<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>blog.z3r.ru</title><link>https://blog.z3r.ru/</link><description>Recent content on blog.z3r.ru</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 16 Nov 2025 23:00:00 +0300</lastBuildDate><atom:link href="https://blog.z3r.ru/index.xml" rel="self" type="application/rss+xml"/><item><title>[CVE-2026-25628] Qdrant arbitrary file write to RCE</title><link>https://blog.z3r.ru/posts/qdrant-rce/</link><pubDate>Sun, 16 Nov 2025 23:00:00 +0300</pubDate><guid>https://blog.z3r.ru/posts/qdrant-rce/</guid><description>Writeup for Qdrant Remote code execution vulnerability</description></item><item><title>[CVE-2025-41243] Spring Cloud Gateway: complicating evaluation context</title><link>https://blog.z3r.ru/posts/spring-cloud-gateway-spel-vuln/</link><pubDate>Sun, 21 Sep 2025 00:00:00 +0300</pubDate><guid>https://blog.z3r.ru/posts/spring-cloud-gateway-spel-vuln/</guid><description>Bypassing some restrictions in Spring Cloud Gateway filters to DoS, secrets leak or RCE</description></item><item><title>VolgaCTF 2025: s3waaas writeup</title><link>https://blog.z3r.ru/posts/volgactf2025-s3waaas/</link><pubDate>Wed, 17 Sep 2025 18:55:00 +0400</pubDate><guid>https://blog.z3r.ru/posts/volgactf2025-s3waaas/</guid><description>Writeup for VolgaCTF 2025 A/D service s3waaas, a vulnerable S3 implementation with analytics via ClickHouse</description></item><item><title>Bypassing Content-Disposition: attachment</title><link>https://blog.z3r.ru/posts/content-disposition-attachment-bypass/</link><pubDate>Wed, 28 May 2025 02:20:39 +0300</pubDate><guid>https://blog.z3r.ru/posts/content-disposition-attachment-bypass/</guid><description>Exploring techniques to bypass Content-Disposition: attachment header restrictions.</description></item><item><title>About me</title><link>https://blog.z3r.ru/about/</link><pubDate>Fri, 23 May 2025 00:20:39 +0300</pubDate><guid>https://blog.z3r.ru/about/</guid><description>&lt;p&gt;Hello. My name is Egor Zonov aka ezzer. I play CTFs with the
&lt;a href="https://ctftime.org/team/586"&gt;Bushwhackers&lt;/a&gt; team, work in application security
and sometimes do vulnerability research. You can find some of my work on this
website.&lt;/p&gt;
&lt;div class="socialNavbar" style="text-align: center;"&gt;
 &lt;ul style="display: inline-block; margin: 0; padding: 0;"&gt;
 &lt;li&gt;
 &lt;a href="https://github.com/Ezzer17" target="_blank" aria-label="GitHub" title="github"&gt;
 GitHub
 &lt;/a&gt;
 &lt;/li&gt;
 &lt;li&gt;
 &lt;a href="https://x.com/ez_z3r"&gt;X&lt;/a&gt;
 &lt;/li&gt;
 &lt;li&gt;
 &lt;a href="https://t.me/z3rblog" rel="Blog"&gt;Telegram Blog&lt;/a&gt;
 &lt;/li&gt;
 &lt;li&gt;
 &lt;a href="mailto:zonoveg@gmail.com"&gt;email&lt;/a&gt;
 &lt;/li&gt;
 &lt;li&gt;
 &lt;a href="https://blog.z3r.ru/index.xml" target="_blank" aria-label="RSS" title="RSS"&gt;
 RSS
 &lt;/a&gt;
 &lt;/li&gt;
 &lt;/ul&gt;
&lt;/div&gt;</description></item><item><title>Apport Lpe</title><link>https://blog.z3r.ru/posts/apport-lpe/</link><pubDate>Fri, 23 May 2025 00:20:39 +0300</pubDate><guid>https://blog.z3r.ru/posts/apport-lpe/</guid><description>Investigating a local privilege escalation vulnerability in Ubuntu&amp;rsquo;s Apport crash reporting system.</description></item></channel></rss>