A specialized research team focused on web security vulnerabilities and exploitation techniques

Joined July 2025
Include

Only show posts containing:

Exclude

Hide posts containing:

Time range
-
Minimum likes
RewriteLab
@RewriteLab
Jul 15
Our long-standing RewriteLab research pages have been completely redesigned! A huge thanks to @OpenAI for helping with the design! ❤️ You can now check out the new look at: rewritelab.org/research Stay tuned for the new research we'll be publishing in the future as well : )
8
1
28
1,670
RewriteLab
@RewriteLab
Jul 5
🚨 Bounty Update Someone solved the challenge in just 58 minutes using an unintended solution. (It was a completely unexpected approach—seriously impressive!) However, they kindly said the bounty should go to the first person who solves it via the intended path, and voluntarily declined the reward. (Huge thanks for the incredible sportsmanship!) The bounty is still open. 🎉 That said, I'm adding one new rule: ✅ The challenge must be solved via the intended solution path. (The current unintended path will be patched soon.) If you solve the challenge, please open a ticket and explain your solution. If it matches the intended path, you'll receive the bounty.
RewriteLab
@RewriteLab
Jul 5
🚨 OPEN BOUNTY — $300 Can your AI agent solve an unsolved CTF challenge? We launched the damn-vulnerable-web on February 1st, and one challenge has remained at 0 solves for over 5 months despite the rise of LLM slopping. This bounty is only available until the end of July. Challenge: chronostasis First Blood: 200 USDT 300 USDT if you solve it using a fully autonomous LLM agent ("pure slopping") and can demonstrate the complete solving process. Still sitting at 0 solves. Huge respect to @icesfont2 for creating such an insane challenge 👏 Bring your best agent. Let it cook!
4
2
50
7,993
RewriteLab
@RewriteLab
Jul 5
You can try the challenge here : wargame.rewritelab.org
7
2,817
RewriteLab
@RewriteLab
Jul 5
🚨 OPEN BOUNTY — $300 Can your AI agent solve an unsolved CTF challenge? We launched the damn-vulnerable-web on February 1st, and one challenge has remained at 0 solves for over 5 months despite the rise of LLM slopping. This bounty is only available until the end of July. Challenge: chronostasis First Blood: 200 USDT 300 USDT if you solve it using a fully autonomous LLM agent ("pure slopping") and can demonstrate the complete solving process. Still sitting at 0 solves. Huge respect to @icesfont2 for creating such an insane challenge 👏 Bring your best agent. Let it cook!
11
19
2
219
30,738
RewriteLab
@RewriteLab
Jun 12
We published a new research article on the Chromium 146 Renderer Process! In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE. Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research! Check out the PoC! Full article: research.rewritelab.org/2026…
1
34
169
12,810
RewriteLab
@RewriteLab
Apr 3
We published a new research article on prompt injection in modern agentic systems This write-up covers: - direct and indirect prompt injection - multi-turn attack methodology - tool-calling and MCP-related abuse cases - case studies including WhatsApp MCP, GitHub MCP, and OpenClaw mitigation strategies such as permission segmentation, - sandboxing, PTC, and HITL Our goal was to provide a structured overview of how these attacks work and how they can be addressed in practice Full write-up: research.rewritelab.org/2026…
2
9
25
2,009
RewriteLab
@RewriteLab
Mar 25
We’ve launched our main page!! Huge thanks to our frontend developer and designer @GeminiApp 😆 rewritelab.org
2
11
1,160
RewriteLab
@RewriteLab
Mar 16
D-10 !!!!!
RewriteLab
@RewriteLab
Mar 9
[ RewriteLab Web Security Research Team, 2026 First Half Researcher Recruitment ] Rewrite is a specialized web security research team composed of web hackers from around the world. Researchers from various regions including Korea, Europe, Asia, and Africa collaborate to conduct in-depth research on the latest web exploitation techniques and technologies, while also working on a range of web security related projects We are now publicly recruiting new researchers who would like to join RewriteLab and conduct research together with us For detailed information about the recruitment requirements and the application process, please refer to the recruitment page below! recruit.rewritelab.org
1
10
2,243
RewriteLab
@RewriteLab
Mar 9
