<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Chocapikk&apos;s Cybersecurity Blog</title><description>Blog about ethical hacking and vulnerability research by Valentin Lobstein</description><link>https://chocapikk.com/</link><item><title>Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists</title><link>https://chocapikk.com/posts/2026/monstaftp-ssrf-ipv6-blocklist-bypass/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/monstaftp-ssrf-ipv6-blocklist-bypass/</guid><description>An unauthenticated SSRF in Monsta FTP 2.14.4. The product ships a real SSRF blocklist that correctly blocks 127.0.0.1, 169.254.169.254 and RFC1918, then forgets that ::ffff:169.254.169.254 is the exact same host. One missing normalization, both gates bypassed, and a static AAAA record is all it takes.</description><pubDate>Mon, 13 Jul 2026 22:00:00 GMT</pubDate></item><item><title>NVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in Inference API</title><link>https://chocapikk.com/posts/2026/gen3c-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/gen3c-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in NVIDIA&apos;s GEN3C project. Two FastAPI inference endpoints deserialize raw HTTP POST bodies with pickle.loads() without any authentication, giving instant code execution to anyone with network access.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FOSSBilling: One Missing throw - From Auth Bypass to Unauthenticated RCE</title><link>https://chocapikk.com/posts/2026/fossbilling-unauth-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/fossbilling-unauth-rce/</guid><description>A missing throw keyword in FOSSBilling&apos;s API router exposes the entire admin surface to unauthenticated attackers. Combined with an unsandboxed Twig SSTI that leaks the full DI container, this leads to arbitrary SQL execution, admin takeover, and unauthenticated RCE via malicious extension installation.</description><pubDate>Sun, 05 Jul 2026 22:00:00 GMT</pubDate></item><item><title>CVE-2026-29514: NetBox Jinja2 Sandbox Bypass to RCE via RenderTemplateMixin environment_params</title><link>https://chocapikk.com/posts/2026/netbox-export-template-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/netbox-export-template-rce/</guid><description>A Jinja2 sandbox bypass in NetBox allows low-privilege users to achieve remote code execution via the RenderTemplateMixin environment_params finalize parameter, affecting both ExportTemplate and ConfigTemplate.</description><pubDate>Thu, 30 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Unauthenticated RCE in OpenCATS via Installer Config Injection</title><link>https://chocapikk.com/posts/2026/opencats-installer-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/opencats-installer-rce/</guid><description>Unauthenticated remote code execution in OpenCATS through unsanitized input in the installer AJAX endpoint, allowing PHP code injection into config.php.</description><pubDate>Mon, 27 Apr 2026 22:00:00 GMT</pubDate></item><item><title>CVE-2026-26210: ktransformers Unauthenticated RCE via Pickle Deserialization in ZMQ Scheduler</title><link>https://chocapikk.com/posts/2026/ktransformers-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/ktransformers-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in ktransformers&apos; balance_serve backend. A ZMQ ROUTER socket binds to all interfaces and proxies messages to worker threads that deserialize them with pickle.loads() - no authentication, no validation.</description><pubDate>Wed, 22 Apr 2026 22:00:00 GMT</pubDate></item><item><title>CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer</title><link>https://chocapikk.com/posts/2026/lerobot-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/lerobot-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in HuggingFace&apos;s LeRobot project (21.5k stars). The gRPC PolicyServer deserializes attacker-controlled data with pickle.loads() in two RPC handlers, allowing instant code execution without authentication.