aresinheaven
cryptography · web exploitation · reverse engineering
Second-year cybersecurity student focused on cryptography and Web3. I play CTFs with L3ak and captain of GODSEC. I also enjoy reverse engineering, solving math problems, and participating in Codeforces.
CryptoHack: World #79 · India #2
Latest posts
View all →Solve for z3kapig R3CTF 2026
My writeup and solution for the z3kapig crypto challenge from R3CTF 2026, breaking Paillier modulus validation to extract secret shares.
aresinheaven bio
aresinheaven info
CVE-2026-54699: Warp Terminal WSL Command Injection: Escaping the Sandbox via OSC 8 Hyperlinks
How we found an OS command injection in Warp Terminal on WSL that lets an attacker escape the Linux sandbox and execute arbitrary commands on the Windows host through crafted terminal hyperlinks.
Hacking Smart Vending Machines: From Weak Password to RCE
How weak credentials, exposed internal APIs, leaked cloud secrets, and remote device access chained into root shells across 300+ smart vending machines.
Unmasking Etherhiding: Reverse Engineering a Modular ClickFix Loader
A deep dive into bypassing anti-emulation, rebuilding decoders, and uncovering Web3-based C2 infrastructure in a sophisticated ClickFix campaign variant.
The Hidden Cost of Misconfiguration: Exploiting Exposed Ray Clusters
An educational look at insecure deserialization in distributed AI systems - how misconfigured Ray clusters lead to instant remote code execution.