<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://incendium.rocks/</id><title>Remco van der Meer</title><subtitle>Security blog of Remco van der Meer</subtitle> <updated>2026-08-13T21:40:55+02:00</updated> <author> <name>Remco van der Meer</name> <uri>https://incendium.rocks/</uri> </author><link rel="self" type="application/atom+xml" href="https://incendium.rocks/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://incendium.rocks/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Remco van der Meer </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Understanding safeguards/guardrails for cybersecurity work to not get blocked</title><link href="https://incendium.rocks/posts/bypassing-guardrails-for-cybersecurity-work/" rel="alternate" type="text/html" title="Understanding safeguards/guardrails for cybersecurity work to not get blocked" /><published>2026-08-13T15:31:14+02:00</published> <updated>2026-08-13T21:40:19+02:00</updated> <id>https://incendium.rocks/posts/bypassing-guardrails-for-cybersecurity-work/</id> <content type="text/html" src="https://incendium.rocks/posts/bypassing-guardrails-for-cybersecurity-work/" /> <author> <name>remco</name> </author> <category term="Research" /> <category term="AI" /> <summary>Hitting AI guardrails on frontier models is annoying, therefore this blog explains them and describes how to work around them.</summary> </entry> <entry><title>Recursively fuzzing MS-RPC structures and monitoring using ETW</title><link href="https://incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/" rel="alternate" type="text/html" title="Recursively fuzzing MS-RPC structures and monitoring using ETW" /><published>2026-05-04T05:33:00+02:00</published> <updated>2026-05-04T05:33:00+02:00</updated> <id>https://incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/</id> <content type="text/html" src="https://incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/" /> <author> <name>remco</name> </author> <category term="Research" /> <category term="Windows" /> <category term="Exploit" /> <summary>Updates to the MS-RPC fuzzer includes fuzzing over complex structures and logging using ETW and we found a way to escalate to nt authority\system!</summary> </entry> <entry><title>Remotely crashing the Spooler service</title><link href="https://incendium.rocks/posts/Remotely-crashing-spooler/" rel="alternate" type="text/html" title="Remotely crashing the Spooler service" /><published>2025-11-19T04:33:00+01:00</published> <updated>2025-11-19T20:03:38+01:00</updated> <id>https://incendium.rocks/posts/Remotely-crashing-spooler/</id> <content type="text/html" src="https://incendium.rocks/posts/Remotely-crashing-spooler/" /> <author> <name>remco</name> </author> <category term="Research" /> <category term="Windows" /> <category term="Exploit" /> <summary>Showcasing a vulnerability in Windows that causes the Spooler service to crash remotely.</summary> </entry> <entry><title>Deleting the BCD through COM as low privileged user (external)</title><link href="https://incendium.rocks/posts/CVE-2025-59253/" rel="alternate" type="text/html" title="Deleting the BCD through COM as low privileged user (external)" /><published>2025-11-15T04:33:00+01:00</published> <updated>2025-11-27T21:26:26+01:00</updated> <id>https://incendium.rocks/posts/CVE-2025-59253/</id> <content type="text/html" src="https://incendium.rocks/posts/CVE-2025-59253/" /> <author> <name>remco</name> </author> <category term="Research" /> <category term="Windows" /> <summary>CVE-2025-59253: Demonstrating a vulnerability in Windows that leads to a low privileged user being able to delete the boot configuration data (BCD) through COM.</summary> </entry> <entry><title>Automating COM/DCOM vulnerability research</title><link href="https://incendium.rocks/posts/Automating-COM-Vulnerability-Research/" rel="alternate" type="text/html" title="Automating COM/DCOM vulnerability research" /><published>2025-10-30T04:33:00+01:00</published> <updated>2025-10-30T04:33:00+01:00</updated> <id>https://incendium.rocks/posts/Automating-COM-Vulnerability-Research/</id> <content type="text/html" src="https://incendium.rocks/posts/Automating-COM-Vulnerability-Research/" /> <author> <name>remco</name> </author> <category term="Research" /> <category term="Windows" /> <summary>Diving into COM/DCOM and how to automate vulnerability research using a fuzzing approach.</summary> </entry> </feed>