</description><pubDate>Wed, 22 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Microsoft tensorwatch: Local Code Execution via Pickle Deserialization in ZMQ Listener</title><link>https://chocapikk.com/posts/2026/tensorwatch-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/tensorwatch-pickle-rce/</guid><description>A local code execution vulnerability in Microsoft&apos;s tensorwatch. Calling tw.Watcher() - the first line in every README example - silently creates a ZMQ REP socket on localhost that deserializes incoming messages with pickle.loads(). Any local user on the same machine gets code execution.</description><pubDate>Wed, 22 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Instagram&apos;s &apos;Seen&apos; Is a Lie — And They&apos;re About to Charge You for the Proof</title><link>https://chocapikk.com/posts/2026/instagram-seen-is-a-lie/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/instagram-seen-is-a-lie/</guid><description>Instagram&apos;s &apos;seen&apos; indicator is a separate GraphQL call that any browser extension can block. It&apos;s been this way since 2019. Now Meta wants to charge $2/month for it.</description><pubDate>Fri, 17 Apr 2026 22:00:00 GMT</pubDate></item><item><title>How to Start Contributing to Metasploit: Field Notes from 68 Modules</title><link>https://chocapikk.com/posts/2026/contributing-to-metasploit/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/contributing-to-metasploit/</guid><description>68 modules in 2.5 years. Here&apos;s what the official docs don&apos;t tell you about writing Metasploit modules - from finding targets to surviving code review.</description><pubDate>Thu, 16 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Your .swp Files Are Telling on You: A Git Forensics Guide</title><link>https://chocapikk.com/posts/2026/swap-files-in-git/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/swap-files-in-git/</guid><description>Swap files from Vim and nano can leak usernames, hostnames, and sensitive data in git repos. Even after deletion, the blob stays in git history forever. Here&apos;s how to find them and how to actually clean them.</description><pubDate>Wed, 15 Apr 2026 22:00:00 GMT</pubDate></item><item><title>CeWL Is Dead. Here&apos;s What Replaces It.</title><link>https://chocapikk.com/posts/2026/cewlai-ai-powered-wordlist-generator/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/cewlai-ai-powered-wordlist-generator/</guid><description>CeWL has been the default wordlist generator for 10 years. CeWL AI crawls HTTP, FTP, SFTP, SMB, and S3 targets, feeds context to an LLM, scans for secrets with 800+ trufflehog detectors, and dumps files - all from one binary.</description><pubDate>Mon, 13 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Xboard / V2Board: Magic Link Token Leak - Unauthenticated Account Takeover</title><link>https://chocapikk.com/posts/2026/xboard-v2board-account-takeover/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/xboard-v2board-account-takeover/</guid><description>The loginWithMailLink endpoint in Xboard and V2Board returns the magic login link in the HTTP response body, allowing unauthenticated attackers to take over any account - including admin.</description><pubDate>Wed, 08 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Dumping PostgreSQL Without Credentials: Heap File Parsing for Offensive Security</title><link>https://chocapikk.com/posts/2026/dumping-postgresql-without-credentials/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/dumping-postgresql-without-credentials/</guid><description>A technique for extracting PostgreSQL data through arbitrary file read vulnerabilities - without credentials, without SQL access, without knowing the schema. Full auto-discovery via system catalogs.</description><pubDate>Mon, 06 Apr 2026 22:00:00 GMT</pubDate></item><item><title>Windfall: From Path Traversal to RCE in Nextcloud Flow &amp; Windmill</title><link>https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/</guid><description>Critical vulnerabilities in Windmill: unauthenticated path traversal leading to RCE, plus an authenticated SQL injection enabling full privilege escalation (operator → super admin → root RCE). Affects standalone Windmill and Nextcloud Flow.