# exploitation

Published articles for exploitation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## EU chat-control proposal would require messaging services to scan photos and links with AI

DevFeed: [EU chat-control proposal would require messaging services to scan photos and links with AI](<https://devfeed.tech/articles/chatcontrol-edition-2025-en-bref-36280.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/chatcontrol-francais/>)

Published: 2025-08-17T15:15:00Z

Content type: opinion

Language: fr

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Meta](<https://devfeed.tech/topics/meta.md>), [Image](<https://devfeed.tech/topics/image.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [images](<https://devfeed.tech/tags/images.md>), [meta](<https://devfeed.tech/tags/meta.md>), [photos](<https://devfeed.tech/tags/photos.md>), [surveillance](<https://devfeed.tech/tags/surveillance.md>)

### AI overview

The article discusses an EU chat-control proposal, reportedly driven by Denmark and supported by numerous member states, that would require messaging services such as WhatsApp and Signal to use AI to inspect users' photos and links. It says suspected material and associated details could be reported to Europol and local police, while refusal to allow scanning could restrict image and link sharing. The article also notes that Signal has said it would leave the EU if the law were adopted.

### Source excerpt

En bref, sous l'impulsion du Danemark, de nombreux États membres de l'UE demandent que les messageries comme WhatsApp/Signal/etc. soient contraintes d'inspecter toutes nos photos et tous nos liens en utilisant de l'IA. Si l'IA a le moindre "doute" quant à la possibilité qu'il s'agisse de pédopornographie, votre photo, votre localisation, votre numéro de téléphone ainsi que d'autres détails sont signalés à Europol et aux forces de police locales. La suite n'est pas précisée, mais vos vacances à Chypre pourraient se vite se terminer par l'obligation d'expliquer vos photos au poste de police local.

## Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64

DevFeed: [Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64](<https://devfeed.tech/articles/competing-in-pwn2own-ics-2022-miami-exploiting-a-zero-click-remote-memory-corruption-in-iconics-genesis64-39716.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2023/05/05/competing-in-pwn2own-ics-2022-miami-exploiting-a-zero-click-remote-memory-corruption-in-iconics-genesis64/>)

Author: Axel "0vercl0k" Souchet

Published: 2023-05-05T15:00:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [infosec](<https://devfeed.tech/topics/infosec.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [0-click-remote-code-execution](<https://devfeed.tech/tags/0-click-remote-code-execution.md>), [cve-2022-33318](<https://devfeed.tech/tags/cve-2022-33318.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [genbroker64-exe](<https://devfeed.tech/tags/genbroker64-exe.md>), [genesis64](<https://devfeed.tech/tags/genesis64.md>), [iconics](<https://devfeed.tech/tags/iconics.md>), [iconics-genesis64](<https://devfeed.tech/tags/iconics-genesis64.md>), [ics](<https://devfeed.tech/tags/ics.md>), [icsa-22-202-04](<https://devfeed.tech/tags/icsa-22-202-04.md>), [memory](<https://devfeed.tech/tags/memory.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [paracosme](<https://devfeed.tech/tags/paracosme.md>), [pwn2own](<https://devfeed.tech/tags/pwn2own.md>), [pwn2own-2022](<https://devfeed.tech/tags/pwn2own-2022.md>), [pwn2own-miami](<https://devfeed.tech/tags/pwn2own-miami.md>), [remote](<https://devfeed.tech/tags/remote.md>), [zdi-22-1041](<https://devfeed.tech/tags/zdi-22-1041.md>), [zero-click](<https://devfeed.tech/tags/zero-click.md>)

### AI overview

A participant recounts preparing for and demonstrating a winning zero-click remote entry at the 2022 Pwn2Own ICS competition in Miami. The article focuses on exploiting a memory-corruption vulnerability in ICONICS Genesis64 software running on Windows.

### Source excerpt

🧾 Introduction After participating in Pwn2Own Austin in 2021 and failing to land my remote kernel exploit Zenith (which you can read about here), I was eager to try again. It is fun and forces me to look at things I would never have looked at otherwise. The one thing I ...

## Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup

DevFeed: [Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup](<https://devfeed.tech/articles/pwn2own-2021-canon-imageclass-mf644cdw-writeup-39715.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2022/06/11/pwn2own-2021-canon-imageclass-mf644cdw-writeup/>)

Author: Nicolas "NK" Devillers & Jean-Romain "JRomainG" Garnier & Raphaël "\_trou\_" Rigo

Published: 2022-06-11T15:00:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Printer](<https://devfeed.tech/topics/printer.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Load Balancing](<https://devfeed.tech/topics/load-balancing.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [canon](<https://devfeed.tech/tags/canon.md>), [cve-2022-24674](<https://devfeed.tech/tags/cve-2022-24674.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [imageclass](<https://devfeed.tech/tags/imageclass.md>), [macos](<https://devfeed.tech/tags/macos.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [mf644cdw](<https://devfeed.tech/tags/mf644cdw.md>), [printers](<https://devfeed.tech/tags/printers.md>), [pwn2own](<https://devfeed.tech/tags/pwn2own.md>), [pwn2own-austin](<https://devfeed.tech/tags/pwn2own-austin.md>), [research](<https://devfeed.tech/tags/research.md>), [writeup](<https://devfeed.tech/tags/writeup.md>), [zdi-22-516](<https://devfeed.tech/tags/zdi-22-516.md>)

### AI overview

A technical writeup of research targeting the Canon ImageCLASS MF644Cdw printer for Pwn2Own Austin 2021. It describes analyzing the printer's firmware, obtaining firmware downloads, and investigating Canon's firmware URL structure and version availability.

### Source excerpt

Introduction Pwn2Own Austin 2021 was announced in August 2021 and introduced new categories, including printers. Based on our previous experience with printers, we decided to go after one of the three models. Among those, the Canon ImageCLASS MF644Cdw seemed like the most interesting target: previous research was limited (mostly targeting ...

## Competing in Pwn2Own 2021 Austin: Icarus at the Zenith

DevFeed: [Competing in Pwn2Own 2021 Austin: Icarus at the Zenith](<https://devfeed.tech/articles/competing-in-pwn2own-2021-austin-icarus-at-the-zenith-39714.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2022/03/26/competing-in-pwn2own-2021-austin-icarus-at-the-zenith/>)

Author: Axel "0vercl0k" Souchet

Published: 2022-03-26T15:00:00Z

Content type: opinion

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Ghidra](<https://devfeed.tech/topics/ghidra.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Network](<https://devfeed.tech/topics/network.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [archer-c7](<https://devfeed.tech/tags/archer-c7.md>), [competition](<https://devfeed.tech/tags/competition.md>), [cve-2022-24354](<https://devfeed.tech/tags/cve-2022-24354.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [ghidra](<https://devfeed.tech/tags/ghidra.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [netusb](<https://devfeed.tech/tags/netusb.md>), [network](<https://devfeed.tech/tags/network.md>), [pwn2own](<https://devfeed.tech/tags/pwn2own.md>), [pwn2own-austin](<https://devfeed.tech/tags/pwn2own-austin.md>), [remote-kernel](<https://devfeed.tech/tags/remote-kernel.md>), [reverse](<https://devfeed.tech/tags/reverse.md>), [router](<https://devfeed.tech/tags/router.md>), [routers](<https://devfeed.tech/tags/routers.md>), [security](<https://devfeed.tech/tags/security.md>), [tp-link](<https://devfeed.tech/tags/tp-link.md>), [tp-link-archer-c7-v5](<https://devfeed.tech/tags/tp-link-archer-c7-v5.md>), [zenith](<https://devfeed.tech/tags/zenith.md>)

### AI overview

A personal account of preparing for and entering the Pwn2Own 2021 Austin competition. The author describes reverse-engineering consumer router firmware, selecting a router target with teammates, and working toward participation in the contest.

### Source excerpt

Introduction In 2021, I finally spent some time looking at a consumer router I had been using for years. It started as a weekend project to look at something a bit different from what I was used to. On top of that, it was also a good occasion to play ...

