Blog

Security research, exploit development, and technical write-ups covering various aspects of offensive security and penetration testing.

[xbz0n@blog]$ ls -la articles/ | wc -l
12 articles published
from-zero-creds-to-ea.md
From Zero Creds to Enterprise Admin

From Zero Creds to Enterprise Admin

Active DirectoryPenetration TestingNTLM Relay+4
16 min read

This article details how I was able to go from having zero credentials to obtaining Enterprise Admin access during a recent engagement. The attack chain demonstrates how several seemingly minor...

> cat from-zero-creds-to-ea.md
cve-2023-0830.md

Finding and Exploiting CVE-2023-0830 in EasyNas

Vulnerability ResearchCommand InjectionCVE+3
6 min read

In this post, I'll show you how I found this vulnerability using Burp Suite and walk through the exploitation process. I'll also show the vulnerable code and explain what makes this such a dangerous...

> cat cve-2023-0830.md