Spaceraccoon's Blog
InfoSec and White Hat Hacking
About π
Eugene Lim is a security researcher and white hat hacker dedicated to hacking for good. From Amazon to Zoom, he has helped secure applications and data from a wide range of critical vulnerabilities. Ranked #2 globally on the HackerOne leaderboard and inducted into the H1-Elite Hall of Fame, his research has been presented at premier conferences like DEF CON, Black Hat USA, and Microsoft BlueHat, and featured in top industry publications including WIRED and The Register. Eugene is the author of From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research (No Starch Press, 2025).
Hackerone | Github | LinkedIn | Twitter
Book π
I’ve published a book with No Starch Press! I wrote “From Day Zero to Zero Day” for newcomers looking to enter the rarefied world of vulnerability research. From code review to reverse engineering to fuzzing, I go through the “how”, not just the “what”, of hunting zero days - stuff that I wish I could’ve learned from the beginning. Available at No Starch Press and all your usual channels including Amazon!
Conferences and Talks π
- DEF CON 33 2025: Escaping the Privacy Sandbox with Client Side Deanonymization Attacks
- Nullcon Goa 2025: Pwning Smart Weighing Machines with API & Hardware Hacking
- Div0 Community Meetup November 2024: Is Shift-Left Dead? The Evolution of Secure Development Tools
- Off-By-One Conference 2024: Universal Code Execution by Chaining Messages in Browser Extensions
- CSIT TechCon 2024: Uncovering Cloud Security Claims with Chaos Testing
- GISEC 2023: Re-Discovering Code Review in Bug Hunting
- DEF CON 30 2022: “You Have One New Appwntment - Hacking Proprietary iCalendar Properties” | Slides | Whitepaper
- DEF CON 30 Recon Village 2022: “(Not-So-Secret) Tunnel: Digging into Exposed ngrok Endpoints”
- DEF CON 30 Cloud Village 2022: “Sign of the Times: Exploiting Poor Validation of AWS SNS SigningCertUrl”
- ShmooCon 2022: “Why No One Pwned Synology at Pwn2Own and TianFu Cup This Year: Analyzing Defensive Coding Techniques from a Vulnerability Researcher’s Perspective”
- HacktivityCon 2021: “All Your (Data)base Are Belong To Us: Getting Started in Vulnerability Research with Code Execution Bugs in Office Applications”
- Black Hat USA 2021: “Turing in a Box: Applying Artificial Intelligence as a Service to Targeted Phishing and Defending Against AI Generated Attacks”
- DEF CON 29 2021: “Hacking Humans with AI as a Service”
- Black Hat USA Arsenal 2020: “Manuka: A modular, scalable OSINT honeypot targeting pre-attack reconnaissance techniques”
- Black Hat Asia Arsenal 2019: “npm-scan: An Extensible, Heuristic-Based Vulnerability Scanning Tool for Installed NPM Packages”
Research π
- CVE-2026-50658: Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2026-50657: Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
- CVE-2026-7865: Command injection in Crestron TSW-xx70 and TSW-1060 touch panels.
- CVE-2026-26461: RCE in Aver PTC320UV2 0.1.0000.65 PTZ camera.
- CVE-2026-0651, CVE-2026-0652, CVE-2026-0653: RCE, Local File Disclosure, and Privilege Escalation on TP-Link Tapo C260
- CVE-2023-41973: Lack of input santisation on Zscaler Client Connector enables arbitrary code execution.
- CVE-2023-41972: Revert password check incorrect type validation on Zscaler Client Connector.
- MSRC Online Services: Injection in Microsoft Whiteboard.
- CVE-2023-5449: Theft Deterrence bypass in HP display monitors.
- CVE-2023-3991: FreshTomato router firmware OS command injection vulnerability.
- CVE-2023-26140: Cross-Site Scripting in Excalidraw.
- CVE-2023-25196, CVE-2023-25197: SQL injections in Apache Fineract
- CVE-2023-0996: Buffer Overflow in heif_js_decode_image in libheif v1.14.2
- GHSA-m4qf-8rrq-mph9: Remote code execution in SONiC (Software for Open Networking in the Cloud) network operating system via buffer overflow.
- CVE-2022-31014: SMTP Command Injection in NextCloud Calendar.
- CVE-2022-24838: SMTP Command Injection in NextCloud Calendar.
- HT213257: Vulnerability in Apple Calendar.
- CVE-2022-22682: Stored XSS in Synology Calendar.
- CVE-2022-22944: VMware Workspace ONE Boxer update addresses a stored cross-site scripting (XSS) vulnerability.
- CVE-2022-24704, CVE-2022-24705: Buffer overflow in Accel-PPP VPN server via crafted packet.
- CVE-2021-43929, CVE-2022-22679, CVE-2021-43925, CVE-2021-43926, CVE-2021-43927, CVE-2022-22680: Various vulnerabilities in Synology DiskStation Manager (NAS OS).
- CVE-2021-43083: Buffer overflow in Apache PLC4X (communication libraries for industrial programmable logic controllers) via crafted packet.
- CVE-2021-38646: Remote code execution in Microsoft Office Access Connectivity Engine via write-what-where gadget.
- CVE-2021-33035: Remote code execution in Apache OpenOffice via return pointer overwrite with DEP/ASLR bypass.
- CVE-2021-42783, CVE-2021-42784: Unauthenticated remote code execution in D-Link DWR-932C router.
- CVE-2021-42785: Buffer Overflow in tvnviewer.exe via Crafted Packet in TightVNC Viewer 2.8.59.
- CVE-2021β35297: Scalabium dBase Viewer Remote Code Execution via Buffer Overflow.
- CVE-2020-7788: Prototype pollution in
inipackage included in core Node.js installer and downloaded 16 million times a week.
Media π
- Sven Dietrich’s review of From Day Zero to Zero Day, by Eugene Lim, IEEE Cipher 187, Sep 25, 2025
- Review: From Day Zero to Zero Day - Help Net Security
- 0-day Hunting Strategy with Eugene βSpaceraccoonβ Lim - Off By One Security
- Critical Thinking Podcast Episode 120
- Jen and Tod on Hacker Summer Camp 2022, Rapid7
- A malicious document could lead to RCE in Apache OpenOffice, Help Net Security
- Apache OpenOffice can be hijacked by malicious documents, fix still in beta, The Register
- Malicious documents can hijack Apache OpenOffice, TechRadar
- AI Wrote Better Phishing Emails Than Humans in a Recent Test, WIRED Magazine
- New npm scanning tool sniffs out malicious code, The Daily Swig
- SQL injection flaw opened doorway to Starbucks’ accounting database, The Daily Swig
- SQL Injection Vulnerability Exposed Starbucks Financial Records, SecurityWeek
- Yale graduate earns $11,000 finding bugs by ‘hacking’ into government systems, The Straits Times
- NSF is top hacker in Mindef’s programme that gives cash for discovering software bugs, The Straits Times
- NSF bug hunter wins big, PIONEER Magazine
- Hacking the Singapore Government: A Q&A With A Top Hacker & MINDEF 2.0 Results, HackerOne