Menu IconMenu Icon
Minimize
Maximize
Close

Adrian "vurlo" Junge

Welcome to my bug collection ๐Ÿ›

CTF player, vulnerability researcher, and computer science student creating writeups, collecting CVEs, bounties, and notes from real targets and challenges. I poke things politely and occasionally convince software to confess.

Latest notes

Frankendancer

WIP

Funny Java Strings?

Java Strings are immutable, interned, optimized, and surprisingly easy to misunderstand when secrets are involved. This post digs into String pooling, reflection, Base64 copies, library APIs, and why ...

xmalloc

All of our slot machines switched from using the very insecure libc heap implementation to something much more secure internally. Surely this new heap implementation is unbreakable :D