RSSAmplifier

Blog

too much pwn

beep boop

heinen.devRSS feed ↗14 posts

Latest posts

Disabling new Firefox mobile tab UX

Firefox's new tab UX is bad; here's how to disable it

Go's append should consume the input slice

If a slice has capacity then appending to it will alias the input and output slices. This can cause subtle and difficult to diagnose bugs.

Jane Street Puzzle - October 2025

Robot Baseball - Using backward induction to find Nash equilibria of a multi-stage game

Storing Foreign Keys in a SQLite JSON Array

Using SQLite JSON Arrays to represent uniqueness in many-to-many relationships where relations are the only differentiating factor

So I tried vibe coding

First week vibe coding hot takes

Using Tailscale as an OpenID Connect provider for homelab authentication

Setting up Tailscale's tsidp to provide OpenID Connect authentication for homelab applications using your tailnet

Why are stack addresses not constant offset from the base?

Linux ASLR adds 30 bits of entropy to the initial stack pointer through both base randomization and initial stack pointer offset

TextMate grammar for Binary Ninja HLIL

Textmate grammar to allow Shiki and others to syntax highlight Binary Ninja HLIL

DiceCTF 2024 Quals -- boogie-woogie

boogie-woogie was a pwn challenge in DiceCTF 2024 Quals with a .data relative byte swap primitive.

Battelle @ Shmoocon 2024 -- Time Jump Planner

Time Jump Planner was a pwn challenge from the Battelle booth at Shmoocon 2024. It was a stack buffer overflow challenge with a shadow stack to prevent ROP. Exploitation uses "GOT Oriented Programming", a code-reuse technique which works by chaining together gadgets terminating in a call to a GOT entry.

Potluck CTF 2023 -- Cake of Paranoia

Cake of Paranoia was a multi-stage docker-inside-nspawn sandbox escape challenge at Potluck CTF 2023

WreckCTF 2023

Blind format string oneshot

UTCTF 2022

I cleared pwn in UTCTF 2022 with the Texas A&M Cybersecurity club placing in 23rd :) There were three challenges -- an automatic exploit challenge, a stack bof+fmt string vuln, and unchecked write kernel driver.

Battelle Winter CTF 2022 -- Holy Grail of ROP

Holy Grail of ROP was an automatic exploitation challenge in the 2022 Battelle Winter CTF. It provided five randomly generated vulnerable binaries and players needed to solve each within a timeout to get the flag.