Skip to content
RouSoftware

// field notes

Posts

CVE analysis, original research, tutorials, engineering notes, and practical security work.

Hack The BoxLinuxAug 19, 2026

Interdimensional Internet

A Python exec chain exploitation that abuses a check->execute->execute chain, with a very restrictive 300 byte limit.

mediumWeb
Hack The BoxLinuxAug 19, 2026

wafwaf

A classic decode-after-check vulnerability to blacklist based WAF bypass, leading to a blind SQLi.

mediumSQL InjectionWeb
Hack The BoxLinuxAug 18, 2026

Breaking Grad

A beautiful prototype pollution puzzle on an old Node version, with multiple solutions via symbolic links, Node executable arguments or straight up shell commands.

mediumPrototype PollutionWeb
Posts — RouSoftware