56,966 blogs · [ { "id": "01a0e50c-5205-727f-8fee-442a72d8fe27", "title": "Exploiting a Windows 10 PagedPool off-by-one overflow (WCTF 2018)", "url": "https://j00ru.vexillium.org/2018/07/exploiting-a-windows-10-pagedpool-off-by-one/", "published_at": "2018-07-18T11:23:25+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a739ae499", "title": "Wrapping up the kernel infoleak research with a whitepaper", "url": "https://j00ru.vexillium.org/2018/07/wrapping-up-the-kernel-infoleak-research/", "published_at": "2018-07-10T09:59:01+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a7407354b", "title": "Announcing Bochspwn Reloaded and my REcon Montreal 2017 slides", "url": "https://j00ru.vexillium.org/2017/06/announcing-bochspwn-reloaded-and-my-recon-montreal-2017-slides/", "published_at": "2017-06-20T16:14:58+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a74c062b8", "title": "Windows Kernel Local Denial-of-Service #5: win32k!NtGdiGetDIBitsInternal (Windows 7-10)", "url": "https://j00ru.vexillium.org/2017/04/windows-kernel-local-denial-of-service-5/", "published_at": "2017-04-24T09:39:26+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a754433d4", "title": "Windows Kernel Local Denial-of-Service #4: nt!NtAccessCheck and family (Windows 8-10)", "url": "https://j00ru.vexillium.org/2017/04/windows-kernel-local-denial-of-service-4/", "published_at": "2017-04-03T10:59:46+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a757e8402", "title": "Windows Kernel Local Denial-of-Service #3: nt!NtDuplicateToken (Windows 7-8)", "url": "https://j00ru.vexillium.org/2017/03/windows-kernel-local-denial-of-service-3/", "published_at": "2017-03-07T15:34:35+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a75f93370", "title": "Windows Kernel Local Denial-of-Service #2: win32k!NtDCompositionBeginFrame (Windows 8-10)", "url": "https://j00ru.vexillium.org/2017/02/windows-kernel-local-denial-of-service-2/", "published_at": "2017-02-27T14:49:32+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a769dd18c", "title": "Windows Kernel Local Denial-of-Service #1: win32k!NtUserThunkedMenuItemInfo (Windows 7-10)", "url": "https://j00ru.vexillium.org/2017/02/windows-kernel-local-denial-of-service-1/", "published_at": "2017-02-22T16:24:23+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a778d9337", "title": "Slides about my Windows Metafile research and fuzzing now public", "url": "https://j00ru.vexillium.org/2016/11/slides-about-my-windows-metafile-research-and-fuzzing-now-public/", "published_at": "2016-11-15T14:12:22+00:00" }, { "id": "01a0e50c-5205-727f-8fee-442a77b999fa", "title": "Windows system call tables updated, refreshed and reworked", "url": "https://j00ru.vexillium.org/2016/08/windows-system-call-tables-updated-refreshed-and-reworked/", "published_at": "2016-08-15T13:07:11+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a478398fb6", "title": "Disclosing stack data (stack frames, GS cookies etc.) from the default heap on Windows", "url": "https://j00ru.vexillium.org/2016/07/disclosing-stack-data-from-the-default-heap-on-windows/", "published_at": "2016-07-25T09:29:02+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a478a7af98", "title": "Windows user-mode exploitation trick – refreshing the main process heap", "url": "https://j00ru.vexillium.org/2016/07/windows-user-mode-exploitation-trick-refreshing-the-main-process-heap/", "published_at": "2016-07-12T09:53:51+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a479a52172", "title": "Details on a (not so recent now) stack-based buffer overflow in the Adobe CFF rasterizer in FreeType2 (CVE-2014-2240, CVE-2014-9659)", "url": "https://j00ru.vexillium.org/2016/06/details-on-a-stack-based-buffer-overflow-in-the-adobe-cff-rasterizer-in-freetype2/", "published_at": "2016-06-07T13:53:14+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47a0efb74", "title": "44CON slides and details about further Windows kernel font vulnerabilities", "url": "https://j00ru.vexillium.org/2015/09/44con-slides-and-details-about-further-windows-kernel-font-vulnerabilities/", "published_at": "2015-09-17T10:17:25+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47a8ccf7a", "title": "Results