Advertisement · 728 × 90

Posts by

Preview
Are criminals vibe coding malware? All signs point to yes Interview: They also hallucinate when writing ransomware code

Are criminals vibe coding malware? All signs point to yes

3 months ago 8 2 1 2
David Chisnall (*Now with 50% more sarcasm!*) (@david_chisnall@infosec.exchange) @lina@vt.social @commdserv@mastodon.social I can’t speak for fd.o, but I was in a leadership position on another project where we got a similar case disastrously wrong, so I might be able to illumin...

Read this if you're wondering how Code of Conduct teams go wrong. It's hard, and not a job/team to be taken lightly. This is an A+ explanation everyone should read and boost.

infosec.exchange/@david_chisn...

5 months ago 50 16 1 0
Preview
Sweden scrambles after ransomware attack puts sensitive worker data at risk Municipal government organisations across Sweden have found themselves impacted after a ransomware attack at a third-party software service supplier.

Sweden scrambles after ransomware attack puts sensitive worker data at risk.

At the heart of the problem? A third-party software supplier.

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...

7 months ago 8 4 0 0
Post image

@bskyphotos.bsky.social

#olympus #EM1MK2

7 months ago 6 2 0 0

At last, sex appeal is coming back to anime

10 months ago 8 1 0 0
Post image

New poster for "The Ghost In The Shell" anime series by Science Saru studio (2026).
Directed by Mokochan. Story by EnJoe Toh. Character design & animation direction by Shuhei Handa.
Teaser Trailer 2 >> www.youtube.com/watch?v=rk27...

1 year ago 3254 978 35 204
A red light passes through the tunnel. A CCTV is on the wall. Two people are talking outside and there is an array of air conditioner condensers.

A red light passes through the tunnel. A CCTV is on the wall. Two people are talking outside and there is an array of air conditioner condensers.

@bskyphotos.bsky.social

1 year ago 2 1 0 0
Post image

nothing here, just one small step 🤓

1 year ago 0 0 0 0

😢

1 year ago 0 0 0 0
Preview
Malicious PyPI Packages Stole Cloud Tokens—Over 14,100 Downloads Before Removal

Malicious PyPI Packages Stole Cloud Tokens—Over 14,100 Downloads Before Removal

1 year ago 5 2 0 0
Advertisement
Preview
Powerful Linux Tricks That Will Change Your Life If you’ve ever worked in a Linux environment, you know how powerful and versatile it can be. But let’s be honest, at first glance the…

Powerful Linux Tricks That Will Change Your Life

1 year ago 4 1 0 0
Post image

マンガ『ベルセルク』の電子版が1巻から20巻までほぼ30%オフで購入できるセール開催、定価1万4300円のところ約1万円(税込)とお得に。150話まで無料で読めるキャンペーンも3月21日まで実施。三浦建太郎氏の描くダークファンタジーの巨編
https://news.denfaminicogamer.jp/news/250315i

1 year ago 30 19 0 0
Preview
Ubuntu Server 22.04 LTS Installation — Step by Step Guide Hello, my digital adventurers! Today, I am going to show you how to install Ubuntu Server 22.04 LTS.

Ubuntu Server 22.04 LTS Installation — Step by Step Guide

1 year ago 3 2 0 0
Full list – Game Accessibility Guidelines All three sets of guidelines displayed together as a single categorised list. Levels explained Basic Easy to implement, wide reaching and apply to almost all game mechanics. Intermediate Require some ...

Even if you can’t implement everything, every step helps more folks to enjoy your game.

For a full list of accessibility considerations, check out gameaccessibilityguidelines.com/full-list/

#GameDev #Accessibility

1 year ago 8 3 0 0

✅ Difficulty & Assist Modes – Can players tweak settings like aim assist, speed, or damage taken?
✅ UI & Text – Is text large, clear, and high contrast?
✅ Audio & Visual Feedback – Are there cues for important events beyond just sound?

2/3

1 year ago 9 2 1 0

Want to make your game more accessible? Start with these simple checks->

✅ Subtitles – Are they on by default? Adjustable size & background?
✅ Controls – Can players remap buttons? Are there alternate input options?

1/3

1 year ago 19 5 2 0

"souls weighed down by earth's gravity" is one of the most complex and nuanced phrases in Gundam. In Sci-fi in general, even

when Zeon Deikun coined it(?) he was probably referring to capitalism and upper classes. but Amuro clearly uses it to talk about depression. For Char it is like a religion

1 year ago 359 111 4 3
Preview
Bug Bounty Hunting: Web Vulnerability (Cross-Site Request Forgery) Mastering CSRF: Techniques, Bypasses, and Exploits

Bug Bounty Hunting: Web Vulnerability (Cross-Site Request Forgery)

