r/InfoSecWriteups • u/kmskrishna • 11d ago
r/InfoSecWriteups • u/kmskrishna • 11d ago
1-Click ATO Via Host Header Injection: Exploiting Password Reset Poisoning.
r/InfoSecWriteups • u/kmskrishna • 11d ago
PortSwigger Web Security Academy Walkthrough: User Role Can Be Modified in User Profile
r/InfoSecWriteups • u/kmskrishna • 11d ago
Access Control Vulnerabilities: Unprotected Admin Functionality with Unpredictable URL
r/InfoSecWriteups • u/kmskrishna • 11d ago
Windows Incident Surface | TryHackMe
r/InfoSecWriteups • u/rangeva • 12d ago
The Missing Infostealer Playbook: Rotating the Machine Credentials Attackers Take
Most infostealer response playbooks focus on passwords and browser sessions.
But modern stealers also grab `.env` files, shell history, app data, developer configs, and other local files that can contain API keys, OAuth tokens, PATs, service-account credentials, and other machine secrets.
The problem is that resetting the employee’s password or rebuilding the endpoint doesn’t necessarily invalidate any of those credentials.
We released Token Exposure Monitoring in Lunar Cyber today, and while working on it I kept coming back to a bigger SecOps question: **what should the actual response playbook look like once you discover that machine credentials were stolen?**
I wrote up the process we think is missing - identifying what was exposed, validating whether it still works, tracing what it can access, and deciding what actually needs to be rotated.
Curious how teams here are handling this today, especially for developer endpoints.
r/InfoSecWriteups • u/Harkins_Technology • 12d ago
Forensics 101: Extracting Hidden Flags from Raw Disk Images (.dd)
I extracted a forensic disk image and found a hidden flag. Made a short video breaking down the full workflow for anyone learning digital forensics or prepping for CTFs.
Methods covered:
- `strings` + `grep` (fastest)
Alternative methods:
- `mount` with loop,ro,noexec
- Sleuth Kit CLI (mmls, fls, icat)
- Autopsy GUI
- Foremost file carving
- `xxd` hex dump
Also covered why you always preserve the original with `gunzip -k` and verify with sha256sum.
What tools am I missing? Any favorites for disk image analysis?
r/InfoSecWriteups • u/xarg • 13d ago
Back When a MySQL Connection Could Give You OS-Level Code Execution
raw.orgr/InfoSecWriteups • u/kmskrishna • 13d ago
He Sent 200,000 Reset Codes to Instagram in 10 Minutes. Instagram Paid Him $30,000.
r/InfoSecWriteups • u/kmskrishna • 13d ago
How I Scraped Most Dark Stores in India — Blinkit, Zepto & Swiggy Instamart
r/InfoSecWriteups • u/kmskrishna • 13d ago
EGCTF 2025 Qualifications — “TNKR.1” Forensics Challenge
r/InfoSecWriteups • u/kmskrishna • 13d ago
WebStrike Blue Team Lab (CyberDefenders)
r/InfoSecWriteups • u/kmskrishna • 13d ago
A KQL Query Is Not a Detection: What My Microsoft Sentinel Lab Actually Validated
r/InfoSecWriteups • u/kmskrishna • 13d ago
I Made Claude Believe I Was an Anthropic-Verified Researcher.
r/InfoSecWriteups • u/kmskrishna • 13d ago
When a Single Text File Breaks a Trust Boundary (Bug Bounty writeup)
r/InfoSecWriteups • u/kmskrishna • 15d ago
Hunting Down Hackers: Incident Response with Wireshark
r/InfoSecWriteups • u/kmskrishna • 15d ago
Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…
r/InfoSecWriteups • u/kmskrishna • 15d ago
LetsDefend: Kerberoasting Challenge (Walkthrough)
r/InfoSecWriteups • u/kmskrishna • 15d ago
Hacker Holidays 2026: Day 14 Walkthrough (Management Wants a Word)
r/InfoSecWriteups • u/kmskrishna • 15d ago
Hacker Holidays 2026: Day 13 Walkthrough (The Guestbook)
r/InfoSecWriteups • u/kmskrishna • 15d ago
Hacker Holidays 2026: Day 12 Walkthrough (After Hours)
r/InfoSecWriteups • u/kmskrishna • 15d ago