Writing

Notes & Write-ups

Research notes and field write-ups on exploitation, web security, network tradecraft, and the tools I build.

15 entries
Web Security GraphQL Introspection: Exposing API Architecture Using introspection queries to map hidden GraphQL APIs and surface unauthenticated query paths in production endpoints. reconexploit Exploit Jenkins Exploitation: Script Console RCE Exploiting exposed Jenkins Script Console endpoints for immediate unauthenticated remote code execution and post-exploitation. rceweb-sec Web Security CORS Misconfiguration & Data Exfiltration How misconfigured CORS headers let attackers steal sensitive data from authenticated sessions across origins. exploitnetwork Web Security Unauthorized Cache Purge: DoS via HTTP Methods Abusing CDN cache-purging endpoints over HTTP to cause targeted denial of service without authentication. networkdos Exploit React2Shell: Modern Web Frameworks as Attack Vectors How React-based SPAs expose attack surface through client-side bundling, public source maps, and exposed API schemas. rceweb-sec Exploit CVE-2025-24893: Unauthenticated RCE in XWiki Template injection in XWiki's search endpoint leading to unauthenticated remote code execution on the host. cverce Exploit Mirth Connect RCE: Healthcare Meets Insecure Defaults Exploiting default credentials and an exposed Groovy console in Mirth Connect for RCE in healthcare environments. rcemalware Exploit Sudo NSS Library Hijack: From User to Root Abusing NSS plugin loading in sudo to inject a malicious shared library and escalate to root without a CVE. privescsudo Exploit Post-Exploitation Part 1: Privilege Escalation Techniques for local privilege escalation after initial access: SUID binaries, sudo misconfigs, cron jobs, and kernel exploits. privesclinux Network Post-Exploitation Part 2: Pivoting Network pivoting after gaining a foothold: SSH tunnels, proxychains, and lateral movement through segmented networks. pivotlateral Network Detecting Firewalls Before They Detect You Passive and active techniques for fingerprinting firewall rules and WAF behaviour without triggering IDS alerts. reconevasion Culture The Death of the Underground Hacking Scene The hacking underground shifted from curiosity and idealism to commoditization. Where did the culture actually go? cultureopinion Tools Microsurf: Stripping Windows 10 Down to the Metal Removing telemetry, bloat services, and background processes to build a minimal, privacy-respecting Windows 10 install. windowsprivacy Tools gr4v1ty: Network-Wide Ad Blocking on a $0 Server Running DNS-level network ad blocking on a spare Android device with no additional hardware cost. dnsandroid Tools VANTA: Official Documentation Complete reference for VANTA, a modular security framework in Go with a stdin/stdout JSON protocol for any-language modules. goframework