RSSAmplifier

Blog

Jro's Blog

Jro's Blog

jro.sgRSS feed ↗43 posts

Latest posts

AGAR

IDA Plugin for Assisting Go Analysis and Reversing

CVE-2025-52692: Linksys E9450-SG Auth Bypass

A home router implements its own HTTP parser. What could go wrong?

The Boss Needs Help

Flare-On Level 7 challenge involving a heavily obfuscated binary

10000

Flare-On Level 9 challenge where I reverse-engineer 10,000 DLLs

NTFSM

Flare-On Level 5 challenge involving alternate data streams and a finite state machine

CVE-2025-62453: Case closed? Not quite.

Patch bypass for CVE-2025-53773 on Windows via uppercased file path

lz1

Zero Day Pwnable

Countdown to Root: Pwning the Temporal Paradox Engine

Exploiting a controlled decrement primitive via Dirty Pagetable

Auto Review - Intended solution

Escape Room

Chroot escape

CVE-2025-52688

Alcatel AP1361D Command Injection in Web Login

CVE-2025-52690

Alcatel AP1361D Command Injection in cluster_cor service

(Ab)using channels to implement a 3D pipe game

Channels? Did you mean 'fancy pipes'?

CVE-2025-48469

Advantech WISE-4060LAN Unauthenticated Firmware Upload

ropvm

Exploiting a stack buffer overflow in a custom VM

Looney Tunable

CVE-2023-4911 reimplemented as a CGI service

C2 Postmortem

Is it really a web challenge if there aren't unintended solutions?

Undead Survivor

Reverse Engineering Unity il2cpp

Key Value Store

Improper checks in resizing of hashmap results in OOB access

cloud/escalate

pwn/squ1rrel-logon

Code Execution in IDA MCP Servers

Crafting malicious binaries that trick LLMs into executing code

Solving (and Pwning) Flare-On level 10

Solution to the final challenge of Flare-On 11

Notes App

Secure Login

Level 1: Disk Archaeology (foren)

Level 2: XIPHEREHPIX's Reckless Mistake (crypto)

Level 3: KPA (Rev)

Level 4: Really Unfair Battleships Game (rev)

Level 5: PALINDROME's Invitation (osint/misc)

Level 6A: The chosen ones (Web)

Level 6B: 4D (RE, Pwn)

(Solving and) Pwning Flare-On level 10

Exploiting a vulnerability in a Flare-On challenge

Level 7A: DevSecMeow (Cloud)

Level 8: Blind SQL Injection (Web/RE/Pwn/Cloud)

Level 7B: The Library (RE, Pwn)

Level 9: PalinChrome (Browser exploitation)

Level 10: dogeGPT (rev, pwn, web, crypto)

Imphash

TISC 2024 Level 9 Pwn Challenge

Porting an IDAPython Plugin to IDA 9

Alternatives for some APIs removed in IDA 9

Auto Enum

IDA/Binary Ninja Plugin to automatically identify and set enums for standard functions

ida2py

An intuitive query API for IDA Pro