Skip to main content
  1. Tags/

Pwn

2025


[TALK] gpg.fail

Lexi and I gave a talk about vulnerabilities in PGP implementations and related software. Find writeups and recordings on gpg.fail. Slides are here. The impacts reach from chancing the content of signed messages without access to the private key, over tricking a user into decrypting data of the attacker’s choice, to memory corruption in the ASCII-armor decoder.

2024


2023


BH-MEA Profile GOT overwrite

This is a writeup of an easy/medium pwn challenge called “Profile” featuring a type confusion, some GOT overwriting, and a funny but unnecessary one gadget exploit for the fun of it.

[TALK] Introduction to V8 JIT Compilation

A talk by ju256 and me about Chrome V8 internals with some case studies of common bugs. While the slides are okay to look at, there is a fair bit of context missing without the audio track. Maybe we will give the talk in a similar form somewhere where it is recorded in the future.