RSSAmplifier

Blog

kqx

Recent content on kqx

kqx.ioRSS feed ↗23 posts

Latest posts

One of the many flaws of Phi untagging: CVE-2026-4447

A technical writeup on a 0day vulnerability I reported inside V8, Chrome’s JS engine

Exploiting a 0day on QEMU

Cheesing challenges running on QEMU TCG from v9.1 on with this 0day

faulty-road - TRX CTF Quals 2026

rev challenge that I wrote for TRX CTF Quals 2026

down-the-line - TRX CTF Quals 2026

real mode challenge that I wrote for TRX CTF Quals 2026

krwd - TRX CTF Quals 2026

kernel pwn challenge that I wrote for TRX CTF 2026

triforce - TRX CTF Quals 2026

A V8 exploitation challenge I authored for TRX CTF Quals 2026

triforce-sbx - TRX CTF Quals 2026

A V8 exploitation challenge I authored for TRX CTF Quals 2026

🍼🤏🤏 - TRX CTF Quals 2026

kernel pwn challenge that I wrote for TRX CTF Quals 2026

cornelslop - DiceCTF Quals 2026

kernel pwn challenge authored by FizzBuzz101 I first-blooded at DiceCTF Quals 2026

How a single typo led to RCE in Firefox

A technical writeup on a 0day vulnerability I reported inside SpiderMonkey, Firefox’s JS engine

Singleton - ASIS CTF Finals 2025

Colliding hashes and confusing types for fun and profit

vibe-kode - backdoor CTF 2025

kernel pwn challenge that we first-blooded at backdoor CTF 2025

Exploiting a 13-years old bug on QEMU

Learn how to cheese kpwn challenges running on a Ubuntu 24.04 container using a nday on QEMU

Inline8 - DefCamp DCTF Finals 2025

Exploiting a pretty broken JS-engine

FileNo - ASIS CTF 2025

kernel pwn challenge authored by ptr_yudai that we first-blooded at ASISctf 2025

zenerational-aura - corCTF 2025

uarch challenge authored by FizzBuzz101 I first-blooded at corctf 2025

pwning with... "QEMU"?

This post is about exploiting IOPL privilege escalation using QEMU’s Firmware Configuration (fw_cfg) device.

make cpu-entry-area great again

Reviving an old linux novel technique to bypass SMAP through an unimplemented x86 feature in QEMU’s TCG

/dev/mem - TRXCTF 2025

kernel pwn challenge that I wrote for TRXCTF 2025

🍼🤏 - TRXCTF 2025

kernel pwn challenge that I wrote for TRXCTF 2025

fetipop

Novel technique I found in the linux kernel useful to exploit restricted dirty pagetable scenarios in a completely reliable and leakless way, through a new kind of “Oriented Programming”.

krwx - ToHCTF 2025

Writeup for the kernel pwn challenge that I wrote for ToH CTF 2025. In this post I will talk about a way of bypassing kCFI (norand) using BPF filters.

about

Welcome to kqx! We are three CTF players that enjoy breaking stuff that have to do with kernels, QEMU, x86 and browsers!. Alessio Ghidini (@Erge): * pwner for TRX * member of TeamItaly 🇮🇹 (2024, 2025) * student @ unipd Manuele Pandolfi (@leave): * pwner for TRX * member of TeamItaly 🇮🇹 (2025) * student @ jk still a kiddo, when I’ll start uni I’ll let you know Gabriel Prostitis…