Recent Posts

The Web-Facing ESC6: SAN Injection Over CEP/CES

10 minute read

The Certificate Enrollment Web Service (CES) forwards a SAN AdditionalContext ContextItem to the CA as a SAN request attribute. Where EDITF_ATTRIBUTESUBJECTA...

HackTheBox: DarkZero

18 minute read

This box is rated hard difficulty on HTB. It involves us using given credentials to attack a linked MSSQL server, enabling xp_cmdshell to grant command execu...