<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pablo Seoane · Pentester &amp; Security Researcher</title><link>https://bardlaudian.github.io/</link><description>Recent content on Pablo Seoane · Pentester &amp; Security Researcher</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>© 2026</copyright><lastBuildDate>Mon, 10 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bardlaudian.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Aug 2–9, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-05/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-05/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Fifth weekly report from the T-Pot honeypot, period &lt;strong>August 2–9, 2026&lt;/strong>. Volume rises to &lt;strong>~2,814,000 events&lt;/strong>. The residential ConPot botnet reaches its &lt;strong>third consecutive week with now-global reach&lt;/strong> (NTT DOCOMO, Wind Tre, Bouygues Telecom joining the already known Comcast, AT&amp;amp;T, Charter). RDPHoneypot nearly matches its historical maximum driven by a new actor: &lt;strong>Datacamp Limited&lt;/strong>. Cowrie sees a cryptocurrency credential wave and a new malware family named &lt;code>iran&lt;/code> for the first time. And the Adbhoney campaign tracked since the first report — 110→228→287→102 downloads — &lt;strong>closes definitively&lt;/strong>.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> August 2–9, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-03/" >Jul 19–25&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-04/" >Jul 26–Aug 2&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 26 – Aug 2, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-04/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-04/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Fourth weekly report from the T-Pot honeypot, period &lt;strong>July 26 – August 2, 2026&lt;/strong>. With four weeks of accumulated data, patterns stop being anecdotal and become trends: the &lt;strong>residential SNMP botnet on ConPot is confirmed for a second consecutive week&lt;/strong> (Comcast, AT&amp;amp;T, Verizon, Charter with not a single VPS in the top 10), IP &lt;strong>&lt;code>91.199.133.133&lt;/code> catalogued in ThreatFox as a Mirai Katana C2 reappears&lt;/strong> serving payloads in Cowrie, &lt;strong>Redtail adds RISC-V architecture&lt;/strong>, and the brute force campaign against Turkish ERP software in Dionaea is confirmed with a second week of consistent data.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 26 – August 2, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-03/" >Jul 19–25&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 19–25, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-03/</link><pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-03/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Third weekly report from the T-Pot honeypot, period &lt;strong>July 19–25, 2026&lt;/strong>. Total volume drops to &lt;strong>~1,820,000 events&lt;/strong> (half of last week), but the relevant data isn&amp;rsquo;t the total — it&amp;rsquo;s the composition: &lt;strong>ConPot spikes x27&lt;/strong> with origin in residential ISPs (Comcast, AT&amp;amp;T, Virgin Media, Free SAS) — the signature of a domestic router botnet attacking SNMP, a qualitatively different actor from anything seen so far. Meanwhile, Flyservers S.A. collapses on RDP, the same Adbhoney payload is in its third week of growth, and Dionaea detects brute force specifically targeting Turkish accounting software over MSSQL.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 19–25, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 12–18, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-02/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-02/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Second weekly report from the T-Pot honeypot, period &lt;strong>July 12–18, 2026&lt;/strong>. Total volume spikes to &lt;strong>~3,213,000 events&lt;/strong> (x3.2 compared to the previous week), but growth is not uniform: it&amp;rsquo;s almost entirely explained by two sensors — &lt;strong>RDPHoneypot x20.7&lt;/strong> with Flyservers S.A. as the dominant source, and &lt;strong>Sentrypeer x9.3&lt;/strong> with a target shift toward UK numbering. Recurring actors are confirmed across multiple sensors, and a new loader compiled for unusual architectures (&lt;code>loongarch64&lt;/code>, &lt;code>m68k&lt;/code>) is identified.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 12–18, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous report:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >week of July 7–11, 2026&lt;/a>&lt;/p></description></item><item><title>HTB Walkthrough: GoodGames</title><link>https://bardlaudian.github.io/posts/htb-goodgames/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-goodgames/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>GoodGames&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux&lt;/strong>. The chain starts with a &lt;strong>SQL Injection&lt;/strong> on the login form that allows both authentication bypass and database dumping. A cracked MD5 hash grants access to an internal Flask admin panel where the username field is vulnerable to &lt;strong>SSTI with Jinja2&lt;/strong>, giving RCE as &lt;code>root&lt;/code> inside a Docker container. Exiting to the real host combines &lt;strong>credential reuse&lt;/strong> via SSH with a &lt;strong>classic container escape&lt;/strong>: the user&amp;rsquo;s home directory is mounted as a volume, and without &lt;code>user namespace remapping&lt;/code> the container&amp;rsquo;s root can plant a SUID bit on &lt;code>bash&lt;/code> that is effective on the host.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Sau</title><link>https://bardlaudian.github.io/posts/htb-sau/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-sau/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Sau&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux&lt;/strong>. An SSRF in Request Baskets v1.2.1 (CVE-2023-27163) lets us pivot to Maltrail v0.53, a malicious traffic detection service accessible only from localhost. Maltrail has an unauthenticated RCE in its login endpoint that gives us a shell as &lt;code>puma&lt;/code>. Escalation to root exploits &lt;strong>CVE-2023-26604&lt;/strong>: &lt;code>systemctl status&lt;/code> run via &lt;code>sudo&lt;/code> invokes &lt;code>less&lt;/code> as a pager inheriting root privileges, which we escape with &lt;code>!/bin/bash&lt;/code>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 7–11, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-01/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-01/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 First weekly report from the T-Pot honeypot. During the week of &lt;strong>July 7–11, 2026&lt;/strong>, approximately &lt;strong>1,011,000 attack events&lt;/strong> were recorded across 10 active sensors. Top findings: multi-architecture &lt;em>Redtail&lt;/em> malware captured in Cowrie, a complete Android infection chain in Adbhoney (Rebirth → UFO miner → Trinity botnet), active scanning of exposed AI services (Ollama, Gradio, Streamlit), and probing of the IEC-104 protocol used in European electrical substations.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 7–11, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR&lt;/p></description></item><item><title>I Captured a Rebirth Botnet Sample in My Honeypot: Here's What I Pieced Together</title><link>https://bardlaudian.github.io/honeypot/rebirth-botnet/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/rebirth-botnet/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 While reviewing traffic from my T-Pot honeypot I found something more interesting than the typical SSH brute-force attempt: a complete infection chain, captured live, that turned out to be a variant of the &lt;strong>Rebirth&lt;/strong> botnet, from the Mirai/Gafgyt family. This post covers exactly what I captured, how I pieced it together to identify it, and what the security community says about this family — making clear throughout what is my direct observation and what is third-party research.
&lt;/div>

