On June 14, 2025, I organized a hardware hacking focused village as part of the ØxOPOSɆC Hack Day, and this is a post-mortem analysis of the village, focusing on some of the observations and common mishaps, and how to improve your journey in the hardware hacking world, especially from...
This is going to get messed up. And, in fact, the goal was order. I recently did some tidying up of my commands and steps for checking a service/pen testing/bounty hunting/hacking/red taming/messing around. I decided to write it down in one place and expand it as needed. Here is my list of steps...
Inspired by the blogpost My Red Team assessment hardware by David Sopas this post describes hardware tools that I have in my inventory, their purpose as well as the features/firmwares/tricks that motivated me to buy them. This is not intended to be an exhaustively detailed list, but I...
Well, I guess it is better late than never, so almost four months after the closing of the OPOSEC XMAS CTF Challenge Christmas 2022 this is my write-up on how I did manage to solve all the challenges and finish in the 4th place. There was a total of...
Couple of weeks back I installed PostmarketOS on my idle phone Leeco Le 1s , which was paper weight for some time now. It all started with a roadtrip to Pondicherry (I will soon write about this trip). As I was sitting on the front seat where Praveen’s Librem 5 kept charging on the car...
Some weeeks ago I’ve participated in the “Portuguese Cybersecurity Competition” organized by InvestAmarante and powered by hackrocks. Given that this was a begginer friendly (maybe too friendly…) Capture The Flag competition there were no major learning takeways, but it is always useful to pratice...
In my previous post, I demonstrated how to gain root access by enabling a Telnet daemon via the router’s AT-over-TCP interface. In this post I will close this gaping security hole by replacing the Telnet with a Secure Shell (SSH) daemon. Netgear’s firmware does not ship with an SSH daemon itself....
This blog post covers the required steps to gain root access via Telnet on Netgear Nighthawk Mobile 5G/LTE Routers. It’s the first post in a small series covering my experiences playing around with this device. Last month I obtained one of Netgear’s latest mobile 5G routers, the Netgear Nighthawk...
Surprisingly, for a memoir about a guy who spends most of his time sitting in front of a computer, Ghost in the Wires: My Adventures as the World’s Most Wanted Hacker is a gripping thrill ride. And it’s a testament to Kevin Mitnick and his co-author, William Simon, that it works. In the wrong...
Introduction: Hello Reviewers, and fellow cybersecurity enthusiasts. Greetings ! I know, you are here to read the write-ups for the Hackerone CTF (h1-702) which is an online jeopardy CTF conducted by the amazing team of Hackerone. If you are a ethical hacker (Good Guys) and have not used Hackerone...
Most of the time when we see a code snippet online to do something, we often blindly copy paste it to the terminal. Even the tech savy ones just see it on the website before copy pasting. Here is why you shouldn't do this. Try pasting the following line to your terminal (SFW) .malicious {...