41554 blogs · [ { "id": "01a087e3-ecb3-70e2-9564-2bd6c23b9ea0", "title": "Negative-Days with Vulnerability Spoiler Alert: Three Months Later", "url": "https://spaceraccoon.dev/negative-days-vulnerability-spoiler-alert/", "published_at": "2026-05-24T00:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c2676839", "title": "Discovering Vulnerabilities in Enterprise Audiovisual Hardware", "url": "https://spaceraccoon.dev/discovering-vulnerabilities-enterprise-audiovisual-hardware/", "published_at": "2026-05-01T00:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c2cbee60", "title": "Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653)", "url": "https://spaceraccoon.dev/getting-shell-tapo-c260-webcam/", "published_at": "2026-03-06T08:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c34d9da5", "title": "Discovering Negative-Days with LLM Workflows", "url": "https://spaceraccoon.dev/discovering-negative-days-llm-workflows/", "published_at": "2026-02-07T00:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c3ed2562", "title": "Ticket Tricking OpenSSL.org with Google Groups", "url": "https://spaceraccoon.dev/ticket-trick-openssl-google-groups/", "published_at": "2026-02-02T12:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c4d4bbf2", "title": "Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2", "url": "https://spaceraccoon.dev/reverse-engineer-tapo-c260-tdp-v2/", "published_at": "2026-01-02T00:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c53b759f", "title": "Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling", "url": "https://spaceraccoon.dev/nokia-beacon-router-uart-command-injection/", "published_at": "2025-10-13T00:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c5b1943a", "title": "Escaping the Matrix: Client-Side Deanonymization Attacks on Privacy Sandbox APIs", "url": "https://spaceraccoon.dev/client-side-deanonymization-attacks-privacy-sandbox-apis/", "published_at": "2025-08-17T12:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c5e4739a", "title": "Getting a Shell on the LAU-G150-C Optical Network Terminal", "url": "https://spaceraccoon.dev/getting-shell-lau-g150-c-optical-network-terminal/", "published_at": "2025-07-27T12:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c6147546", "title": "Cybersecurity (Anti)Patterns: Frictionware", "url": "https://spaceraccoon.dev/cybersecurity-antipatterns-frictionware/", "published_at": "2025-06-12T11:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c6ad74fd", "title": "Cybersecurity (Anti)Patterns: Busywork Generators", "url": "https://spaceraccoon.dev/cybersecurity-antipatterns-busywork-generators/", "published_at": "2025-04-19T00:01:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c79e0106", "title": "Pwning Millions of Smart Weighing Machines with API and Hardware Hacking", "url": "https://spaceraccoon.dev/pwning-millions-smart-weighing-machines-api-hardware-hacking/", "published_at": "2025-03-24T00:03:05+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c7a3c916", "title": "Universal Code Execution by Chaining Messages in Browser Extensions", "url": "https://spaceraccoon.dev/universal-code-execution-browser-extensions/", "published_at": "2024-07-07T12:01:06+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c80f0437", "title": "Cache Me If You Can: Local Privilege Escalation in Zscaler Client Connector (CVE-2023-41973)", "url": "https://spaceraccoon.dev/zscaler-client-connector-local-privilege-escalation/", "published_at": "2024-05-27T12:01:06+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c8a9e3cf", "title": "Back to the (Clip)board with Microsoft Whiteboard and Excalidraw in Meta (CVE-2023-26140)", "url": "https://spaceraccoon.dev/clipboard-microsoft-whiteboard-excalidraw-meta/", "published_at": "2024-02-04T05:01:06+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c9293033", "title": "Hacking HP Display Monitors via Monitor Control Command Set (CVE-2023-5449)", "url": "https://spaceraccoon.dev/hacking-display-monitors-monitor-command-control-set/", "published_at": "2023-10-31T05:01:06+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c95143d1", "title": "Passing the New OSEE Exam After Forgetting Everything", "url": "https://spaceraccoon.dev/awe-osee-exam/", "published_at": "2023-10-07T06:47:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6c9cb0b30", "title": "Rule Writing for CodeQL and Semgrep", "url": "https://spaceraccoon.dev/comparing-rule-syntax-codeql-semgrep/", "published_at": "2023-04-08T16:14:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6ca839ce8", "title": "I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS", "url": "https://spaceraccoon.dev/analyzing-clipboardevent-listeners-stored-xss/", "published_at": "2022-12-17T15:29:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cb29f4f5", "title": "Challendar: Creating a Challenge for The Infosecurity Challenge 2022", "url": "https://spaceraccoon.dev/challendar-creating-challenge-infosecurity-challenge-2022/", "published_at": "2022-09-19T00:40:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cb6e3086", "title": "Exploiting Improper Validation of Amazon Simple Notification Service SigningCertUrl", "url": "https://spaceraccoon.dev/exploiting-improper-validation-amazon-simple-notification-service/", "published_at": "2022-08-29T14:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cbbe17fe", "title": "You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications", "url": "https://spaceraccoon.dev/exploiting-icalendar-properties-enterprise-applications/", "published_at": "2022-08-18T00:45:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cbc9cb6f", "title": "Embedding Payloads and Bypassing Controls in Microsoft InfoPath", "url": "https://spaceraccoon.dev/embedding-payloads-bypassing-controls-microsoft-infopath/", "published_at": "2022-06-18T10:00:00+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cbdb9be4", "title": "Solving