<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Wwws on dubell.io</title><link>https://dubell.io/www/</link><description>Recent content in Wwws on dubell.io</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 24 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://dubell.io/www/index.xml" rel="self" type="application/rss+xml"/><item><title/><link>https://dubell.io/</link><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><guid>https://dubell.io/</guid><description/></item><item><title>Vibe Recipes: Turning AI Coding Experience Into Reusable Blueprints</title><link>https://dubell.io/vibe-recipes-turning-ai-coding-experience-into-reusable-blueprints/</link><pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate><guid>https://dubell.io/vibe-recipes-turning-ai-coding-experience-into-reusable-blueprints/</guid><description>&lt;p&gt;Here&amp;rsquo;s a concept I&amp;rsquo;ve been thinking about: vibe recipes.&lt;/p&gt;
&lt;p&gt;Today, people are vibe coding. They have an idea, they fire up their preferred coding agent, and they start giving instructions and building the application they want to build.&lt;/p&gt;
&lt;p&gt;This process can take a day. A week. Sometimes longer, before you end up with the result you&amp;rsquo;re looking for.&lt;/p&gt;
&lt;p&gt;But during that time, you&amp;rsquo;ll encounter problems with the AI model. You&amp;rsquo;ll get incorrect results. You may have to repeat yourself. The AI might introduce bugs, introduce security vulnerabilities, misunderstand the business logic you&amp;rsquo;re trying to implement, or mess up the workflow entirely.&lt;/p&gt;</description></item><item><title>Building Your Personal Council of Experts</title><link>https://dubell.io/building-your-personal-council-of-experts/</link><pubDate>Sat, 24 Jan 2026 00:00:00 +0000</pubDate><guid>https://dubell.io/building-your-personal-council-of-experts/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;
&lt;p&gt;My council of experts is three (or more) AI personas designed to argue from specific perspectives such as application security, and software development and software architecture.&lt;/p&gt;
&lt;p&gt;The idea is that when you use, for example, Claude Code or some other coding agent to generate a development plan, the council will receive the plan and debate it amongst themselves. The output from the council is returned to the coding agent, and the plan can be updated if needed.&lt;/p&gt;</description></item><item><title>Stop using chat interfaces for your command line interfaces!</title><link>https://dubell.io/stop-using-chat-interfaces-for-your-command-line-interfaces/</link><pubDate>Tue, 01 Jul 2025 00:00:00 +0000</pubDate><guid>https://dubell.io/stop-using-chat-interfaces-for-your-command-line-interfaces/</guid><description>&lt;p&gt;You are running an Nmap scan on a target, you encounter an unfamiliar service, what do you do? Alt-tab to your preferred AI, query: &amp;ldquo;what is this service and is there any known vulnerabilities?&amp;rdquo;, wait for the response, and then you continue your vulnerability research.&lt;/p&gt;
&lt;p&gt;This workflow is fundamentally broken. We&amp;rsquo;re using AI as a glorified command line when it should be our always-on research assistant, integrated directly into our security workspace.&amp;quot;&lt;/p&gt;</description></item><item><title>Leveraging BM25 and Vector Search in a Local RAG Application</title><link>https://dubell.io/leveraging-bm25-and-vector-search-in-a-local-rag-application/</link><pubDate>Tue, 01 Apr 2025 00:00:00 +0000</pubDate><guid>https://dubell.io/leveraging-bm25-and-vector-search-in-a-local-rag-application/</guid><description>&lt;p&gt;As a consultant in cybersecurity, I write numerous of reports documenting security vulnerabilities discovered in the customer&amp;rsquo;s application or network. Sometimes, there&amp;rsquo;s a considerable amount of findings, and this requires me to focus more of my hours on writing the report, instead of discovering vulnerabilities. For example, I have written a report that contained 70+ security vulnerabilities. This took time to write and to QA (quality assurance).&lt;/p&gt;
&lt;p&gt;To reduce hours spent on writing the report, I turned to AI. Can I use AI to automatically expand my raw notes into well defined security findings? Turns out that worked very well. With the right prompting and relevant model, expanding my raw notes into a well structured finding worked great.&lt;/p&gt;</description></item><item><title>Unicode's Secret Compartment: The Variation Selector Trick</title><link>https://dubell.io/unicodes-secret-compartment-the-variation-selector-trick/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://dubell.io/unicodes-secret-compartment-the-variation-selector-trick/</guid><description>&lt;p&gt;I recently stumbled upon an &lt;a href="https://paulbutler.org/2025/smuggling-arbitrary-data-through-an-emoji/"&gt;article&lt;/a&gt; written by Paul Butler. It caught my eye because it described a method for hiding data in text using unicode variation selectors. The method does not distort the main text or add any characters that might give away the secret message. You can try it out &lt;a href="https://dubell.io/mnt/tools/unicode-variation-selector/tool.html"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The idea is simple, by using variation selectors which are used to modify the presentation of the preceding character, you can inject a unicode variation selector that does not modify the preceding character and is ignored during rendering.&lt;/p&gt;</description></item><item><title>So you want to run AI models locally?</title><link>https://dubell.io/so-you-want-to-run-ai-models-locally/</link><pubDate>Wed, 15 Jan 2025 00:00:00 +0000</pubDate><guid>https://dubell.io/so-you-want-to-run-ai-models-locally/</guid><description>&lt;p&gt;AI has undoubtedly been the center of human thought in 2024 and 2025. The improvement potential AI can bring to humanity is epic. However, there is a fundamental problem with the current state of AI. The best and brightest models often require immense computing power which the majority of people do not have. Instead, people are forced into using proprietary models and are also required to accept that their conversations will be mined and analysed.&lt;/p&gt;</description></item><item><title>DLL Hijacking in MobilePASS version 8.4.4.99</title><link>https://dubell.io/dll-hijacking-in-mobilepass-version-8.4.4.99/</link><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><guid>https://dubell.io/dll-hijacking-in-mobilepass-version-8.4.4.99/</guid><description>&lt;p&gt;During an engagement, I identified a DLL hijacking vulnerability in &lt;a href="https://apps.microsoft.com/detail/9nblggh10pdq?hl=en-us&amp;amp;gl=US"&gt;MobilePASS&lt;/a&gt; for Windows, version 8.4.4.99. MobilePASS is a Two-factor authentication solution, which can run on Windows.&lt;/p&gt;
