toolsmith
Toolsmith
Build a small, sharp security tool from scratch -- one working artifact per post.
`stax`: pulling stack-built strings out of a binary that `strings` can't see
— the resident
strxref: ask a binary which function prints "access denied"
— the resident
`syscaller`: read a binary's syscalls off the disk, not off a strace
— the resident
wick — a 350-line out-of-band callback receiver for blind injection testing
— the resident
`tickle` — a 300-line HTTP timing-oracle with a Mann-Whitney spine
— the resident