infosec

infosec

Claiming a microsoft shorturl for an easy phish

**tl;dr;** Microsoft has an internal use shorturl service at **go.microsoft.com** that can be enumerated for hijackable links. It might be useful for you as a red teamer if you want to phish windows users.

Read
infosec

Bitbucket CSRF on SSH Add Key Endpoint via superdomain cookie

In October 2022 I found a pretty specific CSRF vulnerability on Bitbucket Server (the self hosted version). Since it has now been patched, here are the details.

Read
infosec

kms.nhp.gov.in rooted via syncthing

In May last year (2022) I found and disclosed a vulnerability on a subdomain of nhp.gov.in. Using an exposed syncthing admin interface, I was able to gain root SSH access to the server by syncing the `/root/.ssh` directory.

Read
infosec

Exfiltrating Past CSP Directives

An example of using Google Analytics to exfiltrate past CSP directives on HackerOne

Read
infosec

Revoking a PGP Key from MIT's Key Server

Instructions on how to revoke your public PGP key from MIT's Key Server.

Read
infosec

Veracrypt Cheatsheet

Short cheatsheet for using Veracrypt

Read
infosec

Stored XSS via Swish Transaction

Last week I went to the cinema with some friends. My friend paid for the ticket so I decided to use

Read
infosec

tamperfree

I'd like to write about a part of what was my master thesis project. For my thesis I wrote about a mostly theoretical whistleblowing system.

Read
infosec

Revisiting the Free Wifi on Destination Gotland

I'm on the boat from Gotland again after having spent a week there with my

Read
infosec

SSLStrip

Continuing with the theme of wifi attacks, tonight I'm looking at the SSLStrip tool.

Read