This is your work, valued
GDBleed. Dynamic-Static binary instrumentation framework on top of GDB
50CVE-2023-35086-POC. POC of CVE-2023-35086 only DoS
44CVE-2025-27363. Integer overflow in FreeType software, which also affects Chrome
31Stuff_and_POCs. Containing vulnerabilities I've discovered and maybe CVE
19narly.js. narly.js - print binary protections with Windbg JS (/SafeSEH, /GS, ASLR, etc.)
15CVE-2021-20294-POC. Simple CVE-2021-20294 poc
11heapwn_Cheatsheet. A repository that contains some memo about heap exploitation in Linux
9OSED_scripts. Scripts developed for OSED exam preparation
9IDC_OSED_scripts. IDC plugins to support OSED exam preparation, some of the scripts are simplified port of devttyS0 IDAPython plugins
9pthC. Framework analysis assembly code by Intel processor trace
9IoT_toolbox. Rudimentary tools for vulnerability research and reverse engineering tasks for IoT routers
8windbg-code-tracing. Pykd script to perform simple code tracing and so inspecting control flow executed (CFE).
8smart_contract_auditor_tool. Python
7Linux-kernel-forensics-scripts. Gdb, r2, python scripts i made to perform binary analysis and forensic tasks.
7CVE-2018-14714-POC. POC CVE-2018-14714
6coccinelle_exercises. coccinelle notes and exercises
5solidity_CVE-2021-42574-POC. POC of CVE-2021-42574 for solidity and solc compiler
3mY_Writ3_Up5. CTF & security related write-ups done by me
3kvm-fuzz. PoC of fuzzing closed-source userspace binaries with KVM
2toolbox_python. Helper functions in python exploiting python internals
2malware-naming. Malware naming convention
2tin-z.
2report_BFS_ekoparty_2022_exploitation_challenges. BFS 2022 ekoparty windows challenge writeup
2Useful-bash-aliases-and-functions. List of useful bash aliases and functions that i made during work
2Audits. My personal smart contract findings during code audit sessions
2CVE-2020-36109-POC. PoC DoS CVE-2020-36109
2Windows-stuffs. Win32
1qemu_blog. A series of posts about QEMU internals:
1nvram-faker. C
1tin-z.github.io. The Lambda driver blog
1PartitionAlloc_gdb. Python
1intro-to-semgrep. TypeScript
1pino_obfuscator. C
1codeql-uboot. CodeQL
1fahook. A simple script that using angr aims to reach and avoid some section of code and hook others. "Usefull" for RE
1AppliedMathForSecurityBook. Jupyter Notebook
1yarb. 方便获取每日安全资讯的爬虫和推送程序
1upgradeable-proxy-from-scratch. Code from "Upgradeable proxy contract from scratch" blog post
1coccinelleforrust_personal_mirror. https://gitlab.inria.fr/coccinelle/coccinelleforrust
1hardhat-tracer. 🕵️ allows you to see internal calls, events and storage operations in the console
1general-scripts. Python
1vr-rev-jobs. List of organizations offering vulnerability research, reverse engineering, and security research jobs
1