John Carroll
Exploitation

CVE-2026-34910

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. https://github.com/gadievron/raptor

Hollow Pentesting
OffSec

Hollow Pentesting

Confidently using AI in your Pentests. Hollow Testing.

30 Mar 2026 · 4 min read
Synology DSM 7.3.2
Exploitation

Synology DSM 7.3.2

Chaining three issues to gain root from a low privileged user.

25 Jan 2026 · 4 min read
CVE-2025-37186 HP
Exploitation

CVE-2025-37186 HP

The HP Aruba VIA VPN client for Linux contains a local privilege escalation vulnerability that allows any unprivileged local user to gain root access. - CVE-2025-37186 - Another Scalp for Raptor

26 Dec 2025 · 4 min read
Hacklore ...
Random

Hacklore ...

What Hacklore get's wrong. and the precursor to https://lolwifi.network

6 Dec 2025 · 12 min read
Ghosted.
Exploitation

Ghosted.

Ghosted Domains coming to haunt you, one more check for your scanners, vendor assurance, OSINT, Supply chain, Appsec and all the rest of that good stuff.

19 Sep 2025 · 23 min read
Poll-Dancing & Age Verification
Privacy

Poll-Dancing & Age Verification

Poll-Dancing & Age Verification - a critical view of yougov's obvious biased framing of the age verification shit-show

4 Aug 2025 · 4 min read
Sunsetting Domains
InfoSec

Sunsetting Domains

What to do when you no longer need a domain

7 Mar 2025 · 3 min read
Amature.
Privacy

Amature.

The wrong people in the room when the decisions where made to reduce citizen data security.

7 Mar 2025 · 5 min read
The BYOD Post.
EntSec

The BYOD Post.

BYOD Problem, options.

14 Feb 2025 · 4 min read
Files, Folders & Fun (revisited)
Exploitation

Files, Folders & Fun (revisited)

Playing with folder resolution to build a better pretext

4 Nov 2024 · 1 min read
The Cost of Expiration
EntSec

The Cost of Expiration

Who needs to know when a domain has expired ? It Depends, and it Deepens.

30 Oct 2024 · 4 min read
File Folding.
Ideas

File Folding.

File Folding is a technique that moves a file into hex, and that hex is broken into folder file names in a fashion that can be reconstructed.

17 Apr 2024 · 4 min read
Untrusted Wi-Fi Networks,  Advice for All.
Random

Untrusted Wi-Fi Networks, Advice for All.

Nine words unpacked.

4 Oct 2023 · 8 min read
Data-bouncing
OffSec

Data-bouncing

Data-Bouncing - The art of indirect exfiltration. Using & Abusing Trusted Domains as a 2nd Order Transport.

11 Sep 2023 · 19 min read
Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy
Random

Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy

How to implement MFA in Ghost Blog with Cloudflare's Zerotrust Access Policy.

1 Sep 2023 · 5 min read
Three-Word Password Attacks
OffSec

Three-Word Password Attacks

The idea behind three word passwords as a concept is in my opinion a nice nudge in the right direction, In a perfect world, a passphase or a sentence

16 Aug 2023 · 3 min read
Get TI from historical breach data?
OSINT

Get TI from historical breach data?

We can do more with breach data.

28 Jul 2023 · 5 min read
Identity Inheritance via expired domains
Exploitation

Identity Inheritance via expired domains

I wonder if any of these leaked email address domains are expired, and I wonder if I can buy them and inherit the identities associated with them via password resets

10 Jul 2023 · 3 min read
Inference.
OSINT

Inference.

The way we leak information will eventually change...

8 Jun 2023 · 4 min read
'ExpLoading'
Exploitation

'ExpLoading'

If you have ever dismissed a search order binary plant attack because the folder from where it takes place doesn’t allow for writes without elevation?

6 Dec 2022 · 4 min read
Bigger Benefits of Password Cracking
EntSec

Bigger Benefits of Password Cracking

Visibility everywhere yeilds a better understanding of work working, or work needing more support or new approaches. this is that for AD passwords en-mass.

6 Dec 2022 · 4 min read
Paying or Preventing Ransom Payments
Random

Paying or Preventing Ransom Payments

Don't make criminals of victims, think a little harder on this problem.

6 Dec 2022 · 2 min read
DNS Security TXT
Ideas

DNS Security TXT

DNS Security TXT record A method to hold security contact signposting from an authoritative position - from Casey Ellis & myself https://dnssecuritytxt.org/?tc

6 Dec 2022 · 3 min read
Vertical Vulnerability Managment
InfoSec

Vertical Vulnerability Managment

Vulnerabilities are technology, security and risk vertical, as should be the management.

6 Dec 2022 · 2 min read
The Internet Facing Velocity Problem
EntSec

The Internet Facing Velocity Problem

It's probably faster to find a flaw in all IPv4 Assets with Open-source attack and exploit validation tools than it is for someone internal to hunt down the owners, maintainers and appropriate people for remedial actions - The Internet Facing Velocity Problem

6 Dec 2022 · 5 min read
DNS Stewardship
EntSec

DNS Stewardship

DNS Stewardship, the art of controlling internet facing projects from conception.

5 Dec 2022 · 2 min read
OWASP Top 10 - 2021
AppSec

OWASP Top 10 - 2021

This post is as much as an internal sit-rep as it is one for others to witness, share and challenge, I'm trying to understand the Top10's value eleven years on, the current top10 (2021) is in draft and open for comment, I've put my comments here, as well as the opening to this conversation on github

3 Dec 2022 · 4 min read
A Method for identifying .onion associated IP addresses
OSINT

A Method for identifying .onion associated IP addresses

This post is in theory, sound, however executing it would take real collaboration that probably doesn't exist and due to the benefits of tor to certain operations is going to be counterproductive,but, something to think about all the same

1 Dec 2022 · 2 min read
Imposter.
InfoSec

Imposter.

Thoughts on Imposter Syndrome, In summation; Imposter Syndrome is the consequence of poor support.

1 Dec 2022 · 2 min read
Publicker.
Defence

Publicker.

Cross-referencing acquired credentials against public known, known bad credentials in a bid to really hit home the cultural change required. or just fully breaking down a target.

1 Jul 2022 · 4 min read
Privacy

Privacy Engineering ?

Grammarly taking more data than it should, a exploration and musings over the idea of privacy engineering in conjunction with application security assessments

9 Apr 2022 · 5 min read
Folders, Files & Canary Fun
Post

Folders, Files & Canary Fun

7 May 2020 · 4 min read
Installation Security Considerations
Defence

Installation Security Considerations

A little tip for defence when software is installed outside of default locations. A little tip for offence when software is installed outside of default locations.

1 Apr 2020 · 3 min read
Active Directory Network Agents and not-good deployments
Exploitation

Active Directory Network Agents and not-good deployments

That’s a Nice Palo-Alto Firewall Forescout Active Directory Integrated Network Appliance you have ther

8 Jul 2016 · 5 min read