Posts in Zero Day Research

Zero-Day Research: ehttp Use-after-Free and Out-of-Bounds Read

The ehttp library advertises itself as a ‘simple HTTP server based on epoll’. The primary goal of[…]

Zero-Day Research: PicoC Version 3.2.2 Null Pointer Dereference (CVE-2022-34556) Speedrun

PicoC is a miniature code interpreter developed for C scripting. According to their documentation, PicoC was first[…]

Zero-Day Research: md2roff Version 1.7 Buffer Overflow (CVE-2022-34913)

The best part about security research is the myriad of ways you can find bugs. Sometimes bugs[…]

Zero-Day Research: Mechanical Keyboard Finder Version 4.31

Introduction In this edition of Zero-Day Research, I happen to come across a DOM-based Cross Site Scripting Vulnerability[…]

Defcon 27: Hacking the Badge

What did we do? We made modifications to the DEFCON27 Badge and turned it into a ‘Jackp0t’[…]

Zero-Day Research: Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers

Background As technology continues to advance and more devices become networked together, new vulnerabilities will inevitably rise[…]