Open in app

Sign In

Write

Sign In

LobuhiSec
LobuhiSec

43 Followers

Home

About

Jan 27

Learning Golang: From 0 to multithreading in 3 days thanks to ChatGPT

Some of you may already know about my tool byp4xx, a simple script to bypass 40X/HTTP responses that uses different methodologies. It started being a simple bash script using cUrl but at some point I decided to move to Python. Just a personal challenge, I never wrote anything in Python…

ChatGPT

6 min read

Learning Golang: From 0 to multithreading in 3 days thanks to ChatGPT
Learning Golang: From 0 to multithreading in 3 days thanks to ChatGPT
ChatGPT

6 min read


Jan 16

Abusing ETCD to Inject Resources and Bypass RBAC and Admission Controller Restrictions

During my journey to become a Certified Kubernetes Administrator (CKA) and Certified Kubernetes Security Specialist (CKS), I was focused on exploring ways an attacker could exploit an exposed ETCD. I attempted various methods without success until now. DISCLAIMER: Please note that this technique can only be used when the attacker…

Kubernetes Security

7 min read

Abusing ETCD to Inject Resources and Bypass RBAC and Admission Controller Restrictions
Abusing ETCD to Inject Resources and Bypass RBAC and Admission Controller Restrictions
Kubernetes Security

7 min read


Dec 3, 2022

Las implicaciones de ChatGPT para el sector IT y la ciberseguridad

El lanzamiento de ChatGPT ha sido uno de los eventos más importantes en el sector de tecnología e informática en los últimos años. …

2 min read

Las implicaciones de ChatGPT para el sector IT y la ciberseguridad
Las implicaciones de ChatGPT para el sector IT y la ciberseguridad

2 min read


Nov 3, 2022

How I made a reliable hacking tools and resources search engine in two days (~6500 entries!)

https://lobuhi.github.io/ In fairness, this is just a fork from Ippsec.Rocks, a great resource which I visited oftenly when I was enrolled for OSCP. …

Hacking Tools

3 min read

How I made a reliable hacking tools and resources search engine in two days (~6500 entries!)
How I made a reliable hacking tools and resources search engine in two days (~6500 entries!)
Hacking Tools

3 min read


Sep 9, 2022

We all should stop reporting missing headers just because Burp Suite burps it

Sure, I’ve reported HSTS and cookie secure flags more times that I’d admit just because Burp says so. Sometimes customers are ashamed to ask how things work or why any header would improve its security posture, sometimes even security consultants are afraid about it. One day a curious customer just…

Burpsuite

4 min read

We all should stop reporting missing headers just because Burp Suite burps it
We all should stop reporting missing headers just because Burp Suite burps it
Burpsuite

4 min read


Jun 5, 2021

My OSCP story: tips, tricks and hints

First, let me explain you about my background. I mess with security stuff since I was a teenager, not always with the same intensity but I’ve been always connected to cybersec scene in one way or another. My first IT job it was as a night shift helpdesk, it seems…

Oscp

6 min read

My OSCP story: tips, tricks and hints
My OSCP story: tips, tricks and hints
Oscp

6 min read


Mar 7, 2021

Cómo montar un laboratorio de pentesting para Android en Windows…

…sin sufrir demasiado. La mayoría de guías destinadas a este propósito obvian algunos errores típicos durante la instalación de algunos de estos componentes y se limitan al siguiente, siguiente, siguiente del emulador de turno, pero montar un laboratorio para Android destinado a pentesting, sin ser una tarea compleja, requiere de…

8 min read

Cómo montar un laboratorio de pentesting para Android en Windows…
Cómo montar un laboratorio de pentesting para Android en Windows…

8 min read


Jan 16, 2021

Kubernetes Pentest: Checklist, tools and resources

Kubernetes is a maze: deployments, pods, containers, namespaces, services… When you arrive at kube-world as a beginner (like me) nothing has sense. For a while, I’ve been thinking about to create a checklist for pentesting purposes and put together every tool, repo or technique I’ve been discovering about kubernetes lately…

Kubernetes

7 min read

Kubernetes Pentest: Recon checklist, tools and resources
Kubernetes Pentest: Recon checklist, tools and resources
Kubernetes

7 min read


Aug 6, 2020

[Writeup] TryHackMe — Skynet — Another privesc approach

ROOM: https://tryhackme.com/room/skynet Let me show you another way than the official writeup you can find here https://blog.tryhackme.com/skynet-writeup/. First things first, let’s scan: Looks like too much info, but we just got ssh, web, pop3, imapd and samba. First change versus the official writeup, I’ll use dirsearch instead of gobuster:

4 min read

[Writeup] TryHackMe — Skynet — Another privesc way
[Writeup] TryHackMe — Skynet — Another privesc way

4 min read


Jun 4, 2020

How I gained Domain Admin rights without fancy tools…

…like responder, mitm6 or others kerberos related methods. This is the story of a lucky boy. Responder didn’t work at all, it just didn’t get anything interesting for two days so I gave up. Then a colleague told me to try with mitm6. Same results. Later I confirmed with admins…

Active Directory

2 min read

Active Directory

2 min read

LobuhiSec

LobuhiSec

43 Followers

https://twitter.com/lobuhisec

Following
  • Thexssrat

    Thexssrat

  • kleiton0x7e

    kleiton0x7e

  • Sec-0ps

    Sec-0ps

  • Nitesh Pandey

    Nitesh Pandey

  • donut

    donut

See all (7)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech