Research · Tag · Security Research

Posts tagged security research.

15 entries · sorted: recency← All research
NRDAX
2026-07-16

The overlap is empty

We crosswalked NRDAX against MITRE AADAPT. Twenty-two NRDAX techniques touch AADAPT and none are reproduced. Everything we have reproduced sits where MITRE does not model; everything MITRE models, we have only read about. The empty column is the finding.

Simon Morley
Read →3 min read
NRDAX
2026-07-13

NRDAX: browsable by chain and family, readable by machines

NRDAX now holds 623 techniques across 64 chains, 162 reproduced with bundles. New per-chain and per-family landing pages, a pretty Atom feed, JSON and STIX 2.1 and knowledge-pack distributions surfaced for machines, and a fix for the first_seen date bug.

Simon Morley
Read →2 min read
NRDAX
2026-07-11

NRDAX now includes known-but-not-reproduced techniques

NRDAX v0.1-import now contains 368 techniques across 21 chains: 140 with reproduced instances and bundles, and 228 known from public disclosures (CVEs, GHSAs, vendor advisories) but not yet reproduced in the lab. A CVE maps to its technique even when no bundle exists yet.

Simon Morley
Read →1 min read
NRDAX
2026-07-09

NRDAX: the canonical technique registry for decentralized infrastructure attacks

We have published NRDAX, the NullRabbit Decentralised Attack indeX, at nrdax.com. It is the reference registry for attack techniques against decentralized infrastructure: 135 chain-agnostic techniques, grouped into mechanism families, with a coverage matrix across 21 chains.

Simon Morley
Read →1 min read
SECURITY-RESEARCH
2026-07-07

Eighteen advisories, ten node implementations, one attack class

Since NR-2026-001, eighteen advisories across ten independent node implementations. Not unrelated bugs: one recurring attack class, unauthenticated ingress surfaces where a cheap request forces disproportionate cost. Egress and memory amplification, pre-auth CPU exhaustion, connection exhaustion, and crashes.

Simon Morley
Read →1 min read
CLOUDFLARE
2026-06-26

We slipped a path past Cloudflare's edge. The fix is one checkbox.

Cloudflare resolves dot-segments in a URL only far enough to reject the obvious escapes, then forwards the raw, still-encoded path to your origin, which quietly resolves it the rest of the way. Your edge rules see one path; your server serves another. Cloudflare even warns you about it, in a banner most people scroll past.

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-26

The same method, pointed at the packet path

We took the parser-family lens that finds HTTP smuggling bugs and pointed it at the Linux kernel's network receive path, through Google's sanctioned bug-bounty programs. Then we measured our own opportunity honestly, and the honest answer was 'thin, for now.'

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-25

How we hunt request smuggling without breaking anything

A timing hunch is not a finding. The discipline that separates real desync research from noise is the part nobody photographs: a lab of real proxies, a back-end you own that logs the literal forwarded bytes, and a hard line about who you're allowed to point any of it at.

Simon Morley
Read →6 min read
SECURITY-RESEARCH
2026-06-24

Meet Keith, and why we're keeping it closed

We built our own HTTP engine from scratch. No normalisation, no typed header map, no helpfulness at all, because a well-behaved client quietly fixes the exact malformations you need to send. Here is what Keith is, and why we changed our minds about open-sourcing it.

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-23

What we build when we're not looking at validators

The method we built for blockchain validator security turns out to be a general-purpose bug-finding method. We've started pointing it at two pieces of infrastructure everyone shares: the open-source HTTP proxy ecosystem, and the Linux kernel's packet path.

Simon Morley
Read →3 min read
SECURITY-RESEARCH
2026-06-22

The h3 FIN/EOM desync, and why your smuggling tool can't send it

HTTP/3 request smuggling is almost unploughed ground. Not because the surface is small, but because nearly every tool speaks h1/h2 only, and the few that speak h3 do it through a conformant QUIC library that won't let you send the bug.

NullRabbit Labs
Read →4 min read
SECURITY-RESEARCH
2026-06-21

Keith, day 0: byte-exact or bust

Starting a build-in-public log for Keith, an HTTP/1.1/2/3 desync prober. The premise: a conformant HTTP client is the wrong tool for finding HTTP parser bugs, because it normalises away exactly the malformed framing you need to send.

NullRabbit Labs
Read →2 min read
SECURITY-RESEARCH
2026-06-09

The 99% was wrong. So was the 0.32.

Our detector's 99% accuracy was memorisation, and the 0.32 we nearly published in its place was wrong too. The clean experiment found the real split: cross-chain detection generalises, attribution doesn't.

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-02

Anyone can knock a validator over once. The skill is designing an attack you can learn from

Making a node fall over is easy and proves nothing. The craft is building a reproducer that isolates the mechanism, measures it against an honest baseline, bounds the cost, and runs on one command, so the number actually means something.

Simon Morley
Read →3 min read
SECURITY-RESEARCH
2026-05-27

How we decide a finding is real before we tell you about it

We had a clean denial-of-service against consensus. Re-verification said the baseline was that low by config. No attack. So we pulled it. The discipline that catches our own mistakes is the reason our advisories are worth reading.

Simon Morley
Read →3 min read