🦜 mahaloz.re
@mahaloz.re@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
The blog of mahaloz: all things hacking and computer science included!
Your feed and you don't want it here? Just
e-mail the birb.
Decompiling 2024: A Year of Resurgence in Decompilation Research
https://mahaloz.re/dec-progress-2024
Published: January 29, 2025 00:00
The year 2024 was a resurgent year for decompilation. Academic publications from that year made up nearly 30% of all top publications ever made in decompilation. In this post, I do a summarization and retrospective of both the academic and ideological…
30 Years of Decompilation and the Unsolved Structuring Problem: Part 2
https://mahaloz.re/dec-history-pt2
Published: January 10, 2024 00:00
A two-part series on the history of decompiler research and the fight against the unsolved control flow structuring problem. In part 1, we revisit the history of foundational decompilers and techniques, concluding on a look at modern works. In part 2, we…
30 Years of Decompilation and the Unsolved Structuring Problem: Part 1
https://mahaloz.re/dec-history-pt1
Published: January 2, 2024 00:00
A two-part series on the history of decompiler research and the fight against the unsolved control flow structuring problem. In part 1, we revisit the history of foundational decompilers and techniques, concluding on a look at modern works. In part 2, we…
PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749
https://mahaloz.re/2023/02/25/pwnagent-netgear.html
Published: February 25, 2023 00:00
A breakdown of a bug SEFCOM T0 and I exploited to achieve a WAN-side RCE in some Netgear RAX routers for pwn2own 2022. The bug is a remotely accessible command injection due to bad packet logging, cataloged as CVE-2023-24749.
Tips and tricks for reversing foreign architecture games
https://mahaloz.re/2022/09/23/0ctf22-rev.html
Published: September 23, 2022 00:00
Some common techniques used while reversing unknown architectures seen through the lens of an 80's game hacking challenge from 0CTF22
Insomnihack22: Reversing a flawed ECC rng-as-a-service Go Server
https://mahaloz.re/2022/02/07/Insomnihack22-go-rev.html
Published: February 7, 2022 00:00
Reversing a Go binary to find it generates flawed RNG from a P256 Elliptic Curve chosen with a reversible P and Q for number generation. Solution based on the Dual EC crypto paper.
Tasteless 21: Godot Game Hacking in Tasteless Shores
https://mahaloz.re/2021/10/03/tasteless-21-tasteless-shores.html
Published: October 3, 2021 00:00
A series of game hacking challenges hosted in Tasteless 21. Decompiling, modifying, and recompiling Godot scripts to abuse client-side computations for a multiplayer game. Fly hacks, no-damage, super speed, and rng abuse.
Exploiting a custom tetris game in CSAW Quals 2020
https://mahaloz.re/2020/09/13/csaw-quals-2020-blox.html
Published: September 13, 2020 00:00
Pwning a custom Tetris game through an out-of-bounds write to memory through block manipulation and changes to the `.text` segment.
Reversing printf-as-a-VM service in Google Quals 2020
https://mahaloz.re/2020/08/30/google-quals-2020-sprint.html
Published: August 30, 2020 00:00
Solving a virtual machine implemented inside format strings found in the printf library in C with @kylebot.
Lambda calculus challenges for ASU Undergrads
https://mahaloz.re/2020/04/14/lambda_calc_challenge.html
Published: April 14, 2020 00:00
This was a challenge written for a programming languages and compilers course at ASU. This is meant to test your skill in lambda calculus.