#writeup — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #writeup, aggregated by home.social.
-
Full Writeup of the Windows GDID
https://github.com/SmtimesIWndr/gdid-reversal
Comments: https://news.ycombinator.com/item?id=48811081
#HackerNews #Windows #GDID #GDID #Reversal #GitHub #Tech #Writeup
-
Full Writeup of the Windows GDID
https://github.com/SmtimesIWndr/gdid-reversal
Comments: https://news.ycombinator.com/item?id=48811081
#HackerNews #Windows #GDID #GDID #Reversal #GitHub #Tech #Writeup
-
#Hello World
Neighbour merupakan Room CTF dari Tryhackme dimana kita memanfaatkan celah kerentanan IDOR untuk dapat mengakses halaman profil administrator.
Baca selengkapnya:
https://analis-siber-purwakarta.blogspot.com/2026/07/tryhackme-neighbour-ctf-challenge-writeup.html#tryhackme #ctf #cybersecurity #ethicalhacking #websecurity #idor #writeup #infosec #penetrationtesting
-
Армагеддон в миниатюре: DC-1 WriteUp
Сегодня у нас на обзоре занимательная машинка от Vulnhub: DC-1 от автора DCAU. По ощущениям предназначена для уровня Beginner/Intermediate, хотя сам автор сложность не указал. Машина отличается нестандартными флагами - всего их раскидано пять, хотя интересен лишь один рут-флаг, остальные - просто подсказки на пути к нему. Для классификации моих действий будем использовать матрицу MITRE ATT&CK - в конце статьи вас ждет полный KillChain
-
WriteUp: 16 Bytes of x86 that turn Matrix rain into sound
-
WriteUp: 16 Bytes of x86 that turn Matrix rain into sound
-
HTB: AirTouch
https://0xdf.gitlab.io/2026/04/18/htb-airtouch.html
Read on HackerWorkspace: https://hackerworkspace.com/article/htb-airtouch
-
Breaking into the Vulnerable Controler VM | VulNyx Writeup
Controler is a medium-level Windows machine. We start by enumerating the Kerberos account for initial access. By exploiting Active Directory replication rights, we extract the Domain Administrator’s password hash, gaining full administrative control.
https://thecybercraft.medium.com/vulnyx-controler-writeup-b9ada8e12fdd
-
HTB Season 10 | Kobold WriteUp— MCP-инструменты как новый attack surface
Разбор Easy-машины из HTB Season 10. Точка входа - RCE через MCP Inspector (dev-тулза для AI-серверов), дальше LFI в контейнере, credential reuse и Docker privesc. Два пути до root, MITRE маппинг, и разбор почему MCP-экосистема - это новый attack surface.
https://habr.com/ru/articles/1018656/
#информационная_безопасность #ctf #hackthebox #пентест #docker #MCP #AI_security #writeup
-
if anyone is interested... i made a CAN-BUS reverse engineering tool over the past few days.. check out my #writeup about it? <3
https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6
#carhacking #canbus #reverseengineering #hacking #tools #showdev #project #creativity
-
if anyone is interested... i made a CAN-BUS reverse engineering tool over the past few days.. check out my #writeup about it? <3
https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6
#carhacking #canbus #reverseengineering #hacking #tools #showdev #project #creativity
-
HackQuest ZeroNights 2025: райтапы
Всем привет! 26 ноября 2025 года мы провели долгожданную конференцию по информационной безопасности ZeroNights. Было классно – пусть и не всегда легко :) За атмосферой предлагаем заглянуть в Галерею , а за ценным опытом спикеров – в Материалы , где вы найдете презентации и видеозаписи докладов. А пока хотим поделиться некоторыми райтапами заданий для HackQuest ZeroNights. Это традиционный квест, проводимый до начала конференции, где за решение тасок и CTF победители получают билеты на ZeroNights. Отличный способ встряхнуться перед мероприятием! Кстати, в этом году конференция пройдет 30 сентября! HackQuest тоже будет. Все связанные с ZeroNights активности анонсируем отдельно. Будем на связи в Telegram и ВК ! А пока – к райтапам. Возможно, эти решения помогут участникам с задачками в этом году :)
-
T-CTF 2025. Разбор задачи «Капибегущая строка»
Разберём задачу «Капибегущая строка» с соревнований T-CTF 2025, где хакеры взломали освещение жилого дома и использовали его как бегущую строку для того, чтобы сообщить свои требований.
