RSSAmplifier

Blog

m4iler

Recent content on m4iler

localhostRSS feed ↗78 posts

Latest posts

Grilovačka

Zahrada plná vůně a včel 
kouř se do oblečení vsakuje 
Zelenina i hovězí maso 
tatínek ochotně griluje

Jen Si Hodil Korunou

Jen si hodil korunou, co by se mohlo stát? 
Setkal se s ní v Kredenci, prý jen na kávu 
On netušil, co osud mu může ještě dát.

Trénink

Na trénink se vloudil 
chtěl jenom chvilku trénovat 
a nakonec musel od dvou 
do šesti normálnost fingovat.

Toulavá

Na procházce po městě 
kočku vidíš toulavou 
být to na mně, pohladím ji 
pak ji nechám za hlavou.

Tábor krtků

Tlupa krtků leze hlínou 
a žížalu nevidí 
každý chvilku hrabe díru 
ale červa nechytí.

Studená sprcha

Odstavili teplou vodu 
naši milí opraváři 
ten, kdo se chce teple koupat 
vodu v hrnci kvapem vaří

Let's Get Physical

I am become physical threat, the stealer of bins

Proper Preparation Prevents Poor Phone

It has finally happened. A crisis, some incident. And I am ready for it.

Internet Independence Instructions

In this post, I would like to discuss the what and why of self-hosting and the Zen of maintaining my own infrastructure

DNS on VPN or how I left PiHole

If I run a VPN server on my own VPS, why not run a DNS server as well?

The NixOS life

I did it, I installed the hot new thing. And it’s not too bad!

Bag of Tricks

In security, anything you learn can be useful. Anything. Blue and Red teams are bullshit delimiters.

Sim Free Life

So I stopped using my in-phone SIM card and replaced it with two.

Fuck ChatControl

Let’s talk about a hot topic today, how it’s bad and how to break it (should you wish to).

Phone Proxy 2: the SIM card boogaloo

I have some news about the SIM card setup, which may be interesting to no one, but if you are going this way, here are some snags I encountered along the way.

Software Freedom

In this post, I would like to veer off-course for a bit and discuss a topic I find myself talking about more and more, which is freedom in all its senses. I will discuss certain kinds of freedom we have, ones we’re slowly gaining back, and what I understand under freedom of choice.

Phone Proxy

This will be a story about what I and a dear friend of mine are doing to keep our phone usage a little more private. I must admit he is faster at this, but I will try to weigh all the options before I go all in.

Route to (private) self-employment

This is very country-specific, concerning a way to get self-employed in a privacy nightmare. Some parallels to US laws are mentioned.

I split my keyboard in half

I broke my keyboard

Librebooting the T480 - Easier than it looks

Good news, everyone! There is now a Libreboot image for the T480! Some purists may call this a sellout, a fake, but I call it a step forward. Anything less snooping than what is currently inside stock thinkpads is a step in the right direction.

Suckless project management

It is with great sadness that I announce that I am back. This time, I would like to take a moment to talk about a topic I only recently realized is not talked about enough: Project management in penetration testing and the approach some companies take.

Back to pentest fumblings!

I’m back, baby! I fell back into the old lines. It took a few months, but I went from “Okay, I’ll go into the blue team for some more calm and a stable work environment” to “Well, since the pentests are already there, mind if I snatch one up?” This is my comfort zone. This is my happy place. After all that happened in the last 3 months, it’s good.

Two certs in one week? Doable!

In this post, I will try to review, compare, and contrast two cybersecurity certificates I had the pleasure of passing in the same week: Certified Ethical Hacker v12 and BTL1 from Security Blue Team, which one I would pick if it hadn’t been paid for by my employer, and general tips on how to succeed.

SOC Jitsu - Preparing for day one

Well, T-$(several days) until I start my new job. I am having some doubts about my skillset, and in this post I will try to describe my doubts, the way I intend to tackle them, and maybe a way to boost anyone’s self confidence who is trying to jump from red to blue or vice versa.

BPRBP - The journey there and back again

A short summary of my life in cybersecurity

Bez práce nejsou koláče (ale kurzy ano!)

NOTE: Sorry for all you English-speakers, this one is mostly meant for the Czech audience. I will be posting a more general post on the same topic soon. In the meantime, Google translate is usable, but there will be terminology that will not fit your situation or legislature. Be advised.

Lockpicking zen and webapps

In this blogpost, I will once again try to recapitulate my findings from this month. If you’re too busy to read, webapps are not as shit as previously believed and lockpicking is similar to buffer overflows. This sentiment is subject to change.

