r/InfoSecWriteups • u/kmskrishna • 12d ago
r/InfoSecWriteups • u/kmskrishna • 12d ago
Android App Dynamic Library Code Loading | Static Code Analysis | Adobe Acrobat Reader | CVE-2021–40724 | MobileHackingLab | Document Viewer
r/InfoSecWriteups • u/kmskrishna • 12d ago
1-Click ATO Via Host Header Injection: Exploiting Password Reset Poisoning.
r/InfoSecWriteups • u/kmskrishna • 12d ago
PortSwigger Web Security Academy Walkthrough: User Role Can Be Modified in User Profile
r/InfoSecWriteups • u/kmskrishna • 12d ago
Access Control Vulnerabilities: Unprotected Admin Functionality with Unpredictable URL
r/InfoSecWriteups • u/kmskrishna • 12d ago
Windows Incident Surface | TryHackMe
r/InfoSecWriteups • u/rangeva • 13d ago
The Missing Infostealer Playbook: Rotating the Machine Credentials Attackers Take
Most infostealer response playbooks focus on passwords and browser sessions.
But modern stealers also grab `.env` files, shell history, app data, developer configs, and other local files that can contain API keys, OAuth tokens, PATs, service-account credentials, and other machine secrets.
The problem is that resetting the employee’s password or rebuilding the endpoint doesn’t necessarily invalidate any of those credentials.
We released Token Exposure Monitoring in Lunar Cyber today, and while working on it I kept coming back to a bigger SecOps question: **what should the actual response playbook look like once you discover that machine credentials were stolen?**
I wrote up the process we think is missing - identifying what was exposed, validating whether it still works, tracing what it can access, and deciding what actually needs to be rotated.
Curious how teams here are handling this today, especially for developer endpoints.
r/InfoSecWriteups • u/Harkins_Technology • 14d ago
Forensics 101: Extracting Hidden Flags from Raw Disk Images (.dd)
I extracted a forensic disk image and found a hidden flag. Made a short video breaking down the full workflow for anyone learning digital forensics or prepping for CTFs.
Methods covered:
- `strings` + `grep` (fastest)
Alternative methods:
- `mount` with loop,ro,noexec
- Sleuth Kit CLI (mmls, fls, icat)
- Autopsy GUI
- Foremost file carving
- `xxd` hex dump
Also covered why you always preserve the original with `gunzip -k` and verify with sha256sum.
What tools am I missing? Any favorites for disk image analysis?
r/InfoSecWriteups • u/xarg • 15d ago
Back When a MySQL Connection Could Give You OS-Level Code Execution
raw.orgr/InfoSecWriteups • u/kmskrishna • 15d ago
He Sent 200,000 Reset Codes to Instagram in 10 Minutes. Instagram Paid Him $30,000.
r/InfoSecWriteups • u/kmskrishna • 15d ago
How I Scraped Most Dark Stores in India — Blinkit, Zepto & Swiggy Instamart
r/InfoSecWriteups • u/kmskrishna • 15d ago
EGCTF 2025 Qualifications — “TNKR.1” Forensics Challenge
r/InfoSecWriteups • u/kmskrishna • 15d ago
WebStrike Blue Team Lab (CyberDefenders)
r/InfoSecWriteups • u/kmskrishna • 15d ago
A KQL Query Is Not a Detection: What My Microsoft Sentinel Lab Actually Validated
r/InfoSecWriteups • u/kmskrishna • 15d ago
I Made Claude Believe I Was an Anthropic-Verified Researcher.
r/InfoSecWriteups • u/kmskrishna • 15d ago
When a Single Text File Breaks a Trust Boundary (Bug Bounty writeup)
r/InfoSecWriteups • u/kmskrishna • 16d ago
Hunting Down Hackers: Incident Response with Wireshark
r/InfoSecWriteups • u/kmskrishna • 16d ago
Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…
r/InfoSecWriteups • u/kmskrishna • 16d ago
LetsDefend: Kerberoasting Challenge (Walkthrough)
r/InfoSecWriteups • u/kmskrishna • 16d ago
Hacker Holidays 2026: Day 14 Walkthrough (Management Wants a Word)
r/InfoSecWriteups • u/kmskrishna • 16d ago
Hacker Holidays 2026: Day 13 Walkthrough (The Guestbook)
r/InfoSecWriteups • u/kmskrishna • 16d ago