DOM XSS Puzzles", "url": "https://spaceraccoon.dev/solving-dom-xss-puzzles/", "published_at": "2022-02-03T00:05:45+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cc83d65d", "title": "2Q21: New Year's Reflections", "url": "https://spaceraccoon.dev/2q21-new-years-reflections/", "published_at": "2021-12-31T10:24:09+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cd704574", "title": "The InfoSecurity Challenge 2021 Full Writeup: Battle Royale for $30k", "url": "https://spaceraccoon.dev/the-infosecurity-challenge-2021-full-writeup-battle-royale-for-30k/", "published_at": "2021-11-26T03:32:20+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6ce01c651", "title": "All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646)", "url": "https://spaceraccoon.dev/all-your-d-base-are-belong-to-us-part-2-code-execution-in-microsoft-office/", "published_at": "2021-10-22T11:43:10+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6ce6f47ad", "title": "All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021-33035)", "url": "https://spaceraccoon.dev/all-your-d-base-are-belong-to-us-part-1-code-execution-in-apache-openoffice/", "published_at": "2021-09-29T03:35:58+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cee624c1", "title": "Down the Rabbit Hole: Unusual Applications of OpenAI in Cybersecurity Tooling", "url": "https://spaceraccoon.dev/down-the-rabbit-hole-unusual-applications-of-openai-in-cybersecurity-tooling/", "published_at": "2021-09-17T13:16:55+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cf310b5f", "title": "ROP and Roll: EXP-301 Offensive Security Exploit Developer (OSED) Review and Exam", "url": "https://spaceraccoon.dev/rop-and-roll-exp-301-offensive-security-exploit-development-osed-review-and/", "published_at": "2021-06-23T15:21:40+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6cfeaa88c", "title": "Life's a Peach (Fuzzer): How to Build and Use GitLab's Open-Source Protocol Fuzzer", "url": "https://spaceraccoon.dev/lifes-a-peach-fuzzer-how-to-build-and-use-gitlabs-open-source-protocol/", "published_at": "2021-05-22T03:08:55+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d097ed96", "title": "Offensive Security Experienced Penetration Tester (OSEP) Review and Exam", "url": "https://spaceraccoon.dev/offensive-security-experienced-penetration-tester-osep-review-and-exam/", "published_at": "2021-03-11T09:40:44+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d0b7d805", "title": "Applying Offensive Reverse Engineering to Facebook Gameroom", "url": "https://spaceraccoon.dev/applying-offensive-reverse-engineering-to-facebook-gameroom/", "published_at": "2021-02-02T17:03:30+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d13da9cc", "title": "Supply Chain Pollution: Hunting a 16 Million Download/Week npm Package Vulnerability for a CTF Challenge", "url": "https://spaceraccoon.dev/supply-chain-pollution-hunting-a-16-million-download-week-npm-package/", "published_at": "2020-12-23T15:29:57+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d19ebce4", "title": "Imposter Alert: Extracting and Reversing Metasploit Payloads (Flare-On 2020 Challenge 7)", "url": "https://spaceraccoon.dev/imposter-alert-extracting-and-reversing-metasploit-payloads-flare-on-2020/", "published_at": "2020-12-03T13:04:53+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d2949b4f", "title": "Beat The Clock: The CSIT InfoSecurity Challenge", "url": "https://spaceraccoon.dev/beat-the-clock-the-csit-infosecurity-challenge/", "published_at": "2020-09-18T03:44:44+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d2ae0a3d", "title": "Open Sesame: Escalating Open Redirect to RCE with Electron Code Review", "url": "https://spaceraccoon.dev/open-sesame-escalating-open-redirect-to-rce-with-electron-code-review/", "published_at": "2020-08-14T11:43:43+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d3276e49", "title": "Closing the Loop: Practical Attacks and Defences for GraphQL APIs", "url": "https://spaceraccoon.dev/closing-the-loop-practical-attacks-and-defences-for-graphql-apis/", "published_at": "2020-05-15T13:37:11+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d4087a5d", "title": "Same Same But Different: Discovering SQL Injections Incrementally with Isomorphic SQL Statements", "url": "https://spaceraccoon.dev/same-same-but-different-discovering-sql-injections-incrementally-with/", "published_at": "2020-04-05T09:04:58+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d4e28863", "title": "A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell", "url": "https://spaceraccoon.dev/a-tale-of-two-formats-exploiting-insecure-xml-and-zip-file-parsers-to-create-a/", "published_at": "2020-02-18T06:02:34+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d560df9f", "title": "Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2", "url": "https://spaceraccoon.dev/remote-code-execution-in-three-acts-chaining-exposed-actuators-and-h2-database/", "published_at": "2020-01-12T23:15:18+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d5c9e219", "title": "Low-Hanging Apples: Hunting Credentials and Secrets in iOS Apps", "url": "https://spaceraccoon.dev/low-hanging-apples-hunting-credentials-and-secrets-in-ios-apps/", "published_at": "2019-12-29T14:58:40+00:00" }, { "id": "01a087e3-ecb3-70e2-9564-2bd6d6a38073", "title": "From checkra1n to Frida: iOS App Pentesting Quickstart on iOS 13", "url": "https://spaceraccoon.dev/from-checkra1n-to-frida-ios-app-pentesting-quickstart-on-ios-13/", "published_at": "2019-12-15T15:41:06+00:00" } ] posts Claim your blog
Back to spaceraccoon.dev
Blog · corpus.blog/blogs/spaceraccoon.dev/posts

spaceraccoon.dev

spaceraccoon.dev

2026

2025

2024

2023

2022

2021

2020

2019