Open in app

Sign In

Write

Sign In

ismail kaleem
ismail kaleem

29 Followers

Home

About

Jan 10

Threat Hunting WordPress with Bash

Incident handling and Response is often a tiring task when you are not equipped with the right tools. I often use ELK for tactical analysis for crunching data but at times; all you might have access is to a terminal. The plan here is to quickly identify IOCs for Threat…

3 min read

Threat Hunting WordPress with Bash
Threat Hunting WordPress with Bash

3 min read


Apr 26, 2022

Finding IP addresses in a Network

When you land on a huge big network with several VLAN’s and are unsure of where to look or start! # install git clone https://github.com/dirkjanm/adidnsdump sudo pip3 install . # NOTE: HOSTNAME is the domain controller which is running the DNS service adidnsdump -u domain\\username -p <password> --print-zones <HOSTNAME> #…

Ffuf

1 min read

Ffuf

1 min read


Sep 1, 2021

Exploiting Laravel v8.30.0 (PHP v7.3.25) debug RCE

A fairly easy exploit and works for Ignition <= 2.5.1 Ignition is a beautiful and customizable error page for Laravel applications running on Laravel 5.5 and newer. It is the default error page for all Laravel 6 git clone https://github.com/rocketscientist911/CVE-2021-3129 cd CVE-2021-3129 docker-compose up -d vulnerable host starts at port…

4 min read

Exploiting Laravel v8.30.0 (PHP v7.3.25) debug RCE
Exploiting Laravel v8.30.0 (PHP v7.3.25) debug RCE

4 min read


May 5, 2021

Annoyed with your WiFi being slow?

I live in a country where often the service providers are known for providing a terrible service and citizens are known for their high expectations. This article is intended for Maldives but feel free to read.. The first thing I am going to be talking about is clean channels, and…

Wlan

7 min read

Annoyed with your WiFi being slow?
Annoyed with your WiFi being slow?
Wlan

7 min read


Apr 8, 2021

SSRF Payloads

Some decent filter bypasses! — http%3A// /%5cpoc.10degres.net /%2f%2fpoc.10degres.net /poc.10degres.net /%2f%2e%2e/http:/poc.10degres.net /.poc.10degres.net ///\;@poc.10degres.net Top SSRF parameters extracted from hackerone reports ?dest= ?redirect= ?uri= ?path= ?continue= ?url= ?window= ?next= ?data= ?reference= ?site= ?html= ?val= ?validate= ?domain= ?callback= ?return= ?page= ?feed= ?host= ?port= ?to= ?out= ?view= ?dir= ?file=

Ssrf

1 min read

Ssrf

1 min read


Sep 18, 2020

Testing Blind XSS Payloads

Get the payloads list and load it up! git clone https://github.com/rocketscientist911/webpayloads.git Intruder is kinda cumbersome with burpcollaborator to test as we do not know which payload has actually worked! For this very reason we will be using bountyburp plugin. Now, scan with extensions only option…

Burpsuite

1 min read

Testing Blind XSS Payloads
Testing Blind XSS Payloads
Burpsuite

1 min read


Sep 17, 2020

ApFell rebranded to Mythic

Mythic C2 Framework — A review by a purple team engineer It took me almost a day to understand and setup cloud auto configuration for the framework. I personally think in the long run this is going to be a pretty decent project as the scope is huge. …

3 min read

ApFell rebranded to Mythic
ApFell rebranded to Mythic

3 min read


Sep 14, 2020

#Terraform #RedTeam C2

Covenant, Digital Ocean, Docker and Cloudflare Proxy — A lazy security engineer automating his C2 Cloud Environment Setup with HTTPS for both C2 Host and Listeners without redirecting. Terraform will be used to auto deploy Infrastructure Digital Ocean — Hosting (It’s cheap and stable). Cloudflare — Hiding Origin IP & Traffic Shaping First is first; install Terraform and…

Red Team

4 min read

#Terraform #RedTeam C2
#Terraform #RedTeam C2
Red Team

4 min read


Jun 16, 2020

#HTB Purple Team Writeup! (RE) #1

This was my first box and attempt on #Hackthebox This article will be more focused towards the blue team in implementing defenses which I would be covering in the part #2. 1. Reconnaissance Extra: Ping to understand what is the underlying operating system. A TTL above 64 suggests the operating system might…

14 min read

#HTB Purple Team Writeup! (RE) #1
#HTB Purple Team Writeup! (RE) #1

14 min read


Mar 9, 2020

Password-less VPN Split-Tunneling using OpenVPN + Google OTP + Key

CoVID-19 has forced people to stay at home & also to work-from-home! Work-from-home is easy to adopt for organizations who are already mostly using the cloud and hardly have anything on-premises. This is not the case for a lot of corporate and government organizations. …

5 min read

Docker OpenVPN + OTP
Docker OpenVPN + OTP

5 min read

ismail kaleem

ismail kaleem

29 Followers

Follow me on Twitter https://twitter.com/@roketscientist

Following
  • Sajeth Jonathan

    Sajeth Jonathan

  • Peterjson

    Peterjson

  • Hannah Suarez

    Hannah Suarez

  • fa li

    fa li

  • Andrii Shevchenko

    Andrii Shevchenko

See all (12)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech