As with any recent domain, I’ve heard the term “AI pentesting” more often than one would want to. From my perspective, it feels tiring to hear that artificial intelligence touches every conceivable subject. While I am on the side of using it consciously, if at all, I will try to keep my biases in...
Following my previous case study on Windows application security testing, I returned to my area of expertise: web applications. Familiarity doesn’t guarantee ease, particularly when facing deadlines and a client who’s had their web application penetration tested twice in the past four years. This...
During my OSCE exam preparation I had to deal with shellcode writing experience where very few allower characters were available. This brilliant talk by @muts, lead us to get in touch with a new encoding technique. When you can’t directly write words on the stack, due to bad characters, you can...