Tuesday, 9 June 2026

RoguePlanet, a quick history

 -----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512


In initial development, it was confirmed that this vulnerability was a remote code execution. It required an attacker to coerce a victim to open a .vhd(x) in a remote SMB server, succesful exploitation resulted in defender overwriting its own files and obviously the end outcome was an RCE.

In other scenario, where a victim has symlink evaluation R2L enabled, it was wraps up, RCE was possible by just coercing the victim to open the SMB share, nothing else.


Another scenario was bitlocker bypass, it required specialized device that would push different data to NTFS.sys when defender attempted to read the dirty file, it was possible to redirect the newly remediated file to an arbitrary location and the end result was the same, a full bitlocker bypass.


All of the cases above were verified using a debugger.


Now after mid May, a patch was pushed to Defender in mpengine!SysIO* api that made any junction attacks useless. Rewriting RoguePlanet to make it functional again drained my soul and I couldn't complete the other scenarios and for now it remains unclear if RoguePlanet is limited to LPE or there is some sort of way to turn it into an RCE.

I think the bitlocker bypass might be doable even with the changes but I'm really not sure.


I'm also pretty sure Microsoft will ban the new github account, a special thanks to a great developer who made it possible for us to have our own hosting solution, circumventing Microsoft ridiculous attempts to wipe me out of the internet.


https://git.projectnightcrawler.dev/NightmareEclipse


We are working with the community to provide additional code hosting solutions.

-----BEGIN PGP SIGNATURE-----


iHUEARYKAB0WIQRJTvAf/AWVhAKEeb7FFoRCS0/SbAUCaiiA5AAKCRDFFoRCS0/S

bPS2AQDeuHXCxcn0V2K5Gz9mXQHZPfZv7EYQBXGI0g31OTrXFAD/eg7rOZuJS5HB

uOUnCsQdVpxnqN1hZKgQcZRMAGCUoAE=

=Zlcc

-----END PGP SIGNATURE-----


It's patch Tuesday !!!

 -----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512


Yes the rumors were true, a zero day vulnerability will be dropped this month as well


https://github.com/MSNightmare/RoguePlanet


Yes it's github again, Microsoft forgot that even if they banned my GitLab and Github accounts, they cannot unwrite my code. Once it's public, you can't remove it.


As mentioned in the repo, it's a race condition, I managed to stabilize it as much as I can but writing this PoC geniunely drained my soul. I have worked on this non stop since the start of May, at some point in the second week of May, I managed to get a working prototype but after installing an engine update. The PoC stopped working, Microsoft has invested massive effort to stop me from doing the same thing again and again with Defender.

Unfortunately for them, I was determined to make the PoC work again, for 3 weeks, I did not eat, I did not drink water, I even forgot what outside looked like. I slept for 3 hours after 96 hours of non stop continuous work. Getting this PoC to work geniunely drained my soul, it severely degraded my mental and physical health but in the end of May, a full PoC was developed.

Microsoft efforts to protect Defender from path redirection attacks are useless, I have a batch of memory corruption vulnerabilities in defender as well and not to mention the other batch of vulnerabilities I have in several other components.


-----BEGIN PGP SIGNATURE-----


iHUEARYKAB0WIQRJTvAf/AWVhAKEeb7FFoRCS0/SbAUCaihqbwAKCRDFFoRCS0/S

bMTsAQCTZZjLuqomDgRUVjDsQCDuITc2tfZ89W3WyXm7HI5NyQD/fkRwxFxGjqj9

3TSY2vFKAePmX9/ZcFwZQUd/45f35Qk=

=9uXs

-----END PGP SIGNATURE-----


Monday, 8 June 2026

It's hard to keep going

 -----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512


I'm starting to genuinely struggle with sleep and constant fevers. I feel like my muscles are degenerating as time passes by lack of nutrition and severe fevers, not mention that I just can't find a reasonable way to put myself as sleep anymore.

The issue of me not sleeping is i end up writing more and more code and it will keep getting worst.


Lord help me.

-----BEGIN PGP SIGNATURE-----


iHUEARYKAB0WIQRJTvAf/AWVhAKEeb7FFoRCS0/SbAUCaic8rwAKCRDFFoRCS0/S

bOGqAP0aVbyHHYzgPRmvCC9Ud5XOsE3Tee6WkNsUqzz2FESC5AEAsvepLtbciukZ

OuwAHKe13vGylrB+wkjGRd1cywP2qgg=

=36Gs

-----END PGP SIGNATURE-----