Pokazywanie postów oznaczonych etykietą ctf. Pokaż wszystkie posty
Pokazywanie postów oznaczonych etykietą ctf. Pokaż wszystkie posty

wtorek, 9 czerwca 2026

WatchGuard BruteForce

Some time ago I wrote a post and a small script to run a brute force attack against FortiGate appliances. (Link to that post you can find here). This time I decided to check if similar bug is present in latest WatchGuard appliance (FireboxV, version 12.12). Below you'll find the details and poc code to test it in your own LAB. Below you'll find more details about it. Here we go...

sobota, 6 czerwca 2026

Building BHADGUI: Automating BloodHound Data Collection for AD Attack Paths

When you're doing Active Directory pentesting on a tight schedule, running SharpHound manually and then clicking through BloodHound's UI gets old fast. BHADGUI started as a simple wrapper and evolved into something more useful.

Hack The Box - Reactor

Reactor is an 'easy' Linux CTF machine from Season 11 at Hack The Box platform. Few days ago I decided to check it. Below you'll find more details about it. Here we go...

niedziela, 23 lutego 2025

Python GUI from AI

After a while I decided to look back again at the Python's GUI in Tkinter. Below you'll find few notes about it. Here we go...

wtorek, 22 października 2024

Hack The Box - Instant

Few days ago I had a pleasure to check one of the Hack The Box 'Season 6' machine called Instant. Few details about it you will find below. Here we go...

środa, 11 września 2024

niedziela, 21 kwietnia 2024

Few notes from CTF@CIT

During this weekend I had a moment to read what's new at CTFTime and that's how I found CTF@CIT prepared by HACK@CIT. Below you'll find few notes about it. Here we go...

czwartek, 20 kwietnia 2023

Bruting FortiGates

After my previous adventures with FortiGate VM's I decided to check it again and finally finish some of the ideas I was talking about during the last The Hack Summit Conference (PL, 2022). One of them was to bypass FortiGate's "anti-bruteforce protection". Below you'll find the details about it. Here we go...

środa, 6 kwietnia 2022

Pentesting Pentesters with MSF Jump Host

Let's think about the scenario for a pentest/redteam project during which we are using 'our dedicated jump host'. "What if" someone will takeover this host? This time we'll try to check the potential results of this kind of attack. Here we go...

piątek, 15 października 2021

Postauth Chained RCE with Nagios IM

Some time ago I started searching for bugs in NagiosIX. Few days ago I decided to continue my "research" and that's how I landed with NagiosIM (2.0.0 afaik ;)). Below you'll find few notes about it. :) Here we go...

czwartek, 14 października 2021

Pentesting Jenkins

Some time ago I started a small project called 'enlil'. As you already know - I'm using it during pentests and redteam projects. Below you'll find few notes about the test prepared for Jenkins. Here we go...

piątek, 13 sierpnia 2021

Kernel: Jump into Device

In previous post about kernel I tried to start with some basic kernel modules. Below we'll continue - this time with so called 'devices'. Here we go...

środa, 11 sierpnia 2021

Bounty CORSare

Few days ago someone asked me about CORS-related vulnerabilities. I decided it will be a good idea o try to create a small tool. Below you'll find the whole story. Here we go...

sobota, 7 sierpnia 2021

Kernel: Introduction

Few weeks ago I was invited by one Team to participate as a "guest" during some international CTF competition. Spoiler alert: as I failed strongly during kernel pwn challenges;) (read as: 'mostly all that I tried' ;)) I decided to 'go back' and learn more (to 'try harder' "next time" ;))... Below you'll find few notes from the journey. Here we go...

poniedziałek, 14 czerwca 2021

Crashing Aspire 9.5

Hi :) This time I decided to publish few details from one of the fuzzing I runned for a while some about 2 weeks ago. Below you'll find 3 bugs I found for Aspire 9.5 software. Here we go...

środa, 19 maja 2021

Creating Simple File Format Fuzzer

Hi ;) This time I decided to present a short draft for the small and simple 'file format fuzzer' I created some time ago. Here we go...

sobota, 15 maja 2021

(Mass) Hunting for domains

Hi ;) During one of the CTFs I decided to check a domain enumeration tool called massdns. Below you'll find few details and my notes about it. Here we go...

czwartek, 13 maja 2021

Enlil.py - example module

Hi :) last time we talked about wooper.py and enlil.py projects I started some time ago. Since last few weeks I was wondering "what if" we'll combine results from both "proof-of-concepts". Below you'll find few notes about it. Here we go...