<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability Research on Kemetmüller</title><link>https://xn--kemetmller-feb.com/tags/vulnerability-research/</link><description>Recent content in Vulnerability Research on Kemetmüller</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Christoph Kemetmüller</copyright><atom:link href="https://xn--kemetmller-feb.com/tags/vulnerability-research/index.xml" rel="self" type="application/rss+xml"/><item><title>Behind the LLM Cybersecurity Hype</title><link>https://xn--kemetmller-feb.com/blog/behind-the-llm-cybersecurity-hype/</link><pubDate>Mon, 27 Apr 2026 16:46:29 +0200</pubDate><guid>https://xn--kemetmller-feb.com/blog/behind-the-llm-cybersecurity-hype/</guid><description>&lt;h2 class="relative group"&gt;Introduction
 &lt;div id="introduction" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#introduction" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The same vendors publishing breakthrough numbers on LLM cyber capability are publishing the disclaimers in the same posts. Read both halves and the picture changes.&lt;/p&gt;</description></item><item><title>Anatomy of the One Fox Toolkit</title><link>https://xn--kemetmller-feb.com/blog/anatomy-of-the-one-fox-toolkit/</link><pubDate>Wed, 11 Feb 2026 21:25:10 +0100</pubDate><guid>https://xn--kemetmller-feb.com/blog/anatomy-of-the-one-fox-toolkit/</guid><description>&lt;h2 class="relative group"&gt;Introduction
 &lt;div id="introduction" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#introduction" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;When EclecticIQ analyzed a 2023 Cobalt Strike intrusion&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; at Taiwan&amp;rsquo;s Directorate General of Highways (MOTC), the most useful artifact wasn&amp;rsquo;t the malware. It was a filesystem path leaked in the C2 logs:&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;C:\Users\Test\Desktop\ONE-FOX集成工具箱_V1.0魔改版_by狐狸\gui_other\Cobalt_Strike_4.5\plugin\TaoWu\script\lazagne.exe&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>Aviosoft Digital TV Player Professional 1.0 Stack Buffer Overflow</title><link>https://xn--kemetmller-feb.com/blog/aviosoft-buffer-overflow/</link><pubDate>Mon, 26 May 2014 13:05:09 +0000</pubDate><guid>https://xn--kemetmller-feb.com/blog/aviosoft-buffer-overflow/</guid><description>&lt;div
 
 class="flex px-4 py-3 rounded-md shadow bg-primary-100 dark:bg-primary-900"
 
 &gt;
 &lt;span
 
 class="text-primary-400 pe-3 flex items-center"
 
 &gt;
 &lt;span class="relative block icon"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512"&gt;&lt;path fill="currentColor" d="M506.3 417l-213.3-364c-16.33-28-57.54-28-73.98 0l-213.2 364C-10.59 444.9 9.849 480 42.74 480h426.6C502.1 480 522.6 445 506.3 417zM232 168c0-13.25 10.75-24 24-24S280 154.8 280 168v128c0 13.25-10.75 24-23.1 24S232 309.3 232 296V168zM256 416c-17.36 0-31.44-14.08-31.44-31.44c0-17.36 14.07-31.44 31.44-31.44s31.44 14.08 31.44 31.44C287.4 401.9 273.4 416 256 416z"/&gt;&lt;/svg&gt;
&lt;/span&gt;
 &lt;/span&gt;

 &lt;span
 
 class="dark:text-neutral-300"
 
 &gt;&lt;strong&gt;Historical Content (2014):&lt;/strong&gt; This article demonstrates classic stack-based buffer overflow exploitation on Windows XP SP3. Modern Windows systems include mitigations such as ASLR, DEP/NX, and CFG that would prevent these techniques from working directly. The concepts remain valuable for understanding exploit development fundamentals.&lt;/span&gt;
&lt;/div&gt;

&lt;p&gt;This post documents the process of developing a working exploit for a stack buffer overflow in Aviosoft Digital TV Player Professional 1.0. The vulnerability exists in the application&amp;rsquo;s playlist file parser, which copies user-supplied data into a fixed-size stack buffer without bounds checking.&lt;/p&gt;</description></item></channel></rss>