https://habr.com/ru/articles/996766/
#TCTF #Капибегущая_строка #scapy #python #writeup #wireshark
-
VulNyx Hosting Writeup
A Step-by-Step Guide to Exploiting SMB and WinRM Services on the VulNyx Hosting Machine:
https://medium.com/@thecybercraft/vulnyx-hosting-writeup-fa1bf2aa3825#pentest #cybersecurity #infosec #winrm #vulnyx #smb #writeup
-
VulNyx Misconfigured Writeup
A Step-by-Step Walkthrough of Enumerating AD Services and Gaining Administrator Access on the Misconfigured Machine
https://thecybercraft.medium.com/vulnyx-misconfigured-writeup-f3f35cb52673 -
I might be a few months late, but I finally found some time to publish my "magnetic_tape" crypto challenge from #NullCon #Berlin #HackIM #CTF 2025:
https://github.com/OOTS/magnetic_tape
I included the source code (was published anyway during the CTF), my own solution, my own #writeup, and some internal files (#Dockerfile, docker-compose, minimal #python #unittests).
Also: #NullCon #Goa #HackIM #CTF 2026 is happening in a few days: https://ctf.nullcon.net
Go check it out! -
Published a new writeup:
"HackTheBox - White Rabbit"
-
With the Era box on #HTB retired I now finally can publish my writeup of this box
https://blog.maschmi.net/era-htb/
Thank you @mkalmes for reading it a few months ago and for the feedback on it. It helped me going forward with this!
I also submitted it as a community supplied walkthrough. Now I wait and hope it will be accepted 🤞
-
With the Era box on #HTB retired I now finally can publish my writeup of this box
https://blog.maschmi.net/era-htb/
Thank you @mkalmes for reading it a few months ago and for the feedback on it. It helped me going forward with this!
I also submitted it as a community supplied walkthrough. Now I wait and hope it will be accepted 🤞
-
Три неудачных патча и одно озарение: реверсим клиентскую аутентификацию на HTB
Название: Bypass Категория: Reversing Сложность: Easy Ссылка: https://app.hackthebox.com/challenges/Bypass Разбираю задачу Bypass с Hack The Box. Путь от трех неудачных патчей в IDA Pro до элегантного решения с помощью dnSpy. Показываю, как выбор правильного инструмента решает всё.
https://habr.com/ru/articles/963086/
#hacking #hackthebox #реверсинжиниринг #htb #writeup #bypass #ida_pro #net #c# #dnspy
-
Истории о «partial PEM»
Задачка с Offzone 2025 натолкнула на мысль составить свой маленький букет «этюдов» на тему « partial PEM private key » (закрытый ключ с неполной информацией в формате PEM-файла). Будем рассматривать CTF-задачки по восстановлению закрытых ключей популярной криптосистемы RSA.
-
That whole experience was nuts. It was 95 degrees outside. They were checking bags at the front for unsanctioned water bottles. They sold five dollar bottles of water. lol
Though, overall, good weekend with family. Im writing about it. May post later today if I feel good about this next draft. #blogger #blogging #writeup
-
That whole experience was nuts. It was 95 degrees outside. They were checking bags at the front for unsanctioned water bottles. They sold five dollar bottles of water. lol
Though, overall, good weekend with family. Im writing about it. May post later today if I feel good about this next draft. #blogger #blogging #writeup
-
When Backups Open Backdoors: We discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of organizations that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data such as all Teams channel messages. #synology #disclosure #modzero #writeup
https://modzero.com/en/blog/when-backups-open-backdoors-synology-active-backup-m365/ -
When Backups Open Backdoors: We discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of organizations that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data such as all Teams channel messages. #synology #disclosure #modzero #writeup
https://modzero.com/en/blog/when-backups-open-backdoors-synology-active-backup-m365/ -
Wohoo...
