XENOPS
Blog Tags
Blog Tags
Tag Archive

PHP

Zend internals, runtime behavior, and application security research around PHP systems.

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500
Aug 08, 2026
XENOPS Research

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500

IceWarp's X-File-Operation RCE (CVE-2025-14500) is really a missing null-byte check in the FastCGI parameter builder. One null byte in a request is enough for unauthenticated code execution as root.

  • Reverse Engineering
  • PHP
  • Penetration Testing
Breaking the Cube: Under the Hood of ionCube Loader
Mar 06, 2026
XENOPS Research

Breaking the Cube: Under the Hood of ionCube Loader

Reverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.

  • Reverse Engineering
  • PHP
  • ionCube
XENOPS © 2026 XENOPS. All rights reserved. RSS Sitemap