Cyber security

Pwn : Mastering The Art Of Digital Exploitation – Unveiling Advanced Techniques And Pwn2Own Triumphs

In the high-stakes world of cybersecurity, the art of “pwnage” represents not just a win, but a display of supreme technical mastery.

This article delves into the intricacies of advanced exploits I’ve developed, showcased in the elite Pwn2Own competitions and beyond.

From remote code execution vulnerabilities in JavaScript engines to sophisticated VM escapes, each exploit demonstrates a leap in the ongoing dance between security professionals and the systems they seek to fortify.

Join me as we explore the frontier of digital exploitation, where each technique unfolds the next chapter in cybersecurity innovation.

Advanced exploits that I created for Pwn2Own competitions and other occasions

JavaScript Jscript9 Remote Code Execution Exploit

Full proof-of-concept exploit for a JIT Type Confusion vulnerability in Microsoft JavaScript engine (Jscript9.dll), 2017.

Parallels Desktop VM Escape

Parallels Desktop 16.1.3 arbitrary code execution exploit (guest-to-host VM escape), as showcased at Pwn2Own 2021.

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

Starship : Revolutionizing Terminal Experiences Across Shells

Starship is a powerful, minimal, and highly customizable cross-shell prompt designed to enhance the terminal…

1 day ago

Lemmy : A Decentralized Link Aggregator And Forum For The Fediverse

Lemmy is an innovative, open-source platform designed for link aggregation and discussion, providing a decentralized…

1 day ago

Massive UX Improvements, Custom Disassemblers, And MSVC Support In ImHex v1.37.0

The latest release of ImHex v1.37.0 introduces a host of exciting features and improvements, enhancing…

1 day ago

Ghauri : A Powerful SQL Injection Detection And Exploitation Tool

Ghauri is a cutting-edge, cross-platform tool designed to automate the detection and exploitation of SQL…

1 day ago

Writing Tools : Revolutionizing The Art Of Writing

Writing tools have become indispensable for individuals looking to enhance their writing efficiency, accuracy, and…

1 day ago

PatchWerk : A Tool For Cleaning NTDLL Syscall Stubs

PatchWerk is a proof-of-concept (PoC) tool designed to clean NTDLL syscall stubs by patching syscall…

2 days ago