&lt;p&gt;When MobilePASS is executed, it attempts to load &lt;code&gt;etoken.dll&lt;/code&gt; from several locations, including the user&amp;rsquo;s desktop folder and the &lt;code&gt;%APPDATA%&lt;/code&gt; directory.&lt;/p&gt;
&lt;p&gt;&lt;img src="process-monitor.png" alt="process-monitor.png"&gt;&lt;/p&gt;
&lt;p&gt;This enables an attacker with local access to place a malicious &lt;code&gt;etoken.dll&lt;/code&gt; in the directory where MobilePASS attempts to load it. As a result, the attacker can disguise their activity behind MobilePASS.&lt;/p&gt;</description></item><item><title>Server-Side Request Forgery in HikCentral Professional &lt;= V2.5.1</title><link>https://dubell.io/server-side-request-forgery-in-hikcentral-professional-v2.5.1/</link><pubDate>Tue, 14 May 2024 23:00:00 +0200</pubDate><guid>https://dubell.io/server-side-request-forgery-in-hikcentral-professional-v2.5.1/</guid><description>&lt;p&gt;During an engagement, I encountered HikCentral Professional. I did not find any relevant CVEs and therefore decided to download the software and perform a quick analysis. Upon examining the related configuration files, I immediately identified a Server-Side Request Forgery (SSRF) in the NGINX configuration file. The SSRF allowed an attacker to proxy requests via HikCentral Professional, which could lead to severe consequences. For example, an attacker could use the vulnerability to reach into a private network and access internal services.&lt;/p&gt;</description></item><item><title>Rusty Beginnings: Error Handling in Rust</title><link>https://dubell.io/rusty-beginnings-error-handling-in-rust/</link><pubDate>Fri, 26 Apr 2024 20:32:37 +0000</pubDate><guid>https://dubell.io/rusty-beginnings-error-handling-in-rust/</guid><description>&lt;p&gt;I never liked the verbosity of Rust. Rust code always looked messy and so different from what I am used to. But since I started learning Rust, I have begun to enjoy the language. However, one thing that has been more difficult than what I have imagined it to be, is error handling.&lt;/p&gt;
&lt;p&gt;For example, in Go it is normal to return &lt;code&gt;Error&lt;/code&gt; and simply set it &lt;code&gt;nil&lt;/code&gt; if there is no error. In Rust however, error handling has far more expressive. As part of my rusty learning experience, I would like to document how to perform structured error handling which involves managing errors in a consistent and maintainable manner to create more robust code.&lt;/p&gt;</description></item><item><title>Hacking the Success Code: 6 Habits Every Penetration Tester Must Have</title><link>https://dubell.io/hacking-the-success-code-6-habits-every-penetration-tester-must-have/</link><pubDate>Thu, 05 Oct 2023 14:51:17 +0200</pubDate><guid>https://dubell.io/hacking-the-success-code-6-habits-every-penetration-tester-must-have/</guid><description>&lt;p&gt;After have working professionally in cyber security as a penetration tester for half a decade (hacking scene for 10+), I feel I have learned a few things on how to improve your skill set, way of working and communicating with customers. I have also had the opportunity to work with some great people in cyber security from which I have learned considerably from.&lt;/p&gt;
&lt;p&gt;In this article, I will present six habits which I believe represent a strong penetration tester. Let&amp;rsquo;s dive in!&lt;/p&gt;</description></item><item><title>Supercharge Your Integration Tests with the Power of Docker</title><link>https://dubell.io/supercharge-your-integration-tests-with-the-power-of-docker/</link><pubDate>Tue, 19 Sep 2023 12:25:17 +0200</pubDate><guid>https://dubell.io/supercharge-your-integration-tests-with-the-power-of-docker/</guid><description>&lt;p&gt;In the beginning of my developer career, I learned to use in-memory databases for running integration tests. The in-memory database made it easy to spin up a local database which is often needed for integration testing. However, there are some drawbacks with this approach.&lt;/p&gt;
&lt;h3 id="a-clever-illusion"&gt;A Clever Illusion&lt;/h3&gt;
&lt;p&gt;Using an in-memory database does not reflect the real database running in production. The local database may look and feel like the real deal, but it&amp;rsquo;s essentially an illusion, and a clever one.&lt;/p&gt;</description></item><item><title>Learn AI or Get Left Behind</title><link>https://dubell.io/learn-ai-or-get-left-behind/</link><pubDate>Tue, 12 Sep 2023 12:25:17 +0200</pubDate><guid>https://dubell.io/learn-ai-or-get-left-behind/</guid><description>&lt;p&gt;The AI boom has not gone unnoticed, ChatGPT captured everyone&amp;rsquo;s attention with its science fiction like behavior, and the generative image AIs have gone super nova, disrupting everything we knew about art.&lt;/p&gt;
&lt;p&gt;We have not yet figured out what all this means for the future. One thing is clear though, if you want to be apart of the future, you&amp;rsquo;re going to need to learn AI.&lt;/p&gt;
&lt;p&gt;Large language models (LLMs) have already taken people by storm and changed how people work. Professions like human resources, content writers, support and many more, have seen their respective fields disrupted beyond imagination. This is only the beginning, more professions are going to experience the same shock to their systems.&lt;/p&gt;</description></item><item><title>Deploying Django with Github Actions and Docker</title><link>https://dubell.io/deploying-django-with-github-actions-and-docker/</link><pubDate>Sat, 02 Sep 2023 14:51:17 +0200</pubDate><guid>https://dubell.io/deploying-django-with-github-actions-and-docker/</guid><description>&lt;p&gt;In this article, you will learn how to deploy your Django application to your VPS using Github Actions.&lt;/p&gt;
&lt;p&gt;If you want to, you can checkout one of my Django applications here, where I have implemented the steps described in this article.
The main idea is that every time you create a &amp;ldquo;release&amp;rdquo;, Github will pick up newest release version and trigger a docker build for that release. The end result is quite amazing, because now you can simply run &lt;code&gt;docker pull ghcr.io/&amp;lt;user&amp;gt;/repo:latest&lt;/code&gt; on your VPS to get the latest version.
