Mar 06, 2026
XENOPS Research
Breaking the Cube
Reverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.
Long-form analysis, incident notes, and defensive engineering references.
Reverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.
Imported writeup on a :visited-based XS-Leak oracle from AngstromCTF 2024.
A visual smoke test covering images, code blocks, and callout styling.
A repeatable method for surfacing beacon patterns that evade simple interval checks.
Mapping certificate validation gaps across common out-of-band management stacks.
A staged rotation plan that avoids service collapse while removing attacker persistence.
Tracking long-lived tokens that persist after service teardown.
A compact checklist for evaluating escape paths before production rollout.