top of page
Search
All Posts


Leigh Gilbert
Aug 10 min read


Leigh Gilbert
Jul 310 min read


Leigh Gilbert
Jul 290 min read


Leigh Gilbert
Jun 210 min read


Ransomware module complete for DEFCON 34.
Prep for DEFCON 34 has begun!! This year I am putting together a new project for Malware village. I want to teach noobs how to trojanize normal programs to do really bad stuff! My inspiration was APT38 Lazarus who cracked the expensive IDA pro and placed malicious dll's inside to download a rat. Thus stealing a bunch of secrets from exploit developers. We have some huge sponsors in the works so stay tuned as this workshop comes together!
Leigh Gilbert
Jun 131 min read


Initial access. Client side container attack
Afternoon everyone from the Great white North. I've moved my research posts to my own site to avoid being banned on traditional social media. Many platforms such a X have begun a crackdown on anything it deems illegal; leading me to be banned near weekly. =0) Now I speak in code to keep my social media accounts alive.=0) Unfortunately, I still have a vocational need for American social media in 2026. So here we are. It's honestly kind of weird to be subjected to American comp
Leigh Gilbert
Jun 73 min read


SEH Overflow Vuln Server (GMON)
Hey friends. Let's deep dive into a structured exception handler overflow on Vuln server. Playing with the vuln server with ncat we can see the commands it takes and that it takes inputs. I decided on GMON. I then fired up IDA pro. I quickly find GMON via the strings search and begin my static analysis. First, we walk the program with the help of Windbg and Ida pro. We first discover the requirement of "GMON " The space after GMON is required as denoted in the 5 bytes prior t
Leigh Gilbert
Jan 275 min read
bottom of page