&lt;hr>

&lt;h2 class="relative group">What I Captured (this part is mine)
 &lt;div id="what-i-captured-this-part-is-mine" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-i-captured-this-part-is-mine" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>The honeypot that recorded this was &lt;strong>Adbhoney&lt;/strong>, one of T-Pot&amp;rsquo;s sensors that simulates the &lt;strong>ADB (Android Debug Bridge)&lt;/strong> protocol — Android&amp;rsquo;s remote debugging system, which when exposed to the internet without authentication is a trivial entry point for automated bots.&lt;/p></description></item><item><title>I Set Up a Honeypot and I'm Going to Report What I See Every Week</title><link>https://bardlaudian.github.io/honeypot/introduccion/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/introduccion/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 I&amp;rsquo;m going to intentionally expose a server to the internet so it gets attacked — and then write about it here, every week. No simulations or lab data: real malicious traffic, from the real internet, against a server that does nothing but wait for someone to try to break in.
&lt;/div>

&lt;hr>

&lt;h2 class="relative group">What This Is
 &lt;div id="what-this-is" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-this-is" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>This blog documents what a &lt;strong>honeypot&lt;/strong> — a decoy system designed to look vulnerable and attract attacks — detects in real time, week by week.&lt;/p></description></item><item><title>HTB Walkthrough: CCTV</title><link>https://bardlaudian.github.io/posts/htb-cctv/</link><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-cctv/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>CCTV&lt;/strong> on Hack The Box. &lt;strong>Medium&lt;/strong> difficulty machine running &lt;strong>Linux&lt;/strong>. ZoneMinder exposed with default credentials is vulnerable to &lt;strong>CVE-2024-51482&lt;/strong>, a blind SQL Injection that lets us extract bcrypt hashes and gain SSH access. Once inside, motionEye runs as root with its API signing key exposed in a readable configuration file — a combination that exploits &lt;strong>CVE-2025-60787&lt;/strong> to inject a command into a capture filename and set SUID on &lt;code>/bin/bash&lt;/code>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Medium
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Jerry</title><link>https://bardlaudian.github.io/posts/htb-jerry/</link><pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-jerry/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Jerry&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Windows Server 2012 R2&lt;/strong>. Apache Tomcat 7.0.88 exposed with default credentials in the Manager. We use them to deploy a malicious WAR that delivers remote code execution directly as &lt;strong>NT AUTHORITY\SYSTEM&lt;/strong> — no privilege escalation needed.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Windows
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: NetMon</title><link>https://bardlaudian.github.io/posts/htb-netmon/</link><pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-netmon/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>NetMon&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Windows Server 2016&lt;/strong>. Anonymous FTP exposes the Windows root filesystem, allowing us to read a PRTG configuration backup with cleartext credentials. With admin panel access we exploit CVE-2018-9276, a command injection in PRTG&amp;rsquo;s notification system that executes code as &lt;strong>NT AUTHORITY\SYSTEM&lt;/strong>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Windows
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Devel</title><link>https://bardlaudian.github.io/posts/htb-devel/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-devel/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Devel&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Windows 7 x86&lt;/strong>. Anonymous FTP shares the root directory with the IIS webroot, letting us upload an ASPX webshell and gain remote code execution. We escalate to &lt;strong>NT AUTHORITY\SYSTEM&lt;/strong> by exploiting MS10-015 (KiTrap0D), a flaw in the Windows x86 kernel.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Windows
