and Prevention", "url": "https://chocapikk.com/posts/2023/faille_idor/", "published_at": "2023-04-07T15:40:43+00:00" }, { "id": "01a0875e-f390-7052-8869-132e51ad0b14", "title": "Using Python Sockets for Offensive Security", "url": "https://chocapikk.com/posts/2023/utilisation_socket_python/", "published_at": "2023-04-07T07:37:40+00:00" }, { "id": "01a0875e-f390-7052-8869-132e52423991", "title": "Upload Vulnerabilities: Understanding, Exploiting, and Fixing", "url": "https://chocapikk.com/posts/2023/faille_upload/", "published_at": "2023-04-05T14:21:38+00:00" }, { "id": "01a0875e-f390-7052-8869-132e528587a3", "title": "Privilege Escalation on Unix Systems via Crontab", "url": "https://chocapikk.com/posts/2023/elevation_privileges_unix_crontab/", "published_at": "2023-04-04T14:06:19+00:00" }, { "id": "01a0875e-f390-7052-8869-132e52bfdcef", "title": "What is a Command Injection?", "url": "https://chocapikk.com/posts/2023/injection_de_commande/", "published_at": "2023-04-04T13:20:38+00:00" }, { "id": "01a0875e-f390-7052-8869-132e52cd4604", "title": "Configuring an Apache Server with SSL/TLS Hardening", "url": "https://chocapikk.com/posts/2023/configurer_un_serveur_apache/", "published_at": "2023-04-03T14:52:33+00:00" }, { "id": "01a0875e-f390-7052-8869-132e532c619e", "title": "Creating a Shodan Dork Using MMH3 Hash", "url": "https://chocapikk.com/posts/2023/creer_un_dork_shodan/", "published_at": "2023-04-03T12:55:21+00:00" }, { "id": "01a0875e-f390-7052-8869-132e535fc3b7", "title": "Oteria Cyber Cup 2022", "url": "https://chocapikk.com/posts/2022/oteria_cyber_cup_2022/", "published_at": "2023-04-03T12:52:19+00:00" } ] posts Claim your blog
Back to chocapikk.com
Blog · corpus.blog/blogs/chocapikk.com/posts

chocapikk.com

chocapikk.com

2026

2025

2024

2023