John Carroll
Author

File Folding.
Ideas

File Folding.

File Folding is a technique that moves a file into hex, and that hex is broken into folder file names in a fashion that can be reconstructed.

17 Apr 2024 · 4 min read
Untrusted Wi-Fi Networks,  Advice for All.
Random

Untrusted Wi-Fi Networks, Advice for All.

Nine words unpacked.

4 Oct 2023 · 8 min read
Data-bouncing
OffSec

Data-bouncing

Data-Bouncing - The art of indirect exfiltration. Using & Abusing Trusted Domains as a 2nd Order Transport.

11 Sep 2023 · 19 min read
Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy
Random

Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy

How to implement MFA in Ghost Blog with Cloudflare's Zerotrust Access Policy.

1 Sep 2023 · 5 min read
Three-Word Password Attacks
OffSec

Three-Word Password Attacks

The idea behind three word passwords as a concept is in my opinion a nice nudge in the right direction, In a perfect world, a passphase or a sentence

16 Aug 2023 · 3 min read
Get TI from historical breach data?
OSINT

Get TI from historical breach data?

We can do more with breach data.

28 Jul 2023 · 5 min read
Identity Inheritance via expired domains
Exploitation

Identity Inheritance via expired domains

I wonder if any of these leaked email address domains are expired, and I wonder if I can buy them and inherit the identities associated with them via password resets

10 Jul 2023 · 3 min read
Inference.
OSINT

Inference.

The way we leak information will eventually change...

8 Jun 2023 · 4 min read
'ExpLoading'
Exploitation

'ExpLoading'

If you have ever dismissed a search order binary plant attack because the folder from where it takes place doesn’t allow for writes without elevation?

6 Dec 2022 · 4 min read
Bigger Benefits of Password Cracking
EntSec

Bigger Benefits of Password Cracking

Visibility everywhere yeilds a better understanding of work working, or work needing more support or new approaches. this is that for AD passwords en-mass.

6 Dec 2022 · 4 min read
Paying or Preventing Ransom Payments
Random

Paying or Preventing Ransom Payments

Don't make criminals of victims, think a little harder on this problem.

6 Dec 2022 · 2 min read
DNS Security TXT
Ideas

DNS Security TXT

DNS Security TXT record A method to hold security contact signposting from an authoritative position - from Casey Ellis & myself https://dnssecuritytxt.org/?tc

6 Dec 2022 · 3 min read