<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>davidrochester</title><link>https://davidrochester.com/</link><description>Recent content on davidrochester</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 20 May 2026 00:00:00 -0600</lastBuildDate><atom:link href="https://davidrochester.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Container Escape via Inference: Two Vulnerabilities in Docker Model Runner</title><link>https://davidrochester.com/posts/container-escape-via-inference/</link><pubDate>Wed, 20 May 2026 00:00:00 -0600</pubDate><guid>https://davidrochester.com/posts/container-escape-via-inference/</guid><description>Two container-to-host RCE vulnerabilities in Docker. vllm-metal hardcoded trust_remote_code=True, letting a malicious model execute arbitrary Python on the host. When Docker quietly patched it, we found mlx-lm doing the same thing through an importlib path with no gate at all.</description></item><item><title>Arbitrary File Read in Ollama via Tensor Digest Path Traversal</title><link>https://davidrochester.com/posts/cve-2026-7020/</link><pubDate>Sat, 25 Apr 2026 00:00:00 -0600</pubDate><guid>https://davidrochester.com/posts/cve-2026-7020/</guid><description>Arbitrary file read in Ollama via tensor digest path traversal. A malicious OCI registry can trick Ollama into exfiltrating any file on the host — including SSH private keys — in three unauthenticated API calls.</description></item><item><title>From SSRF to Data Exfiltration in Ollama</title><link>https://davidrochester.com/posts/cve-2026-5530/</link><pubDate>Thu, 09 Apr 2026 00:00:00 -0600</pubDate><guid>https://davidrochester.com/posts/cve-2026-5530/</guid><description>SSRF in Ollama&amp;rsquo;s OCI registry redirect handling. A malicious registry can redirect blob downloads to internal endpoints, bypass hash verification, and exfiltrate full responses via the push API.</description></item><item><title>SSRF and Token Theft in Docker Model Runner</title><link>https://davidrochester.com/posts/cve-2026-33990/</link><pubDate>Sun, 29 Mar 2026 23:19:00 -0600</pubDate><guid>https://davidrochester.com/posts/cve-2026-33990/</guid><description>SSRF in Docker Model Runner&amp;rsquo;s OCI authentication flow. A malicious registry can redirect the token exchange to scan internal networks and exfiltrate tokens during a model pull.</description></item><item><title>No Pairing Required: Unauthorized Image Uploads to the smART Sketcher 2.0</title><link>https://davidrochester.com/posts/cve-2026-0842/</link><pubDate>Fri, 09 Jan 2026 23:19:00 -0600</pubDate><guid>https://davidrochester.com/posts/cve-2026-0842/</guid><description>Missing authentication in the smART Sketcher 2.0 allows anyone within Bluetooth range to send arbitrary images to a child&amp;rsquo;s toy without any pairing or authorization.</description></item><item><title>HTB Season 9 - Signed</title><link>https://davidrochester.com/posts/htb-season-9-signed/</link><pubDate>Tue, 14 Oct 2025 23:32:00 -0400</pubDate><guid>https://davidrochester.com/posts/htb-season-9-signed/</guid><description>HTB Season 9. Signed is a Medium Windows Active Directory box involving MSSQL enumeration, Silver Ticket forging, and NTLM reflection via CVE-2025-33073.</description></item><item><title>CMU Binary Bomb Lab - Phase 6</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-6/</link><pubDate>Mon, 19 Aug 2024 23:27:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-6/</guid><description>Phase 6 of the CMU Binary Bomb. Reversing a linked list sorting algorithm to find the correct node ordering and defuse the final bomb.</description></item><item><title>CMU Binary Bomb Lab - Phase 5</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-5/</link><pubDate>Sat, 17 Aug 2024 23:27:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-5/</guid><description>Phase 5 of the CMU Binary Bomb. Mapping an array lookup chain to find the input that iterates exactly 15 times and lands on 0xF.