Syst3m Failure
  • Home
  • Research
  • CTF
  • Various
  • About
D3v17

D3v17

6 posts •
Ctf Research

[corCTF 2022] CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel

CoRJail is a kernel exploitation / Docker escape challenge designed for corCTF 2022. Players were asked to escape from a hardened Docker container with custom seccomp filters exploiting a Off-By-Null vulnerability in a

D3v17 D3v17 27 min read
Research

[CVE-2021-42008] Exploiting A 16-Year-Old Vulnerability In The Linux 6pack Driver

CVE-2021-42008 is a Slab-Out-Of-Bounds Write vulnerability in the Linux 6pack driver caused by a missing size validation check in the decode_data function. A malicious input from a process with CAP_NET_ADMIN capability can lead

D3v17 D3v17 33 min read
Ctf Research

[corCTF 2021] Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel

Wall of Perdition is the second and harder part of a two part series of kernel exploitation challenges designed by FizzBuzz101 and me for corCTF 2021. You can find the writeup for the

D3v17 D3v17 38 min read
Research

[CVE-2021-3156] Exploiting Sudo Heap Overflow On Debian 10

Recently the Qualys Research Team did an amazing job discovering a Heap overflow vulnerability in Sudo. In the next sections, we will analyze the bug and we will write an exploit to gain

D3v17 D3v17 21 min read
Ctf

[CUCTF 2020] Hotrod: Exploiting timerfd_ctx Objects In The Linux Kernel

Hotrod is a kernel exploitation challenge created by my friend FizzBuzz101 for CUCTF 2020. I tested the challenge before release and since the exploitation process was really interesting, I decided to write this

D3v17 D3v17 30 min read
Research

Ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries

In this article, we will start analyzing the lazy binding process, we will proceed dissecting dl-runtime, understanding when is possible to use this technique without a leak, and finally we will build our

D3v17 D3v17 22 min read
Syst3m Failure © 2022
Proudly published with Jekyll using Jasper2
Latest Posts Ghost