Offensive SecurityFeatured labCompleted labVulnCMS: Web-to-Root Penetration TestFrom a Drupal flaw to full Linux accessA hands-on VulnHub lab that went from a Drupal 7 vulnerability to root through an exposed password file and an unsafe sudo rule.Network PentestingLinuxWeb SecurityNmapMetasploitDrupalCVE-2018-7600Privilege EscalationView project
Security EngineeringHome security projectOperationalSelf-Hosted Network-Wide DNS Security GatewayRaspberry Pi DNS filtering at home and on the goA small Raspberry Pi setup that blocks ads, trackers and known bad domains at home and when my own devices are on public Wi-Fi.Network SecurityRaspberry PiLinuxDNSAdGuard HomeView project
Offensive SecurityFeatured labCompleted labKioptrix 3: File Inclusion to RCESQL injection, file inclusion and a Linux privilege jumpA Kioptrix 3 lab where SQL injection, an unsafe upload and local file inclusion led to a web shell, SSH access and root.Kioptrix 3Web SecuritySQL InjectionLFIRCEView project
Security EngineeringPersonal toolReleasedPrompt Otter: Private Navigation for Long ChatGPT ConversationsA local userscript and Chrome extensionA small local tool that makes long ChatGPT chats easier to scan: it collects prompts, lets me search them, and does not send prompt text anywhere.JavaScriptTampermonkeyChrome ExtensionManifest V3Privacy by DesignView project
Security NotesWork-in-progress guideMethodology readyA Simple Vulnerability Triage GuideUsing CVSS as a starting point, not the whole answerA work-in-progress guide for turning technical findings into a sensible order of fixes.CVSS v3.1Risk AssessmentVulnerability TriageRemediationTechnical ReportingStill in progressWork in progressRisk guide in progress