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Facts</title><link>https://bardlaudian.github.io/posts/htb-facts/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-facts/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Facts&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux (Ubuntu 25.04)&lt;/strong>. We exploit a Mass Assignment in Camaleon CMS to escalate our role to administrator without knowing any password, abuse a Path Traversal in the AWS uploader to read system files and extract an encrypted SSH key, crack the passphrase with John the Ripper, and escalate to root by abusing &lt;code>sudo NOPASSWD&lt;/code> permissions over &lt;code>facter&lt;/code> with a malicious custom Ruby fact.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Kobold</title><link>https://bardlaudian.github.io/posts/htb-kobold/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-kobold/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Kobold&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux&lt;/strong>. Exploitation goes through &lt;strong>CVE-2026-23744&lt;/strong>, an unauthenticated RCE in MCPJam Inspector 1.4.2: the &lt;code>/api/mcp/connect&lt;/code> endpoint passes the &lt;code>command&lt;/code> field directly to &lt;code>child_process.spawn()&lt;/code> without any validation. Privilege escalation to root exploits the fact that user &lt;code>ben&lt;/code> belongs to the &lt;code>operator&lt;/code> group, which has permissions over the Docker socket — accessible via &lt;code>sg docker&lt;/code> without needing to log out. With access to the Docker daemon, we mount the host filesystem and get root with &lt;code>chroot&lt;/code>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Cap</title><link>https://bardlaudian.github.io/posts/htb-cap/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-cap/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Cap&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux (Ubuntu 20.04 LTS)&lt;/strong>. We exploit an IDOR on a network capture download endpoint to obtain cleartext FTP credentials, gain SSH access by reusing the password, and escalate to root by abusing the &lt;code>cap_setuid&lt;/code> capability assigned to the Python 3.8 binary.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Principal</title><link>https://bardlaudian.github.io/posts/htb-principal/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-principal/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Step-by-step walkthrough of &lt;strong>Principal&lt;/strong> on Hack The Box. &lt;strong>Medium&lt;/strong> difficulty machine running &lt;strong>Linux (Ubuntu 24.04 LTS)&lt;/strong>. We chain a JWT authentication bypass via CVE-2026-29000, credential extraction from an admin dashboard, and privilege escalation to root by forging an SSH certificate with the server&amp;rsquo;s private CA key.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Medium
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: DevArea</title><link>https://bardlaudian.github.io/posts/htb-devarea/</link><pubDate>Sun, 29 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-devarea/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>DevArea&lt;/strong> on Hack The Box. &lt;strong>Medium&lt;/strong> difficulty machine running &lt;strong>Linux Ubuntu&lt;/strong>. A Java SOAP service downloaded via anonymous FTP turns out to be Apache CXF 3.2.14, vulnerable to &lt;strong>CVE-2022-46364&lt;/strong> (XOP Include LFI). We use the flaw to read Hoverfly credentials from the systemd configuration and get RCE through the Middleware system. Root escalation exploits &lt;strong>PATH Hijacking&lt;/strong> in a script executed with &lt;code>sudo&lt;/code>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Medium
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Blue</title><link>https://bardlaudian.github.io/posts/htb-blue/</link><pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-blue/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Blue&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Windows 7 SP1&lt;/strong>. The vector is the infamous &lt;strong>EternalBlue&lt;/strong> exploit (MS17-010), a vulnerability in SMBv1 that compromises the Windows kernel and delivers direct access as &lt;strong>NT AUTHORITY\SYSTEM&lt;/strong> with no credentials required.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Windows
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: Lame</title><link>https://bardlaudian.github.io/posts/htb-lame/</link><pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-lame/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>Lame&lt;/strong>, one of the most classic machines on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty running &lt;strong>Linux&lt;/strong>. The main vector is a remote code execution vulnerability in &lt;strong>Samba 3.0.20&lt;/strong> (CVE-2007-2447) that, through the way Samba processes usernames, executes arbitrary shell commands with the service&amp;rsquo;s privileges — in this case, &lt;strong>root&lt;/strong>.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>HTB Walkthrough: WingData</title><link>https://bardlaudian.github.io/posts/htb-wingdata/</link><pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/posts/htb-wingdata/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Walkthrough of &lt;strong>WingData&lt;/strong> on Hack The Box. &lt;strong>Easy&lt;/strong> difficulty machine running &lt;strong>Linux&lt;/strong>. RCE via CVE-2025-47812, a null-byte authentication bypass in Wing FTP Server that grants access to the admin panel and remote code execution. After cracking user credentials with hashcat (SHA-256 with salt), we escalate to root by exploiting a &lt;code>PATH_MAX&lt;/code> bypass in Python&amp;rsquo;s &lt;code>tarfile&lt;/code> module executed with &lt;code>sudo&lt;/code> privileges.
&lt;/div>

