RSSAmplifier

Blog

Graham Helton

Personal website and blog

grahamhelton.comRSS feed ↗35 posts

Latest posts

Human Memory Management And Obsidian V2

How I structure five Obsidian vaults, enforce atomic notes through templated creation flows, and use frontmatter properties to turn notes into queryable databases.

I’m Sorry Dave, This Request Triggered Restrictions On Violative Cyber Content

The more tweets about breachs being

AI apathy is a tragedy, falling behind is a crime

Reflecting on some of the conversations I've been having about AI.

Building A Hacker Van

I'm converting a Ram Promaster into a mobile vacation and hacking-mobile.

Building A Custom Obsidian Publishing Pipeline

I built a custom blog publishing CI/CD pipeline that lets me write and deploy blogs from obsidian.

Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission

An authorization bypass in Kubernetes RBAC allows for nodes/proxy GET permissions to execute commands in any Pod in the cluster.

Ublock Origin Script Injection

The Ublock Origin extension can load arbitrary JavaScript

Testing out Crush, a TUI based coding agent (in neovim btw)

Using Charm's new AI coding agent to build an open graph image generator for this site.

a working KVM solution

The KVM solution I landed on that (for once) isn't terrible

site updates and milk

I've flooded your RSS feed but I come bearing milk.

Guideline For New Roles

An unordered list of general guidelines I keep in mind when starting a new role

Building Gold Images With Packer + GCP

Notes on how to setup packer within GCP

which $(nc) && when?

Notes on netcat

D-Bus Drifting For User-Land Persistence

In Linux systems with a desktop environment such as GNOME, a non-root user can write D-Bus configuration files that execute automatically upon user login. Groundbreaking? No. Fun? Absolutely.

Offsec RSS feeds

A massive collection of offensive security and security engineering focused RSS feeds

Exploring kubernetes privileged pods

Investigating the difference between privileged pods and container namespace isolation

notes vs blogs

Why do I differentiate between notes and blogs?

AI Security Fails

A quick look at some of the failures I've seen when tasking AI

Kubernetes audit log volume

Investigating and baselining how many logs a vanilla minikube cluster generates

Strategic work identification

Finding what to work on

Kubernetes golden tickets

Notes on how the kubernetes golden ticket attack works

Notes on using Incus to run a .OVA file

How to use a .OVA in incus

A Guide To Kubernetes Logs That Isn’t A Vendor Pitch

A guide to kubernetes logging at each cluster layer with a focus on AuditPolicy.

The Certification Industrial Complex

The Certification Industrial Complex and other Cyber Education Embarrassments

Human Memory Management: Techniques For Actionable Security Research

How to utilize an atomic note taking system to effectively research new topics and advance your career.

An Excruciatingly Detailed Guide To SSH (But Only The Things I Actually Find Useful)

Oh you like SSH? Name every flag.

Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement

A walkthrough of compromising private keys in SSH-Agent for post-exploitation lateral movement shenanigans.

How I Got Hired On A Google Red Team

A summary of all the information I learned while looking for new jobs and how I ended up getting hired on Google's red team.

My 2022 Security Year In Review

Looking back on 2022 and looking forward into 2023: What I learned and what I hope to learn.

How To Setup Spotify-TUI and Spotifyd With Pulseaudio.

How to be a Linux elitist and play music from your T E R M I N A L

Wandering Vagrant: A Crash Course in Vagrant Virtual Machines

A crash course of all the disparate knowledge I wish I had when I first delved into Vagrant

A Guide To Doing Things

A collection of tips I use to focus on my most important tasks.

Do As I Say, Not As I Do: Should You Get A Master’s Degree In CyberSecurity?

My thoughts on if you should get a masters degree in cybersecurity

Spoofing Youtube For Fun And Profit: An Examination Of Punycode For Phishing

Exploring some of the interesting edge cases when it comes to buying domains with non-standard characters!

Thou Shall Not Snoop Our Searches - Searx Installation and Discussion

How to install and use Searx