We have successfully published a new research article! This research takes an in-depth look at several interesting security incidents that occurred in 2025 and analyzes them in detail While some of these incidents were already widely known, this research focuses more closely on cases that people may have only glanced over without examining thoroughly Special thanks to One, TCP/IP, and @filime_sec for conducting this research! We hope it receives a lot of interest! : ) research.rewritelab.org/2026…
9
20
1,829
RewriteLab
@RewriteLab
Mar 9
[ RewriteLab Web Security Research Team, 2026 First Half Researcher Recruitment ] Rewrite is a specialized web security research team composed of web hackers from around the world. Researchers from various regions including Korea, Europe, Asia, and Africa collaborate to conduct in-depth research on the latest web exploitation techniques and technologies, while also working on a range of web security related projects We are now publicly recruiting new researchers who would like to join RewriteLab and conduct research together with us For detailed information about the recruitment requirements and the application process, please refer to the recruitment page below! recruit.rewritelab.org
13
2
71
11,683
RewriteLab
@RewriteLab
Feb 1
Hello! We’ve just launched a new wargame site called damn vulnerable web! It consists only of web challenges, primarily designed for intermediate to advanced players rather than beginners. We hope this wargame helps more people gain deeper and broader knowledge in web hacking :) For now, we’re planning to accept only 300 users initially for open beta testing and capacity checks. Starting from this tweet, we’ll gradually increase the number of allowed sign-ups each week. Your interest and support will be a huge help to our future activities We’ll do our best to deliver even better work going forward. Thank you! Wargame site: wargame.rewritelab.org Join our Discord: discord.gg/wYAm2n4M4J
6
90
5
514
28,809
RewriteLab
@RewriteLab
31 Dec 2025
We’ve published a new article! This is a full writeup of the web challenges from the SECCON 14 Qual round. It has been written in detail so that readers can understand the core concepts and techniques even if they did not attempt the challenges themselves. We would like to express our sincere gratitude to the researchers @Predic02 , @masamunee2003 , @ElleuchX1 , and @ irogir for their hard work on this writeup. To everyone reading this, we wish you a very happy New Year 2026! We’re planning to release something new that we’ve been preparing between January and February, so please stay tuned and show lots of interest : )
1
8
2
16
2,669
RewriteLab
@RewriteLab
24 Sep 2025
We have successfully published our third research! This research focuses on diving deep into the Spring framework. Spring is an important framework used by many companies. However, since the Spring framework doesn't frequently appear in challenges, we expect many people are unfamiliar with it Through this research, we conducted an in-depth study of the Spring framework centered on case studies - what the Spring framework is and what actual bug cases have occurred. We hope it receives a lot of interest! : )
1
5
10
1,328
RewriteLab
@RewriteLab
25 Aug 2025
We have published a new article! You can check out the research in both Korean and English versions below :) This article is not research, but a complete writeup of the web challenges from the CODEGATE 2025 final round. We have organized it in as much detail as possible so that you can understand the core concepts even without code comprehension of the challenges We will show more activities going forward. Please show us lots of interest and look forward to it! We deeply appreciate @goldleo01 and @Predic02 for their hard work in writing the writeup
1
10
16
1,875
RewriteLab
@RewriteLab
29 Jul 2025
We have successfully published our second research! This research focuses on various XSLeaks techniques through real case studies. It explains why XSLeaks are dangerous in the real world and how XSLeaks techniques can be utilized in challenges such as CTFs. This is a series research consisting of 3 parts! We hope it will attract a lot of interest :)
1
6
1
14
1,757
RewriteLab
@RewriteLab
29 Jul 2025
We have successfully published our first research! This research conducts an in-depth study of potential security vulnerabilities and issues in the Next.js framework. We highlight security vulnerabilities in Next.js based on various CVEs and case studies.
1
6
1
10
1,455