The article assumes a moderate level of understanding of docker.&lt;/p&gt;</description></item><item><title>Should you take a black box approach or a white box approach in penetration testing?</title><link>https://dubell.io/should-you-take-a-black-box-approach-or-a-white-box-approach-in-penetration-testing/</link><pubDate>Sun, 20 Nov 2022 12:25:17 +0200</pubDate><guid>https://dubell.io/should-you-take-a-black-box-approach-or-a-white-box-approach-in-penetration-testing/</guid><description>&lt;p&gt;Lately, customers have been asking for a black box approach when performing a penetration test of their system/web application. During meetings, it has been clear to me that the stakeholders do not fully understand the differences between a white box and a black box approach and what benefits they provide. Therefore I would like to write down some of my thoughts on the subject, perhaps it will give an additional perspective when choosing between these approaches.&lt;/p&gt;</description></item><item><title>Measuring attack paths in web applications</title><link>https://dubell.io/measuring-attack-paths-in-web-applications/</link><pubDate>Sat, 29 Oct 2022 14:51:17 +0200</pubDate><guid>https://dubell.io/measuring-attack-paths-in-web-applications/</guid><description>&lt;p&gt;Recently a customer asked us after our penetration test against their web application, the percentage of possible attack paths we had covered. It was a difficult question to answer because, a) the customer wanted us to focus on SQL injection and XSS (long story why) and b) it was a legacy application from 2003 containing a lot of code. The short answer I gave was that since the test was focused towards SQLi and XSS, naturally, some attack paths were not considered. The customer understood this and accepted it.&lt;/p&gt;</description></item><item><title>My thoughts on Secure Code Review</title><link>https://dubell.io/my-thoughts-on-secure-code-review/</link><pubDate>Fri, 01 Jul 2022 09:51:17 +0200</pubDate><guid>https://dubell.io/my-thoughts-on-secure-code-review/</guid><description>&lt;p&gt;In this article I would like to share my thoughts, methodologies and techniques on how I perform &lt;em&gt;secure&lt;/em&gt; code review. By &lt;em&gt;secure&lt;/em&gt; I mean code review with the purpose of finding unknown vulnerabilities. My focus is generally on web applications, but the ideas mentioned below apply to other types of software as well.&lt;/p&gt;
&lt;h3 id="1-understanding-"&gt;1. Understanding 👨‍🏫&lt;/h3&gt;
&lt;p&gt;Begin by understanding the application. Browse through the code and the application&amp;rsquo;s functionality until you have a clear intuition for what the application is capable of. By browsing the code, you get a feel for the quality and style of the code. By quality I mean: is there a lot of duplicate code, how are variables and functions named? Is there a lot of over-engineering going on? This may be an indication of unnecessary complexity that might contain vulnerabilities.&lt;/p&gt;</description></item><item><title>Python gems to look out for</title><link>https://dubell.io/python-gems-to-look-out-for/</link><pubDate>Wed, 29 Jun 2022 00:00:00 +0000</pubDate><guid>https://dubell.io/python-gems-to-look-out-for/</guid><description>&lt;p&gt;A few weeks ago I was looking into Python specific code patterns that would lead to vulnerabilities. I was surprised when I found a few patterns that I hadn&amp;rsquo;t really thought about, most likely because I never write Python code like the examples I found. Nevertheless, I learned something new and thought I share it here.&lt;/p&gt;
&lt;h2 id="example-one"&gt;Example One&lt;/h2&gt;
&lt;p&gt;Passing an untrusted string to an &lt;code&gt;f-string&lt;/code&gt; while passing a dict as an argument to the logger, may give the attacker the possibility to read keys in the dict that should not be readable.&lt;/p&gt;</description></item><item><title>Unauthenticated LFI in Appwrite 0.5.0 &lt;= 0.12.1</title><link>https://dubell.io/unauthenticated-lfi-in-appwrite-0.5.0-0.12.1/</link><pubDate>Tue, 22 Feb 2022 13:13:37 +0000</pubDate><guid>https://dubell.io/unauthenticated-lfi-in-appwrite-0.5.0-0.12.1/</guid><description>&lt;p&gt;While exploring cyber space I stumbled upon a project called &lt;a href="https://appwrite.io"&gt;Appwrite&lt;/a&gt;. Looked interesting, started browsing the code. Eventually, I discovered an undisclosed vulnerability in one of the endpoints allowing an attacker to read local files on the system.&lt;/p&gt;
&lt;p&gt;The endpoint &lt;code&gt;/.well-known/acme-challenge&lt;/code&gt; is vulnerable against local file inclusion which allows an attacker to read arbitrary files on the system. The endpoint contains incorrect checks for verifying that file is located within a defined base path. Vulnerable versions include version 0.5.0 to 0.11.0. The vulnerability does not require authentication.&lt;/p&gt;</description></item><item><title>Overwriting HttpOnly cookies with Javascript</title><link>https://dubell.io/overwriting-httponly-cookies-with-javascript/</link><pubDate>Mon, 01 Nov 2021 13:13:37 +0000</pubDate><guid>https://dubell.io/overwriting-httponly-cookies-with-javascript/</guid><description>&lt;p&gt;So I got in contact with &lt;a href="https://twitter.com/SamuelAnttila"&gt;Sam Anttila&lt;/a&gt; on twitter regarding his &lt;a href="https://netsec.expert/posts/mitigation-schmitigation-xss-and-httponly/"&gt;article&lt;/a&gt; about overwriting HttpOnly enabled cookies using Javascript, which &lt;em&gt;should&lt;/em&gt; not be possible. I asked him if he had verified if Firefox exhibits the same behavior. He answered yes and the result was negative, but the test was done a long time ago and things could have changed. So I decided to try it out myself, as you should :)&lt;/p&gt;</description></item><item><title>Technical Analysis Of The Necr0 Python Malware</title><link>https://dubell.io/technical-analysis-of-the-necr0-python-malware/</link><pubDate>Mon, 20 Apr 2020 13:13:37 +0000</pubDate><guid>https://dubell.io/technical-analysis-of-the-necr0-python-malware/</guid><description>&lt;p&gt;I recently got a hold of a malware sample written in python that dropped crypto currency miners, among other things. It was built with Python2.7 and was heavily obfuscated. I decided to analyse it and try to break it apart to understand it better and its capabilities.&lt;/p&gt;
