Web Applications and Internal Penetration Tests

Adventures in ATM Hacking

Intro Before this pandemic, Neil Burrows and myself (Bruno Oliveira) from Trustwave's SpiderLabs ...

Read More

Windows Debugging and Exploiting Part 5 SMBGhost CVE-2020-0796 Technical Review

Introduction Hi everyone, how are you? I know the times are strange but we should fight together, ...

Read More

Windows Debugging and Exploiting Part 4: NTQuerySystemInformation

Introduction Hello again! We are back with more Windows internals and it's time to get real. We ...

Read More

Windows Debugging & Exploiting Part 3: WinDBG Time Travel Debugging

Introduction Hi, my fellow friends! How are you? Hopefully, you had a terrific holiday and much ...

Read More

Windows Debugging & Exploiting Part 2 - WinDBG 101

Introduction Hello again! After our previous post about the environment setup, now it is time to ...

Read More

Windows Debugging & Exploiting Part 1 - Environment Setup

Introduction In this blog series, I will try to set some base knowledge for Windows system ...

Read More

CVE-2018-8006: XSS in Apache ActiveMQ

A cross site scripting (XSS) vulnerability exists in Apache ActiveMQprior to version 5.15.5. Apache ...

Read More

Discovering BMW Car Systems: Getting Started

Since I love both (in)security and cars, it is not uncommon for me to mix those things on a regular ...

Read More

My 5 Top Ways to Escalate Privileges

During a penetration test, rarely will the tester get access to a system with the administrator ...

Read More

PenTesting: From Low Risk Issues to Sensitive Data Compromising

Yes, I imagine you are probably tired to see blog posts about "real-world" PenTesting, people ...

Read More