InformationRoom#Name: CheckmateProfile: tryhackme.comDifficulty: EasyDescription: Exploit weak password practices across Marco’s internal systems to achieve full compromise.Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S legba cewl cupp john ruby var ctx =...
🔍 Master Shodan Like a Pentest & Bug Bounty ProAre you a pentester, bug bounty hunter, or OSINT enthusiast? You’ve probably heard of Shodan—the search engine that doesn’t crawl websites, but scans the entire internet for connected devices. But do you truly know how to harness its power to...
InformationRoom#Name: SupportProfile: tryhackme.comDifficulty: MediumDescription: Pentest the Support Ops platform to exploit vulnerabilities and achieve RCE.Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap ffuf legba curl john var ctx =...
InformationRoom#Name: RecruitProfile: tryhackme.comDifficulty: MediumDescription: Infiltrate Recruit's new portal. Map the site, hunt for flaws, and gain unauthorised accessWrite-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S curl var ctx =...
Last week I closed the lid and went to make dinner. When I came back, a 40-file refactor was done. It ran in tmux on a VM I can snapshot and throw away. I didn't have to sit there and watch it.That only works because of where it ran. The work wasn't on my Windows machine with all my usual keys and...
InformationRoom#Name: Capture!Profile: tryhackme.comDifficulty: EasyDescription: Can you bypass the login form?Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S ruby var ctx = document.getElementById('chart3792').getContext('2d'); var options = { type:...
InformationRoom#Name: OverpassProfile: tryhackme.comDifficulty: EasyDescription: What happens when some broke CompSci students make a password manager?Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap wget ffuf curl htmlq hydra john ruby openssh var ctx =...
InformationRoom#Name: W1seGuyProfile: tryhackme.comDifficulty: EasyDescription: A w1se guy 0nce said, the answer is usually as plain as day.Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S ruby var ctx =...
tl;dr LLMs are bad password generators. They generate “random” strings with predictable, model-specific patterns. The password reveals exactly which model produced it, kind of like a shibboleth. whorl exploits this: Like the whorls that make every human fingerprint unique, each model leaves a...
TL;DR: This article covers a novel way to expand parameter abuse from a detectable misconfiguration into a stealth, second-stage exploit. What is parameter abuse? The team at HiddenLayer wrote an article titled “Exploiting MCP Tool Parameters,” about an MCP risk that has come to be referred to...
Keep your data safe when running AI-powered tools! Introduction AI-powered development tools like Claude Code are incredibly powerful. They can read files, execute commands, modify code, and interact with your system in ways that boost productivity tremendously. However, this power comes with...
InformationRoom#Name: Lesson Learned?Profile: tryhackme.comDifficulty: EasyDescription: Have you learned your lesson?Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap legba var ctx = document.getElementById('chart7275').getContext('2d'); var options =...
Introduction#You have all seen the hype around XBOW: “the AI that climbed 1st on HackerOne leaderboard”.As often, when something new appears or a new critical vulnerability is discovered, everyone is exited and specialized journalists (or influencers) are overexaggerating to create a buzz.In order...
InformationRoom#Name: BillingProfile: tryhackme.comDifficulty: EasyDescription: Some mistakes can be costly.Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap nuclei ffuf pass-station metasploit var ctx =...
InformationRoom#Name: Bypass Disable FunctionsProfile: tryhackme.comDifficulty: InfoDescription: Practice bypassing disabled dangerous features that run operating system commands or start processes.Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap ffuf...
Tweet In the last year, I have taken over a few npm packages that have been abandoned by their original maintainers. One of them, which I published today, is called passport-keycloak-oauth2-oidc-portable, and is a library that extends the original passport-oauth2 strategy to allow authenticating...
InformationRoom#Name: New York FlankeesProfile: tryhackme.comDifficulty: MediumDescription: Can you, the rogue adventurer, break through Stefan's defences to take control of his blog!Write-upOverview#Install tools used in this WU on BlackArch Linux:sudo pacman -S nmap curl rustpad...
InformationRoom#Name: Frosteau Busy with VimProfile: tryhackme.comDifficulty: InsaneDescription: Stay frosty!This is the Side Quest Challenge 3 of Advent of Cyber '23 Side Quest (advanced bonus challenges alongside Advent of Cyber 2023).Write-upOverview#Install tools used in this WU on BlackArch...
SaisonÉpisode17SpotifyDeezerYoutubeYoutube MusicAmazon MusicGoogle PodcastApple PodcastPodcast IndexpodCloudPodchaserpodtailPodcasts FrançaisVodioSpreakerNotes#Avantages alert() :Facilement visiblePas le 1 :Ça ne sert à rienOn ne sait pas d'où ça vient, si on a un formulaire avec 10 champs et...
InformationRoom#Name: The Bandit SurferProfile: tryhackme.comDifficulty: HardDescription: The Bandit Yeti is surfing to town.This is the Side Quest Challenge 4 of Advent of Cyber '23 Side Quest (advanced bonus challenges alongside Advent of Cyber 2023).Write-upOverview#Install tools used in this...