&lt;p&gt;In this article, I will show some parts of the malware and explain its purpose. I will also provide some detection techniques for detecting this specific malware.&lt;/p&gt;</description></item><item><title>SLAE 7: Creating your own crypter using golang</title><link>https://dubell.io/slae-7-creating-your-own-crypter-using-golang/</link><pubDate>Mon, 27 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-7-creating-your-own-crypter-using-golang/</guid><description>&lt;p&gt;In this article, we will build a simple crypter for encrypting and decrypting shellcode. I chose to implement the crypter in Go using environmental keys.&lt;/p&gt;
&lt;p&gt;I will not spend time implementing a fancy shellcode execution method in this article, only encryption and decryption methods are in scope for now.&lt;/p&gt;
&lt;h2 id="encryption"&gt;Encryption&lt;/h2&gt;
&lt;p&gt;The encryption/decryption process is using AES GCM and a specific file in &lt;code&gt;/etc/&lt;/code&gt; concatenated with the current user logged in as the key. This is called &lt;em&gt;Environmental Keying&lt;/em&gt;, meaning you use specific values found in the victim&amp;rsquo;s environment such as files, hostname or users. The purpose of this is to make sure that your malware &lt;strong&gt;only&lt;/strong&gt; executes in a specific environment. This means the attacker needs to know some details about the environment before encrypting any shellcode.&lt;/p&gt;</description></item><item><title>SLAE 6: Creating polymorphic shellcode</title><link>https://dubell.io/slae-6-creating-polymorphic-shellcode/</link><pubDate>Sun, 26 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-6-creating-polymorphic-shellcode/</guid><description>&lt;p&gt;The goal of this article is to create polymorphic verions of three different shellcodes from &lt;a href="http://shell-storm.org"&gt;http://shell-storm.org&lt;/a&gt;. Polymorphic shellcode has the ability to mutate its code everytime it runs. The instructions changes while algorithm stays intact. The purpose is to evade signature based detections without manually change the shellcode.&lt;/p&gt;
&lt;p&gt;We won&amp;rsquo;t be creating our own polymorphic engine in this article, instead we will manually modify these three shellcodes from shell-storm.org:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://shell-storm.org/shellcode/files/shellcode-876.php"&gt;Linux/x86 - shutdown -h now Shellcode - 56 bytes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://shell-storm.org/shellcode/files/shellcode-65.php"&gt;Linux/x86 - 40 byte shellcode to flush ipchains for Linux x86&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://shell-storm.org/shellcode/files/shellcode-862.php"&gt;Linux/x86 - Download + chmod + exec - 108 bytes &lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We are not allowed to increase the size more than 50%.&lt;/p&gt;</description></item><item><title>SLAE 5: Analyzing shellcode generated by msfvenom</title><link>https://dubell.io/slae-5-analyzing-shellcode-generated-by-msfvenom/</link><pubDate>Sat, 25 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-5-analyzing-shellcode-generated-by-msfvenom/</guid><description>&lt;p&gt;In this article, I will analyse three shellcode samples generated by msfvenom, specifically:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;linux/x86/read_file&lt;/li&gt;
&lt;li&gt;linux/x86/adduser&lt;/li&gt;
&lt;li&gt;linux/x86/shell/reverse_tcp&lt;/li&gt;
&lt;/ul&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;msfvenom --list payloads -a x86 --platform linux
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Let&amp;rsquo;s see if there is something new we can learn from these samples :)&lt;/p&gt;
&lt;h2 id="analyzing-linuxx86read_file"&gt;Analyzing linux/x86/read_file&lt;/h2&gt;
&lt;p&gt;First, we generate the executable like so:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;msfvenom -p linux/x86/read_file -a x86 --platform linux PATH=/etc/passwd FD=2 -f elf -o read_file
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;I set the payload options &lt;code&gt;PATH&lt;/code&gt; and &lt;code&gt;FD&lt;/code&gt; to &lt;code&gt;/etc/passwd&lt;/code&gt; and &lt;code&gt;2&lt;/code&gt;. Executing the program outputs the contents of &lt;code&gt;/etc/passwd&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>SLAE 4: Custom encoder for bypassing signature based detection</title><link>https://dubell.io/slae-4-custom-encoder-for-bypassing-signature-based-detection/</link><pubDate>Fri, 24 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-4-custom-encoder-for-bypassing-signature-based-detection/</guid><description>&lt;p&gt;Malware detection techniques has improved a lot over the years. Today companies are investing in machine learning methods for detecting malware, which sounds pretty cool if you ask me. However, there is one method that has been used since the first anti-virus software, which is signature based detection.&lt;/p&gt;