</description><pubDate>Mon, 06 Apr 2026 22:00:00 GMT</pubDate></item><item><title>From Zero to Exploit Dev: What Actually Worked</title><link>https://chocapikk.com/posts/2026/from-zero-to-exploit-dev/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/from-zero-to-exploit-dev/</guid><description>How I went from knowing nothing about computers in 2020 to writing exploits. No magic, no shortcuts, just the process.</description><pubDate>Fri, 03 Apr 2026 08:00:00 GMT</pubDate></item><item><title>How I Added PTY Support to Busybox Shells (When Everyone Said It Was Impossible)</title><link>https://chocapikk.com/posts/2026/pwncat-busybox-pty/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/pwncat-busybox-pty/</guid><description>Every shell handler fails on busybox/Alpine. No script, no python, no PTY. I fixed it with 80 lines of C and a base64 upload.</description><pubDate>Wed, 01 Apr 2026 21:00:00 GMT</pubDate></item><item><title>Reverse Engineering the ITE 8910 Keyboard RGB Protocol for OpenRGB</title><link>https://chocapikk.com/posts/2026/reverse-engineering-ite8910-keyboard-rgb/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/reverse-engineering-ite8910-keyboard-rgb/</guid><description>How I reverse-engineered the complete USB HID protocol of the ITE 8910 keyboard controller from a Windows DLL and .NET executable, and contributed per-key RGB support with 14 modes to OpenRGB - the first implementation for this chip on Linux.</description><pubDate>Thu, 26 Mar 2026 22:00:00 GMT</pubDate></item><item><title>OmniGen2: Unauthenticated RCE via Pickle Deserialization in BAAI&apos;s Reward Server</title><link>https://chocapikk.com/posts/2026/omnigen2-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/omnigen2-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in OmniGen2&apos;s reward server infrastructure. The Flask-based servers deserialize raw HTTP POST bodies with pickle.loads() without any authentication, giving instant code execution to anyone with network access.</description><pubDate>Tue, 17 Mar 2026 22:00:00 GMT</pubDate></item><item><title>sglang: Unauthenticated RCE via Pickle Deserialization in ZMQ Transport (Disaggregated Serving)</title><link>https://chocapikk.com/posts/2026/sglang-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/sglang-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in sglang&apos;s ZMQ transport layer for disaggregated serving. ZMQ PULL sockets bind to all interfaces and deserialize messages with pickle.loads() - no auth, no validation. Distinct from CVE-2025-10164 which only covers the HTTP API.</description><pubDate>Tue, 17 Mar 2026 22:00:00 GMT</pubDate></item><item><title>openDCIM: From SQL Injection to RCE via Config Poisoning</title><link>https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/</guid><description>Three chained vulnerabilities in openDCIM turn a missing authorization check into unauthenticated remote code execution on Docker deployments.</description><pubDate>Thu, 26 Feb 2026 22:00:00 GMT</pubDate></item><item><title>CVE-2026-27743 through CVE-2026-27747: Five Vulnerabilities in SPIP Plugins</title><link>https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/</guid><description>Five vulnerabilities across SPIP plugins: two SQL injections, two RCE (one unauth, one auth), and reflected XSS. Same template engine, same mistakes, different entry points.</description><pubDate>Tue, 24 Feb 2026 22:00:00 GMT</pubDate></item><item><title>CVE-2025-71243: AI-Assisted Reversal of SPIP Saisies RCE in 30 Minutes</title><link>https://chocapikk.com/posts/2026/spip-saisies-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/spip-saisies-rce/</guid><description>From VulnCheck advisory to working PoC in 30 minutes. Full AI-assisted reversal of CVE-2025-71243, an unauthenticated PHP code injection in SPIP&apos;s Saisies plugin affecting versions 5.4.0 through 5.11.0.</description><pubDate>Wed, 18 Feb 2026 22:00:00 GMT</pubDate></item><item><title>MajorDoMo Revisited: What I Missed in 2023</title><link>https://chocapikk.com/posts/2026/majordomo-revisited/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/majordomo-revisited/</guid><description>In 2023 I found CVE-2023-50917 in MajorDoMo. In 2026, AI agents found 8 more bugs I completely missed.</description><pubDate>Tue, 17 Feb 2026 23:00:00 GMT</pubDate></item><item><title>Android&apos;s AccessibilityService: A Single Toggle to Total Device Control</title><link>https://chocapikk.com/posts/2026/android-a11y-god-mode/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/android-a11y-god-mode/</guid><description>How one API designed for disability access became the foundation of a $145M surveillance industry. A proof-of-concept implant demonstrates the full attack chain: silent permission escalation in 2.4 seconds, contextual keylogging, see-through overlays, network toggle, self-hiding persistence, and an embedded Linux terminal with apt - all from a single accessibility toggle, no root required.</description><pubDate>Sun, 15 Feb 2026 01:00:00 GMT</pubDate></item><item><title>LightLLM: Unauthenticated RCE via Pickle Deserialization in WebSocket Endpoints</title><link>https://chocapikk.com/posts/2026/lightllm-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/lightllm-pickle-rce/</guid><description>CVE-2026-26220: A critical unauthenticated RCE vulnerability in LightLLM&apos;s PD disaggregation system. Two WebSocket endpoints deserialize binary frames with pickle.loads() without authentication, and the server explicitly refuses to bind to localhost - it&apos;s always network-exposed.</description><pubDate>Wed, 11 Feb 2026 01:00:00 GMT</pubDate></item><item><title>manga-image-translator: Unauthenticated RCE via Pickle Deserialization with Nonce Bypass</title><link>https://chocapikk.com/posts/2026/manga-image-translator-pickle-rce/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/manga-image-translator-pickle-rce/</guid><description>A critical unauthenticated RCE vulnerability in manga-image-translator. Two FastAPI endpoints deserialize raw HTTP POST bodies with pickle.loads(), and the nonce-based authentication is bypassed because the default value is an empty string - which is falsy in Python.</description><pubDate>Tue, 10 Feb 2026 23:00:00 GMT</pubDate></item><item><title>How Internet Scanners Actually Work: The &apos;Passive&apos; Scanning Myth</title><link>https://chocapikk.com/posts/2026/how-internet-scanners-work/</link><guid isPermaLink="true">https://chocapikk.com/posts/2026/how-internet-scanners-work/</guid><description>A deep dive into how internet-wide scanners like Shodan, Censys, and nmap actually identify services. Spoiler: there&apos;s nothing passive about it.</description><pubDate>Sun, 08 Feb 2026 01:00:00 GMT</pubDate></item><item><title>From Zero to Shell: Hunting Critical Vulnerabilities in AVideo</title><link>https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/</guid><description>A comprehensive security audit of AVideo revealing 10 vulnerabilities including a critical unauthenticated RCE that chains cryptographic weaknesses, predictable salt bruteforce, and an eval() vulnerability to achieve complete server compromise in under 10 seconds.</description><pubDate>Thu, 18 Dec 2025 22:00:00 GMT</pubDate></item><item><title>Streama Path Traversal + SSRF: Chaining Vulnerabilities for Arbitrary File Write</title><link>https://chocapikk.com/posts/2025/streama-path-traversal-ssrf/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/streama-path-traversal-ssrf/</guid><description>A critical vulnerability in Streama allows authenticated users to write arbitrary files through a combination of Server-Side Request Forgery (SSRF) and Path Traversal. This write-up covers the root cause analysis, exploitation flow, and the vendor&apos;s comprehensive fix.</description><pubDate>Thu, 18 Dec 2025 16:00:00 GMT</pubDate></item><item><title>Setting Up Giscus: An Ad-Free Alternative to Disqus for Blog Comments</title><link>https://chocapikk.com/posts/2025/setting-up-giscus-comments/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/setting-up-giscus-comments/</guid><description>How I set up Giscus for ad-free blog comments using GitHub Discussions, avoiding Disqus due to ads and other concerns.</description><pubDate>Fri, 14 Nov 2025 12:00:00 GMT</pubDate></item><item><title>When a Wi-Fi SSID Gives You Root on an MT02 Repeater – Part 2</title><link>https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root-part-two/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root-part-two/</guid><description>Deep dive into bind‐shell deployment, payload experiments, and a new ‘time_conf’ primitive for stealthy, persistent root access without reboot or UI lockup.</description><pubDate>Wed, 06 Aug 2025 12:00:00 GMT</pubDate></item><item><title>When a Wi-Fi SSID Gives You Root on an MT02 Repeater</title><link>https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root/</guid><description>How a €5 MT02 Wi-Fi repeater let me pop a root shell with nothing more than a cheeky SSID.</description><pubDate>Sun, 03 Aug 2025 12:00:00 GMT</pubDate></item><item><title>Multiple Vulnerabilities in Xorcom CompletePBX 5.2.35: RCE, File Disclosure and XSS</title><link>https://chocapikk.com/posts/2025/completepbx/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/completepbx/</guid><description>Several critical vulnerabilities discovered in Xorcom CompletePBX 5.2.35, including authenticated file disclosure, remote command execution as root, file deletion, and reflected XSS. This write-up details the black-box methodology, PoCs, and patch timeline.</description><pubDate>Sun, 22 Jun 2025 02:04:00 GMT</pubDate></item><item><title>Patchstack WCEU CTF – Open Contributions</title><link>https://chocapikk.com/posts/2025/patchstack-open-contributions/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/patchstack-open-contributions/</guid><description>Two missing checks inside the Open Contributions plugin let any fresh WordPress subscriber escalate to contributor and read arbitrary files — including the CTF flag — without brute-forcing a thing.</description><pubDate>Thu, 05 Jun 2025 19:30:00 GMT</pubDate></item><item><title>Helping Friends Learn Cybersecurity: Lessons from Teaching Beginners</title><link>https://chocapikk.com/posts/2025/helping-friends-cybersecurity/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/helping-friends-cybersecurity/</guid><pubDate>Fri, 23 May 2025 12:30:00 GMT</pubDate></item><item><title>Vembu BDRSuite: Unauth XSS, Weird Endpoints and Silent Patches (≤ 7.5.0.1)</title><link>https://chocapikk.com/posts/2025/bdrsuite/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/bdrsuite/</guid><description>Analysis of two unauthenticated XSS vulnerabilities and silently patched issues in Vembu BDRSuite up to version 7.6.0. Includes PoCs, API traces, patch timeline and commentary.</description><pubDate>Tue, 15 Apr 2025 17:00:00 GMT</pubDate></item><item><title>WPProbe: A Pragmatic Approach to Detecting WordPress Plugins</title><link>https://chocapikk.com/posts/2025/wpprobe/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/wpprobe/</guid><description>WPProbe is a lightweight tool that leverages the WordPress REST API to detect installed plugins passively. This post covers its design, use cases, technical constraints, and how it helps avoid noisy scans.</description><pubDate>Sat, 12 Apr 2025 19:13:00 GMT</pubDate></item><item><title>Two Stored XSS in MagnusBilling: From CTF Curiosity to CVEs</title><link>https://chocapikk.com/posts/2025/magnusbilling/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/magnusbilling/</guid><description>Two Stored XSS vulnerabilities discovered in MagnusBilling 7.x, including one unauthenticated, initially spotted during a CTF. This write-up covers the discovery process, PoCs, impact, patch timeline, and thoughts on the overall codebase.