Posts on cybersecurity
43 posts on cybersecurity. Notes from public sources and my own test lab.
Dumb Mistakes of Smart Devices: Getting Lost in the IoT Labyrinth
Think your office coffee machine is just for caffeine? Think again. From root passwords like '12345' to open SSH ports, I’m diving into why the IoT world is currently the Wild West of cybersecurity and how these 'toys' can become a bridge to your production database.
What Happens When You Change Just One Digit? The Silent Scream of IDOR
A deep dive into why authorization flaws like IDOR and business logic errors remain the 'invisible' threats that automated scanners often miss, told through real-world Red Team experience.
Think That File Is Gone? The Silent Scream of Digital Traces
A deep dive into the world of digital forensics, why you shouldn't just pull the plug on a compromised system, and how to catch an attacker's 'whispers' using Volatility.
SSH into the Human Terminal: Why the 'Trust' Protocol is Still Unpatched
Red teaming isn't just about zero-days. It's about debugging the 'Human OS' and bypassing danger perception through context and HTML Smuggling.
Hunting for Treasure in the IOC Trash: The ‘Real’ Face of Threat Intel
Stop chasing static IPs and hashes. If you want to actually hurt an attacker, you need to climb the Pyramid of Pain and start targeting our TTPs.
Your Screen Isn’t Just Black, Your Heart Just Stopped: The Reality of Ransomware
A raw look at how ransomware actually works, why speed is everything, and what attackers are really doing inside your network before the big "lockdown."
Hunting Digital Footprints: Why Google is Just the Tip of the Iceberg
Forget basic dorking. Let’s talk about how to find the hidden gaps in a company’s attack surface using subdomains and GitHub leaks.