&lt;p&gt;When disassembling a program you can analyze the assembly instructions in order to understand the program from the lowest level. It&amp;rsquo;s also possible from the assembly code to identify a set of unique instructions that identifies a specific program. These unique instructions form the signature. The instructions can be anything that identifies a specific and unique behaviour in the program. An example could be a decryption routine that identifies a decryption stub used for decrypting shellcode.&lt;/p&gt;</description></item><item><title>SLAE 3: Egg hunting in Linux x86 Assembly</title><link>https://dubell.io/slae-3-egg-hunting-in-linux-x86-assembly/</link><pubDate>Wed, 22 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-3-egg-hunting-in-linux-x86-assembly/</guid><description>&lt;p&gt;When writing exploits, you sometimes encounter a situation where your payload is too big, you can&amp;rsquo;t fit your payload inside the buffer. This is where &amp;ldquo;eggs&amp;rdquo; come in to play. The basic idea of egg hunting is to divide the payload in to two parts, part one is the hunter while part two is the hunted (the egg). The hunter is a set of instructions that searches the program&amp;rsquo;s virtual address space for a given pattern (the egg). Once it is found, the hunter will jump to the payload following the egg.&lt;/p&gt;</description></item><item><title>SLAE 2: Creating a reverse TCP shell in x86 Assembly</title><link>https://dubell.io/slae-2-creating-a-reverse-tcp-shell-in-x86-assembly/</link><pubDate>Tue, 21 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-2-creating-a-reverse-tcp-shell-in-x86-assembly/</guid><description>&lt;p&gt;&lt;strong&gt;What is a reverse TCP shell?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A reverse TCP shell is a program that instead of listening for incoming connections, the program will connect to a remote system and provide a local shell. This is useful in situations where the victim system is behind NAT, meaning you can&amp;rsquo;t directly connect to it, instead the server will connect to you. For this reason, reverse TCP shells are usually prefered over bind shells.&lt;/p&gt;</description></item><item><title>SLAE 1: Creating a bind shell in x86 Assembly</title><link>https://dubell.io/slae-1-creating-a-bind-shell-in-x86-assembly/</link><pubDate>Mon, 20 Jan 2020 13:33:37 +0000</pubDate><guid>https://dubell.io/slae-1-creating-a-bind-shell-in-x86-assembly/</guid><description>&lt;p&gt;&lt;strong&gt;What is a bind shell?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A Bind shell is simply a program that listens for incoming connections. When a connection is made, a local shell is redirected to the newly created connection, thereby giving access to the local machine. Bind shells are usually created for backdoor access, although they could also be used for legitimate purposes, e.g. system administration.&lt;/p&gt;
&lt;h2 id="ok-nuff-said-lets-boogie"&gt;ok, nuff said, let&amp;rsquo;s boogie&lt;/h2&gt;
&lt;p&gt;Our program will follow these steps:&lt;/p&gt;</description></item><item><title>Hack The Box - Olympus Writeup</title><link>https://dubell.io/htb-olympus-writeup/</link><pubDate>Thu, 15 Aug 2019 00:00:00 +0000</pubDate><guid>https://dubell.io/htb-olympus-writeup/</guid><description>&lt;p&gt;I begun by scanning the box to find some interesting ports.&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;PORT STATE SERVICE VERSION
22/tcp filtered ssh
53/tcp open domain (unknown banner: Bind)
80/tcp open http Apache httpd
2222/tcp open ssh (protocol 2.0)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Port 80 was open so I visited the site and found a picture of the almighty God Zeus. I checked the response headers in the developer console and noticed the &lt;code&gt;xdebug&lt;/code&gt; variable. According to my google fu, it&amp;rsquo;s a PHP debugger which among other things, can be used to debug &lt;a href="https://xdebug.org/docs/remote"&gt;&lt;em&gt;remote&lt;/em&gt;&lt;/a&gt; PHP applications.&lt;/p&gt;</description></item><item><title>Security Recommendations For Implementing BankID</title><link>https://dubell.io/security-recommendations-for-implementing-bankid/</link><pubDate>Sun, 19 May 2019 20:32:37 +0000</pubDate><guid>https://dubell.io/security-recommendations-for-implementing-bankid/</guid><description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href="https://kits.se/blogg-2019-05-13/bankid-anyone"&gt;https://kits.se/blogg-2019-05-13/bankid-anyone&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;BankID is the leading identification solution in Sweden that allows companies and government agencies to authenticate individuals over the Internet. BankID offers an API which makes integration easy for companies.&lt;/p&gt;
&lt;p&gt;In this article I will describe BankID API features which developers should use to limit the effectiveness of today’s phishing attacks against BankID. I will also cover how QR codes can be used as a method for authentication/signing with mobile BankID and how it can improve security.&lt;/p&gt;</description></item><item><title>My OSCP Review</title><link>https://dubell.io/my-oscp-review/</link><pubDate>Sun, 20 Jan 2019 00:00:00 +0000</pubDate><guid>https://dubell.io/my-oscp-review/</guid><description>&lt;p&gt;In this blog post I&amp;rsquo;ll write about my experience taking the OSCP certification as well as some recommendations for people wanting to take the exam.&lt;/p&gt;
&lt;p&gt;I got access to the OSCP lab network 2019-09-09 and lost access 2019-12-08. As you can see I chose 90 days of lab time. The number one thing I read in all the OSCP reviews out there was that do not underestimate the amount of time it takes to be successful in the lab network.&lt;/p&gt;</description></item><item><title>SEC-T CTF - G1bs0n Writeup</title><link>https://dubell.io/sec-t-ctf-g1bs0n-writeup/</link><pubDate>Sun, 17 Sep 2017 00:00:00 +0000</pubDate><guid>https://dubell.io/sec-t-ctf-g1bs0n-writeup/</guid><description>Hacking the gibson, one byte at the time&amp;hellip;</description></item><item><title>UIUCTF - Are we out of the woods yet? Reversing 350p</title><link>https://dubell.io/uiuctf-are-we-out-of-the-woods-yet-2/</link><pubDate>Sun, 30 Apr 2017 00:00:00 +0000</pubDate><guid>https://dubell.io/uiuctf-are-we-out-of-the-woods-yet-2/</guid><description>&lt;pre tabindex="0"&gt;&lt;code&gt;It looks like this python script was run through a custom packer. It&amp;#39;s just Python*, which means it must be easy to reverse, right?

*v3.6.1:69c0db5

https://www.youtube.com/watch?v=y8qQsXpcZXA
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This was fun little challenge that our team (&lt;a href="https://chalmersctf.se"&gt;https://chalmersctf.se&lt;/a&gt;) solved together. You are presented with the file &lt;code&gt;packed.py&lt;/code&gt; that contains the following code:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;import marshal, zlib, base64, itertools