of my recent PostScript Charstring security research unveiled", "url": "https://j00ru.vexillium.org/2015/06/results-of-my-recent-postscript-charstring-security-research-unveiled/", "published_at": "2015-06-23T18:38:51+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47b42f0d8", "title": "Insomni’hack 2015, presentation slide deck and CTF results", "url": "https://j00ru.vexillium.org/2015/03/insomnihack-2015-presentation-slide-deck-and-ctf-results/", "published_at": "2015-03-24T18:48:28+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47c1d6656", "title": "SECURE 2014 slide deck and Hex-Rays IDA Pro advisories published", "url": "https://j00ru.vexillium.org/2014/10/secure-2014-slide-deck-and-hex-rays-ida-pro-advisories-published/", "published_at": "2014-10-23T12:32:55+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47c8d5441", "title": "CONFidence 2014 slides from Dragon Sector are now available", "url": "https://j00ru.vexillium.org/2014/05/confidence-2014-slides-from-dragon-sector/", "published_at": "2014-05-29T10:07:24+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47cd8d8df", "title": "A case of a curious LibTIFF 4.0.3 + zlib 1.2.8 memory disclosure", "url": "https://j00ru.vexillium.org/2014/04/a-case-of-a-curious-libtiff-4-0-3-zlib-1-2-8-memory-disclosure/", "published_at": "2014-04-30T14:23:21+00:00" }, { "id": "01a0e51d-536a-73f6-9968-33a47d1a2311", "title": "FFmpeg and a thousand fixes", "url": "https://j00ru.vexillium.org/2014/01/ffmpeg-and-the-tale-of-a-thousand-fixes/", "published_at": "2014-01-10T16:44:13+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e4631506bd7d", "title": "Windows System Call and CSR API tables updated", "url": "https://j00ru.vexillium.org/2013/11/windows-system-call-and-csr-api-tables-updated/", "published_at": "2013-11-16T17:31:13+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e4631547bf95", "title": "ZeroNights 2013 and NTVDM vulnerabilities", "url": "https://j00ru.vexillium.org/2013/11/zeronights-2013-and-ntvdm-vulnerabilities/", "published_at": "2013-11-08T10:00:53+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46315759bad", "title": "Windows win32k.sys menus and some “close, but no cigar” bugs", "url": "https://j00ru.vexillium.org/2013/09/windows-win32k-sys-menus-and-some-close-but-no-cigar-bugs/", "published_at": "2013-09-12T20:04:26+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46315f154c5", "title": "Black Hat USA 2013, Bochspwn, slides and pointers", "url": "https://j00ru.vexillium.org/2013/08/black-hat-usa-2013-bochspwn-slides-and-pointers/", "published_at": "2013-08-13T23:17:27+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46316c6398c", "title": "Approaching BlackHat US 2013 and new Dragon Sector blog", "url": "https://j00ru.vexillium.org/2013/07/approaching-blackhat-and-new-dragon-sector-blog/", "published_at": "2013-07-24T15:04:25+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46316e5a63e", "title": "Changing the cursor shape in Windows proven difficult by NVIDIA (and AMD)", "url": "https://j00ru.vexillium.org/2013/07/changing-the-cursor-shape-in-windows-proven-difficult-by-nvidia-and-amd/", "published_at": "2013-07-01T12:22:49+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46317871abe", "title": "Kernel double-fetch race condition exploitation on x86 – further thoughts", "url": "https://j00ru.vexillium.org/2013/06/kernel-double-fetch-race-condition-exploitation-on-x86-further-thoughts/", "published_at": "2013-06-17T12:04:41+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46317883281", "title": "CONFidence 2013 and the x86 quirks", "url": "https://j00ru.vexillium.org/2013/06/confidence-2013-and-the-x86-quirks/", "published_at": "2013-06-02T13:52:18+00:00" }, { "id": "01a0e52a-b848-7090-9f04-e46318011677", "title": "NoSuchCon’13 and crashing Windows with two instructions", "url": "https://j00ru.vexillium.org/2013/05/nosuchcon13-and-crashing-windows-with-two-instructions/", "published_at": "2013-05-22T01:57:19+00:00" }, { "id": "01a0e52a-b849-7101-96d6-78ea2b21133e", "title": "SyScan 2013, Bochspwn