CTF Writeups
HTB Broker Writeup
Apache ActiveMQ CVE-2023-46604 deserialization RCE for initial shell, then root via nginx sudo misconfiguration allowing config overwrite.
CTF Writeups
Apache ActiveMQ CVE-2023-46604 deserialization RCE for initial shell, then root via nginx sudo misconfiguration allowing config overwrite.
AI Security
Detailed walkthrough of the C-AI/MLPen certification exam — preparation strategy, exam format, key challenges, and practical tips for AI/ML penetration testing.
CTF Writeups
Discovering phpbash webshell on Apache, lateral movement to scriptmanager user, then root access by abusing a Python cron job on Linux.
CTF Writeups
Raspberry Pi default credentials on a Pi-hole device for initial access, then recovering the deleted root flag from a USB drive using Linux forensics.
CTF Writeups
Shellshock (CVE-2014-6271) exploitation through CGI-bin scripts for remote command execution, then root via Perl sudo privilege escalation.
AI Security
Research analyzing how AI text detection tools disagree when facing hybrid evasion techniques. Cross-detector benchmark with paraphrasing and stylistic manipulation.