<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Plaintext Cybersecurity</title>
    <link>https://plaintext.do/en</link>
    <description>Offensive cybersecurity firm in the Dominican Republic: infrastructure and application penetration testing, Red Team and social engineering.</description>
    <language>en</language>
    <lastBuildDate>Mon, 29 Sep 2025 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://plaintext.do/en/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Bypassing Duo Security 2FA (As a Local Administrator)</title>
      <link>https://plaintext.do/en/blog/bypassing-duo-security-2fa</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/bypassing-duo-security-2fa</guid>
      <pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>During an internal penetration test conducted by the Plaintext Cybersecurity Solutions team, we came across an interesting scenario involving Duo Security.</description>
      <category>Security</category>
      <category>MFA</category>
      <category>Windows</category>
    </item>
    <item>
      <title>PlainText Cybersecurity Solutions opens its new offices</title>
      <link>https://plaintext.do/en/news/nuevas-oficinas</link>
      <guid isPermaLink="true">https://plaintext.do/en/news/nuevas-oficinas</guid>
      <pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate>
      <dc:creator></dc:creator>
      <description>PlainText Cybersecurity Solutions officially opens its doors to serve organizations worldwide, anticipating threats through innovation, hacking, research and education.</description>

    </item>
    <item>
      <title>Introducing the News section</title>
      <link>https://plaintext.do/en/news/bienvenido-a-noticias</link>
      <guid isPermaLink="true">https://plaintext.do/en/news/bienvenido-a-noticias</guid>
      <pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate>
      <dc:creator></dc:creator>
      <description>We&apos;re launching the News section to share announcements, events and updates from the Plaintext Cybersecurity team.</description>

    </item>
    <item>
      <title>Exploiting ESC16 Step by Step: A New Privilege Escalation Path in Windows</title>
      <link>https://plaintext.do/en/blog/esc16-escalacion-privilegios-windows</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/esc16-escalacion-privilegios-windows</guid>
      <pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate>
      <dc:creator>Jose Milane</dc:creator>
      <description>A few days ago, during an internal pentest alongside my coworkers, we came across a rather interesting configuration in the Active Directory environment. At…</description>
      <category>Active Directory</category>
      <category>AD CS</category>
      <category>Privilege Escalation</category>
    </item>
    <item>
      <title>100 Days Of BlueTeam</title>
      <link>https://plaintext.do/en/blog/100-days-of-blueteam</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/100-days-of-blueteam</guid>
      <pubDate>Fri, 14 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>2020 came with plenty of surprises for everyone—COVID, social distancing, remote work—and PlainText decided to take a break from its RedTeam learning journey…</description>
      <category>Blue Team</category>
      <category>Learning</category>
      <category>Career</category>
    </item>
    <item>
      <title>My Learning Journey Writing the CVE-2019-19470 Exploit</title>
      <link>https://plaintext.do/en/blog/mi-aprendizaje-exploit-cve-2019-19470</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/mi-aprendizaje-exploit-cve-2019-19470</guid>
      <pubDate>Fri, 14 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>Hey! I&apos;ll try to tell you my story about how I reproduced CVE-2019-19470. This will be both a personal learning experience and technical examples, but it&apos;s…</description>
      <category>Exploit Dev</category>
      <category>CVE</category>
      <category>Windows</category>
    </item>
    <item>
      <title>Firewall Best Practices</title>
      <link>https://plaintext.do/en/blog/buenas-practicas-firewalls</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/buenas-practicas-firewalls</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>When performing a Pentest, it&apos;s much easier to take advantage of the lack of awareness among network/security administrators who don&apos;t realize how we can use…</description>
      <category>Firewalls</category>
      <category>Hardening</category>
      <category>Best Practices</category>
    </item>
    <item>
      <title>My 1st CVE - Capturing FortiGate LDAP Credentials</title>
      <link>https://plaintext.do/en/blog/mi-primer-cve-credenciales-ldap-fortigate</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/mi-primer-cve-credenciales-ldap-fortigate</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>In July 2018, I reported a vulnerability to the Fortinet development team that I discovered in how FortiGate (version 6.0.2 and earlier) handled LDAP…</description>
      <category>CVE</category>
      <category>FortiGate</category>
      <category>LDAP</category>
    </item>
    <item>
      <title>OSCP - My Introduction to Pentesting and Certification Review</title>