1 year ago 1 1 0 0
HTB Pro Lab: Zephyr — A Legit Investment or a Waste of Money ? HTB Pro Lab: Zephyr — A Legit Investment or a Waste of Money ? Picture Created by Leonardo AI | Zephyr A Bit About Me I’m Reju, a full-time bug hunter and an athlete. 💪 I spend my days digging into code, hunting for vulnerabilities, and pushing my limits both online and in the gym. When I’m not breaking things apart, I’m probably tackling a new challenge or chasing that next adrenaline rush. 🚀 hackthebox.com/achievement/badge/1671324/173 Let’s Start: My Experience on Zephyr A few months back, I decided to tackle the Zephyr Pro Lab, provided by Hack the Box. To be honest, the platform had recently launched a new Pro Lab called Alchemy a few months ago, so the addition of Zephyr was a pleasant surprise. This lab featured 17 machines and 17 flags to capture, marked as an intermediate challenge with a Level 2 “Red Team Operator” designation. This honestly seemed a bit daunting, especially considering RastaLabs, which shared a similar rank, was infamously hard to finish at certain stages. Even so, following some encouragement from fellow pentesters, I chose to sign up and dive into the lab. Subscription Cost Hack The Box offers Pro Labs at USD $49/month for the monthly plan or USD $490/year for the annual plan , providing access to all scenarios with the flexibility to switch between them anytime . Your rankings and progress remain active even if you cancel your subscription. You can purchase it  here . Lab Overview Zephyr Pro Lab is presented as an intermediate-level Pro Lab, designed to help learners master red teaming techniques through practical, hands-on experience. Zephyr Pro Labs: Red Team Operator Level II Designed for intermediate-level red teamers, Zephyr Pro Lab offers a Red Team Operator Level II experience, enabling you to elevate your offensive security skills. You’ll navigate a realistic corporate network environment, mastering Active Directory exploitation, lateral movement, and post-exploitation techniques through hands-on challenges. Who Should Try Zephyr ? Zephyr is perfect for security professionals and intermediate red teamers seeking to advance their knowledge of Active Directory attacks. It focuses on uncovering common misconfigurations, leveraging real-world attack paths, and applying practical skills in a simulated corporate setting. 2. Skills & Knowledge Required: Familiarity with penetration testing tools and methodologies Basic understanding of Linux, Windows, and Active Directory environments Knowledge of Microsoft SQL server exploitation Proficiency in web application attacks and PowerShell usage Understanding of pivoting techniques using Proxychains and Metasploit Experience with BloodHound for AD analysis 3. Mindset & Approach: Persistence and a problem-solving mindset A willingness to conduct in-depth research and adapt quickly Embracing failures as learning opportunities Attention to detail for identifying misconfigurations and vulnerabilities 4. What You’ll Gain: Zephyr’s lab environment pushes you to enhance your skills in: Active Directory enumeration and exploitation Relay attacks and credential abuse Lateral movement and bypassing trust boundaries Pivoting and multi-layered attacks SQL injection and password cracking techniques Advanced privilege escalation methods Web application exploitation Successfully completing Zephyr Pro Lab demonstrates your capability to navigate complex Active Directory environments and equips you with practical skills for real-world red teaming scenarios. PROLAB | ZEPHYR Zephyr Lab Breakdown: Strengths and Weaknesses Zephyr is a focused Active Directory lab that sticks strictly to AD exploitation — no web applications or complex advanced techniques are involved. Compared to Offshore and other Red Team Pro Labs, Zephyr is significantly more approachable, making it an excellent starting point for those looking to sharpen their AD skills. The platform’s description of it being “A great introductory lab for Active Directory!” is spot-on. The core of this lab revolves around network enumeration and exploiting common misconfigurations typically seen in beginner-friendly AD-oriented training courses like CRTP and CRTO. In fact, around 85% of the content aligns with the CPTS path, leaving the remaining portion for you to research and figure out on your own. While Zephyr doesn’t include any flashy or overly complex exploits, it does require you to think creatively and approach certain misconfigurations in less conventional ways. This aspect keeps the lab engaging and prevents it from feeling too predictable or repetitive. However, this creativity comes at a cost — some parts of the lab can feel a bit less realistic compared to other environments designed to mimic enterprise networks more closely. The absence of advanced techniques might disappoint those looking for a higher level of challenge, but it serves its purpose well for those who are still building their foundational AD exploitation skills. Conquering Zephyr: An Active Directory Quest Pivoting is a key element in Zephyr, along with the presence of MSSQL Servers, which adds a layer of complexity to the overall experience. The lab does a good job of incorporating these elements without overwhelming players who are still getting comfortable with Active Directory attacks. For anyone who has already earned CRTP or CRTO certifications, Zephyr should be manageable in a few days. Personally, I wrapped it up in about a week, using extra time to revisit certain areas, refine my notes, and experiment with alternative attack paths to see what else might work. One area where Zephyr could see some improvement is the inclusion of more internally running services — similar to what Offshore provides — to create a more realistic enterprise environment. This would not only enhance the immersion but also provide more diverse challenges for players. As it stands, the lab features 17 flags that are relatively easy to spot if you stick to the intended exploitation path. There are no hidden flags or side-quests, which makes the lab feel a bit linear at times. Adding a few more complex or hidden challenges could greatly enhance the overall experience and replay value. A notable aspect of Zephyr is its daily revert system, which ensures a clean slate each day. This setup minimizes the frustration of persistence issues but does make pivoting a bit of a chore since you have to reconfigure everything from scratch every time you log back in. However, this is a common inconvenience in most similar environments, so it’s not a dealbreaker. On the support side, technical assistance for the lab is nearly nonexistent, which can be frustrating if you run into bugs or issues. Thankfully, the Discord server is quite active, and most members are more than willing to lend a hand if you get stuck or need guidance. The daily reverts also act as a safety net in case something goes wrong or if a server becomes unresponsive. Performance-wise, Zephyr is quite stable, with only a few instances where I encountered issues on specific servers. All things considered, Zephyr is a solid option for anyone looking to build or reinforce their Active Directory exploitation skills without getting bogged down by overly complex scenarios. It might not have the depth of some of the other Red Team Pro Labs, but it serves as a great steppingstone for those aiming to transition into more challenging environments. After spending a lot of time in the Zephyr lab, I can confidently say it was worth it . The experience was both challenging and rewarding and finally pwning!!! the lab felt amazing. ZEPHYR PWNED! ZEPHYR PWNED! Final Thoughts Overall, I would highly recommend the Zephyr lab to anyone looking to deepen their understanding of Active Directory security. It strikes a good balance — challenging enough to keep things interesting but not so overwhelming that you feel stuck for days. For the price, it’s a solid investment, especially considering the opportunity to move on to other Pro Labs if you complete it quickly. In my opinion, this lab fits more into the “Penetration Tester Level 2” category rather than being a full-fledged Red Teaming experience. After all, not every AD-centric challenge falls under the Red Teaming umbrella. The absence of web applications might be seen as a drawback by some, but I believe it serves a purpose. Having a lab solely focused on Active Directory is a refreshing change and offers a more streamlined learning experience — especially useful for those who found RastaLabs a bit too advanced. The lab’s structure allows you to hone your skills on AD-specific attacks without the distractions of web app exploitation. Kudos to Hack The Box for continuously expanding their content library with diverse and practical scenarios. Hopefully, we’ll see even more labs of this nature in the future. If you’re considering diving into Zephyr, be sure to explore the subscription options — it might just be the perfect next step in your offensive security journey! If you liked my honest review, you could respect me on Hack The Box!!!  here . Subscribe to me on Medium and be sure to turn on email notifications so you never miss out on my latest walkthroughs, write-ups, and other informative posts. Follow me on below Social Media: LinkedIn: Reju Kole 2. Instagram: reju.kole.9 3. Respect me On HackTheBox! : Hack The Box :: User Profile 4. Check My TryHackMe Profile : TryHackMe | W40X 5. Twitter | X :  @Mr_W40X 6. GitHub : W40X | Reju Kole | Security Researcher incase you need any help feel free to message me on my social media handles. HTB Pro Lab: Zephyr — A Legit Investment or a Waste of Money ? was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.

