Pentest Blog Posts
Reverse SSH: A Fast, Stable Reverse Shell Handler
Jordan Smith
Want to use SSH for reverse shells? Now you can.
Device Code Phishing: A Frontend UI
Daniel Underhay
A framework for OAuth 2.0 device code authentication grant flow phishing.
Hacking the Hive: Discovering Vulnerabilities in Aerohive Devices
Jordan Smith
Learn how to write your own firmware for Aerohive devices! With a bonus side order of some remote code execution!
CCTV: Now You See Me, Now You Don't
Daniel Underhay
How to take over an IoT camera stream.
Same-Origin Policy: From birth until today
Yangren Kelsang
A web browser’s same origin policy plays a major role in preventing Cross-Site Request Forgery attacks. The standard is clear on what the acceptable behaviour is, but do all browsers follow it?
Automating a Thorny SQL Injection With SQLMap
Ahmad Ashraff
SQLMap is one of the best tool in exploiting sql injection. However, there are moments where this tool will not produce the expected results if we do not supplying the correct options. This post covers a tricky SQL Injection vulnerability that I found in a recent assessment.
Universal Second Factor - Phishing-proof 2FA for general human beings
Yuriy Ackermann
U2F is an open, driverless, digital signature challenge-response protocol for secure two factor authentication. It’s designed to improve user security through ease of use.
SCADA Penetration Testing: Do I need to be prepared?
Nilesh Kapoor
In this blog post Nilesh shares his experience performing a SCADA assessment, what pentest approach works best for highly sensitive systems, and preferred tools of the trade.
Hunting For Bugs With AFL 101 - A Primer
Chris Berry
An overview of how to begin searching for vulnerabilities within software, by fuzzing the binary with AFL
Bypassing SAML 2.0 SSO with XML Signature Attacks
Tim Goddard
Unfortunately, many SAML consumers don’t validate responses properly, allowing attacks up to and including full authentication bypass.
