Research
Published work from the MadX lab: proxy and VPN network analysis, adversary infrastructure, internet measurement, and applied security engineering. Follow along via Atom feed.
-
Ollama Probllama: The Internet-Exposed Models Trying to Steal Your Creds... and Mostly Failing
A first-party characterization of 616 internet-exposed Ollama servers. Two automated abuse campaigns and a honeypot show up, but the credential harvesting everyone fears overwhelmingly fails. Every real secret in the data was a planted decoy. The durable risk isn't the model, it's the writable API in front of it.
-
Zero Hits, One Node: Hunting Browser Proxyware When Your Signatures Are Wrong
How we hunt bandwidth-reseller extensions across a store with no index, why static analysis quietly fails on them, the sandbox that lets us confirm behavior without becoming a node, and the uncomfortable result. Most of what we tested wasn't a proxy node, and the one that was, our signatures missed.
-
A Hola-t of Proxies: The 'Free VPN' Feeding Bright Data
We watched the Hola VPN Chrome extension register a browser's IP into Bright Data's commercial residential-proxy pool, with Bright Data's own code loading off Hola's welcome page. An independent team found the same network on smart TVs. Different platform, one supply chain.
-
Touching Grass: A Browser Extension That Enrolls You as a Proxy Node
We loaded the Grass browser extension in an instrumented, sandboxed browser and watched it enroll a logged-out user as a residential-proxy exit node, then get handed a relay target. Here is the traffic, the protocol, and the indicators.
-
Anatomy of a Residential Proxy Network: Who Is Really Behind That IP?
How residential proxy networks recruit everyday devices into rentable exit nodes, why they break IP-based trust, and how defenders can spot them.