<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.hspace.io/</id><title>HSPACE Tech Blog</title><subtitle>hspace</subtitle> <updated>2026-07-20T18:33:15+09:00</updated> <author> <name>hspace</name> <uri>https://blog.hspace.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.hspace.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="ko-KR" href="https://blog.hspace.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 hspace </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Keycloak Admin UI Extension brute-force-user 권한 검증 우회 분석</title><link href="https://blog.hspace.io/posts/keycloak/" rel="alternate" type="text/html" title="Keycloak Admin UI Extension brute-force-user 권한 검증 우회 분석" /><published>2026-07-04T00:00:00+09:00</published> <updated>2026-07-04T00:00:00+09:00</updated> <id>https://blog.hspace.io/posts/keycloak/</id> <content src="https://blog.hspace.io/posts/keycloak/" /> <author> <name>양진영(yd1ng)</name> </author> <category term="Web Security" /> <category term="Server Side" /> <summary>Keycloak 26.6.3 FGAP v2 환경에서 query-users 권한만 가진 제한 관리자가 Admin UI extension endpoint를 통해 숨겨진 사용자 정보를 조회할 수 있는 권한 검증 우회 사례를 분석합니다.</summary> </entry> <entry><title>2026 SpaceWar#1 (AI) 풀이</title><link href="https://blog.hspace.io/posts/space-war-2026-ai-write-up/" rel="alternate" type="text/html" title="2026 SpaceWar#1 (AI) 풀이" /><published>2026-05-09T19:00:00+09:00</published> <updated>2026-05-09T19:00:00+09:00</updated> <id>https://blog.hspace.io/posts/space-war-2026-ai-write-up/</id> <content src="https://blog.hspace.io/posts/space-war-2026-ai-write-up/" /> <author> <name>HSPACE</name> </author> <category term="Tech" /> <category term="CTF" /> <category term="AI" /> <summary>HSPACE에서 출제한 2026 SpaceWar AI 문제 5종 풀이입니다.</summary> </entry> <entry><title>OpenEXR libOpenEXRCore 취약점 발견 및 분석 with Fuzzing</title><link href="https://blog.hspace.io/posts/OpenEXR/" rel="alternate" type="text/html" title="OpenEXR libOpenEXRCore 취약점 발견 및 분석 with Fuzzing" /><published>2026-05-07T00:00:00+09:00</published> <updated>2026-05-07T00:00:00+09:00</updated> <id>https://blog.hspace.io/posts/OpenEXR/</id> <content src="https://blog.hspace.io/posts/OpenEXR/" /> <author> <name>이재영(Finder)</name> </author> <category term="Vulnerability Research" /> <category term="Fuzzing" /> <summary>HSPACE Knights Frontier의 OpenEXR libOpenEXRCore AFL++ 퍼징 하네스 설계 및 취약점 분석 연구 내용입니다.</summary> </entry> <entry><title>2026 제5회 한양 해킹방어대회 HCTF with HSPACE 풀이</title><link href="https://blog.hspace.io/posts/hctf-2026-writeup/" rel="alternate" type="text/html" title="2026 제5회 한양 해킹방어대회 HCTF with HSPACE 풀이" /><published>2026-02-11T00:00:00+09:00</published> <updated>2026-02-11T00:00:00+09:00</updated> <id>https://blog.hspace.io/posts/hctf-2026-writeup/</id> <content src="https://blog.hspace.io/posts/hctf-2026-writeup/" /> <author> <name>HSPACE</name> </author> <category term="CTF" /> <category term="Writeup" /> <summary>제 5회 HCTF 풀이입니다.</summary> </entry> <entry><title>폰트 라이브러리 취약점 발견 및 분석 with Fuzzing</title><link href="https://blog.hspace.io/posts/font-fuzzing/" rel="alternate" type="text/html" title="폰트 라이브러리 취약점 발견 및 분석 with Fuzzing" /><published>2026-02-04T00:00:00+09:00</published> <updated>2026-02-04T00:00:00+09:00</updated> <id>https://blog.hspace.io/posts/font-fuzzing/</id> <content src="https://blog.hspace.io/posts/font-fuzzing/" /> <author> <name>이재영(Finder)</name> </author> <category term="Vulnerability Research" /> <category term="Fuzzing" /> <summary>HSPACE Knights Frontier의 폰트 라이브러리 취약점 연구 내용입니다.</summary> </entry> </feed>
