Skip to content
Ali / 3lyly0 • Vulnerability Research & Systems Archive

Investigating how complex systems behave when pushed past their limits.

I take apart browsers, embedded network protocols, and native applications to understand what happens beneath the abstractions - turning subtle software flaws into documented research, exploits, and tools.

3lyly0 Turtle
Selected Work

Research Investigations

Complete Archive →
New
SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It cover art

SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It

From 15 out-of-bounds bytes to full root and a walk out of a chroot jail: a technical teardown of a Linux kernel exploit chain that starts with a size mix-up between SHA-256 and SHA-384 inside a custom crypto module, travels through MSG_COPY, pipe_buffer, and struct page, and ends with a data-only write into cred followed by swapping task->fs for init_fs.

#linux-kernel #exploit-development #heap-exploitation #type-confusion #privilege-escalation

Why take systems apart?

Read the conversational Q&A exploring my background, reverse engineering methodology, CTF experience, and the curiosity driving this research space.

Read the Q&A →
⌘
Suggested Searches