KalemSec

  • Home
  • About
  • Writing
  • Projects
  • 2025

  • 2025-04-26
    From SSTI to SSTI to RCE - Bypassing Thymeleaf sandbox <= 3.1.3.RELEASE
  • 2025-02-15
    CVE-2025-0001
  • 2025-01-22
    VPN-in-the-browser
  • 2024

  • 2024-06-07
    Exploiting CVE-2024-37148
  • 2024-05-09
    Exploiting CVE-2024-29889 and CVE-2024-31456
  • 2024-03-24
    Exploiting CVE-2024-27096
  • 2024-02-29
    CVE-2024-27937 - CVE-2024-27930 - Walkthrough
  • 2023

  • 2023-12-28
    From SSRF to authentication bypass
  • 2023-11-05
    Hidden in plain sight - Part 2
  • 2023-10-31
    Hidden in plain sight
  • 2023-09-27
    Tiny File Manager - There's no place like home
  • 2023-08-06
    I want to talk to your managed code
  • 2023-07-09
    Qakbot JScript dropper analysis
  • 2023-06-02
    CVE-2023-3064, CVE-2023-3065, and CVE-2023-3066
  • 2023-06-01
    CVE-2023-3031
  • 2023-06-01
    CVE-2023-3032
  • 2023-06-01
    CVE-2023-3033
  • 2023-02-05
    FuckFastCGI made simpler
  • 2023-02-01
    PHP .user.ini risks
  • 2023-01-30
    PHP open_basedir bypass
  • 2020

  • 2020-05-05
    Attacking Android Accessibility Service (AAS) - Part I
  • 2020-05-05
    Attacking Android Accessibility Service (AAS) - Part II
  • 2020-05-05
    Attacking Android Accessibility Service (AAS) - Part III
  • 2020-05-05
    Attacking Android Accessibility Service (AAS) - Part IV
  • 2020-05-05
    Diving into dsencrypt - Android malware analysis
  • 2020-05-05
    Diving into ruMMS - Android malware analysis
  • 2020-05-05
    Diving into Sberbank Android banker - Android malware analysis
  • 2020-05-05
    Diving into SLocker - Android malware analysis
  • 2020-05-05
    Diving into Viking Horde - Android malware analysis
  • 2020-05-05
    Self modifying C program - Metamorphic (Basic)
  • 2020-05-05
    Self modifying C program - Polymorphic
  • 2020-05-01
    Practical attacks against mobile browsers using extensions
Copyright © 2016-2026 Ender Papyrus
  • Home
  • About
  • Writing
  • Projects