exploitarium
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
Find the QEMU CXL Type-3 Mailbox Escape PoC in the bikini/exploitarium GitHub repository. Get the complete exploitarium guide and explore the vulnerability.
Key Files for QEMU CXL Type-3 Mailbox Exploitation in ExploitariumExplore the 7 key Exploitarium files crucial for QEMU CXL Type-3 mailbox exploitation. Understand the build and execution process for a successful guest-to-host escape.
How to Trigger libc::system on QEMU Host from Guest: CXL Type-3 Mailbox ExploitLearn how to trigger libc system on QEMU host from guest using a CXL Type-3 mailbox exploit. Execute arbitrary commands by leveraging an out-of-bounds read vulnerability. Proof of concept available.
How to Build the QEMU CXL PoC with build.shEasily build the QEMU CXL PoC with build.sh. Automate compilation of bootloader and payload, creating a bootable poc.img for QEMU.
What Is the Purpose of stage2.c in the QEMU CXL Exploit?Discover the purpose of stage2.c in the QEMU CXL exploit. This code manipulates the CXL Type-3 mailbox interface to trigger host memory corruption and achieve arbitrary code execution.
How to Use the QEMU CXL PoC Bootloader: Complete Setup and Execution GuideLearn how to use the QEMU CXL PoC bootloader to demonstrate CXL mailbox escape vulnerabilities. This guide covers setup and execution for the two-stage bootloader.
How to Exploit the CXL SET_FEATURE Handler Vulnerability in QEMU: A Complete GuideLearn to exploit the QEMU CXL SET_FEATURE handler vulnerability. Gain guest-to-host escape and execute arbitrary code with this comprehensive guide.
How to Exploit the CXL GET_LOG Handler Vulnerability in QEMU: A Full Chain GuideExploit the CXL GET_LOG handler vulnerability in QEMU with this full chain guide. Learn to leak host pointers and achieve arbitrary code execution in the QEMU host process.
QEMU CXL Guest-to-Host Code Execution Vulnerability: Technical Analysis of the Type-3 Mailbox EscapeUncover the QEMU CXL guest-to-host code execution vulnerability. Learn how two flaws in mailbox command handlers allow VM guests to run arbitrary commands on the host.
How to Escape QEMU CXL Type-3 Mailbox: A Full Exploit WalkthroughLearn how to escape the QEMU CXL Type-3 mailbox by chaining an out-of-bounds read with an unbounded write to execute arbitrary host code. Full exploit walkthrough.
Discord IPC Calls for RCE: Technical Analysis of the bikini/exploitarium ExploitDiscover how Discord IPC calls enable RCE. Technical analysis of the bikini exploitarium exploit reveals attacker control via DISCORD_SETTINGS_SET and DISCORD_APP_RELAUNCH.
How to Run the Discord RCE Exploit with run.ps1: A Complete GuideLearn to run the Discord RCE exploit with run.ps1. Validate hashes, set your public origin, and let the PowerShell script manage the Node.js server and Discord settings restoration for you.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →