RGROSEC
open-menucloseme
Home
About me
github linkedin
  • Web Application Hacking - Server-Side Request Forgery

    calendar Jun 20, 2022 · 14 min read · OWASP Webapp  ·
    Share on: twitter facebook linkedin copy
    Web Application Hacking - Server-Side Request Forgery

    This blog post will cover server-side request forgery (SSRF) attacks. Along the way we will be covering what a SSRF is, take a look at the basics of a SSRF attack, discuss several more advanced SSRF attacks and learn about the ways to prevent your web application of being vulnerable to these types of attacks. While …


    Read More
  • Web Application Hacking - Command Injection

    calendar May 18, 2022 · 11 min read · OWASP Webapp  ·
    Share on: twitter facebook linkedin copy
    Web Application Hacking - Command Injection

    In the fourth post regarding web application security, we will be diving into OS command injection or shell injection attacks. We will be covering what command injection is, what different types of command injection attacks exist and how to prevent command injection vulnerabilities within your own web applications. …


    Read More
  • Web Application Hacking - Directory Traversal

    calendar May 18, 2022 · 9 min read · OWASP Webapp  ·
    Share on: twitter facebook linkedin copy
    Web Application Hacking - Directory Traversal

    In this post we will be taking a look at the directory traversal or path traversal vulnerability. I'll go over what directory traversal exactly is, how we can weaponize it, how we can bypass common protections and misconfigurations and lastly how to prevent it within your own web application. While elaborating on this …


    Read More
  • Web Application Hacking - SQL Injection

    calendar May 13, 2022 · 31 min read · OWASP Webapp  ·
    Share on: twitter facebook linkedin copy
    Web Application Hacking - SQL Injection

    This post will explain what SQL-injection (SQLi) is, how we can find SQLi vulnerabilities in web applications, how we can weaponize this vulnerability and how to prevent it. While researching and explaining the topic, we will go through several easy and more advanced examples that are available for free at PortSwigger …


    Read More

Ruben Groenewoud

Security researcher at Elastic, writing about detection engineering, Linux security, and offensive security.
Read More

Featured Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Recent Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Categories

ELASTIC 18 DETECTION ENGINEERING 12 LINUX 12 MALWARE ANALYSIS 7 WALKTHROUGHS 7 PERSISTENCE 5 WEB APPLICATION HACKING 4 BINARY EXPLOITATION 2 PRIVILEGE ESCALATION 2 CVE 1

Tags

LINUX 25 ELASTIC 18 DETECTION ENGINEERING 12 HACK THE BOX 7 MALWARE ANALYSIS 7 HUNTING 5 PERSISTENCE 5 OWASP 4 WEBAPP 4 WINDOWS 4 BUFFER OVERFLOW 2 CONTAINERS 2 PRIVILEGE ESCALATION 2 ROOTKIT 2
All Tags
AUDITD1 BUFFER OVERFLOW2 CONTAINERS2 CVE1 DETECTION ENGINEERING12 ELASTIC18 HACK THE BOX7 HUNTING5 LINUX25 MALWARE ANALYSIS7 OWASP4 PERSISTENCE5 PRIVILEGE ESCALATION2 ROOTKIT2 WEBAPP4 WINDOWS4
[A~Z][0~9]
RGROSEC

Copyright  RGROSEC. All Rights Reserved

to-top