Cisco202 CVE-2024-20356: Jailbreaking a Cisco Email Appliance to Run DOOM
Aaron Thacker jailbroke a Cisco C195 ESA by splicing a newer BIOS so CIMC came online, exploiting command injection in expRemoteFwUpdate (CVE-2024-20356)…
Cisco202 Aaron Thacker jailbroke a Cisco C195 ESA by splicing a newer BIOS so CIMC came online, exploiting command injection in expRemoteFwUpdate (CVE-2024-20356)…
Exploit Development430 Every hardware security boundary on a modern x86 platform — SMRAM, the AMD PSP's private DRAM, the C6 save area, the live…
buffer overflow397 A complete hardware-to-firmware walkthrough of the Mercusys MB115-4G, the best-selling router on Amazon Spain: pre-purchase firmware recon, PCB teardown, UART pinout discovery…
Hardware395 Runic Labs dissects a QNAP QTS disclosure cycle — four bugs across three plugins (Notes Station 3, QmailAgent, QVPN) — and shows…
Android330 A complete walkthrough of attaching GDB to a running Android kernel on a physical Pixel 8 via KGDB: USB-Cereal UART wiring, custom…
Android301 Raelize B.V. researchers demonstrated a practical electromagnetic fault injection (EMFI) attack on Google's TV Streamer 4K, corrupting the MT8696 SoC's execution of…
Debug327 A first-principles deep-dive into dumping, analyzing, and patching hard drive firmware: Western Digital custom LZHUF decompression, Samsung SSD deobfuscation, JTAG debugging of…
Apple Silicon357 Apple Silicon's chain of trust hands the XNU kernel an SMMU/IOMMU configuration that iBoot builds once and the OS never re-verifies. An…
Hardware264 Quarkslab's black-box teardown of Xiaomi's undocumented MJA1 secure chip: I2C sniffing, SPI NAND flash dumping, MIPS firmware reverse engineering, full command protocol…
Hardware217 Walk-through of Rasmus Moorats' Pwnd Blaster disclosure: the Creative Sound Blaster Katana V2X soundbar accepts the Creative Transport Protocol over Bluetooth Low…
Hardware163 A BadUSB-ETH device can silently create a rogue network interface on locked PCs, capture NetNTLM hashes, expose real-time logs over Wi-Fi, and…
Cybersecurity236 A deep dive into CVE-2021-21735 on the ZTE ZXHN H168N home gateway, where two unauthenticated wizard endpoints (wizard_pppoe_lua.lua and wizard_wlan_config_lua.lua) leaked PPPoE…