HTB Pro Lab: Zephyr — A Legit Investment or a Waste of Money ?

1 year ago 1 1 0 0
Easiest way to Find RCE (Package Dependency) Free Article Continue reading on InfoSec Write-ups »

Easiest way to Find RCE (Package Dependency)

1 year ago 2 1 0 0
Advertisement
Preview
50 World’s Best Penetration Testing Companies - 2025

50 World’s Best Penetration Testing Companies – 2025

1 year ago 4 1 0 0
Preview
THM — Lookup Test your enumeration skills on this boot-to-root machine.

THM — Lookup

1 year ago 2 1 0 0
Preview
What is Windows User Account Control for beginners?👨‍💻 Learn about Windows Internals — what UAC is, how it works, and how to manipulate it to our advantage

What is Windows User Account Control for beginners?‍

1 year ago 4 1 0 0
Post image

Stars are absolutely beautiful today.
#チ球の運動について

1 year ago 23 3 0 0
サカナクション「怪獣」×アニメ『チ。 ―地球の運動について―』コラボレーションMUSIC VIDEO【期間限定公開】
サカナクション「怪獣」×アニメ『チ。 ―地球の運動について―』コラボレーションMUSIC VIDEO【期間限定公開】 YouTube video by サカナクション sakanaction

この未来は好都合に光ってる
だから進むんだ 💫
#チ球の運動について

1 year ago 1 0 0 0
Preview
Gartner: Most Security Leaders Cannot Balance Data Security, Business Goals

Gartner: Most Security Leaders Cannot Balance Data Security, Business Goals

1 year ago 3 1 0 0
Preview
I'm a security expert and I almost fell for this IT job scam Remote position, webcam not working, then glitchy AI face ... Red alert!

I'm a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice

1 year ago 5 1 0 0
Advertisement
Preview
February 11, 2025 February 11, 2025 Russians shot down their own Eleron-3 reconnaissance drone and painted a Ukrainian flag on it in an attempt to receive awards instead of...

February 11, 2025

1 year ago 1 1 0 0
‘Yes, this is real’: hackers targeting high-profile X accounts blur fact and fiction The social media platform X has been hit with a rash of celebrity account takeovers, often by hackers peddling fraudulent products.

‘Yes, this is real’: hackers targeting high-profile X accounts blur fact and fiction

1 year ago 1 2 1 0
Post image

GET INNN!!! 👊

1 year ago 777 60 14 13