Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Why ORMs and Prepared Statements Can't (Always) Win- 1470

Thomas Chauchefoin - Sonar SourcePosted 1 Year Ago

Threshold Transaction Malleability Bugfix Review- 1469

Immunefi - KayabaPosted 1 Year Ago

Ambush Attacks on 160-bit Object IDs and Addresses- 1468

Mysten labsPosted 1 Year Ago

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! - 1467

Orange Tsai Posted 1 Year Ago

0.0.0.0 Day: Exploiting Localhost APIs From the Browser- 1466

Avi Lumelsky - Oligo SecurityPosted 1 Year Ago

Bypassing Rockwell Automation Logix Controllers’ Local Chassis Security Protection- 1465

Sharon Brizinov - Team82Posted 1 Year Ago

Listen to the whispers: web timing attacks that actually work - 1464

James Kettle - PortSwiggerPosted 1 Year Ago

Beyond TCP's 65535 Byte Limit- 1463

Flatt Security - RyotaKPosted 1 Year Ago

Evmos Precompile State Commit Infinite Mint- 1462

Jason MattyserPosted 1 Year Ago

Abusing Subtle C++ Destructor Behavior for a UAF- 1461

Jack Dates - RET2Posted 1 Year Ago