## Modern attacks on the Chrome browser : optimizations and deoptimizations

DevFeed: [Modern attacks on the Chrome browser : optimizations and deoptimizations](<https://devfeed.tech/articles/modern-attacks-on-the-chrome-browser-optimizations-and-deoptimizations-39711.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2020/11/17/modern-attacks-on-the-chrome-browser-optimizations-and-deoptimizations/>)

Author: Jeremy "@\_\_x86" Fetiveau

Published: 2020-11-17T08:00:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Chrome](<https://devfeed.tech/topics/chrome.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [V8](<https://devfeed.tech/topics/v8.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>)

Tags: [chrome](<https://devfeed.tech/tags/chrome.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [turbofan](<https://devfeed.tech/tags/turbofan.md>), [v8](<https://devfeed.tech/tags/v8.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article analyzes a security vulnerability in Chrome's V8 JavaScript engine, focusing on how TurboFan's simplified lowering phase mishandles deoptimization-related nodes. The bug can cause incorrect deoptimization data, allowing a fake object to be materialized and execution to continue with an arbitrary object pointer in an accumulator register.

### Source excerpt

Introduction Late 2019, I presented at an internal Azimuth Security conference some work on hacking Chrome through it's JavaScript engine. One of the topics I've been playing with at that time was deoptimization and so I discussed, among others, vulnerabilities in the deoptimizer. For my talk at InfiltrateCon 2020 in ...

## A journey into IonMonkey: root-causing CVE-2019-9810.

DevFeed: [A journey into IonMonkey: root-causing CVE-2019-9810.](<https://devfeed.tech/articles/a-journey-into-ionmonkey-root-causing-cve-2019-9810-39710.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2019/06/17/a-journey-into-ionmonkey-root-causing-cve-2019-9810/>)

Author: Axel "0vercl0k" Souchet

Published: 2019-06-17T15:00:00Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [spidermonkey](<https://devfeed.tech/topics/spidermonkey.md>), [JIT](<https://devfeed.tech/topics/jit.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Assembly](<https://devfeed.tech/topics/assembly.md>), [Mozilla](<https://devfeed.tech/topics/mozilla.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [browser](<https://devfeed.tech/tags/browser.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [ion](<https://devfeed.tech/tags/ion.md>), [ionmonkey](<https://devfeed.tech/tags/ionmonkey.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jit](<https://devfeed.tech/tags/jit.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [spidermonkey](<https://devfeed.tech/tags/spidermonkey.md>)

### AI overview

This article examines the root cause of CVE-2019-9810, an IonMonkey issue in Mozilla's speculative JIT engine. It describes the author's investigation of Ion's codebase, including the issue's alias information and the related AliasAnalysis optimization pass.

### Source excerpt

A journey into IonMonkey: root-causing CVE-2019-9810. Introduction In May, I wanted to play with BigInt and evaluate how I could use them for browser exploitation. The exploit I wrote for the blazefox relied on a Javascript library developed by @5aelo that allows code to manipulate 64-bit integers. Around the same ...

## Circumventing Chrome's hardening of typer bugs

DevFeed: [Circumventing Chrome's hardening of typer bugs](<https://devfeed.tech/articles/circumventing-chrome-s-hardening-of-typer-bugs-39709.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2019/05/09/circumventing-chromes-hardening-of-typer-bugs/>)

Author: Jeremy "\_\_x86" Fetiveau

Published: 2019-05-09T15:00:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [V8](<https://devfeed.tech/topics/v8.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [turbofan](<https://devfeed.tech/tags/turbofan.md>), [v8](<https://devfeed.tech/tags/v8.md>)

### AI overview

This technical article explains how Chrome's TurboFan engine hardened bounds checks against typer bugs and discusses how those bugs can still be exploited in recent V8 versions. It examines the relevant lowering and linearization changes and presents a sample exploit for V8 7.5.0.

### Source excerpt

Introduction Some recent Chrome exploits were taking advantage of Bounds-Check-Elimination in order to get a R/W primitive from a TurboFan's typer bug (a bug that incorrectly computes type information during code optimization). Indeed during the simplified lowering phase when visiting a CheckBounds node if the engine can guarantee that ...

## Introduction to TurboFan

DevFeed: [Introduction to TurboFan](<https://devfeed.tech/articles/introduction-to-turbofan-39708.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2019/01/28/introduction-to-turbofan/>)

Author: Jeremy "\_\_x86" Fetiveau

Published: 2019-01-28T16:00:00Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [JavaScript](<https://devfeed.tech/topics/javascript.md>), [V8](<https://devfeed.tech/topics/v8.md>), [JIT](<https://devfeed.tech/topics/jit.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [compilers](<https://devfeed.tech/topics/compilers.md>), [debug](<https://devfeed.tech/topics/debug.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [bytecode](<https://devfeed.tech/tags/bytecode.md>), [chromium](<https://devfeed.tech/tags/chromium.md>), [compilers](<https://devfeed.tech/tags/compilers.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [introduction](<https://devfeed.tech/tags/introduction.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jit](<https://devfeed.tech/tags/jit.md>), [turbofan](<https://devfeed.tech/tags/turbofan.md>), [v8](<https://devfeed.tech/tags/v8.md>)

### AI overview

A tutorial on V8's TurboFan optimizing JIT compiler. It explains the sea-of-nodes structure, shows how to build V8 and use its d8 shell and Turbolizer, and examines a vulnerable optimization pass from Google's CTF 2018 before developing an exploit.

