• News
  • Mobile
  • Security
  • Malware
  • Coding
  • Unix
  • DevOps
  • Log In
  • Sign Up
  • No bullshit
  • Cookie Policy
  • Privacy Policy
Log In / Sign Up

Author: snovvcrash

Dumping at nanolevel. How I reinvented SafetyKatz to dump LSASS with NanoDump
Malware

Dumping at nanolevel. How I reinvented SafetyKatz to dump LSASS…

13.06.202523/07/2025snovvcrash3360
This article discusses the covert use of the NanoDump utility from memory (i.e. the simulated attacker doesn’t have a C&C ‘beacon’ on the attacked network node) and compares such an application of NanoDump with the use of SafetyKatz.
CONTINUE READING 🡒
Serpent pyramid. Run malware from the EDR blind spots!
Security

Serpent pyramid. Run malware from the EDR blind spots!

04.04.202308/04/2025snovvcrash1520
In this article, I’ll show how to modify a standalone Python interpreter so that you can load malicious dependencies directly into memory using the Pyramid tool (not to be confused with the web framework of the same name). Potentially, this enables you to evade…
CONTINUE READING 🡒
Poisonous spuds. Privilege escalation in AD with RemotePotato0
Security

Poisonous spuds. Privilege escalation in AD with RemotePotato0

26.03.202308/04/2025snovvcrash1680
This article discusses different variations of the NTLM Relay cross-protocol attack delivered using the RemotePotato0 exploit. In addition, you will learn how to hide the signature of an executable file from static analysis.
CONTINUE READING 🡒
Challenge the Keemaker! How to bypass antiviruses and inject shellcode into KeePass memory
Coding Security

Challenge the Keemaker! How to bypass antiviruses and inject shellcode…

03.06.202217/04/2025snovvcrash1970
Recently, I was involved with a challenging pentesting project. Using the KeeThief utility from GhostPack, I tried to extract the master password for the open-source KeePass database from the process memory. Too bad, EDR was monitoring the system and prevented me from doing this: after…
CONTINUE READING 🡒
Stratosphere flight. How to crack Struts using an Action app and create a Forward Shell
Security

Stratosphere flight. How to crack Struts using an Action app…

19.10.202017/04/2025snovvcrash940
Today, I will show how to conquer the stratosphere - i.e. gain root access on the Stratosphere VM available on [Hack The Box](https://www.hackthebox.eu/) CTF grounds. To capture the root flag, I will have to overcome the Apache…
CONTINUE READING 🡒
The PWN realm. Modern techniques for stack overflow exploitation
Security

The PWN realm. Modern techniques for stack overflow exploitation

19.10.202017/04/2025snovvcrash3641
The buffer overflow vulnerability is an extremely popular topic on hackers' forums. In this article, I will provide a universal and practically-oriented 'introduction' for enthusiasts studying the basics of low-level exploitation. Using stack overflow as an example,…
CONTINUE READING 🡒
Compressed Token Format (CTF). One-time passwords, LDAP injections, and tricks with 7z archiver
Security

Compressed Token Format (CTF). One-time passwords, LDAP injections, and tricks…

19.10.202017/04/2025snovvcrash1310
Today, I will explain how to hack the CTF virtual machine available on [Hack The Box](https://www.hackthebox.eu/) training grounds. For the purposes of this article, the abbreviation "CTF" refers to Compressed Token Format, not Capture the Flag. This…
CONTINUE READING 🡒
Diabolically reddish pentest. Building tunneling chains through docker containers on a Hack the Box virtual machine
Security

Diabolically reddish pentest. Building tunneling chains through docker containers on…

04.08.202008/04/2025snovvcrash3400
How to seize control over a host located in a different subnetwork? The right answer is: build numerous intricate tunnels. This article addresses tunneling techniques and their application in pentesting using as an example Reddish, a hardcore…
CONTINUE READING 🡒
The great mischief. Working your way to the root flag through IPv6 labyrinths on a Hack the Box virtual machine
Security

The great mischief. Working your way to the root flag…

04.05.2020snovvcrash2430
In this article, I will explain how to gain superuser privileges on Mischief VM available on [Hack The Box](https://www.hackthebox.eu/) training grounds. During this journey, you will acquire some SNMP skills, understand the IPv6 routing principles, and learn…
CONTINUE READING 🡒
Where to study pentesting? An overview of training grounds for ethical hackers
Security

Where to study pentesting? An overview of training grounds for…

15.03.202015/03/2020snovvcrash7851
Today, I will give a brief overview of some of the best pentesting portals recognized by security experts. These training grounds enable ethical hackers to polish their skills while preserving 'ethicality' and exploit newly-discovered vulnerabilities while staying…
CONTINUE READING 🡒
Epic pivoting. Polishing traffic routing skills on HackTheBox virtual machines
Security

Epic pivoting. Polishing traffic routing skills on HackTheBox virtual machines

15.03.2020snovvcrash3230
A good knowledge of pivoting (a technique used to route traffic to the victim and back through interim hosts) is essential for any ethical hacker. Furthermore, this skill is absolutely mandatory for corporate network pentesting. In this…
CONTINUE READING 🡒
The taming of Kerberos. Seizing control over Active Directory on a HackTheBox virtual PC
Security

The taming of Kerberos. Seizing control over Active Directory on…

28.02.202009/10/2025snovvcrash970
In this article, I am going to show how to escalate from an unprivileged user to the administrator of the Active Directory domain controller. The demonstration will be performed on a virtual PC available for hacking on…
CONTINUE READING 🡒
  • No bullshit
  • Cookie Policy
  • Privacy Policy
HackMag — Top-notch cybersecurity magazine © 2025
Support:support@hackmag.com