paper and slides", "url": "https://j00ru.vexillium.org/2013/05/syscan-2013-bochspwn-paper-and-slides/", "published_at": "2013-05-02T18:53:36+00:00" }, { "id": "01a0e540-d4ed-72de-8269-77458f2b77fc", "title": "A story of win32k!cCapString, or unicode strings gone bad", "url": "https://j00ru.vexillium.org/2013/04/a-story-of-win32k-ccapstring-or-unicode-strings-gone-bad/", "published_at": "2013-04-16T14:24:21+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774590178157", "title": "Fun facts: Windows kernel and guard pages", "url": "https://j00ru.vexillium.org/2013/04/fun-facts-windows-kernel-and-guard-pages/", "published_at": "2013-04-13T01:36:38+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774590425319", "title": "PDF Fuzzing Fun Continued: Status Update", "url": "https://j00ru.vexillium.org/2013/01/pdf-fuzzing-fun-continued-status-update/", "published_at": "2013-01-09T00:54:18+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774590874c63", "title": "CVE-2012-2553: Windows Kernel VDM use-after-free in win32k.sys", "url": "https://j00ru.vexillium.org/2012/12/cve-2012-2553-windows-kernel-vdm-use-after-free-in-win32k-sys/", "published_at": "2012-12-18T21:21:47+00:00" }, { "id": "01a0e540-d4ed-72de-8269-7745915463be", "title": "Defeating Windows Driver Signature Enforcement #3: The Ultimate Encounter", "url": "https://j00ru.vexillium.org/2012/12/defeating-windows-driver-signature-enforcement-part-3-the-ultimate-encounter/", "published_at": "2012-12-10T09:03:09+00:00" }, { "id": "01a0e540-d4ed-72de-8269-77459226e03f", "title": "ZeroNights slides, Hack In The Box Magazine #9 and other news", "url": "https://j00ru.vexillium.org/2012/12/zeronights-slides-hack-in-the-box-magazine-9-and-other-news/", "published_at": "2012-12-01T11:49:09+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774592881ed3", "title": "Crawling MSDN for fun and profit", "url": "https://j00ru.vexillium.org/2012/11/crawling-msdn-for-fun-and-profit/", "published_at": "2012-11-16T19:41:54+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774592e0cad0", "title": "Defeating Windows Driver Signature Enforcement #2: CSRSS and thread desktops", "url": "https://j00ru.vexillium.org/2012/11/defeating-windows-driver-signature-enforcement-part-2-csrss-and-thread-desktops/", "published_at": "2012-11-10T03:08:33+00:00" }, { "id": "01a0e540-d4ed-72de-8269-77459315ffd0", "title": "Defeating Windows Driver Signature Enforcement #1: default drivers", "url": "https://j00ru.vexillium.org/2012/11/defeating-windows-driver-signature-enforcement-part-1-default-drivers/", "published_at": "2012-11-04T01:48:56+00:00" }, { "id": "01a0e540-d4ed-72de-8269-774593864a9b", "title": "Introducing the USB Stick of Death", "url": "https://j00ru.vexillium.org/2012/10/introducing-the-usb-stick-of-death/", "published_at": "2012-10-21T16:00:13+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96d11a216", "title": "Nullcon 2012 CTF", "url": "https://j00ru.vexillium.org/2012/09/nullcon-2012-ctf/", "published_at": "2012-09-17T05:53:20+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96d4a0a7b", "title": "Fun facts: Windows kernel and Device Extension Size", "url": "https://j00ru.vexillium.org/2012/09/fun-facts-windows-kernel-and-device-extension-size/", "published_at": "2012-09-15T21:47:17+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96e2f2410", "title": "PDF fuzzing and Adobe Reader 9.5.1 and 10.1.3 multiple critical vulnerabilities", "url": "https://j00ru.vexillium.org/2012/08/pdf-fuzzing-and-adobe-reader-9-5-1-and-10-1-3-multiple-critical-vulnerabilities/", "published_at": "2012-08-14T17:36:12+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96ef19ae2", "title": "ATmega328 (Arduino Uno compatible) MD5 optimized assembly implementation", "url": "https://j00ru.vexillium.org/2012/07/atmega328-arduino-uno-compatible-md5-optimized-assembly-implementation/", "published_at": "2012-07-23T21:59:25+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96ef2a4f6", "title": "CVE-2011-2018 exploitation as a standalone paper + other