### Source excerpt

Introduction Ages ago I wrote a blog post here called first dip in the kernel pool, this year we're going to swim in a sea of nodes! The current trend is to attack JavaScript engines and more specifically, optimizing JIT compilers such as V8's TurboFan, SpiderMonkey's IonMonkey, JavaScriptCore's Data ...

## Introduction to SpiderMonkey exploitation.

DevFeed: [Introduction to SpiderMonkey exploitation.](<https://devfeed.tech/articles/introduction-to-spidermonkey-exploitation-39707.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2018/11/19/introduction-to-spidermonkey-exploitation/>)

Author: Axel "0vercl0k" Souchet

Published: 2018-11-19T16:25:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [spidermonkey](<https://devfeed.tech/topics/spidermonkey.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [JIT](<https://devfeed.tech/topics/jit.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [ctf](<https://devfeed.tech/topics/ctf.md>)

Tags: [blazefox](<https://devfeed.tech/tags/blazefox.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [interpreter](<https://devfeed.tech/tags/interpreter.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jit](<https://devfeed.tech/tags/jit.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [payload](<https://devfeed.tech/tags/payload.md>), [spidermonkey](<https://devfeed.tech/tags/spidermonkey.md>), [ttd](<https://devfeed.tech/tags/ttd.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This blog post explains the development of three exploits targeting the SpiderMonkey JavaScript engine and Mozilla Firefox on 64-bit Windows. It progresses from a WinDbg JavaScript extension and a build-specific interpreter exploit to dynamically resolving targets and using the baseline JIT to generate ROP gadgets or native code payloads.

### Source excerpt

Introduction This blogpost covers the development of three exploits targeting SpiderMonkey JavaScript Shell interpreter and Mozilla Firefox on Windows 10 RS5 64-bit from the perspective of somebody that has never written a browser exploit nor looked closely at any JavaScript engine codebase. As you have probably noticed, there has been ...

## CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime.

DevFeed: [CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime.](<https://devfeed.tech/articles/cve-2017-2446-or-jsc-jsglobalobject-ishavingabadtime-39706.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2018/07/14/cve-2017-2446-or-jscjsglobalobjectishavingabadtime/>)

Author: yrp

Published: 2018-07-15T01:49:00Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [WebKit](<https://devfeed.tech/topics/webkit.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2017-2446](<https://devfeed.tech/tags/cve-2017-2446.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [javascriptcore](<https://devfeed.tech/tags/javascriptcore.md>), [jsc](<https://devfeed.tech/tags/jsc.md>), [linux](<https://devfeed.tech/tags/linux.md>)

### AI overview

A technical post describes developing an exploit for the JavaScriptCore engine targeting CVE-2017-2446. It covers the author's background, WebKit exploitation resources, vulnerable-version setup, tooling, and a Linux-based JSC target.

### Source excerpt

Introduction This post will cover the development of an exploit for JavaScriptCore (JSC) from the perspective of someone with no background in browser exploitation. Around the start of the year, I was pretty burnt out on CTF problems and was interested in writing an exploit for something more complicated and ...

## Notes on Unikernels and Memory Corruption Exploitation

DevFeed: [Notes on Unikernels and Memory Corruption Exploitation](<https://devfeed.tech/articles/happy-unikernels-39701.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2016/12/21/happy-unikernels/>)

Author: yrp

Published: 2016-12-22T02:59:00Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Kernel](<https://devfeed.tech/topics/kernel.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [exploitation](<https://devfeed.tech/tags/exploitation.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [networking](<https://devfeed.tech/tags/networking.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [posix](<https://devfeed.tech/tags/posix.md>), [rumpkernel](<https://devfeed.tech/tags/rumpkernel.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [unikernel](<https://devfeed.tech/tags/unikernel.md>)

### AI overview

This article presents notes on unikernels, focusing on how applications can be compiled into a NetBSD-based kernel environment. It uses nginx and php5 examples to discuss memory corruption exploitation and payload options, then introduces a basic rumpkernel "Hello World" build process.

### Source excerpt

Intro Below is a collection of notes regarding unikernels. I had originally prepared this stuff to submit to EkoParty's CFP, but ended up not wanting to devote time to stabilizing PHP7's heap structures and I lost interest in the rest of the project before it was complete. However ...

## Corrupting the ARM Exception Vector Table

DevFeed: [Corrupting the ARM Exception Vector Table](<https://devfeed.tech/articles/corrupting-the-arm-exception-vector-table-39695.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2014/04/30/corrupting-arm-evt/>)

Author: Amat "acez" Cama

Published: 2014-05-01T04:01:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Arm](<https://devfeed.tech/topics/arm.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Exception](<https://devfeed.tech/topics/exception.md>), [Assembly](<https://devfeed.tech/topics/assembly.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [arm](<https://devfeed.tech/tags/arm.md>), [assembly](<https://devfeed.tech/tags/assembly.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [exception](<https://devfeed.tech/tags/exception.md>), [exceptions](<https://devfeed.tech/tags/exceptions.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>)

### AI overview

This article explains how the ARM Exception Vector Table can be abused during Linux kernel exploitation when an attacker has a write-what-where primitive. It covers the table's relationship to exception handlers, processor modes, and banked registers, and introduces local and remote exploit scenarios.

### Source excerpt

Introduction A few months ago, I was writing a Linux kernel exploitation challenge on ARM in an attempt to learn about kernel exploitation and I thought I'd explore things a little. I chose the ARM architecture mainly because I thought it would be fun to look at. This article is ...

## Deep dive into Python's VM: Story of LOAD\_CONST bug

DevFeed: [Deep dive into Python's VM: Story of LOAD\_CONST bug](<https://devfeed.tech/articles/deep-dive-into-python-s-vm-story-of-load-const-bug-39694.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2014/04/17/deep-dive-into-pythons-vm-story-of-load_const-bug/>)

Author: Axel "0vercl0k" Souchet

Published: 2014-04-18T06:22:00Z

Content type: article

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [bug](<https://devfeed.tech/topics/bug.md>), [x86](<https://devfeed.tech/topics/x86.md>), [Code](<https://devfeed.tech/topics/code.md>), [C](<https://devfeed.tech/topics/c.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [c](<https://devfeed.tech/tags/c.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [python](<https://devfeed.tech/tags/python.md>), [virtual-machine](<https://devfeed.tech/tags/virtual-machine.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

A technical deep dive into a known bug in Python 2.7.5's virtual machine. The article explains how the bug can be used to control the virtual processor, instrument the VM, and execute native x86 code, with a focus on Windows.

### Source excerpt

Introduction A year ago, I've written a Python script to leverage a bug in Python's virtual machine: the idea was to fully control the Python virtual processor and after that to instrument the VM to execute native codes. The python27_abuse_vm_to_execute_x86_code.py script wasn't really self-explanatory, so I believe only a ...

## First dip into the kernel pool : MS10-058

DevFeed: [First dip into the kernel pool : MS10-058](<https://devfeed.tech/articles/first-dip-into-the-kernel-pool-ms10-058-39693.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2014/03/11/first-dip-into-the-kernel-pool-ms10-058/>)

Author: Jeremy "\_\_x86" Fetiveau

Published: 2014-03-11T09:52:37Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [exploit](<https://devfeed.tech/tags/exploit.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [integer-overflow](<https://devfeed.tech/tags/integer-overflow.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [kernel-pool](<https://devfeed.tech/tags/kernel-pool.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [ms10-058](<https://devfeed.tech/tags/ms10-058.md>), [poc](<https://devfeed.tech/tags/poc.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [tcpip-sys](<https://devfeed.tech/tags/tcpip-sys.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This tutorial explores a proof-of-concept exploit for the MS10-058 vulnerability in Windows 7 kernel pool memory management. It explains how an integer overflow in tcpip.sys causes an undersized non-paged pool allocation and subsequent pool overflow, based on the author's testing in a Windows 7 32-bit virtual machine.

