Skip to content
View Unrealisedd's full-sized avatar
:shipit:
:shipit:
  • 20:02 (UTC +02:00)

Block or report Unrealisedd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Unrealisedd/README.md
Typing SVG

NASAUbisoftBritish MODNSF

HackerOne


I'm a 20-year-old security researcher from the Netherlands. I find and report vulnerabilities in production systems, from kernel drivers to web applications.

Currently focused on binary exploitation, Windows kernel-level vulnerability research, and expanding my public research archive.


Selected Research exploitarium

TargetTypeImpact
dam.sysKernel driver bugs (x4)BSOD + confused deputy + info leak + session freeze from standard user
Windows DefenderNTLM coercionStandard user forces SYSTEM credential leak via UNC path
Windows DefenderSignature lock bypassFILE_SHARE_READ locks signatures on patched systems
FirefoxIPC sandbox escapeUnvalidated AddCertException → silent MITM on arbitrary hostnames
MosquittoPre-auth RCEEmpty WebSocket frame heap overwrite → code execution
MySQL RouterOAuth cache ATODisplay-name cache collision → account takeover (CVSS 9.1)
KeepUnauth RCEProvider invoke chain → unauthenticated remote code execution
OpenVPN (ovpn-dco-win)Kernel UAFCNG key use-after-free in kernel driver
Overwolf UpdaterLPE to SYSTEMForged Authenticode cert + insecure service DACL
Safe Exam BrowserAuth bypass + RCEService auth bypass → log injection → RCE as SYSTEM
StorSvcDLL hijack LPELoadLibraryW without LOAD_LIBRARY_SEARCH_SYSTEM32 → SYSTEM
Discord DesktopRCEMultiple desktop client RCE attack paths
NextcloudXXE + SSRFFile read/SSRF + protection bypass chain
WazuhStack BOF + DoSStack buffer overflow + SCA denial of service
n8nSSRFServer-side request forgery via OAuth2 callback
Fluent BitPre-auth DoScollectd parser infinite loop from unauthenticated input
Woodpecker CIPipeline RCE\r bypass of newline sanitization → YAML injection
spacedeskLPE to SYSTEMEveryone full-control service DACL
LibreNMSSSTI → RCETemplate injection to remote code execution chain
RetroArch (libchdr)Heap overflowInteger overflow → OOB write on 32-bit via crafted CHD
BitLocker (bootmgfw.efi)OOB read DoSType-0x15 count mismatch → persistent boot brick + data loss
IncrediBuildgRPC preauth chainNTLM coercion + crashes + XOR key cracked + RSA key exposed
Paho MQTTWebSocket UAFQueued-frame use-after-free → allocator overlap + PC control
NanoMQcJSON UAFRule republish double-free: 5/5 ASan + 5/5 release crash
SambaDNS talloc UAFForwarded MX response talloc parent UAF → deterministic abort

"You can't secure what you don't understand."
— Bruce Schneier


Support My Work

vanmoorseltim@outlook.com

Pinned Loading

  1. exploitariumexploitariumPublic

    Forked from bikini/exploitarium

    A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if hand…

    Python 21 2

  2. pesurfacepesurfacePublic

    PE Attack Surface Mapper — find LPE primitives in Windows binaries

    Python

  3. nightfallnightfallPublic

    Windows security research framework built around Defender and kernel vulnerability research.

    Python 2