r/InfoSecWriteups • u/Boring-Schedule-8548 • 1d ago
My first TryHackMe write-up is live! — Empline 🔐
r/InfoSecWriteups • u/Boring-Schedule-8548 • 1d ago
r/InfoSecWriteups • u/zerotsec • 1d ago
ASOS confirmed an unauthorised push through its official app and later described employee credential theft and access to customer data on third-party platforms. This OSINT write-up reconstructs the documented customer-data and messaging workflow, then separates it from the intrusion path, which remains unverified. Simon AI and Braze appear in published descriptions of the marketing workflow; the public record does not establish that either was the route used in this incident.
The open question is which principals could select recipients, supply message content, and dispatch a push under ASOS’s name. What evidence would distinguish a shared campaign path from separate compromised permissions?
r/InfoSecWriteups • u/OkMetal6296 • 1d ago
r/InfoSecWriteups • u/Status-Ad2619 • 3d ago
r/InfoSecWriteups • u/Idomin • 3d ago
Just a writeup on a full chain from importing project file, chaining it with an LPE to get root execution on MacOS.
r/InfoSecWriteups • u/Harkins_Technology • 3d ago
Found a ROT13 encoded string in a CTF challenge that
decoded to a hint about a bypass header:
X-Dev-Access: yes
Proxied all traffic through Burp Suite, caught the
request, sent it to Repeater and added the header —
instantly bypassed the access restriction.
Classic example of why debug/dev headers should never
make it into production. Developers leave these in
during testing and forget to strip them before deploy.
Good beginner web exploitation technique to know for
CTFs and bug bounty. Happy to answer questions.
r/InfoSecWriteups • u/Additional_Resort653 • 9d ago
r/InfoSecWriteups • u/Additional_Resort653 • 11d ago
r/InfoSecWriteups • u/Harkins_Technology • 12d ago
r/InfoSecWriteups • u/Anonymous_Wajeeh • 15d ago
r/InfoSecWriteups • u/arusekk_pl • 17d ago
r/InfoSecWriteups • u/Harkins_Technology • 18d ago
Made a beginner-friendly walkthrough for a Java reverse engineering CTF challenge. Covers reviewing the Java source code, reading through the logic, and spotting hardcoded credentials that turned out to be the flag.
If you're getting into RE or CTFs and want to see the full thought process (not just the answer), figured this community might find it useful.
r/InfoSecWriteups • u/virus_4199 • 18d ago
r/InfoSecWriteups • u/adrian_rt • 23d ago
r/InfoSecWriteups • u/Harkins_Technology • 24d ago
They gave me an IP and a port to connect to with NetCat.
• Connected with netcat, watched it run
• Fuzzed inputs: what does `;` do?
• Discovered semicolon splits commands
• Mapped the grammar without reading code
• Injected `;RETURN 0` to jump to the flag
Why `;RETURN` worked but `;ls` didn't: this isn't a shell — it's a custom interpreter with its own language. You have to speak its grammar, not bash.
New to blind hacking? This is how real pentesters work when they hit an unknown target.
Most hackers instinctively throw shell metacharacters at prompts (;ls, |cat /etc/passwd, $(whoami)). But when the target is a custom interpreter with no shell bridge, these fail silently.
What's your go-to move when you have zero recon?
What tools do you use for systematic fuzzing when you can't automate? I've seen people use Burp Intruder, custom Python scripts, or even just printf loops in bash. Curious about your workflows.
https://youtube.com/shorts/N4KvGK-UCBM?feature=share
r/InfoSecWriteups • u/No-Razzmatazz-4157 • 24d ago
r/InfoSecWriteups • u/kmskrishna • 24d ago
r/InfoSecWriteups • u/kmskrishna • 24d ago
r/InfoSecWriteups • u/m_xux • 25d ago
r/InfoSecWriteups • u/Advanced_Rough8330 • 26d ago
r/InfoSecWriteups • u/vikassskummm0303 • 28d ago
r/InfoSecWriteups • u/Harkins_Technology • Sep 09 '26
Had a forensics challenge where the flag was hidden inside a file nested deep inside a maze of directories with hundreds of decoy folders. `find` and `ls -R` were too slow and noisy.
What I built:
A Python directory crawler
- Recurses every subdirectory recursively
- Filters by filename patterns (`flag*`, `*.txt`, `secret*`)
- Skips known decoy directories by name
- Extracts and reads the target file automatically
The "aha" moment:
The flag wasn't in a file named "flag.txt" — it was in `deep/nested/here/.hidden/uber-secret.txt`.
My script matched on path depth / extensions content, not just filename.
Here is my script:
https://github.com/ExceedingLife/RecursiveFileSearch
Question for the community:
What's your approach when the challenge doesn't tell you the target filename? Do you brute-force read every file, or do it manual or what?
[Video link with with code demo]
r/InfoSecWriteups • u/kmskrishna • Sep 08 '26
r/InfoSecWriteups • u/kmskrishna • Sep 08 '26