RSSAmplifier

Blog

Steflan’s Security Blog

steflan-security.comRSS feed ↗10 posts

Latest posts

Certified Azure Red Team Expert (CARTE) Review

Introduction The Certified Azure Red Team Expert is a penetration testing/red teaming certification and course provided by Altered Security, which is known in the industry for providing great courses and bootcamps. In this review, I take the time to talk... The post Certified Azure Red Team Expert (CARTE) Review appeared first on Steflan's Security Blog .

OffSec Web Expert (OSWE) Review

Introduction The OffSec Web Expert (OSWE) is an web application penetration testing certification offered by Offsec that teaches advanced web attacks and exploits, with an emphasis of performing white-box engagements and source code review. It comes with the Advanced Web... The post OffSec Web Expert (OSWE) Review appeared first on Steflan's Security Blog .

Certified Read Team Operator (CRTO) Review

Introduction Certified Red Team Operator (CRTO) is a penetration testing/red teaming certification and course that teaches the basic red team principles, tools and techniques, entirely through the Cobalt Strike command and control (C2) framework. In this review, I take the... The post Certified Read Team Operator (CRTO) Review appeared first on Steflan's Security Blog .

Certified Red Team Expert (CRTE) Review

Introduction Certified Red Team Expert (CRTE) is a penetration testing/red teaming certification and course provided by Altered Security, which is known in the industry for providing great courses and bootcamps. In this review, I take the time to talk about... The post Certified Red Team Expert (CRTE) Review appeared first on Steflan's Security Blog .

TryHackMe – Nax Walkthrough

Introduction This was an intermediate Linux machine that required to identify a set of credentials hidden within an image file using the Piet programming language and exploiting a known remote code execution vulnerability in Nagios XI to escalate privileges to... The post TryHackMe – Nax Walkthrough appeared first on Steflan's Security Blog .

Certified Azure Red Team Professional (CARTP) Review

StefLan’s Security Blog Introduction The Certified Azure Red Team Professional is a penetration testing/red teaming certification and course provided by Altered Security, which is known in the industry for providing great courses and bootcamps. In this review, I take the... The post Certified Azure Red Team Professional (CARTP) Review appeared first on Steflan's Security Blog .

A Complete Guide to Hacking GraphQL

Introduction I decided to make this guide due to the lack of material on this topic and my own struggles with GraphQL. Its purpose is to provide pentesters with the necessary tools to perform tests against GraphQL implementations. I encourage... The post A Complete Guide to Hacking GraphQL appeared first on Steflan's Security Blog .

Offensive Security Experienced Penetration Tester (OSEP) Review

Introduction The Offensive Security Experienced Penetration Tester is an ethical hacking certification offered by Offensive Security that teaches penetration testing techniques with an emphasis on evading security mechanisms , phishing, and attacking Active Directory environments in order to perform advanced... The post Offensive Security Experienced Penetration Tester (OSEP) Review appeared first…

TryHackMe – DogCat Walkthrough

Introduction This was an intermediate Linux machine that involved capturing four flags by exploiting local file inclusion (through Apache log poisoning), the env binary with Sudo permissions enabled and a misconfigured cron job which allowed to escape the Docker container... The post TryHackMe – DogCat Walkthrough appeared first on Steflan's Security Blog .

TryHackMe – The Marketplace Walkthrough

Introduction This was an intermediate Linux machine that involved exploiting a stored cross-site scripting and SQL injection vulnerability to gain initial access and misconfigured sudo rules to escalate privileges to Root. Enumeration The first thing to do is to run... The post TryHackMe – The Marketplace Walkthrough appeared first on Steflan's Security Blog .