My poem in the English language has been published!A big thank you to Paper Boat and The Alipore Post for organizing such a delightful event. It was a rare and cherished opportunity to stretch my literary muscles in English, especially through poetry. The experience was not only exhilarating but also incredibly soothing, stirring up a beautiful sense of nostalgia.
-
I noticed a (minor but abusable) data leak in the RMM/PSA tool Atera a while ago, reported it and it's now fixed. I think it's somewhat interesting so I wrote it up.
https://fyr.io/post/atera-leaked-their-customers-to-mailinator
Tldr: if you tested your SMTP settings, it used a public mailbox on mailinator, allowing anyone to watch for (and respond to, if you're so inclined) mail. Phishing opportunity!
#infosec #atera #privacy #dataleak #mailinator #writeup #phishing #netsec
-
I noticed a (minor but abusable) data leak in the RMM/PSA tool Atera a while ago, reported it and it's now fixed. I think it's somewhat interesting so I wrote it up.
https://fyr.io/post/atera-leaked-their-customers-to-mailinator
Tldr: if you tested your SMTP settings, it used a public mailbox on mailinator, allowing anyone to watch for (and respond to, if you're so inclined) mail. Phishing opportunity!
#infosec #atera #privacy #dataleak #mailinator #writeup #phishing
-
My #writeup for hxp 38C3 #ctf @hxp - alcoholic variety (#crypto hard) https://affine.group/writeup/2024-12-hxp-AlcoholicVariety (#EllipticCurves)
-
Step 2 of the #Proxmox #NUT #Homelab #HowTo covers setting up email using #Google #gmail as an #smtp relay and configuring #Debian to send an email on server start-up and shutdown. Each stage is tested.
#Writeup #Video : https://www.alanbonnici.com/2024/07/proxmox-nut-homelab-howto-step-2-setup.html. -
Just a public announcement that, I will be beginning with 2 topics; I have said this before I think but not 'officially' (if that even makes sense, lmao) but I will begin with (or have, begun with more specifically)
1) ( AI : ML)
2) ( nls933_w.dll reversing )so , everyone who knows me(knows as in follow/know who I am online) will see more of these 2 topics, especially AI:ML because I Will use it as help as well. 2 proof of concepts: A AI that will(in some small measure) learn itself to improve, itself. (I am still new to the topic but some proof of concept will be possible) I am going to post it here, in hope - it will be useful!
The other one, nls933_w.dll (or Nls_933_(..) whatever to call it) is a rootkit, which I have, many times talked about to reverse but not actually done it, why? Well, we `all` need breaks, we really do!
I - am not an exclusion to that phrase! I needed and still need, some breaks , it's my amazing friends that keep me energized ❤️ thanks to them! I can continue to do this :hi_cirno:#thank #thanks #appreciation #project #reverse #reverseengineering #blog #writeup #ai #ml #dl #cs #artificialintelligence #intelligence #malware #virus #bootkit #rootkit #firmware #debug #debugging
I am reading the book
- https://github.com/probml/pml-book
To get started in it *kind of*!so a bit of a message from me:
Let's do this! ^_^ Stuxnet is done and now it's nls933_w.dll's and ML's turn!