### Source excerpt

Introduction I am currently playing with pool-based memory corruption vulnerabilities. That's why I wanted to program a PoC exploit for the vulnerability presented by Tarjei Mandt during his first talk "Kernel Pool Exploitation on Windows 7" [3]. I think it's a good exercise to start learning about pool overflows ...

## Adversarial Bandits and the Exp3 Algorithm

DevFeed: [Adversarial Bandits and the Exp3 Algorithm](<https://devfeed.tech/articles/adversarial-bandits-and-the-exp3-algorithm-40333.md>)

Original publisher: [Read original article](<https://www.jeremykun.com/2013/11/08/adversarial-bandits-and-the-exp3-algorithm/>)

Published: 2013-11-08T09:00:40Z

Content type: tutorial

Language: en

Sources: [Jeremy Kun](<https://devfeed.tech/sources/jeremy-kun.md>)

Topics: [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [Learning](<https://devfeed.tech/topics/learning.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [bandit-learning](<https://devfeed.tech/tags/bandit-learning.md>), [bandits](<https://devfeed.tech/tags/bandits.md>), [exp3](<https://devfeed.tech/tags/exp3.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [exploration](<https://devfeed.tech/tags/exploration.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [mathematics](<https://devfeed.tech/tags/mathematics.md>), [multiplicative-weights-update-algorithm](<https://devfeed.tech/tags/multiplicative-weights-update-algorithm.md>), [programming](<https://devfeed.tech/tags/programming.md>), [python](<https://devfeed.tech/tags/python.md>)

### AI overview

This article introduces adversarial bandit learning and explains how the Exp3 algorithm addresses decisions with uncertain outcomes. It contrasts adversarial payoffs with the simpler stochastic setting and frames success relative to the best single action over repeated trials.

### Source excerpt

In the last twenty years there has been a lot of research in a subfield of machine learning called Bandit Learning. The name comes from the problem of being faced with a large sequence of slot machines (once called one-armed bandits) each with a potentially different payout scheme. The problems in this field all focus on one central question: If I have many available actions with uncertain outcomes, how should I act to maximize the quality of my results over many trials?

## Optimism in the Face of Uncertainty: the UCB1 Algorithm

DevFeed: [Optimism in the Face of Uncertainty: the UCB1 Algorithm](<https://devfeed.tech/articles/optimism-in-the-face-of-uncertainty-the-ucb1-algorithm-40332.md>)

Original publisher: [Read original article](<https://www.jeremykun.com/2013/10/28/optimism-in-the-face-of-uncertainty-the-ucb1-algorithm/>)

Published: 2013-10-28T11:42:55Z

Content type: tutorial

Language: en

Sources: [Jeremy Kun](<https://devfeed.tech/sources/jeremy-kun.md>)

Topics: [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [Mathematics](<https://devfeed.tech/topics/mathematics.md>), [Data Science](<https://devfeed.tech/topics/data-science.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [bandit-learning](<https://devfeed.tech/tags/bandit-learning.md>), [bandits](<https://devfeed.tech/tags/bandits.md>), [big-o-notation](<https://devfeed.tech/tags/big-o-notation.md>), [calculus](<https://devfeed.tech/tags/calculus.md>), [confidence-bounds](<https://devfeed.tech/tags/confidence-bounds.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [exploration](<https://devfeed.tech/tags/exploration.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [mathematics](<https://devfeed.tech/tags/mathematics.md>), [programming](<https://devfeed.tech/tags/programming.md>), [python](<https://devfeed.tech/tags/python.md>), [random-variables](<https://devfeed.tech/tags/random-variables.md>), [randomized-algorithm](<https://devfeed.tech/tags/randomized-algorithm.md>), [science](<https://devfeed.tech/tags/science.md>)

### AI overview

This tutorial introduces the multi-armed bandit problem as a model of the exploration-exploitation tradeoff and presents the UCB1 algorithm, which the article describes as performing close to optimally.

### Source excerpt

startups The software world is always atwitter with predictions on the next big piece of technology. And a lot of chatter focuses on what venture capitalists express interest in. As an investor, how do you pick a good company to invest in? Do you notice quirky names like "Kaggle" and "Meebo," require deep technical abilities, or value a charismatic sales pitch? When it comes to innovation in software engineering and computer science, and that as a society we should value big pushes forward much more than we do.