def xor_strings(_left, _k):
 out = b&amp;#39;&amp;#39;
 for l, r in zip(_left, itertools.cycle(_k)):
 out += (l ^ ord(r)).to_bytes(1, byteorder=&amp;#39;big&amp;#39;)
 return out

def YET_eval_code(p1, p2):
 YET_code = marshal.loads(zlib.decompress(xor_strings(base64.b64decode(p2), p1)))
 eval(YET_code)

YET_eval_code(&amp;#34;YET&amp;#34;, b&amp;#39;IdkZDw77+o1N7Di7tKvNdbcGSyxAHBQCMDw12oRMcF9ROnVSwvKV+QF5+XW7ro70gu6ab7p1grlxNvbOLDMNXJpNfMagxOrwCrApxe8WxToZJ7Fo1LSzaO87HkVHachzv7ItMwuLq4nI5KBzqkyYmZaLf6NnIUN7OjslBoVvqbufNX+mk6G33qpKTDwzrwa5znSK1ARqs3rO2ayzgCgJFhtzrHHI5AvrFfqYL9brp6R76oobxtoLPuobrJa/qtJ9aEzLRviUqpozgaGn9b3hZzzJ1FgKoTprUzpjRKSqPUKKnqypcv77hOlQN7ylvLtgXbyp8uUikn+fu6+qu7EatZvLH7uq+ItqZKMCuvnDFvQv9KrnFpScbLApQ5rzvHpzvIqSm7qtk+WAhTd2TpkrK46eFhAJX+wDZCEBRlup/oqHNuPrwtPrQYKrCr6g2qdj7DpI+NvQij9CZ5CbrA6st+SiLLcxby9KLuQqpn/anzjP1e/ypYJbrrLdDBPqTJoLu4lWjLgt0Uavp3AkxGmdEvL+h/+JhpwCvOvFCLBOIDWU5Hrv9FArJXczYHFSNTsZR2wWp7G0h7EoVnor9bu9rpE3mF6rCRZp5gyutPGoP4mykp7As1p3fKWQ2COHQwB1cBrTy93iUvdvyoDiNYlHZ2Fgcr8zuRc6dKx1WtF052zhQuxMwo1eZ61u0k9XhOJPfBYeJ/QGU3yfiN4IHmgMOXznCRLgRmul7B+DYKLbXOHAHjYfvV+7RSQ1FrzxfFt/NWpaRTzKHvUltc4s3JiC4SvJpYQ5AiLrcF079BsC4ktOKZBrAU5Ys7n2kCYn6sbNd5uOlOMdEJXmL6t0UNpi7aXv0ntvswTVEyDCkgb3cUwDSxBREu3SKkQ+TSAaq6G6MRkHle9k9bJp5FwGMZBY9Gy605jyH7O6vKd5IkLX82SVQt6UVYmz4DHtTTP5wvWn9yf7HAb8X5pB4e1eoZQWjrsm56SjGvoGSGpqkei8yG32OecHjq4i8rBJu5hA1RgedxkKk2eNkhQnB9E8n1rE631x8sh+iY7YBfOvrGja0tPWHU5lQw3oBCsndS4fuHOgqeBGQz3xOIN51f2VG9N6in8xKP3iPxWBFPEZMi+LRYByR/PdMBDcm2xgLS2dAX650nh3uf/nwR4okZAn5Kesl17aJFtxRH/wIeiewc5v/ma77CKa3sdEKB6QYXT8V6DzlI9AVLCwlY4wbGrQJ50FwaXCexviMm+SvK/mar/wg7R4n9DJkqQG9ttSOiD4JNGxlciIU+8l1yFvSIwx2lZv95BGkoeUJWtNeHwDjsze/d3pLJL5WS5uxGeQxSaRf33/ZQ3hC1ImnSOj7CvgCzX+ONPZ015B/DbPO4If9B0KSAIXMnZRvNDN3Vj6rRTaZIpG5ILBqMAAYP//GSoFybXk9TF/OvD0SuN6TYpXyA9LrTF5RN1aezlNzGbT+d2uLRxdh0CRjRPnXACEAIU8oz9X3DT8emRPIaSi7UZ2LXiwUjT7MNIfIv76rNNAAjc7M3+0umCXiRBn51xRkFA+jAe88B6ZY0z/gpCyrNeV+3bAKkPLAR0bslOTfh69TwE23FONJ9uw1OSnE/lfcY5fJUL/l/37lfhB/fbtciyOhw5dQbM+0h8FgAjc3OkxrlIpyW0PYTa0VTJPzmgnCQxpKwCnFEUd22j4Wv/t38NeqsAVdNB2sVUlPFSn4/ls9EW57sddKVwZBIK9QX577WWHsM+8C0b1bN/ebkyTxaIAguZ/35b0Tzcbh/UNScwgDbXKtjLGvu5mKG0GBFfcg3NkDnmF6YCxztszEwX72DinUfpAk3AhnIpSJMMco//VTrg2JiuHNPrtdfYpNiadE3dvIBQTqu/VNId0uYEaxEEGnWl6LoBGKLPVK6NpUM7gwZzTHMCUiTAtyXXQ2OCAi272ZFfkhc10+YwkguyQb+VT+VjZqmCJKn4HT/bOG4XoM5ROd36u5cvdWE7goOyetdbcgfdqoZB6cwUvqSqdAMuvOA6z7vtrI3dbLBj7sbv5DlYe2omV2tGhTy++usTqOBL9PutSEI6ebG+MMtkfB52mDRb0QYkykqfkm3Fdy6ODbJ96wYknnY0Qr52e5clvtLHJ4aCzzHNK+d/c4i0NuLYtUTliEBdROV535dzoPAPcl98gN0DsWFBAFmAsNEkOUFRhvP4kk3FT23/MGakbnm6a2IN7G6vgsl1yaQb9BQfODdtnh8SYkyVHqhUfYdh5LuNV3qYT7O2WSo33y8n3XBhQ/gSGAe7ALRNhfD3HQtgVcH2WyoL/kmRi/WohIfjf6MA2jPHPQckasFxwKVc5rwS6/N0F4EJAAkFYDiODN/29r5uMQtnjtB/6gdZNT/Umjr8QkdRFgCKwX2mB/K1kf+5AZfIATOgZ9+gAd0/veeClPhYU7m6D99OS7zctg4NR8LCivwxjPI4UcfuTqf3i2Dk5ebw+Y35RKdwSkRgJxHMh13GeoPPuW1S90qYsyfGDg6KCgBt6qyP60lX/BbNOASutLMLxnQBZgNkISVfVsuz2vUlAWsq0E4ZEqd+JoOn6BkRQvpQ9Ltb0o8nEwj0jjEpyXMZ56RMXEay0IyG5WvJD1309fKdyTlidj74Hw/B8yEeK3CvPVCwsvsQlvIbeVxnqCN1SE1LDa5Q2dEO0H9CP9Brs9F9Afr182V0/XNkyghuLvPOEatSbo86KO8DI+flZ80gIBZ09DD2Ojxoy+Bz73L8UQV3mAUV8kbYuMA02J34BSFX8qhAhM+ACgjtT7JnFgt3x9Bz0h0SJZl3VxhrcK/Ynqw1pAEHE2exvnVRhX9tNTibRXhA/LZEc0xholsdG73ZG4xi4I2s7DnidKX0w1jLXPaXIuRP5esIV2ygPM1j1veSroeuovIaOpa9V5jyUokJoJZfPzrzForzrXL+k/mFXFKkqorXEjIbKpzuuuJjTvrpWCUQt2Q==&amp;#39;)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;We could quickly deduce that there was an embedded python program encoded with base64. In order to reveal the program we decompiled &lt;code&gt;YET_code&lt;/code&gt; variable with &lt;a href="https://docs.python.org/3/library/dis.html" title="Disassembler for Python bytecode"&gt;dis&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>VolgaCTF - Bloody Feedback writeup</title><link>https://dubell.io/volgactf-bloody-feedback-writeup/</link><pubDate>Tue, 28 Mar 2017 00:00:00 +0000</pubDate><guid>https://dubell.io/volgactf-bloody-feedback-writeup/</guid><description>&lt;pre tabindex="0"&gt;&lt;code&gt;Bloody Feedback

Send your feedback at bloody-feedback.quals.2017.volgactf.ru

DO. NOT. USE. SQLMAP
Otherwise your IP will be banned
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The challenge basically has two functions, 1) Send feedback and 2) view the status of the sent feedback. There is also page that cotains &amp;ldquo;Top Messages&amp;rdquo; which is the feedback people send in. When you send feedback you get a token back which you can use to see if the feedback has been processed or not.&lt;/p&gt;</description></item><item><title>VolgaCTF - Share Point writeup</title><link>https://dubell.io/volgactf-share-point-writeup/</link><pubDate>Tue, 28 Mar 2017 00:00:00 +0000</pubDate><guid>https://dubell.io/volgactf-share-point-writeup/</guid><description>&lt;pre tabindex="0"&gt;&lt;code&gt;Share Point

Look! I wrote a good service for sharing your files with your friends, enjoy)
share-point.quals.2017.volgactf.ru
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The challenge begun by signing in to the control panel by simply entering random account details. Once logged in you had the ability to upload files and share them with an other user. Since the site only had one functionality, uploading files, I assumed the goal had to be to upload a web shell and find the flag on the file system.&lt;/p&gt;</description></item><item><title>Chalmers CTF</title><link>https://dubell.io/chalmers-ctf/</link><pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate><guid>https://dubell.io/chalmers-ctf/</guid><description>&lt;p&gt;Hey, long time since last post, been busy with university and starting Chalmers very first CTF team: &lt;strong&gt;Chalmers CTF&lt;/strong&gt;!!&lt;/p&gt;
