YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
OLOyinlola Lawalinlawaloyinlola.hashnode.dev·1d ago · 8 min readEthical hacking is not a toolset, it is a mindset with a permission slipMost confusion around ethical hacking is vocabulary, not difficulty. People use hacker, ethical hacker and penetration tester interchangeably, then argue past each other about what is legal and what i00
MM1Hinm1h.hashnode.dev·2d ago · 5 min readOSCP-LK: Achieving System Administrator Privileges via Credential Harvesting, MSSQL Impersonation, and Registry ExtractionOverview: This box is an OSCP preparation, a hosted version of the OSCP-LK set. OSCP-LK is a set of machines in the style of the PEN 200 labs and exam to help you sharpen your enumeration, creative th10
YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 4 min readTryHackMe - CyberHeroes WriteupSummary CyberHeros is an easy-rated web challenge built on the iPortfolio Bootstrap template. The site advertises a "login page" challenge directly in its About section. Inspection of login.html revea00
AJAmartya Jhainsecurity-research.hashnode.dev·3d ago · 25 min readExternal Penetration Testing in 2026: A Technical Methodology, Tool Stack, and Attack Surface GuideExternal penetration testing is often reduced to a familiar sequence: nmap → nuclei → Burp → report That workflow is useful, but it misses the hardest part of the engagement. Finding the assets worth00
AJAmartya Jhainsecurity-research.hashnode.dev·3d ago · 13 min readWhy Your $6,500 Penetration Test Will Cost You More Than the $47,000 One Two penetration testing quotes land in your inbox. One says $6,500. The other says $22,000. Both vendors say they use AI. Both promise comprehensive coverage. Both have credible-looking reports, exper00
NKNitya Kaulinenterprisesecurity.hashnode.dev·3d ago · 5 min readTop 10 Web Application Vulnerabilities We Still Find in 2026The pace of software development has never been faster, thanks to cloud architecture and automated code generation. Nevertheless, regardless of all the technological advancements that have occurred, t00
SSshadow Senseiinshadowsensei-sec.hashnode.dev·4d ago · 10 min readVesperAegis: My Journey of Building a Linux-Based FirewallVesperAegis Firewall — Adaptive Network Security & Traffic Intelligence Over the past few days, I have been working on something different from my usual penetration-testing labs. Instead of only test00
AJAmartya Jhainsecurity-research.hashnode.dev·5d ago · 8 min readRed Team Authorization: Solving the Paradox of Testing People Who Can't Know They're Being TestedA red team engagement exists to answer one question: can your security team detect and respond to a real attack. For that answer to mean anything, the security team being tested, the blue team, cannot00
AJAmartya Jhainsecurity-research.hashnode.dev·5d ago · 14 min readSOC 2 Penetration Testing: What Auditors Actually Check For (And Where Most Programs Fail)Day three of a SOC 2 Type II audit. The auditor pulls up the penetration testing section of the audit program and asks: "Can you show me evidence that exploitable vulnerabilities identified during you00