Skip to content

Blog

Security Research Blog

Field notes on vulnerability research, penetration testing, and the security of OT/ICS and IoT systems.

Subscribe via RSS
10 min read

Grammar-Based Fuzzing: What Random Mutation Misses

Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.

Read full article
11 min read

An LLM Doesn't Know Whether It Finished — Designing a Harness That Moves the Completion Verdict Outside the Model

Multiple studies conclude that an LLM agent's completion bias and overconfidence cannot be corrected by prompting. This post lays out the design principles of a vulnerability-checking automation harness that makes "surveyed everything" and "0 vulnerabilities" computed from an HMAC receipt ledger and deterministic hooks rather than from the model's narrative. A "200 OK" without a negative control is not confirmation.

Read full article
19 min read

Anatomy of Achilles Certification — How Industrial Control Devices Get Fuzzed

An anatomy of how Achilles Communications Certification (ACC) tests PLCs, RTUs, and industrial switches. It covers the classification of 31 L1 / 54 L2 test cases, the seven test types (Scans, Storms, Fuzzers, Grammars), control-protocol coverage from the IP stack up to DNP3, Modbus, and IEC 61850, and what the Normal/Warning/Failure monitors actually determine.

Read full article
19 min read

IEC 62443-4-2 Primer — A Map of FR1-7 and Component Requirements

A primer map for anyone new to IEC 62443-4-2. Covers why the 62443 series is divided by audience rather than topic, the four faces of SL and the three faces of SL 0, the Component Requirements (CR) of the seven Foundational Requirements (FR1-7), the SAR/EDR/HDR/NDR component types, and the distinctly industrial-security idea of "maintain degraded mode instead of preventing DoS."

Read full article
13 min read

Why "IEC 62443-4-2 Certified" Means Nothing on Its Own

When a manufacturer says "we're IEC 62443-4-2 SL2 certified," the sentence alone tells you nothing about what was actually verified. This post dissects the arithmetic behind the three numbers (RA, NAR, TR) printed on a certificate, the decisive difference between N/A and out-of-scope, and why confusing SL-T/SL-C/SL-D/SL-A ruins any reading of the certificate.

Read full article
11 min read

What the CRA Changes in 2027 — How 62443 Became the Baseline Standard for CE Marking

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the world's first law to mandate cybersecurity for physical products with digital elements. This post lays out the incoming timeline (reporting obligations on 2026-09-11, full application on 2027-12-11), how 62443 becomes the basis of CE marking as a harmonised standard, and the 6 CRA-specific requirements 62443 does not cover.

Read full article
13 min read

Designing CTFs That Target LLMs — The Structural Weaknesses of Transformers

In an era where LLM agents have started solving CTFs automatically, how do you design a challenge that "machines struggle with but a skilled human solves in a reasonable time"? This organizes the anti-LLM design principles that target the structural limits of transformers — state tracking, carry propagation, tokenization, and context loss.

Read full article
22 min read

Reading the MFDS Medical Device Cybersecurity Guideline — Guidance No. 0995-05

An explanation of the MFDS medical device cybersecurity approval/review guideline (Guidance No. 0995-05, 2025.01.10) on the basis of IEC 62443-4-2. It organizes, from the perspective of regulatory practitioners and developers, the structure of the 35 requirements across 6 categories, the mapping to the IEC 62443 FR/CR system, the approval submission requirements, and the transition schedule before and after revision.

Read full article
12 min read

AI Security Agent Architecture: From Reconnaissance to Exploitation

The architecture of a hierarchical multi-agent system that performs autonomous vulnerability assessment, from network reconnaissance to exploit validation. Seven specialists, a five-phase workflow, and the confirmation oracle, execution isolation, and RoE reference monitor that pull the judgment authority out of the model.

Read full article
10 min read

Fuzzer Design for LS Electric PLC Protocol Analysis

A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.

Read full article
5 min read

RITSEC 2021: baby WASM

A writeup for RITSEC CTF 2021's baby WASM challenge, covering WebAssembly bytecode reversing, the WASM memory model, and flag extraction.

Read full article
11 min read

Angr for CTF: A Symbolic Execution Tutorial

A practical guide to using angr for CTF binary analysis: symbolic execution basics, find/avoid strategies, setting up symbolic registers and stack arguments, and solving crackmes automatically

Read full article
3 min read

Linux kernel btrfs use-after-free

Mounting a crafted btrfs image, performing some operations, and unmounting leads to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.

Read full article
3 min read

Linux kernel btrfs use-after-free

Mounting a crafted btrfs image twice causes an rwsem_down_write_slowpath use-after-free because rwsem_owner_flags returns an already freed task_struct pointer.

Read full article
3 min read

Linux kernel btrfs NULL pointer dereference

A crafted btrfs image triggers a NULL pointer dereference in btrfs_verify_dev_extents because fs_devices->devices is mishandled inside find_device (fs/btrfs/volumes.c) in Linux kernels before 5.1.

Read full article
4 min read

ROP Emporium: ret2win and callme

Writeups for the ROP Emporium ret2win (basic ROP control-flow hijacking) and callme (chained function calls with specific arguments) challenges.

Read full article
3 min read

Pwnable.tw: Start

A shellcode injection writeup for Pwnable.tw's Start challenge, exploiting a stack-based buffer overflow in a minimal 32-bit Linux binary with no NX protection.

Read full article
9 min read

Protostar Wargame Writeup

Solving the Protostar wargame: stack buffer overflows, format string bugs, heap exploitation, and a network challenge.

Read full article
5 min read

DEF CON 22 CTF Qualifier: r0pbaby

Solving DEF CON 22 CTF Qualifier's r0pbaby: leaking the shared library base, finding gadgets via PLT/GOT, and building a 64-bit ROP chain to call system().

Read full article