news", "url": "https://j00ru.vexillium.org/2012/05/cve-2011-2018-exploitation-as-a-standalone-paper-other-news/", "published_at": "2012-05-20T13:37:11+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96f33d795", "title": "Hack in the Box Magazine #8 available now", "url": "https://j00ru.vexillium.org/2012/04/hack-in-the-box-magazine-8-available-now/", "published_at": "2012-04-11T22:07:23+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96f583cda", "title": "A Bug Hunter’s Diary review", "url": "https://j00ru.vexillium.org/2012/01/a-bug-hunters-diary-review/", "published_at": "2012-01-17T18:57:59+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a96fce4ab8", "title": "FYI: Printable “Windows Kernel Address Protection” paper out", "url": "https://j00ru.vexillium.org/2011/12/printable-windows-kernel-address-protection-paper-out/", "published_at": "2011-12-04T12:02:49+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a9708d2b57", "title": "Magus Ex Machina – a product of a 48h codejam", "url": "https://j00ru.vexillium.org/2011/11/magus-ex-machina-a-product-of-a-48h-codejam/", "published_at": "2011-11-20T16:42:08+00:00" }, { "id": "01a0e55e-905e-7331-91c8-98a970ded773", "title": "Refreshed Windows System Call Table (NT/2000/XP/2003/Vista/2008/7/8) released", "url": "https://j00ru.vexillium.org/2011/11/refreshed-windows-system-call-table-released/", "published_at": "2011-11-18T12:04:13+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09acfe4d501", "title": "Hack in the Box Magazine #7 on the wild, at last", "url": "https://j00ru.vexillium.org/2011/10/hack-in-the-box-magazine-7-on-the-wild-at-last/", "published_at": "2011-10-19T14:30:46+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad0ddaeec", "title": "PiXiEServ out for public", "url": "https://j00ru.vexillium.org/2011/10/pixieserv-out-for-public/", "published_at": "2011-10-08T12:55:48+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad152c434", "title": "Windows 8 Syscall Interface and Export Table diffing fun", "url": "https://j00ru.vexillium.org/2011/09/windows-8-syscall-interface-and-export-table-diffing-fun/", "published_at": "2011-09-21T16:42:31+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad1f61834", "title": "0-day Windows XP SP3 Denial of Service (CSRSS Crash)", "url": "https://j00ru.vexillium.org/2011/08/0-day-windows-xp-sp3-denial-of-service-csrss-crash/", "published_at": "2011-08-03T20:23:38+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad2a8a8d7", "title": "CVE-2011-1282: User-Mode NULL Pointer Dereference & co.", "url": "https://j00ru.vexillium.org/2011/07/cve-2011-1282-user-mode-null-pointer-dereference/", "published_at": "2011-07-21T16:22:44+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad355cfe9", "title": "CVE-2011-1281: A story of a Windows CSRSS Privilege Escalation vulnerability", "url": "https://j00ru.vexillium.org/2011/07/cve-2011-1281-a-story-of-a-windows-csrss-privilege-escalation-vulnerability/", "published_at": "2011-07-12T17:54:58+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad35dcb9e", "title": "PE Import Table and custom DLL paths", "url": "https://j00ru.vexillium.org/2011/07/pe-import-table-and-custom-dll-paths/", "published_at": "2011-07-03T19:27:28+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad3c77093", "title": "Protected Mode Segmentation as a powerful anti-debugging measure", "url": "https://j00ru.vexillium.org/2011/06/protected-mode-segmentation-as-a-powerful-anti-debugging-measure/", "published_at": "2011-06-18T22:54:50+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad4c1ebba", "title": "The HITB Magazine #6 now available!", "url": "https://j00ru.vexillium.org/2011/06/the-hitb-magazine-6-now-available/", "published_at": "2011-06-13T07:25:08+00:00" }, { "id": "01a0e570-6b16-71d6-91e5-e09ad5a75607", "title": "How to crash EXPLORER.EXE on all Windows versions", "url": "https://j00ru.vexillium.org/2011/06/how-to-crash-explorer-exe-on-all-windows-versions/", "published_at": "2011-06-12T18:24:29+00:00" } ] posts Claim your blog
Back to j00ru.vexillium.org
Blog · corpus.blog/blogs/j00ru.vexillium.org/posts

j00ru.vexillium.org

j00ru.vexillium.org

2018

2017

2016

2015

2014

2013

2012

2011