Welcome to the blog.
Recent Posts
Replace Google Analytics with a shell script
I started blogging in December 2020. I wanted to collect my old stories, software and notes all in one place. I thought others may like the content and I was curious how popular it may be, so I setup Google Analytics to keep track of things.
read moreExfiltrate files using the DNS
Once upon a time, a government auditor insisted to me that keystroke loggers had to run as root, otherwise they would not function properly. So, I wrote a keystroke logger that ran as a normal user and showed it to him.
read moreCracking passwords with cheap hardware
There were roughly 30 Street teams that participated in Korelogic’s 2020 Crack Me If You Can password cracking contest at Defcon. I took 4th place.
read moreFinding a hacked server
It was a cold Wednesday morning, about ten ‘til eight. I had been in the office a few minutes when the phone rang.
Hello. “Yes, hi, the server has been hacked!
read moreNow they have 2FA problems
There’s an old quip about solutions causing more problems:
Some people, when confronted with a problem, think “I know, I’ll use regular expressions.” Now they have two problems.
read more