Generated by All in One SEO v4.9.10, this is an llms.txt file, used by LLMs to index the site. # fin3ss3g0d's Blog ## Sitemaps - [XML Sitemap](https://fin3ss3g0d.net/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Blog](https://fin3ss3g0d.net/index.php/blog/) - [Static Keys, Shattered Security Dreams: A CVE-2024–5764 Story](https://fin3ss3g0d.net/index.php/2024/12/27/static-keys-shattered-security-dreams-a-cve-2024-5764-story/) - Red teaming is all about seizing opportunities, and in a recent assessment, we did just that. We came across a Sonatype Nexus Repository 3 instance — perfect timing, as a fresh vulnerability (CVE-2024–4956) was burning a hole in our pocket thanks to a timely tip-off from Phithon (@phithon_xg) on X. This unauthenticated path traversal flaw had the - [Crack Faster, Hack Smarter: Custom Hashcat Module for Apache Shiro 1 SHA-512](https://fin3ss3g0d.net/index.php/2024/06/24/crack-faster-hack-smarter-custom-hashcat-module-for-apache-shiro-1-sha-512/) - Introduction During a recent assessment, we identified a server running Nexus Repository 3 that was vulnerable to CVE-2024–4956. This led to us pillaging data from the system and ultimately extracting Apache Shiro 1 SHA-512 password hashes to the web application from this data. Apache Shiro’s version 1 SHA-512 hashing implementation involves salting the input - [QR Code Phishing with EvilGophish](https://fin3ss3g0d.net/index.php/2024/02/24/qr-code-phishing-with-evilgophish/) - In the evolving landscape of cybersecurity, adversaries are continually seeking innovative methods to bypass traditional security measures. One such method gaining traction is the use of QR codes. At first glance, QR codes appear as benign tools for quick access to websites or information. However, their inherent characteristics offer unique advantages for cyber threats, particularly - [EvilGophish's Approach to Advanced Bot Detection with Cloudflare Turnstile](https://fin3ss3g0d.net/index.php/2024/04/08/evilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile/) - Introduction Bots pose a significant threat to the integrity of phishing infrastructure, primarily by automating detection and countermeasures that can prematurely expose and neutralize simulated phishing campaigns. These automated agents can range from security scanners, which seek out and report phishing attempts, to malicious bots designed to flood systems with fake submissions, obscuring genuine interactions - [Smishing with EvilGophish](https://fin3ss3g0d.net/index.php/2024/03/04/smishing-with-evilgophish/) - Introduction to Smishing: Understanding SMS Phishing Tactics In the evolving landscape of cybersecurity threats, smishing—or SMS phishing—stands out as a formidable technique employed by adversaries to exploit human vulnerabilities. Smishing operates on a principle similar to its email-based counterpart, phishing, but leverages the ubiquity and perceived trustworthiness of text messaging (SMS) to deceive targets. What - [Weaponizing Windows Thread Pool APIs: Proxying DLL Loads Using I/O Completion Callbacks](https://fin3ss3g0d.net/index.php/2024/03/18/weaponizing-windows-thread-pool-apis-proxying-dll-loads/) - In today’s blog, we are going to be covering the topic of proxying DLL loads using the Windows thread pool API with C++/assembly. This specific example is going to use an I/O completion callback and is a complementary article for my GitHub repository here. Before we jump in, let me introduce some background information. Background - [Simple Thread Stack Spoofing in Assembly](https://fin3ss3g0d.net/index.php/2024/02/25/simple-thread-stack-spoofing-in-assembly/) - A while ago I came across this technique for thread stack spoofing by Mariusz Banach. I wanted to see if I could replicate the technique using assembly (MASM), and so I set off to do just that. For those who aren’t aware of the technique, it can be demonstrated from C using the following code: Copy - [Stealing the Bank Vault Codes via Insecure Microsoft Default Settings](https://fin3ss3g0d.net/index.php/2024/02/25/stealing-the-bank-vault-codes-via-insecure-microsoft-default-settings/) - The blog is actually hosted here from the perspective of a colleague and myself. ## Pages - [Home](https://fin3ss3g0d.net/) - Welcome to the blog of Dylan Evans! Here you will find various blog posts about offensive cybersecurity topics. Select the blogs tab to get started and to see the various posts. ## Categories - [Blog](https://fin3ss3g0d.net/index.php/category/blog/) - Your blog category