</description><pubDate>Fri, 21 Mar 2025 16:30:00 GMT</pubDate></item><item><title>How I Got Hacked: A Warning about Malicious PoCs</title><link>https://chocapikk.com/posts/2025/s1nk/</link><guid isPermaLink="true">https://chocapikk.com/posts/2025/s1nk/</guid><description>An in-depth forensic analysis of how a seemingly legitimate Proof-of-Concept (PoC) for CVE-2020-35489 turned out to be a cleverly disguised malware. This blog post details the attack vector, payload deobfuscation, Indicators of Compromise (IoCs), and the steps taken to analyze and neutralize the threat.</description><pubDate>Fri, 07 Feb 2025 12:35:21 GMT</pubDate></item><item><title>Wikimedia/svgtranslate 2.0.1 Remote Code Execution</title><link>https://chocapikk.com/posts/2024/svgtranslate/</link><guid isPermaLink="true">https://chocapikk.com/posts/2024/svgtranslate/</guid><description>Analysis of Unauthenticated Remote Command Execution Vulnerability in Wikimedia/svgtranslate</description><pubDate>Thu, 23 May 2024 13:43:51 GMT</pubDate></item><item><title>Exploring Mocodo Vulnerabilities: A Compilation of CVEs from 2024</title><link>https://chocapikk.com/posts/2024/mocodo-vulnerabilities/</link><guid isPermaLink="true">https://chocapikk.com/posts/2024/mocodo-vulnerabilities/</guid><description>A Detailed Analysis of Two Critical Remote Command Execution Vulnerabilities in Mocodo: Implications and Fixes</description><pubDate>Thu, 09 May 2024 11:10:00 GMT</pubDate></item><item><title>Exploring AVideo Vulnerabilities: A Deep Dive into CVE-2024-31819</title><link>https://chocapikk.com/posts/2024/cve-2024-31819/</link><guid isPermaLink="true">https://chocapikk.com/posts/2024/cve-2024-31819/</guid><description>A technical analysis of CVE-2024-31819, uncovering a critical Remote Code Execution vulnerability in the AVideo platform&apos;s WWBNIndex plugin.</description><pubDate>Tue, 09 Apr 2024 18:35:21 GMT</pubDate></item><item><title>Exploring DerbyNet Vulnerabilities: A Compilation of CVEs from 2024</title><link>https://chocapikk.com/posts/2024/derbynet-vulnerabilities/</link><guid isPermaLink="true">https://chocapikk.com/posts/2024/derbynet-vulnerabilities/</guid><description>A Comprehensive Analysis of Ten Critical Vulnerabilities in DerbyNet v9.0: From Cross-Site Scripting to SQL Injection</description><pubDate>Wed, 03 Apr 2024 18:35:21 GMT</pubDate></item><item><title>CVE-2023-50917</title><link>https://chocapikk.com/posts/2023/cve-2023-50917/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/cve-2023-50917/</guid><description>Deep Dive: CVE-2023-50917 - Unmasking an Unauthenticated Remote Code Execution Flaw in MajorDoMo&apos;s Thumb Module</description><pubDate>Mon, 18 Dec 2023 08:49:15 GMT</pubDate></item><item><title>n00bzCTF 2023 - Conditions</title><link>https://chocapikk.com/posts/2023/n00bzctf2023-conditions/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/n00bzctf2023-conditions/</guid><description>In this article, we will explore the step-by-step walkthrough of the Web challenge &apos;Conditions&apos; presented at n00bzCTF 2023.</description><pubDate>Sun, 11 Jun 2023 16:55:00 GMT</pubDate></item><item><title>n00bzCTF 2023 - EZrev</title><link>https://chocapikk.com/posts/2023/n00bzctf2023-ezrev/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/n00bzctf2023-ezrev/</guid><description>In this article, we will explore the step-by-step walkthrough of the Reverse challenge &apos;EZrev&apos; presented at n00bzCTF 2023.</description><pubDate>Sun, 11 Jun 2023 16:55:00 GMT</pubDate></item><item><title>n00bzCTF 2023 - MyPin</title><link>https://chocapikk.com/posts/2023/n00bzctf2023-mypin/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/n00bzctf2023-mypin/</guid><description>In this article, we will explore the step-by-step walkthrough of the Reverse challenge &apos;MyPin&apos; presented at n00bzCTF 2023.</description><pubDate>Sun, 11 Jun 2023 16:55:00 GMT</pubDate></item><item><title>tjCTF 2023 - Gish</title><link>https://chocapikk.com/posts/2023/tjctf2023-gish/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/tjctf2023-gish/</guid><description>In this article, we will explore the step-by-step walkthrough of the MISC challenge &apos;Gish&apos; presented at tjCTF 2023.