--------
over n out! -
✴ Quick update, there will be most certainly a delay in Sherlocks' writeups publishing as because of following the rule "from most to least solves" my stupid ass started solving the active ones for which I am not allowed to publish writeups yet 😅
So I have 4 of these waiting in queue, but can't really do anything about them now 😬
-
L’ #informatica sta completamente esplodendo nell’ultima settimana… ciò è molto buffo, ma anche #preoccupante. E siamo appena a sabato mattina… c’è tutto il tempo per far andare storto anche qualcos’altro! Siamo messi veramente di cacca. 😬️
- Prima è uscito fuori un #bug che colpisce tutte le CPU Apple Silicon, simile a cosa fu Spectre anni fa, quindi ovviamente #hardware, e chissà se sarà o meno patchabile via software in realtà in futuro (ma in tal caso, il vostro bel #computer con la mela girerà 3 volte peggio, soldi buttati). Fanno proprio schifo ‘sti #processori #moderni, tutti indistintamente, finiscono sempre per avere una caterva di #falle strane perché implementano #hack bruttissime a livello di progettazione per girare più veloci… dovremmo tornare onestamente al 6502. Il sito ufficiale è https://gofetch.fail, e #LowLevelLearning ha ovviamente parlato della cosa: https://youtube.com/watch?v=-D1gf3omRnw 🍎️
- Poi una #falla di incremento dei privilegi a livello kernel in #Linux… è complicatissimo, ma un #ProofOfConcept è stato pubblicato qui (assieme al #writeup), e in pratica si può sfruttare un #problemino nello stack di rete per diventare #root… mi chiedo se si potrà magari utilizzare per rootare sistemi embedded ristretti (telefonini coff coff, ma non solo), anche se dice di colpire tra v5.14 e v6.6 quindi non ho molte speranze. Qui un #video se vi interessa comprendere il #glitch in modo umano: https://youtube.com/watch?v=ixn5OygxBY4 💣️
- E infine, #notizia di ieri, cosa estremamente grave perché è stata fatta apposta, è stata inserita una #backdoor nella libreria di compressione #XZ. Lo ha scoperto un certo #AndresFreund, che non è un ricercatore di #sicurezza, ma era semplicemente diventato estremamente salty dopo aver visto che i suoi login ad SSH facevano schizzare alle stelle l’uso di risorse del sistema, oltre ad essere stranamente più lenti. Quindi ha scavato un po’, pensando ci fosse qualche #problema benigno, ma in realtà ha scoperto che qualche stronzo ha inserito #malware nel processo di build della libreria, nascondendolo tra le cose relative al testing. Mi sarebbe piaciuto navigare tra #issue e pull request per vedere l’utente che ha mandato ‘sta merda al progetto, ma GitHub come al solito si dimostra la piattaforma di condivisione di codice più stupida al mondo, e ha sospeso tutte le repo per “violazione dei Termini di Servizio”… razza di scimmie imbananate che non siete altro, ma credete davvero che i mantenitori di #Tukaani abbiano fatto entrare codice malevolo nelle loro repo consapevolmente? È ovvio che nessuno se n’è accorto, che bisogno c’è di punire chi non ha colpa allora? (Tra l’altro, il loro sito era ospitato lì, quindi ora manco quello è più online… almeno hanno un mirror Git, ma è solo source lì). Mi piacerebbe proprio tanto fare una chiacchierata con il vero colpevole, e di persona, sia ben chiaro, non dietro una tastiera dove questo si crederebbe ovviamente Dio… “eh ma io so fare gli exploit io so programmare meglio di te io io” sei un coglione, questo sei se fai queste cose, scommetto che non riusciresti nemmeno a parlare faccia a faccia. Persino io con le mie manie di protagonismo non mi sognerei mai di fare qualcosa per garantirmi una backdoor nei server #SSH di tutto il mondo, e che cazzo… 💀️
https://octospacc.altervista.org/2024/03/30/3804/
#AndresFreund #backdoor #bug #computer #falla #falle #glitch #hack #hardware #informatica #issue #Linux #LowLevelLearning #malware #moderni #notizia #OpenSSH #preoccupante #problema #problemino #processori #ProofOfConcept #rogne #root #sicurezza #SSH #Tukaani #video #writeup #XZ
-
Published new writeup, in which I show bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation