Container Escape Class Lessons (CVE-2022-0185-Era Themes)

Lab capsh –print and docker inspect seccomp/AppArmor, dropped caps, failed mount — no escape exploit.

February 13, 2026 · 6 min · 1155 words · Jose Adalberto Gutierrez Ochoa

Dirty Pipe Class Analysis for Defenders

Toy splice/pipe lab on a temp file we own, uname -r vs CVE-2022-0847, SIGSEGV on a PROT_READ map — not a setuid hijack.

March 3, 2022 · 8 min · 1571 words · Jose Adalberto Gutierrez Ochoa

ASLR, PIE Bias, and a Lab Pointer Leak

/proc/self/maps across runs, gdb measurement of PIE load bias, a toy %p leak of a text pointer. Entropy is what remains after the leak — no exploit chain.

November 20, 2019 · 8 min · 1558 words · Jose Adalberto Gutierrez Ochoa

Linux LKM and Syscall Hooking Concepts for Defenders

Lab LKM that logs openat on a VM, insmod/rmmod, dmesg artifacts — module does not hide files or hook the table for concealment.

September 14, 2019 · 6 min · 1196 words · Jose Adalberto Gutierrez Ochoa

Format String Lab: Leak, Crash, and the %s Patch

Toy printf(user) lab: gdb dump of stack words matching a %p leak (canary included conceptually), SIGSEGV from %s, ASan on a sprintf companion, patched printf("%s", user).

May 8, 2019 · 8 min · 1565 words · Jose Adalberto Gutierrez Ochoa