</description><pubDate>Sun, 28 May 2023 00:02:50 GMT</pubDate></item><item><title>FCSC 2023 - Lapin Blanc</title><link>https://chocapikk.com/posts/2023/fcsc2023-lapin-blanc/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/fcsc2023-lapin-blanc/</guid><description>In this article, we will explore the step-by-step walkthrough of the &apos;Lapin Blanc&apos; challenge presented at FCSC 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>FCSC 2023 - UID</title><link>https://chocapikk.com/posts/2023/fcsc2023-uid/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/fcsc2023-uid/</guid><description>In this article, we will explore the step-by-step walkthrough of the &apos;uid&apos; challenge presented at FCSC 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>FCSC 2023 - Zéro Pointé</title><link>https://chocapikk.com/posts/2023/fcsc2023-zero-pointe/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/fcsc2023-zero-pointe/</guid><description>In this article, we will explore the step-by-step walkthrough of the &apos;Zéro Pointé&apos; challenge presented at FCSC 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>TamuCTF 2023 - Connect</title><link>https://chocapikk.com/posts/2023/tamuctf2023-connect/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/tamuctf2023-connect/</guid><description>In this article, we will explore the step-by-step walkthrough of the Web challenge &apos;Connect&apos; presented at TamuCTF 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>TamuCTF 2023 - Gamer Redux</title><link>https://chocapikk.com/posts/2023/tamuctf2023-gamer-redux/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/tamuctf2023-gamer-redux/</guid><description>In this article, we will explore the step-by-step walkthrough of the MISC challenge &apos;Gamer Redux&apos; presented at TamuCTF 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>FCSC 2023 -  ENISA Flag Store 1/2</title><link>https://chocapikk.com/posts/2023/fcsc2023-enisa-flag-store-1/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/fcsc2023-enisa-flag-store-1/</guid><description>In this article, we will explore the step-by-step walkthrough of the &apos;ENISA Flag Store 1/2&apos; challenge presented at FCSC 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>TamuCTF 2023 - Logical</title><link>https://chocapikk.com/posts/2023/tamuctf2023-logical/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/tamuctf2023-logical/</guid><description>In this article, we will explore the step-by-step walkthrough of the Web challenge &apos;Logical&apos; presented at TamuCTF 2023.</description><pubDate>Sun, 30 Apr 2023 20:36:07 GMT</pubDate></item><item><title>CAF 2023 - Babyrev</title><link>https://chocapikk.com/posts/2023/caf2023-babyrev/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/caf2023-babyrev/</guid><description>In this article, we will explore the step-by-step walkthrough of the Reverse challenge &apos;BabyRev&apos; presented at the CTF Cyber Africa Forum 2023.</description><pubDate>Tue, 18 Apr 2023 19:02:57 GMT</pubDate></item><item><title>CAF 2023 - Tower of Encryption</title><link>https://chocapikk.com/posts/2023/caf2023-tower-of-encryption/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/caf2023-tower-of-encryption/</guid><description>In this article, we will explore the walkthrough of the Cryptography challenge &apos;Tower of Encryption&apos; presented at the CTF Cyber Africa Forum 2023.</description><pubDate>Tue, 18 Apr 2023 12:22:07 GMT</pubDate></item><item><title>CAF 2023 - IT Administrator Credentials</title><link>https://chocapikk.com/posts/2023/caf2023-it-administrator-credentials/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/caf2023-it-administrator-credentials/</guid><description>In this article, we will explore the walkthrough of the Steganography challenge &apos;IT Administrator Credentials&apos; presented at the CTF Cyber Africa Forum 2023.</description><pubDate>Tue, 18 Apr 2023 11:42:57 GMT</pubDate></item><item><title>CAF 2023 - I Warn You</title><link>https://chocapikk.com/posts/2023/caf2023-i-warn-you/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/caf2023-i-warn-you/</guid><description>In this article, we will explore the step-by-step walkthrough of the Digital Forensic challenge &apos;I Warn You!