May 22, 2022Member-onlyCertifried & Bloodhound: Active Directory Certificate Services AbuseCVE-2022–26923, commonly referred to as ‘Certifried’ is doing the rounds, and it really is a nasty vuln. I posted a video on LinkedIn last week, giving a really high level overview of the risk associated with the vulnerability. …Penetration Testing5 min readPenetration Testing5 min read
Mar 21, 2022Member-onlyActive Directory Certificate Services: Domain DominanceWhen I’m taking part in a penetration test or red team engagement, I love digging down into the intricacies of Active Directory. Oftentimes, I’ll find misconfigurations which, chained with other vulnerabilities, can lead to a complete takeover of that domain. Recently, I watched a video whereby the wonderful harmj0y (Will Schroeder) and Lee Christensen from Specter Ops presented brand new research surrounding the abuse of Active Directory Certificate services. It certainly ticked two boxes for me which got me really excited: Active Directory and intricacy. …Penetration Testing5 min readPenetration Testing5 min read
Jan 13, 2022Member-onlyPNPT: Practical Network Penetration Tester — ReviewI’ve been on a bit of a certification rollercoaster as of late; in the space of three months I’ve taken CRTP, eCPPT and now, the PNPT. I’ve really enjoyed all three for different reasons, and in this post, I’ll be discussing the latter. Background PNPT is offered by TCM Security, which…Penetration Testing7 min readPenetration Testing7 min read
Jan 5, 2022Member-onlyeCPPT: eLearnSecurity Certified Professional Penetration Tester — ReviewI completed my eCPPTv2 exam, originally, on 4th January, and received a reply on 25th January, stating that I had failed. This was unexpected, as I thought I’d compromised the entire environment, and reported on it to a good standard. I was wrong. …Penetration Testing7 min readPenetration Testing7 min read
Nov 8, 2021Member-onlyCVE-2021–43633Stored XSS 😲 On the back of a recent discovery, I felt encouraged to go hunting for some more vulnerabilities in open source software. After some searching, I settled on Messaging Web Application, which is an open-source browser-based messaging application. …Pentesting4 min readPentesting4 min read
Nov 5, 2021Member-onlyCVE-2021–40290In this blog post, I’ll share the recent vulnerability I found in a CMS, how I found it and a POC exploit. I should stress before we get into the nitty-gritty, this is my first CVE. It’s not super technical, it’s not going to turn any heads, but seeing as…Hacking4 min readHacking4 min read
Nov 3, 2021Member-onlyCRTP — Certified Red Team Professional ReviewNote that the Certified Red Team Professional (CRTP) course and labs are offered by Altered Security who are creators of the course and labs. You can get the course from here — https://www.alteredsecurity.com/adlab In October 2021 I undertook and successfully passed the Certified Red Team Professional certification, which is offered…Pentesting5 min readPentesting5 min read