Blog

  • [CTF] HTB Paperwork write-up walkthrough

    5.00 of 5 votes

    This is my write-up and walkthrough for the Paperwork (10.129.99.189) box user and root flags. Paperwork is a Linux machine. When commencing this engagement, Paperwork was listed in HTB (hackthebox) with an easy difficulty rating.   Walkthrough I ran this engagement from my own Kali box, so the first job was getting onto the lab network. From the HackTheBox dashboard I downloaded the

  • [CTF] HTB Nexus write-up walkthrough

    4.50 of 14 votes

    This is my write-up and walkthrough for the Nexus (10.129.99.5) box user and root flags. Nexus is a Linux machine centred on web enumeration and a foothold that leads into a multi-step privilege-escalation chain. When commencing this engagement, Nexus was listed in HTB (hackthebox) with an easy difficulty rating.   Walkthrough I ran this engagement from my own Kali machine, so the first job

  • My long-shot journey to Australia's rarest visa

    4.99 of 470 votes

    I don't mark every milestone publicly, but the moments that mean something do occasionally find their way into my ceremonial practice of an ad hoc blog post. Today is one of those. I'm pleased to report I've been granted the Australian 858 visa and now hold immediate and unconditional permanent residency rights in Australia. For anyone unfamiliar, the 858 is

  • An Entra ID sign-in honeytoken with alerting and blocking

    4.78 of 166 votes

    This post aims to provide some insight into a new approach at tackling a particular type of phishing, and guidance on how to self-host your own honeytoken to help defend against it. Click here to skip to the self-host honeytoken generator AitM (Adversary in the Middle) attacks targeting companies is nothing new. Attackers will typically recon to identify a company

  • A DNS obfuscation technique proof of concept

    • General
    • by Jacob Riggs
    • 21-01-2024
    4.74 of 179 votes

    For my Deadswitch project, I've always been conscious of threat model and wanted to ensure the architecture employed a layered approach. One consideration was DNS tracking mitigations, and what I could do to help make efforts to identify customers more expensive to an adversary.One of the ways Deadswitch works is each customer is issued a uniquely generated subdomain that they

  • Write-up of a reMarkable security vulnerability

    4.93 of 422 votes

    This is a write-up on an integer overflow vulnerability that enabled me to zero balance any order at reMarkable. I was looking to buy a reMarkable tablet as a gift to my boss (for putting up with me) and noticed they had a VDP. Unfortunately, they don’t offer bug bounty rewards, but curious about their ecommerce setup, I figured I’d