Lowlevel
ResearchDraftsHTBAbout
Home/Research

Research

Original security research, vulnerability analysis, and technical deep dives

4 articles

ret2namespace: Bypassing _IO_vtable_check via Loader Namespace Injection
Research

ret2namespace: Bypassing _IO_vtable_check via Loader Namespace Injection

Revisits namespace injection (House of Corrosion, 2019) on modern glibc 2.39-2.43 with BIND_NOW. First working exploit, updated offsets, and new behavioral constraints.

retleave·Apr 21, 2026·14 min
UAF Container Escape: Kernel Heap Exploitation
ResearchDrafts

UAF Container Escape: Kernel Heap Exploitation

End-to-end Linux kernel heap exploitation: from a use-after-free in a misc device driver to container escape, bypassing KASLR, SMEP, SMAP, and SLUB hardening.

Feb 9, 202616m
Composing Weak Heap Primitives
ResearchDrafts

Composing Weak Heap Primitives

A realistic heap exploitation chain showing how weak, byte-wise corruption can break allocator invariants under modern glibc hardening.

Jan 30, 20267m
ret2dso: Runtime Ret2dlresolve Under Full RELRO
ResearchDrafts

ret2dso: Runtime Ret2dlresolve Under Full RELRO

ret2dso demonstrates that runtime symbol resolution remains exploitable under full RELRO through dynamic loader metadata corruption.

Jan 26, 20267m
© 2025 Lowlevel Research
Sitemap