<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit on THALIUM</title><link>/tags/exploit/</link><description>Recent content in Exploit on THALIUM</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright (c) 2026, all rights reserved.</copyright><lastBuildDate>Tue, 16 Dec 2025 08:00:00 +0000</lastBuildDate><atom:link href="/tags/exploit/index.xml" rel="self" type="application/rss+xml"/><item><title>Don't judge an audiobook by its cover: taking over your Amazon account with a Kindle</title><link>/posts/dont-judge-an-audiobook-by-its-cover-taking-over-your-amazon-account-with-a-kindle/</link><pubDate>Tue, 16 Dec 2025 08:00:00 +0000</pubDate><guid>/posts/dont-judge-an-audiobook-by-its-cover-taking-over-your-amazon-account-with-a-kindle/</guid><description>&lt;p&gt;Although Kindle e-readers are a prime target in modding and jailbreaking communities, there is little public work about vulnerability research in remote code execution scenarios.&lt;/p&gt;
&lt;p&gt;In this post, we give technical details about a chain of vulnerabilities we identified that can be triggered by downloading a malicious Audible audiobook, allowing to take full control of the device and its registered Amazon account.&lt;/p&gt;</description></item><item><title>ECW 2023: Centralized Memory (write-up)</title><link>/posts/ecw-2023-centralized-memory-write-up/</link><pubDate>Tue, 07 Nov 2023 12:00:00 +0100</pubDate><guid>/posts/ecw-2023-centralized-memory-write-up/</guid><description>&lt;strong&gt;Centralized Memory&lt;/strong&gt; was a hard Linux pwn challenge created for the European Cyber Week CTF 2023 qualifiers. This write-up covers the intended method of exploitation through a race condition, an AES padding bug and a stack overflow.</description></item><item><title>ECW 2023: The Calculator in Shadow (write-up)</title><link>/posts/ecw-2023-the-calculator-in-shadow-write-up/</link><pubDate>Tue, 07 Nov 2023 12:00:00 +0100</pubDate><guid>/posts/ecw-2023-the-calculator-in-shadow-write-up/</guid><description>&lt;strong&gt;The Calculator in Shadow&lt;/strong&gt; was a hard pwn challenge created for the European Cyber Week CTF 2023 qualifiers. It included exploiting a RISC-V calculator running on top of a customized QEMU that featured a poorly implemented shadow stack.</description></item><item><title>ARM TrustZone: pivoting to the secure world</title><link>/posts/pivoting_to_the_secure_world/</link><pubDate>Fri, 24 Mar 2023 13:37:00 +0000</pubDate><guid>/posts/pivoting_to_the_secure_world/</guid><description>&lt;ol&gt;
&lt;li&gt;Discovery of two vulnerabilities in secure world components&lt;/li&gt;
&lt;li&gt;Exploitation to get code execution in a trusted driver, while not having a debugger for this obscure environment&lt;/li&gt;
&lt;li&gt;Leverage of aarch32 T32 instruction set to find nice stack pivots&lt;/li&gt;
&lt;li&gt;Turning an arbitrary write into an arbitrary code execution&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Remote Deserialization Bug in Microsoft's RDP Client through Smart Card Extension (CVE-2021-38666)</title><link>/posts/deserialization-bug-through-rdp-smart-card-extension/</link><pubDate>Fri, 10 Dec 2021 06:00:01 +0100</pubDate><guid>/posts/deserialization-bug-through-rdp-smart-card-extension/</guid><description>&lt;p&gt;This is the &lt;strong&gt;third installment&lt;/strong&gt; in my three-part series of articles on fuzzing Microsoft&amp;rsquo;s RDP client, where I explain a bug I found by fuzzing the &lt;strong&gt;smart card extension&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Remote ASLR Leak in Microsoft's RDP Client through Printer Cache Registry (CVE-2021-38665)</title><link>/posts/leaking-aslr-through-rdp-printer-cache-registry/</link><pubDate>Fri, 10 Dec 2021 06:00:00 +0100</pubDate><guid>/posts/leaking-aslr-through-rdp-printer-cache-registry/</guid><description>&lt;p&gt;This is the &lt;strong&gt;second installment&lt;/strong&gt; in my three-part series of articles on fuzzing Microsoft&amp;rsquo;s RDP client. I will explain a bug I found by fuzzing the &lt;strong&gt;printer sub-protocol&lt;/strong&gt;, and how I exploited it.&lt;/p&gt;</description></item><item><title>ECW 2021 - WriteUp</title><link>/posts/ecw2021-writeup/</link><pubDate>Mon, 25 Oct 2021 12:00:01 +0100</pubDate><guid>/posts/ecw2021-writeup/</guid><description>&lt;p&gt;For the &lt;a href="https://www.european-cyber-week.eu/"&gt;European Cyber Week&lt;/a&gt; CTF 2021 Thalium created some challenges in our core competencies: reverse and exploitation. This blog post presents some of the write-ups:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#chest"&gt;Chest (36 solve) - reverse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#fsb-as-a-service"&gt;FSB as a service (3 solve) - exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wysiwyg"&gt;WYSIWYG (3 solve) - reverse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pipe Dream (1 solve) - reverse
&lt;ul&gt;
&lt;li&gt;the author posted his solution on &lt;a href="https://face.0xff.re/posts/ecw-ctf-2021-pipe-dream-writeup/"&gt;his personal blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thalium&amp;rsquo;s challenges have been less resolved than others. They were not that difficult, but probably a bit more unexpected. A few additional challenges designed by Thalium are:&lt;/p&gt;</description></item></channel></rss>