&lt;p&gt;Check out our website for information: &lt;a href="https://chalmersctf.se"&gt;https://chalmersctf.se&lt;/a&gt;&lt;/p&gt;</description></item><item><title>SEC-T CTF - Confusion Writeup</title><link>https://dubell.io/sec-t-ctf-confusion-writeup/</link><pubDate>Sat, 10 Sep 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/sec-t-ctf-confusion-writeup/</guid><description>&lt;p&gt;This time I participated in the &lt;a href="https://www.sec-t.org/"&gt;SEC-T CTF&lt;/a&gt; event and it was pretty fun! I played with a group of people from my university and we managed to get quite some points. But I didn&amp;rsquo;t manage to solve some of the challenges on time. However this didn&amp;rsquo;t stop from trying to solve them once the event was over!&lt;/p&gt;
&lt;p&gt;One of the challenges I was hooked on was called &lt;strong&gt;Confusion&lt;/strong&gt;. The reason why was because it seemed like an &amp;ldquo;easy&amp;rdquo; challenge but for some reason I couldn&amp;rsquo;t figure it out! The challenge began by downloading the following image:&lt;/p&gt;</description></item><item><title>Exploiting weak Content Security Policy (CSP) rules for fun and profit</title><link>https://dubell.io/exploiting-weak-content-security-policy-csp-rules-for-fun-and-profit/</link><pubDate>Thu, 21 Jul 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/exploiting-weak-content-security-policy-csp-rules-for-fun-and-profit/</guid><description>&lt;p&gt;This article is based on my findings during a bug bounty. I was looking for any input bugs which could trigger a XSS but didn&amp;rsquo;t find any until I tested the file upload functionality. Users had the option to drag&amp;amp;drop images into the company&amp;rsquo;s website and place it in their gallery, however by specifying an image like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-html" data-lang="html"&gt;&lt;span class="line"&gt;&lt;span class="ln"&gt;1&lt;/span&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;https://hackerdomain.hax/img.php&amp;#34;&lt;/span&gt; &lt;span class="na"&gt;onerror&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;this.src=alert(1)&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;And dropping it into the website trigged an XSS.&lt;/p&gt;
&lt;p&gt;Before I continue my report I will first cover what CSP is and what it tries to accomplish. If you feel you are already experienced in the area you can skip to the next section.&lt;/p&gt;</description></item><item><title>Creating SYN flood attacks with Python</title><link>https://dubell.io/creating-syn-flood-attacks-with-python/</link><pubDate>Wed, 22 Jun 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/creating-syn-flood-attacks-with-python/</guid><description>&lt;p&gt;Today it&amp;rsquo;s very easy for people to download tools that overwhelm computer systems &lt;em&gt;(denial of service)&lt;/em&gt; in order to take them offline. There are different types of attacks that can be used to create a denial of service attack, one of them is the SYN flood attack which this article will cover. I will also show how to develop your own SYN flooder and some protection mitigations.&lt;/p&gt;
&lt;h2 id="what-is-a-syn-flood-attack"&gt;What is a SYN flood attack?&lt;/h2&gt;
&lt;p&gt;The SYN flood attack works by the attacker opening multiple &amp;ldquo;half made&amp;rdquo; connections and not responding to any &lt;code&gt;SYN_ACK&lt;/code&gt; packets. In order to understand the SYN flood attack it is vital to understand the TCP 3-way handshake first.&lt;/p&gt;</description></item><item><title>Monitoring your server with Monit</title><link>https://dubell.io/monitoring-your-server-with-monit/</link><pubDate>Sun, 12 Jun 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/monitoring-your-server-with-monit/</guid><description>&lt;p&gt;I run a couple of services on my server, some of them are web, teamspeak, irc and an openvpn server. I need to be notified if any of these services becomes unresponsive for some reason. This is where &lt;a href="https://mmonit.com/monit/"&gt;Monit&lt;/a&gt; comes in.&lt;/p&gt;
&lt;h2 id="what-is-monit"&gt;What is Monit?&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Monit is a small Open Source utility for managing and monitoring Unix systems. Monit conducts automatic maintenance and repair and can execute meaningful causal actions in error situations.&lt;/p&gt;</description></item><item><title>Securityfest CTF - Defacer Challenge Writeup</title><link>https://dubell.io/securityfest-ctf-defacer-challenge-writeup/</link><pubDate>Wed, 08 Jun 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/securityfest-ctf-defacer-challenge-writeup/</guid><description>&lt;p&gt;I actually learned something entirely new on this challenge, I decided I had to do a writeup to share my findings.&lt;/p&gt;
&lt;p&gt;If you read my &lt;a href="https://dubell.io/securityfest-ctf-coresec-challenge-writeup/"&gt;previous Securityfest CTF writeup&lt;/a&gt; you perhaps know that these challenges were from &lt;a href="https://securityfest.com/"&gt;securityfest&lt;/a&gt; held in Sweden, which I attended. I did not solve this particular challenge on time in order to win any prizes, but that didn&amp;rsquo;t stop me from trying to solve it.&lt;/p&gt;
&lt;p&gt;The challenge is to get the flag by defacing this website &lt;a href="http://alienzon.com/"&gt;http://alienzon.com/&lt;/a&gt; which is protected by &lt;em&gt;(simple)&lt;/em&gt; &lt;a href="https://www.owasp.org/index.php/Web_Application_Firewall"&gt;WAF&lt;/a&gt;. I actually spent 4-5 hours on this challenge testing different attack vectors that did not work. I tried SQL injections and XSS attacks all over the place but no joy. So I turned to the place where I thought would be the correct path because it most the most odd part of the website. It was on the &lt;em&gt;Fun Stuff&lt;/em&gt; page under &lt;strong&gt;Be a hero in a star story!