</description></item><item><title>CMU Binary Bomb Lab - Phase 4</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-4/</link><pubDate>Fri, 16 Aug 2024 23:27:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-4/</guid><description>Phase 4 of the CMU Binary Bomb. Using Ghidra to decompile a recursive function and trace the call tree to find the correct input.</description></item><item><title>CMU Binary Bomb Lab - Phase 3</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-3/</link><pubDate>Fri, 16 Aug 2024 15:16:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-3/</guid><description>Phase 3 of the CMU Binary Bomb. Tracing sscanf format strings and conditional jumps to find the correct two-number input.</description></item><item><title>CMU Binary Bomb Lab - Phase 2</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-2/</link><pubDate>Fri, 16 Aug 2024 07:59:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-2/</guid><description>Phase 2 of the CMU Binary Bomb. Reverse engineering a doubling algorithm that expects the sequence 1 2 4 8 16 32.</description></item><item><title>CMU Binary Bomb Lab - Phase 1</title><link>https://davidrochester.com/posts/cmu-binary-bomb-phase-1/</link><pubDate>Thu, 15 Aug 2024 23:19:00 -0600</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-phase-1/</guid><description>Phase 1 of the CMU Binary Bomb. Using WinDbg to find a plaintext string comparison and defuse the first phase.</description></item><item><title>CMU Binary Bomb Lab - Introduction</title><link>https://davidrochester.com/posts/cmu-binary-bomb-introduction/</link><pubDate>Thu, 15 Aug 2024 23:19:00 -0400</pubDate><guid>https://davidrochester.com/posts/cmu-binary-bomb-introduction/</guid><description>Introduction to the CMU Binary Bomb reverse engineering challenge. Background on the lab, tools used, and what to expect across all 6 phases.</description></item><item><title>Want to Overflow Buffers?</title><link>https://davidrochester.com/posts/want-to-overflow-buffers/</link><pubDate>Fri, 09 Aug 2024 23:32:00 -0400</pubDate><guid>https://davidrochester.com/posts/want-to-overflow-buffers/</guid><description>Walkthrough of the &amp;lsquo;bof&amp;rsquo; challenge from pwnable.kr. Analyzing the stack layout in Ghidra and crafting a buffer overflow payload to overwrite a function parameter.</description></item><item><title>Introducing Myself and File Descriptors</title><link>https://davidrochester.com/posts/introducing-myself-and-file-descriptors/</link><pubDate>Sun, 04 Aug 2024 14:00:00 -0400</pubDate><guid>https://davidrochester.com/posts/introducing-myself-and-file-descriptors/</guid><description>Walkthrough of the &amp;lsquo;fd&amp;rsquo; challenge from pwnable.kr. Exploiting file descriptors to redirect stdin and grab the flag.</description></item><item><title>About</title><link>https://davidrochester.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://davidrochester.com/about/</guid><description>&lt;p&gt;I&amp;rsquo;m David Rochester, a Software and Security Engineer, as well as an independent security researcher focusing on AI, cloud, and software security. I studied computer science in undergrad and found a passion for cybersecurity, specifically offensive cybersecurity. I&amp;rsquo;m currently pursuing my master&amp;rsquo;s in computer science with a focus on AI at the University of Texas at Austin. I have some security certifications and a few CVEs, most notably in Docker and Ollama. I enjoy writing code and hacking things, whether it&amp;rsquo;s new toys my kids get, new technology my wife brings home, or anything else I find interesting. I occasionally participate in CTFs, but recently my efforts have been focused on researching OSS for novel vulnerabilities and on AI security research.&lt;/p&gt;</description></item><item><title>CMU Binary Bomb Lab: Complete Walkthrough</title><link>https://davidrochester.com/series/binary-bomb/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://davidrochester.com/series/binary-bomb/</guid><description>Start with the introduction, then work through all six Binary Bomb phases in order.</description></item></channel></rss>