This is your work, valued

Altin (tin-z)

Expert
@tin-z

insecurity researcher || life &﹥ /dev/null;

GDBleed. Dynamic-Static binary instrumentation framework on top of GDB

50

CVE-2023-35086-POC. POC of CVE-2023-35086 only DoS

44

CVE-2025-27363. Integer overflow in FreeType software, which also affects Chrome

31

Stuff_and_POCs. Containing vulnerabilities I've discovered and maybe CVE

19

narly.js. narly.js - print binary protections with Windbg JS (/SafeSEH, /GS, ASLR, etc.)

15

CVE-2021-20294-POC. Simple CVE-2021-20294 poc

11

heapwn_Cheatsheet. A repository that contains some memo about heap exploitation in Linux

9

OSED_scripts. Scripts developed for OSED exam preparation

9

IDC_OSED_scripts. IDC plugins to support OSED exam preparation, some of the scripts are simplified port of devttyS0 IDAPython plugins

9

pthC. Framework analysis assembly code by Intel processor trace

9

IoT_toolbox. Rudimentary tools for vulnerability research and reverse engineering tasks for IoT routers

8

windbg-code-tracing. Pykd script to perform simple code tracing and so inspecting control flow executed (CFE).

8

smart_contract_auditor_tool. Python

7

Linux-kernel-forensics-scripts. Gdb, r2, python scripts i made to perform binary analysis and forensic tasks.

7

CVE-2018-14714-POC. POC CVE-2018-14714

6

coccinelle_exercises. coccinelle notes and exercises

5

solidity_CVE-2021-42574-POC. POC of CVE-2021-42574 for solidity and solc compiler

3

mY_Writ3_Up5. CTF & security related write-ups done by me

3

kvm-fuzz. PoC of fuzzing closed-source userspace binaries with KVM

2

toolbox_python. Helper functions in python exploiting python internals

2

malware-naming. Malware naming convention

2

tin-z.

2

report_BFS_ekoparty_2022_exploitation_challenges. BFS 2022 ekoparty windows challenge writeup

2

Useful-bash-aliases-and-functions. List of useful bash aliases and functions that i made during work

2

Audits. My personal smart contract findings during code audit sessions

2

CVE-2020-36109-POC. PoC DoS CVE-2020-36109

2

Windows-stuffs. Win32

1

qemu_blog. A series of posts about QEMU internals:

1

nvram-faker. C

1

tin-z.github.io. The Lambda driver blog

1

PartitionAlloc_gdb. Python

1

intro-to-semgrep. TypeScript

1

pino_obfuscator. C

1

codeql-uboot. CodeQL

1

fahook. A simple script that using angr aims to reach and avoid some section of code and hook others. "Usefull" for RE

1

AppliedMathForSecurityBook. Jupyter Notebook

1

yarb. 方便获取每日安全资讯的爬虫和推送程序

1

upgradeable-proxy-from-scratch. Code from "Upgradeable proxy contract from scratch" blog post

1

coccinelleforrust_personal_mirror. https://gitlab.inria.fr/coccinelle/coccinelleforrust

1

hardhat-tracer. 🕵️ allows you to see internal calls, events and storage operations in the console

1

general-scripts. Python

1

vr-rev-jobs. List of organizations offering vulnerability research, reverse engineering, and security research jobs

1