&apos; presented at the CTF Cyber Africa Forum 2023.</description><pubDate>Tue, 18 Apr 2023 10:27:28 GMT</pubDate></item><item><title>CAF 2023 - Baby Hacker Big Brother</title><link>https://chocapikk.com/posts/2023/caf2023-baby-hacker-big-brother/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/caf2023-baby-hacker-big-brother/</guid><description>In this article, we will explore the step-by-step walkthrough of the Web challenge &apos;Baby Hacker Big Brother&apos; presented at the CTF Cyber Africa Forum 2023.</description><pubDate>Mon, 17 Apr 2023 17:46:48 GMT</pubDate></item><item><title>IDOR Vulnerability: Explanation, Exploitation, and Prevention</title><link>https://chocapikk.com/posts/2023/faille_idor/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/faille_idor/</guid><description>In this article, we will explore the Insecure Direct Object Reference (IDOR) vulnerability, a common security vulnerability in web applications that can have significant impacts on data confidentiality, integrity, and availability.</description><pubDate>Fri, 07 Apr 2023 15:40:43 GMT</pubDate></item><item><title>Using Python Sockets for Offensive Security</title><link>https://chocapikk.com/posts/2023/utilisation_socket_python/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/utilisation_socket_python/</guid><description>In this article, we will explore how to use Python sockets in the context of offensive security</description><pubDate>Fri, 07 Apr 2023 07:37:40 GMT</pubDate></item><item><title>Upload Vulnerabilities: Understanding, Exploiting, and Fixing</title><link>https://chocapikk.com/posts/2023/faille_upload/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/faille_upload/</guid><description>This article presents the various variants of the &apos;upload vulnerability&apos; and how to protect against them.</description><pubDate>Wed, 05 Apr 2023 14:21:38 GMT</pubDate></item><item><title>Privilege Escalation on Unix Systems via Crontab</title><link>https://chocapikk.com/posts/2023/elevation_privileges_unix_crontab/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/elevation_privileges_unix_crontab/</guid><description>This article demonstrates how to exploit privilege escalation from insecure scheduled tasks.</description><pubDate>Tue, 04 Apr 2023 14:06:19 GMT</pubDate></item><item><title>What is a Command Injection?</title><link>https://chocapikk.com/posts/2023/injection_de_commande/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/injection_de_commande/</guid><description>This article explains what command injection is, how to exploit it, and how to reduce the risks of this attack.</description><pubDate>Tue, 04 Apr 2023 13:20:38 GMT</pubDate></item><item><title>Configuring an Apache Server with SSL/TLS Hardening</title><link>https://chocapikk.com/posts/2023/configurer_un_serveur_apache/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/configurer_un_serveur_apache/</guid><description>This post explains how to secure an Apache server with SSL/TLS hardening and best practices.</description><pubDate>Mon, 03 Apr 2023 14:52:33 GMT</pubDate></item><item><title>Creating a Shodan Dork Using MMH3 Hash</title><link>https://chocapikk.com/posts/2023/creer_un_dork_shodan/</link><guid isPermaLink="true">https://chocapikk.com/posts/2023/creer_un_dork_shodan/</guid><description>This article explains how to create a Shodan dork based on the `favicon.ico` file using MMH3 hash</description><pubDate>Mon, 03 Apr 2023 12:55:21 GMT</pubDate></item><item><title>Oteria Cyber Cup 2022</title><link>https://chocapikk.com/posts/2022/oteria_cyber_cup_2022/</link><guid isPermaLink="true">https://chocapikk.com/posts/2022/oteria_cyber_cup_2022/</guid><description>In this post, I will write 2 writeups from the &apos;Applicatif&apos; category, 1 and 2, both being Easy level Buffer Overflow challenges.</description><pubDate>Mon, 03 Apr 2023 12:52:19 GMT</pubDate></item></channel></rss>