&lt;p>&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 HackTheBox
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Linux
 &lt;/span>
&lt;/span>


&lt;span class="flex cursor-pointer">
 &lt;span
 class="rounded-md border border-primary-400 px-1 py-[1px] text-xs font-normal text-primary-700 dark:border-primary-600 dark:text-primary-400">
 Easy
 &lt;/span>
&lt;/span>

&lt;/p></description></item><item><title>About Me</title><link>https://bardlaudian.github.io/about/</link><pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/about/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Based in &lt;strong>Sada, Galicia&lt;/strong>. My path in technology started from the ground up — networks, systems, and programming. Today I channel all of that foundation into what I&amp;rsquo;m truly passionate about: &lt;strong>offensive cybersecurity&lt;/strong>.
&lt;/div>


&lt;h2 class="relative group">🎯 Professional Profile
 &lt;div id="-professional-profile" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#-professional-profile" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>Passionate about &lt;strong>Ethical Hacking&lt;/strong> and &lt;strong>Pentesting&lt;/strong>. I studied Robotics Engineering, but it was along that path that I discovered offensive cybersecurity and got hooked — so I decided to orient my entire career toward that field. I&amp;rsquo;m currently working toward the &lt;strong>CPTS&lt;/strong> (Certified Penetration Testing Specialist) certification from Hack The Box.&lt;/p></description></item><item><title>Auditoría Interna - Infraestructura CorpX</title><link>https://bardlaudian.github.io/reports/informe-profesional-ejemplo/</link><pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/reports/informe-profesional-ejemplo/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Documento descriptivo de los hallazgos tras la auditoría de caja negra sobre la infraestructura perimetral de CorpX.
&lt;/div>


&lt;h2 class="relative group">📋 Resumen Ejecutivo
 &lt;div id="-resumen-ejecutivo" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#-resumen-ejecutivo" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>Durante los días &lt;strong>[Fechas]&lt;/strong>, se llevó a cabo una auditoría de seguridad (Pentest) sobre la infraestructura de la empresa CorpX. El objetivo principal fue identificar, explotar y documentar vulnerabilidades en los sistemas expuestos a Internet.&lt;/p></description></item></channel></rss>