Spotted a mistake, want to discuss, or have a suggestion? Open an issue on the
relevant GitHub repository .
Read this before applying anything you find on this blog.
Every write-up, proof-of-concept, exploit chain, tool, and code snippet
published on this website is provided strictly for educational,
academic, defensive-security, and lawful authorised-testing purposes .
Nothing published here constitutes an incitement, endorsement, or offer to
perform any unauthorised or unlawful activity, and nothing published here
should be interpreted as such.
You alone are responsible for what you do with this information.
You must not use, adapt, run, or redistribute any technique, code, or artifact
from this site against any system, network, account, application, or data
unless you own it outright or hold explicit, written, and current authorisation
from the party that does. Testing scope, methods, and boundaries must be
agreed in writing before you touch anything. Verbal or implied permission is
not permission.
Unauthorised access to computer systems, networks, or data is a criminal
offence in most jurisdictions, including under Italian law (art. 615-ter
Codice Penale and related provisions), the U.S. Computer Fraud and Abuse
Act (18 U.S.C. § 1030), the U.K. Computer Misuse Act 1990, and equivalent
statutes elsewhere in the world. Consequences may include criminal
prosecution, civil liability, and permanent damage to your professional
reputation. Read the applicable laws in your jurisdiction before you act.
All content is provided "AS IS", without warranty of any kind ,
express or implied, including but not limited to warranties of merchantability,
fitness for a particular purpose, accuracy, completeness, or non-infringement.
To the fullest extent permitted by applicable law, the author disclaims all
liability for any direct, indirect, incidental, consequential, special, or
exemplary damages arising from, or in connection with, the use of, reliance
on, or inability to use any content published on this site, whether or not the
author was advised of the possibility of such damages.
The techniques described are, to the best of my knowledge, already public
(whether via prior academic work, conference talks, prior disclosures, or
other researchers' write-ups). Publishing them here is a research act intended
to help defenders understand what attackers are already capable of. Where I
have discovered new vulnerabilities, they have been responsibly disclosed to
the affected vendors before anything appeared on this blog.
Opinions expressed here are strictly my own and do not represent the views,
positions, strategies, or opinions of any past, current, or future employer,
client, or affiliated organisation.
If you don't understand or don't accept the above, stop reading and
close this tab. By continuing to browse, read, download, execute,
or otherwise engage with any content on this site, you acknowledge that you
have read, understood, and accepted every part of this disclaimer.