&lt;/strong&gt; section. The odd thing about this part is that when you enter your name and click submit, the post request looks like this:&lt;/p&gt;</description></item><item><title>Securityfest CTF - Coresec challenge writeup</title><link>https://dubell.io/securityfest-ctf-coresec-challenge-writeup/</link><pubDate>Mon, 06 Jun 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/securityfest-ctf-coresec-challenge-writeup/</guid><description>&lt;p&gt;This challenge was produced by &lt;a href="http://coresecsystems.com/"&gt;Coresec Systems&lt;/a&gt; and was released during &lt;a href="https://securityfest.com/"&gt;Securityfest&lt;/a&gt;. I would liked to have spent more time on it during the event but couldn&amp;rsquo;t really find any time for it. Now the event is over and first year of university is completed, I decided to try to finish the challenge. It was quite tricky at some points but now when I think about it in hindsight, the challenge itself was actually fairly simple. Okey, nuff said let&amp;rsquo;s boogie!&lt;/p&gt;</description></item><item><title>Using Amazon S3 for your static site? One thing to keep in mind</title><link>https://dubell.io/using-amazon-s3-for-your-static-site-theres-one-thing-to-keep-in-mind-2/</link><pubDate>Mon, 04 Apr 2016 00:00:00 +0000</pubDate><guid>https://dubell.io/using-amazon-s3-for-your-static-site-theres-one-thing-to-keep-in-mind-2/</guid><description>&lt;p&gt;Amazon is a great service for hosting your static website. The way it works is by creating a S3 bucket with the name of your website, uploading your files to the bucket and changing the permissions so that the bucket can be read by the internet.&lt;/p&gt;
&lt;p&gt;So long as your domain points to this bucket, you are all good. However, as you may have realized, if you delete this bucket your website will display an error saying something like:&lt;/p&gt;</description></item><item><title>Basics of netstat</title><link>https://dubell.io/disecting-netstat/</link><pubDate>Tue, 15 Sep 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/disecting-netstat/</guid><description>&lt;p&gt;Netstat is a network tool available in most versions of Windwos, Mac OS X and Linux. You can use Netstat to view network information and statistics about the network you are currently connected to.&lt;/p&gt;
&lt;p&gt;You could view information about incoming/outgoing connections, routing table, protocol statistics and interfaces.&lt;/p&gt;
&lt;p&gt;On linux netstat has been deprecated, the command &lt;code&gt;ss&lt;/code&gt; should be used instead. The difference between the two is that &lt;code&gt;ss&lt;/code&gt; can display more information about TCP and connection states.&lt;/p&gt;</description></item><item><title>LogRhythm's Blackhat challenge - Write up</title><link>https://dubell.io/logrhythms-blackhat-challenge-write-up/</link><pubDate>Sat, 08 Aug 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/logrhythms-blackhat-challenge-write-up/</guid><description>&lt;p&gt;For Blackhat 2015, LogRhythm Labs had a forensics contest for analyzing a .pcap file and finding the secret missile launch code. Find the password and enter the contest to win one of these:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://dubell.io/images/dji_phantom2.jpg" alt=""&gt;&lt;/p&gt;
&lt;p&gt;I really wanted to win this!&lt;/p&gt;
&lt;h3 id="analyzing-the-pcap-with-wireshark"&gt;Analyzing the PCAP with WireShark&lt;/h3&gt;
&lt;p&gt;I downloaded the .pcap file and loaded it into wireshark. I begun by checking the Protocol Hierarchy under Statistics to get a view on the protocols used.&lt;/p&gt;</description></item><item><title>Alien: Isolation</title><link>https://dubell.io/alien-isolation/</link><pubDate>Tue, 21 Jul 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/alien-isolation/</guid><description>&lt;p&gt;I bought this game during the summer sale 2015, it had a 75% discount and lots of positive reviews. I told my girlfriend that we should play it together so she can experience different types of games rather than playing candy crush all day&amp;hellip;&lt;/p&gt;
&lt;p&gt;Anyway, the first levels aren&amp;rsquo;t that bad, you start out combating other stranded humans on board one of the ships. A few &amp;ldquo;holy shit&amp;rdquo; here and there but nothing too scary. One thing I noticed in the beginning was these weird noises which sounded like they were coming from the ventilation shafts. Like something was tumbling around up there, following me. I soon discovered who was making the noises&amp;hellip;&lt;/p&gt;</description></item><item><title>Digital Steganography</title><link>https://dubell.io/steganography/</link><pubDate>Sat, 02 May 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/steganography/</guid><description>&lt;p&gt;There are many ways to conceal a message from untrusted entities, encryption is the far most used method for making sure no one but the intended receiver can read the message. However, there is an other method not widely used today and that is &lt;strong&gt;Steganography&lt;/strong&gt;. In historical times people hid secret messages in all kinds of places where guards for example wouldn&amp;rsquo;t look. I remember reading about a method where a &amp;ldquo;king&amp;rdquo; would have one his messengers shave their head and then they would write the message on the head and wait for the hair to grow back. Whoever waited for this message wasn&amp;rsquo;t in a hurry&amp;hellip;&lt;/p&gt;</description></item><item><title>Dashing Dashboard</title><link>https://dubell.io/dashing-dashboard/</link><pubDate>Tue, 24 Feb 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/dashing-dashboard/</guid><description>&lt;p&gt;&lt;img src="https://dubell.io/images/vizscreenshot2.png" alt=""&gt;
&lt;small&gt;&lt;em&gt;(Note: Not my dashboard above)&lt;/em&gt;&lt;/small&gt;&lt;/p&gt;
&lt;p&gt;Not long ago I set up a dashboard for our office to show statistics about sales and such. The software we decided to use was &lt;a href="http://dashing.io"&gt;Dashing.io&lt;/a&gt;. Dashing is a Sinatra based framework written in ruby that lets you build beautiful dashboards.&lt;/p&gt;
&lt;p&gt;I had no previous experience with ruby but it went well, as it was mostly syntax that differed from what I was used to.&lt;/p&gt;</description></item><item><title>No Such Agency</title><link>https://dubell.io/no-such-agency/</link><pubDate>Wed, 18 Feb 2015 00:00:00 +0000</pubDate><guid>https://dubell.io/no-such-agency/</guid><description>Thoughts on the NSA leaks and what it means for the world</description></item></channel></rss>