Clear instructions on how to dump firmware from an ESP8684 chipset that I couldn't find an example of anywhere outside of the docs.
Tag: Penetration Testing
Setting up and configuring LibreSDR B210/B220 AD9361 on Windows and Linux
So for a large project I've spent a month or two on I've been delving deeper into embedded device hacking/penetration testing. I've done some hardware engagements and have messed a bit for fun before, but nowhere to this extent. As apart of these escapades I plan to make a bunch of posts of tips & … Continue reading Setting up and configuring LibreSDR B210/B220 AD9361 on Windows and Linux
ConfiguringWindows Subsystem Linux (WSL) to access USB devices.
Been a minute! Here's a quick walkthrough to setting up USB device sharing for your WSL distro. I know it's nothing fancy but I'm happy to be back to making some posts. Should be many more to come. TBH, I'm not a huge fan of WSL for daily use I prefer full VMs but a … Continue reading ConfiguringWindows Subsystem Linux (WSL) to access USB devices.
Sniffing Zigbee Traffic Easily with the M5NanoC6 2024
So I've recently been dabbling into more niche hardware/wireless/RF protocols (thanks flipper zero) which is definitely a subject I'm less knowledgeable in. Of course the first time I used aircrack-ng was well over a decade ago now and I messed with NRF when keysniff and mousejacking was first published as well as reading/researching about Bluetooth, … Continue reading Sniffing Zigbee Traffic Easily with the M5NanoC6 2024
CVE-2024-32210, CVE-2024-32211, CVE-2024-32212, CVE-2024-32213 LoMag (Integrator/CE) WareHouse Management
The post discusses the discovery of multiple CVEs in LoMag WareHouse Management, including hard-coded credentials, weak hash usage, and SQL injection vulnerabilities. The author provides insights into their discovery process and highlights the insecure coding practices in the application.
CVE-2022-35142, CVE-2022-35143, CVE-2022-35144 – DoS, XSS and Weak Password Policy in Renato a Markdown powered knowledge base
Multiple new CVEs discovered and disclosed! XSS, DoS and a weak password policy!
CVE-2022-34613, CVE-2022-34618, CVE-2022-34619 – Multiple XSS (And more) in Mealie
Multiple new CVEs discovered and disclosed! XSS, file uploads and more!
CVE-2022-34625 – Server-Side Template Injection to Remote Code Execution (SSTI) to (RCE) in Mealie – A lesson in patience
A detailed walkthrough of CVE-2022-34625 aka a Server-Side Template Injection (SSTI) to Remote Code Execution (RCE)
Should I add this Repo to TreeHouse Wordlists?
You tell me what you think of this wordlist repo? Is it worth adding?
CLI Web Discovery Alternative to Dirb, Dirsearch, Etc
A great alternative to have for web discovery during web app pen tests or bug bounties.








