corCTF2023-sysruption赛题复现 不知道说什么,放一段作者的话:Sysruption was a hardware, micro-architectural, and kernel exploitation challenge Sysruption was a hardware, micro-architectural, and kernel exploitation challenge I wrote for corCTF 20 2024-05-23 CTFwp #PWN #Linux #Kernel #Syscall
Paper:Cross Container Attacks:The Bewildered eBPF on Clouds 一.介绍eBPF,即扩展的伯克利过滤数据包,起初的版本bpf仅是为了用来实现包过滤的功能,但现在逐渐发展成一个顶级模块,可以极大的将用户可操作性拓展到内核,用户可以通过一系列eBPF程序和其中内核提供的bpf帮助函数来构造钩子甚至通过写rootkit来提升自己的安全水平( 当然凡是也有两面性,在eBPF极大的给予用户自由性的同时,他的安全性也有待考证,论文中提到了一些极度危险的eBPF帮助函数,至 2024-02-26 #Paper
corCTF2022-corjail赛题复现 Players were asked to escape from a hardened Docker container with custom seccomp filters exploiting a Off-By-Null vulnerability in a Linux Kernel Module accessible via procfs. Let’s get started! 2024-01-08 CTFwp #PWN #Linux #Kernel #docker escape
CVE-2016-5195漏洞复现 In fact, all the boring normal bugs are _way_ more important, just because there's a lot more of them. I don't think some spectacular security hole should be glorified or cared about as being any more 2024-01-07 CVE #PWN #Linux #Kernel
CVE-2022-0185漏洞复现 九山八海、为一世界,聚千界则成“小千世界”,此界乘三,无我不断者,三刀流奥义·一大‧三千‧大千‧世界! 2023-10-10 CVE #PWN #Linux #Kernel
羊城杯部分赛题复现 2023羊城杯部分赛题复现shellcode12345678910111213141516171819202122232425262728293031323334353637383940unsigned __int64 __fastcall vuln(const char *a1){ int v2; // [rsp+14h] [rbp-3Ch] void **buf; // [rsp 2023-09-14 CTFwp #PWN #CTF
Linux_Kernel_SLUB分配器 缩小或消除冲突。《文明小史.第一回》:「他见我们地方官以礼相待,就是有点需索便也不好十分需索,能够大事化小,小事化无。」也作「大事化小,小事化了。」、「大事化为小事,小事化为无事。」 2023-07-18 Linux Kernel #Linux #kernel #source