My Blog

Through the Wall: a kernel UAF turned into a Dirty Pipe-style write

kernelexploitationuse-after-free

File Stream Oriented Programming (FSOP) exploitation: House of Apple 2 through a heap FILE overflow

binary-exploitationfsopheap-exploitation

Browser Exploit Design Course Review (Zero Day Engineering)

browserexploit-developmenttraining

Apple CVE-2026-43666: Out-of-Bounds Write in mDNSResponder

CVE-2026-43666

Forcing glibc to Hand You the Flag: Tcache Saturation, Three-Way Consolidation, and a UAF

binary-exploitationheap-exploitationglibcuaf

Became OSCE3 - OffSec Certified Expert 3

certificationexploit-developmentoffsec

Obtained OSED - Windows User Mode Exploit Development

certificationwindows exploit devoffsec

Linux Kernel Exploitation: KASLR bruteforce and Overwriting modprobe_path to gain root privileges

kernelmodprobe_pathexploitation

Linux Kernel Exploitation: Heap Overflow & SMEP/SMAP Bypass using commit_creds(&init_cred)

kernelexploitationheap

Passed the Certified Android Exploit Developer course & exam - Mobile Hacking Lab

androidexploit-developmentcertification

Hacking the Heap: The Data-Only Heap Overflow

binary-exploitationheap-exploitationheap-overflow

1st and 3rd place at SnakeCTF - Italy

ctfhackingsnakeCTF

Format String GOT Overwrite Attack: From Printf to System Shell

binary-exploitationformat-stringgot-overwrite

ret2plt: ASLR Bypass via PLT/GOT Leak

binary-exploitationret2pltgot-leak

ASLR Bypass with Libc given leak: Breaking Address Randomization

binary-exploitationaslr-bypassinformation-leak

ret2libc ROP Attack (No ASLR): Reusing Library Functions

binary-exploitationret2libcropintermediate

PIE Exploitation with Address Leak: Defeating Position Independence

binary-exploitationpieaslr-bypass

Stack Canary Bypass with Format String Leak

binary-exploitationstack-canaryformat-string

ROP Chain Without Memory Leak: Return-Oriented Programming

binary-exploitationropintermediate

Format String Vulnerability: Reading Memory Without Buffers

binary-exploitationformat-stringinformation-disclosure

Shellcode Injection Buffer Overflow: Beyond ret2win

binary-exploitationbuffer-overflowshellcode

Basic ret2win Buffer Overflow: Your First Stack Smashing

binary-exploitationbuffer-overflowbeginner

Hacking the Nexxt Solutions NCM-X1800 router: Four CVEs and exploits

CVE-2025-52376CVE-2025-52377CVE-2025-52378CVE-2025-52379

Exploiting Arbitrary Write via .fini_array in a ropchain

exploitdevroppwn

Fuzzing TCPdump with AFL++ to recreate CVE-2017-13028

fuzzingtcpdumpafl++

Trust your gut when it comes to git: Hiding backdoors in .git files

malwaregitvscode

Event Spoofing in EVM Chains: How Smart Contract Events Can Create Deceptive Transaction Records

blockchainspoofawareness

1st place at EHGN (Ethical Hackers Groep Nederland) CTF - The Netherlands

ctfhacking

Homoglyph Attacks: Confusing Characters to Obfuscate Logic

exploitshomoglyphsbackdoor

Creating an Invisible Unicode Hangul Filler Backdoor in web applications

unicodebackdoorweb

Exploiting delegatecall vulnerabilities in smart contracts

ethereumdelegatecallsmartcontract

Zero-Knowledge Proofs: Prove Your Bank Balance Without Revealing It

zkproofethereumcryptography

Writing Custom Shellcode in Assembly for Windows x86 (Finding Kernel32.dll)

windowsassemblyshellcode

Guest Podcast Thuis In IT (Dutch)

podcastthuis-inn-it

Bypassing ASLR and DEP using WriteProcessMemory

exploit developmentwindowswriteprocessmemory

ASLR and DEP bypass using VirtualAlloc

exploit developmentwindowsvirtualalloc

Android SSL Pinning Bypass

androidsslbypass

Manipulating the Blockchain for Fun and (NOT) for Profit

blockchainethereumsolidity

Stack Pivoting to leaking libc in limited stack space

ropchainstackpivotlibc

Creating a backdoor through APT sources

linuxaptbackdoor

Leaking libc through puts@got with ROPchains

exploit developmentlibcrop

Stealing Browser History: Exploiting CSS Timing Side-Channels with requestAnimationFrame

cssbrowserprivacy

Your Browser Leaks More Than You Think

webbrowserprivacy

Leverage XSS Impact with Capturing Photos and Videos

webxssvideo&photo

Prepared Statement Bypass in NodeJS MySQL

webmysqlbypass

Race against the machine: exploiting race conditions in coupons

webrace-conditionsexploit

Stealing Secrets from internal Web Pages from XSS through command injection

webxsscommand injection

MongoDB Injection (NoSQL) with Mongoose

webmongodbnosql

ImageMath PIL PoC - CVE-2022-22817 | Amidst Us (HTB)

webexploitspil

SQLi to Python Pickle Deserialization RCE | C.O.P (HTB)

webdeserializationsqli

Markdown XSS to Cache Poisoning through Directory Traversal

webxsscache

Bypassing CSP through jsDelivr

webexploitscsp

Manipulating iframes dynamically PoC

webexploitsiframes

Prototype Pollution in PugJS

webnodejsrce

Hiding Malware in SVG's: A new Threat to NFTs (DUTCH)

malwarenftsecurity

File Inclusion Cheat Sheet

webcheatsheetlfi

Circumventing DEP on x86 Windows

exploitswindowsdep

Deploying ERC-20 Tokens on Starknet with Caïro

blockchainsmartcontractscairo

Chainhunters - Criminal Blockchain Investigation

blockchaininvestigationchainhunters

Crypto Crime Training

blockchainsecuritytraining

Development of custom blockchain tokens and smart contracts at cryptomaker.nl

blockchainsmartcontractsweb3

Ethical hacking specialist at tozetta.com

pentestingsecurityconsulting

Hacking Smart Contracts and Exploiting Vulnerabilities on the Blockchain

blockchainsmartcontractssecurity

1st place at Hack The Hague - The Netherlands

ctfhackingsnakeCTF