Skip to content

passkwall.net

Hacking, Red Teaming, Offensive Engineering

Menu
  • /home
  • /about
  • /github
  • /linkedin
  • /youtube
Menu

Category: Uncategorized

A week without “why” and how it changed my thinking

Posted on March 11, 2022April 7, 2022 by passkwall

Truth be told, and if I’m being a bit candid, I really dislike the word “why”. Now, if you find yourself asking inside your head, “but why?” then this article might be for you. Some of the explanations in this article might be overly simplified, but I still encourage the underlying concepts to be explored….

Continue reading

Mindset for hacking GraphQL Applications

Posted on November 23, 2021March 17, 2022 by passkwall

I’ve tried to summarize a lot of information from HackTricks, YouTube, HTB write-ups, disclosed vulnerabilities, and the GraphQL documentation to come up with succinct notes on GraphQL. This way you don’t need to be an expert to focus on what’s important. I’m not claiming to be an expert on GraphQL, but enough to know what…

Continue reading

Shell Games — A closer look at the behavior of different msfvenom shells with strace

Posted on October 13, 2021March 17, 2022 by passkwall

During a recent engagement I had the chance to test various payloads against a few different endpoint detection tools. Think of anti-virus, but with remote administration and enterprise support. The technologies are amazing, however, when testing different kinds of reverse shells, some payloads could be used to easily evade the agents protecting the hosts. This…

Continue reading

Leveraging Postman Collections for Offensive Webapp Testing

Posted on August 12, 2021April 7, 2022 by passkwall

I was recently in an engagement with a web application that was interconnected with about half a dozen services while offering up a few dozen API routes that had to be tested within three days. As I stared at the flow chart provided and tried to gather an understanding of what I needed to test…

Continue reading

How to configure Android Studio with BurpSuite

Posted on July 11, 2021April 7, 2022 by passkwall

Let’s say you’ve been assigned some mobile work. You’re a pentester, mobile developer, or just a tinkerer who needs to be able to see traffic flowing to and from your Android device. Chances are you’re going to want to use BurpSuite to help make your life a little bit easier. Problem is that the instructions…

Continue reading

Timing-Based Username Enumeration: What’s a fix versus mitigation?

Posted on July 7, 2021April 7, 2022 by passkwall

For web-based applications, Timing-based Username Enumeration is a great find. For testers it’s low-hanging fruit and a great way to enumerate valid accounts for password attacks or social engineering. For engineers, fixing can be a pain in the rear end. Recently, I had an interesting debate with a coworker after writing a re-test report for…

Continue reading

The mental tweak that helped me on my OSCP journey

Posted on June 2, 2021March 17, 2022 by passkwall

In a previous post, I highlighted my overall OSCP experience. The high-level ideas around education, studying, and exam attempts are there, but I wanted to touch on something that I didn’t elaborate on — mindset. A lot of the OSCP prep feels like a grind. Enumerate a machine, find something vulnerable, exploit, elevate privileges, repeat. Over time,…

Continue reading

Search blogs + topics

Recent Blogs

  • Finding security bugs across a codebase for beginners
  • How I transitioned into security, and what I would do differently (2022 edition)
  • Securing your CI: How to determine what matters most
  • What the OSCP doesn’t prepare you for in the workforce, and how to get caught up!
  • Docker Cache Poisoning – Part 1

Topics

  • Hacking
  • Hackthebox
  • Mindset
  • OSCP
  • Tools
  • Tutorials
  • Uncategorized
  • /home
  • /about
  • /github
  • /linkedin
  • /youtube
© 2023 passkwall.net | Powered by Minimalist Blog WordPress Theme