LiteLLM, an open-source proxy server for language model APIs, had two vulnerabilities allowing remote code execution via a standard API key. These exploits stemmed from environment variable disclosure and a Jinja2 server-side template injection. Both vulnerabilities were addressed in the v1.84.0-rc.1 patch, implementing multiple security measures.
During summer 2024, I went on holiday and encountered multiple virtual reality (VR) arcades containing a vulnerability which allowed me to breakout and pop a Windows command prompt on the arcade machine.
Introduction In the previous post, we developed a traditional stack buffer overflow exploit in the Okage: Shadow King game which resulted in us being able to execute arbitrary code from within a PlayStation 2 ELF that was embedded inside the exploitable game save file. In Read More
Introduction The following multi-part blog series will cover how I (McCaulay Hudson) developed the mast1c0re exploit on both the PlayStation 4 and PlayStation 5. The initial research on the vulnerabilities used within this blog series were conducted by CTurtE with assistance from flatz, balika011, theflow0, Read More