Febin·Apr 1CVE-2026–24018: A Logic flaw to Local Privilege Escalation 0day $$$My first CVE of 2026. A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4…
Febin·Jun 15, 2024Pwn Challenges writeup — RVCExIITB CTFHello PWNers, This is a walkthrough article for the binary exploitation/PWN challenges from RVCExIITB CTF competition.A response icon3A response icon3
Febin·Jan 17, 2024I found 2 Zero-Days in popular Linux distros that includes Mint, Kali, ParrotThis is the story on how I found 2 Zero-Day Vulnerabilities (4 CVEs). The flaws affected a list popular Linux Desktop distros that…
Febin·Nov 6, 2023Decode-E-Cyber CTF 2023 — PWN/Binary Exploitation Writeup — 1I participated in Decode-E-Cyber CTF 2023 conducted by OWASP VIT Bhopal and we were the Winners! Team Pegasus with 1350 points. We were…
Febin·Nov 6, 2023Decode-E-Cyber CTF 2023 — PWN/Binary Exploitation Writeup — 1I participated in Decode-E-Cyber CTF 2023 conducted by OWASP VIT Bhopal and we were the Winners! Team Pegasus with 1350 points. We were…
Febin·Nov 2, 2023Malware Analysis Challenges from Huntress CTF 2023 — Part 1 — ChainSaw MassacreHuntress CTF is just over, it was a fun ride for 30 days. This blog is a collection of writeups of the Malware Challenges that I solved in…A response icon1A response icon1
Febin·Sep 22, 2023CVE-2023–39612: CSP bypasss + XSS to achieve Admin Account Takeover + Remote Command Execution in…My 5th CVE: CVE-2023–39612
Febin·Mar 28, 2022Post-Exploitation with HackBrowserData.Steal saved passwords, cookies, bookmarks, and history from the victim’s browser.A response icon1A response icon1
Febin·Mar 22, 2022CVE-2021–40662 Chamilo LMS 1.11.14 RCEThis is Febin, a Security Researcher. This article is about my third CVE that I got for finding a Remote Code Execution in a popular…