Archives
All the articles I've archived.
LG webOS TV Zero-Click RCE
A zero-click, unauthenticated LAN remote code execution on LG webOS TVs — chaining an SSG R2R pairing bypass, a privileged browser-to-native bridge, and an unsigned-IPK sideload into OS command execution with no interaction at the TV.
Christmas CTF 2019 / Christmas Pocket
Christmas CTF 2019 Christmas Pocket write-up — recovering the private key of a knapsack-based public-key scheme by working through the key-generation math.
X-MAS CTF 2018 / Santa's List
X-MAS CTF 2018 Santa's List write-up — an RSA chosen-ciphertext attack (CCA) that slips past the decryption filter to recover the flag.
Phishing Analysis for Fun
Reverse-analyzing a secondhand-market phishing site that impersonates Naver — its server layout and the personal data left dangerously exposed.
DEF CON 2019 Quals / RTOoOS
DEF CON 2019 Quals RTOoOS write-up — reversing a custom shell binary that runs on a macOS hypervisor, then abusing malloc's NULL return to plant shellcode at address 0 and bypass the hypercall filter.