
Publications
- Blog4 min
Bypassing Duo Security 2FA (As a Local Administrator)
During an internal penetration test conducted by the Plaintext Cybersecurity Solutions team, we came across an interesting scenario involving Duo Security.
Read - Blog2 min
100 Days Of BlueTeam
2020 came with plenty of surprises for everyone—COVID, social distancing, remote work—and PlainText decided to take a break from its RedTeam learning journey…
Read - Blog7 min
My Learning Journey Writing the CVE-2019-19470 Exploit
Hey! I'll try to tell you my story about how I reproduced CVE-2019-19470. This will be both a personal learning experience and technical examples, but it's…
Read - Blog4 min
Firewall Best Practices
When performing a Pentest, it's much easier to take advantage of the lack of awareness among network/security administrators who don't realize how we can use…
Read - Blog4 min
My 1st CVE - Capturing FortiGate LDAP Credentials
In July 2018, I reported a vulnerability to the Fortinet development team that I discovered in how FortiGate (version 6.0.2 and earlier) handled LDAP…
Read - Blog10 min
OSCP - My Introduction to Pentesting and Certification Review
In March 2017, I started an Ethical Hacking course at CertyAcademy. I saw this course as a way to understand how hackers operate so I could build more…
Read - Blog1 min
Pentesting - Active Directory @Lkys37en LAB - Part 1
---
Read - Blog1 min
Pentesting - Active Directory @Lkys37en LAB - Part 2
In Part 1 we managed to gain access to the internal network through Password Spraying. Now in this second part we'll get into some interesting techniques…
Read - Blog7 min
WhatsApp Protector
Automation is the reason I love programming. I must confess I'm not the best developer, but I can't deny that I really enjoy it.
Read - Blog9 min
How I Discovered Using Dropbox pythonNN.dll to Run Python Scripts Without Python
I was playing Warzone and started noticing some packet loss, which is "not good at all" if you're playing an FPS game. I went into Task Manager and looked…
Read - Blog3 min
WhatsApp Two-Step Verification Reminder Bypass
In February 2019, I reached out to the Facebook team regarding a bug I found in WhatsApp's two-step verification reminder feature—a feature designed to help…
Read - Blog1 min
Phishing Awareness Campaign
I've recently witnessed a wave of Phishing attacks—something that hasn't changed over the years. It simply evolves, shifts, repeats itself, but it always…
Read - Blog1 min
HackTheBox
---
Read - Blog1 min
Pentesting - Active Directory @Lkys37en LAB - Part 3
In Part 2 we had the opportunity to use several mechanisms to evade security controls in Active Directory, and with tools like Metasploit and CrackMapExec we…
Read - Blog1 min
Vulnhub
Vulnhub is another CTF (Capture The Flag) platform where you can practice hacking. The advantage this platform offers is that you can download the virtual…
Read
Get Protected Today
Discover how we help your business protect itself. We strengthen your online presence and shield you against cyberattacks.
Contact us