Vulnerability Research, Exploit Development, Reverse-Engineering
I break things,
then explain how.
I'm Joel Eriksson — a vulnerability researcher, exploit developer and reverse-engineer. This is where I publish kernel exploits, CTF writeups, and the occasional deep dive down an internet rabbit hole.
Latest writing
All posts-
Security in the Age of Agents
So many AI agent orchestration frameworks and “operating systems” are being released right now, that claim to be built with security in mind – proudly listing their extensive security features, related to everything from their use of cryptography to sandboxes…
Read -
The Mystery of Skype
End of an era. Skype is finally shutting down for good.
Read -
Ashley Madison Post-Mortem
What would have I done differently, in the Ashley Madison case, knowing what I know now.
Read -
Android HID device forwarding
As I mentioned in my previous post, Immersed (https://immersed.com) is a great multi-platform (Linux/macOS/Windows) solution for sharing your screens to a VR environment. Unlike Virtual Desktop that is focused mostly on gaming (and more importantly, that does not have a…
Read -
Low-latency VR desktop with Immersed
Immersed (https://immersed.com) is a multi-platform solution (Linux/macOS/Windows) for sharing your monitors (including a couple of virtual ones) to a VR environment. It currently supports the popular Quest and Quest 2 headsets, as well as the VIVE Focus 3, and a…
Read -
31C3 CTF: Maze write-up
This is my write-up for the maze challenge in the 31C3 CTF, that I played with the Hacking For Soju team. We “only” got 10th place (out of the 286 teams that scored any points at all), but considering that…
Read
Notable work & collections
In the press & elsewhere
Ashley Madison: Sex, lies & scandal (Netflix 2024)
What would I have done differently, knowing what I know now…
Ashley Madison Post-Mortem
Some articles about me and/or my research, in English:
- Meet The Man Who Solved The Mysterious Cicada 3301
- The internet mystery that has the world baffled
- Security Guru Gives Hackers a Taste of Their Own Medicine
- Leaked emails don’t prove infidelity: Ashley Madison
- (YouTube) DEF CON 15 – Eriksson and Panel – Kernel Wars
- Kernel Wars @ Defcon
- Kernel Wars @ BlackHat
Some articles about me and/or my research, in Swedish:
- Terrorism eller CIA-kampanj? Här är historien om Cicada 3301
- Klarar du alla rebusar och gåtor? Här är utmaningen som bara två av 22 000 har klarat
- Mysteriet som gäckar världens hackare
- Smarta telefoner lätta att hacka
- Din smarta mobil – snart hackad?
- Sveriges bästa säkerhetsexperter – hela listan
- Microsoft i bråk med svenskt säkerhetsföretag
- Så hittar experterna säkerhetshål
For more information about Cicada 3301 and my solutions for the 2012 challenge, go to:
https://clevcode.org/cicada-3301/
If these kinds of puzzles and challenges interest you, you might also be interested in looking at the old GCHQ challenge:
GCHQ: solve the online code, become a real-life spy
My solutions for that challenge are available here:
https://clevcode.org/canyoucrackit-co-uk-gchq-challenge-solution/
Note that the GCHQ challenge is a bit more technical in nature than the Cicada 3301 puzzles, so it might not be for everyone. ;)
For those of you that are into that sort of stuff, you might take a look at my CTF challenge writeups:
https://www.clevcode.org/category/ctf/writeup/
/ Joel Eriksson <je at clevcode dot org>