John Carroll
Topic

OffSec

Offensive Security Tag, for exploitation, tools, tips and philosophy

Hollow Pentesting
OffSec

Hollow Pentesting

Confidently using AI in your Pentests. Hollow Testing.

30 Mar 2026 · 4 min read
Synology DSM 7.3.2
Exploitation

Synology DSM 7.3.2

Chaining three issues to gain root from a low privileged user.

25 Jan 2026 · 4 min read
File Folding.
Ideas

File Folding.

File Folding is a technique that moves a file into hex, and that hex is broken into folder file names in a fashion that can be reconstructed.

17 Apr 2024 · 4 min read
Data-bouncing
OffSec

Data-bouncing

Data-Bouncing - The art of indirect exfiltration. Using & Abusing Trusted Domains as a 2nd Order Transport.

11 Sep 2023 · 19 min read
Three-Word Password Attacks
OffSec

Three-Word Password Attacks

The idea behind three word passwords as a concept is in my opinion a nice nudge in the right direction, In a perfect world, a passphase or a sentence

16 Aug 2023 · 3 min read
Publicker.
Defence

Publicker.

Cross-referencing acquired credentials against public known, known bad credentials in a bid to really hit home the cultural change required. or just fully breaking down a target.

1 Jul 2022 · 4 min read