When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
A personal site for experiments in cybersecurity, reverse engineering, and whatever breaks along the way.
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
How I found a RCE vulnerability in a privacy VPN.
Scanned 62k Bitcoin addresses from the LockBit ransomware leak to see which wallets were funded. Here’s what I found.