Why I got into cybersecurity

INTRO 
 This is a response to a post by Garrett Mickley

First week of 2024

Well, a lot has happened in the last week, and I want to talk about that, at least in part, and also about a topic that has come up in my discussions lately.

Plans for 2024

Time for the new year’s resolutions! A lot has changed in this year, and I want to summarize my thoughts. This article will probably go into too much detail from time to time, but hey, it’s my blog!

Best burnout remedy: Get a hobby

This one will be short, because I have my hobby getting ready.

Mine or Die: Tech pessimism and a potential solution

Oh boy, I’m writing a lot now, aren’t I? For the last few days, I got myself thinking about tech, the sustainability and what I believe could be the future of tech.

Always be learning

Well, I guess I’ll put my thoughts on page once again. This time, I’ll do a little rant on my fears and goals regarding my profession and on what is waiting for me in 2024.

Tor vs VPN - a quick analysis

In this short post, I want to bring VPNs to your attention, show how I use them and dispel some myths that you may have. If you use VPNs and are familiar, this is probably not for you.

VoIP, Fight club-style

I have (somewhat successfully) reworked my VoIP setup, and would like to share it with you.

When misdirection works (too well)

I had a beautiful experience this week and thought I’d mention it, for the benefit of all you folks building fake profiles to make yourselves harder to find (looking at some people from infosec.exchange.) This story is about how my misdirection got found, and worked very well indeed.

Server fun for days! Part 1: Decisions, decisions

Well, I haven’t posted for a while! Lot of stuff happening in my personal life. But that is irrelevant for this blog post. We’re setting up a new home server!

As per my last blog post

You did not listen. To be honest, I doubt you read this, but still, you did not listen. Let’s try that again, in much clearer terms. In this blogpost, I will ommit any human rights and assume you are trying to ban encryption services with no regard for laws or my right to privacy.

HackTheBox: alone, it's a pain. Two? Then I'm game!

I have had my HackTheBox account for a long time now. Getting close to a decade. For those of you who don’t know, HackTheBox is a training/CTF platform, similar to TryHackMe. It is also a little different, you cannot register a new account without an invite code. You would like an invite code? Sorry, I can’t give you one, and neither can anyone else. To get in, you have to find the…

To the EU: Your proposal is bad and you should feel bad.

I will consider this partially a rant, but also an open letter to the European Parliament (profanity included).

A privacy consulting tightrope

One thing you should do to maximize your personal privacy is to “change coats,” i.e. burning identities, burning bridges, not keeping a permanent record as often as possible.

Life with GrapheneOS - 1 month in

I finally did it. I bought a Google phone and installed GrapheneOS ( https://grapheneos.org ). So far, after a month of usage, it’s not that bad!

How I fucked around and found out

Well, about 2 hours ago, my OSCP exam time ran out. At this point, I should be writing the exam report, right? Well, to tell you the truth, nothing would make me happier, except for one simple fact:

One week to go until OSCP

One week from now, I will be sweating in a lab. The OSCP, you know the one, 24 hours of ball-wrenching AD and other machines, made just for me. It will be purgatory, and I still feel woefully unready, but I’ll go for it. It’s a hill I wanted to climb for close to ten years now, so it’s only fair that I experience it and don’t chicken out. The failure is imminent, but every…

OSCP labs

I am almost through my OSCP lab time. I do not expect to pass on my first try. Why? Simple.

Credit critique - A can of worms

Last week, I found out a fun thing. My country has not one credit bureau, but four .

It's okay to let go, once in a while

Well, I feel like I need to let off a bit of steam and vent about things I learned in the past week, month, in the regular, stream-of-consciousness fashion.

Disaster Recovery or how I messed up this weekend

Intro: A serving of humble pie 
 First of all, I must admit I have messed up this week. It started small, with an issue in my parents’ PiHole. The fix was not that complicated, but I had to upgrade the Raspberry pi zero to Raspbian Bullseye. After the update, I performed several updates. Autossh, VPN, I set all of that up no problem. During the update, I was pivoting through one of my…

Owning a dolphin

Finally bought a Flipper zero! If you’ve seen me on twitter (how else would you find this post), you may have seen me posting some Flipper shenanigans. Now I will try to explain why I bought it and what it has done for me so far.

Unplugged phone pre-review

Unplugged Phone pre-review 
 This is going to be fun. I have no stake in this, I am going to just yell at the clouds in this one. But I will also try to share what is available about the UP Phone (UnPlugged Phone) and the services underneath it.