      <link>https://plaintext.do/en/blog/oscp-introduccion-pentesting</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/oscp-introduccion-pentesting</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>In March 2017, I started an Ethical Hacking course at CertyAcademy. I saw this course as a way to understand how hackers operate so I could build more…</description>
      <category>OSCP</category>
      <category>Certifications</category>
      <category>Career</category>
    </item>
    <item>
      <title>Pentesting - Active Directory @Lkys37en LAB - Part 1</title>
      <link>https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-1</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-1</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>---</description>
      <category>Active Directory</category>
      <category>Pentesting</category>
      <category>Lab</category>
    </item>
    <item>
      <title>Pentesting - Active Directory @Lkys37en LAB - Part 2</title>
      <link>https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-2</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-2</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>In Part 1 we managed to gain access to the internal network through Password Spraying. Now in this second part we&apos;ll get into some interesting techniques…</description>
      <category>Active Directory</category>
      <category>Pentesting</category>
      <category>Lab</category>
    </item>
    <item>
      <title>WhatsApp Protector</title>
      <link>https://plaintext.do/en/blog/whatsapp-protector</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/whatsapp-protector</guid>
      <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>Automation is the reason I love programming. I must confess I&apos;m not the best developer, but I can&apos;t deny that I really enjoy it.</description>
      <category>WhatsApp</category>
      <category>Tools</category>
      <category>Phishing</category>
    </item>
    <item>
      <title>How I Discovered Using Dropbox pythonNN.dll to Run Python Scripts Without Python</title>
      <link>https://plaintext.do/en/blog/dropbox-pythonnn-dll-ejecutar-scripts-python</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/dropbox-pythonnn-dll-ejecutar-scripts-python</guid>
      <pubDate>Sun, 01 Nov 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>I was playing Warzone and started noticing some packet loss, which is &quot;not good at all&quot; if you&apos;re playing an FPS game. I went into Task Manager and looked…</description>
      <category>Red Team</category>
      <category>Windows</category>
      <category>Python</category>
    </item>
    <item>
      <title>WhatsApp Two-Step Verification Reminder Bypass</title>
      <link>https://plaintext.do/en/blog/whatsapp-two-step-verification-reminder-bypass</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/whatsapp-two-step-verification-reminder-bypass</guid>
      <pubDate>Sun, 01 Nov 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>In February 2019, I reached out to the Facebook team regarding a bug I found in WhatsApp&apos;s two-step verification reminder feature—a feature designed to help…</description>
      <category>WhatsApp</category>
      <category>MFA</category>
      <category>Security</category>
    </item>
    <item>
      <title>Phishing Awareness Campaign</title>
      <link>https://plaintext.do/en/blog/campana-concientizacion-phishing</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/campana-concientizacion-phishing</guid>
      <pubDate>Tue, 21 Jul 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>I&apos;ve recently witnessed a wave of Phishing attacks—something that hasn&apos;t changed over the years. It simply evolves, shifts, repeats itself, but it always…</description>
      <category>Phishing</category>
      <category>Awareness</category>
      <category>Security</category>
    </item>
    <item>
      <title>HackTheBox</title>
      <link>https://plaintext.do/en/blog/hackthebox</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/hackthebox</guid>
      <pubDate>Sun, 19 Jul 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>---</description>
      <category>HackTheBox</category>
      <category>CTF</category>
      <category>Learning</category>
    </item>
    <item>
      <title>Pentesting - Active Directory @Lkys37en LAB - Part 3</title>
      <link>https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-3</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/pentesting-active-directory-lab-parte-3</guid>
      <pubDate>Sun, 19 Jul 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>In Part 2 we had the opportunity to use several mechanisms to evade security controls in Active Directory, and with tools like Metasploit and CrackMapExec we…</description>
      <category>Active Directory</category>
      <category>Pentesting</category>
      <category>Lab</category>
    </item>
    <item>
      <title>Vulnhub</title>
      <link>https://plaintext.do/en/blog/vulnhub</link>
      <guid isPermaLink="true">https://plaintext.do/en/blog/vulnhub</guid>
      <pubDate>Sun, 19 Jul 2020 00:00:00 GMT</pubDate>
      <dc:creator>Julio Ureña</dc:creator>
      <description>Vulnhub is another CTF (Capture The Flag) platform where you can practice hacking. The advantage this platform offers is that you can download the virtual…</description>
      <category>Vulnhub</category>
      <category>CTF</category>
      <category>Learning</category>
    </item>
  </channel>
</rss>