Category: Security Research | Tağmaç - root@Tagoletta:~#

Category: Security Research

Posts in Security Research

Windows Credential Access: LSASS, DPAPI, SAM, and Browser Secrets

A complete attacker's guide to Windows credential access: LSASS internals and SSP architecture, DPAPI master key hierarchy, SAM and NTDS extraction, Credential Manager abuse, browser credential decryption (Chrome AES-GCM + DPAPI, Firefox NSS), and GPP credentials — with OPSEC ratings and detection guidance.

Read more

Kerberos Protocol Internals: Tickets, PAC, and the Security Implications

A deep technical dive into Kerberos 5 internals: TGT/TGS structure, PAC buffer breakdown, encryption type selection, AS exchange, S4U extensions, and how Golden/Diamond/Silver Tickets exploit these structures at the byte level — with Wireshark analysis and detection guidance.

Read more

BloodHound CE for Defensive AD Analysis: Attack Path Management

How to use BloodHound Community Edition defensively: tier model implementation, attack path discovery and prioritization, custom Cypher queries for blue teams, remediation workflows, and continuous AD exposure management — based on SpecterOps Attack Path Management.

Read more

AD Certificate Services Deep Dive: ESC1 to ESC8 Attack Paths

A deep-dive into every ADCS misconfiguration from ESC1 to ESC10: template flag analysis, certificate anatomy, NTLM relay chains, ManageCA abuse, and the ESC8+PetitPotam combo — with certipy walkthroughs and defenses based on SpecterOps 'Certified Pre-Owned'.

Read more

Active Directory Security Testing: The Complete Attacker's Perspective

A complete attacker's methodology for Active Directory assessments: enumeration, Kerberoasting, AS-REP Roasting, ACL/attribute abuse, Shadow Credentials, ADCS ESC1-ESC8, delegation attacks, DCSync, ZeroLogon, noPac, PetitPotam, GPO abuse, trust attacks, and persistence — with commands, tools, and detection guidance.

Read more

Web Cache Deception & Poisoning: Weaponizing the Gap Between Cache and Origin

Two sides of cache abuse — Web Cache Deception tricks a CDN into storing a victim's private page, while Web Cache Poisoning injects a malicious response served to every visitor. How cache-key vs origin parsing discrepancies create both, with real-world chains and defenses.

Read more

SSRF to Cloud Credentials: Stealing AWS IAM Tokens via Metadata API

How a single Server-Side Request Forgery vulnerability can escalate to full AWS/GCP/Azure account compromise by targeting cloud instance metadata services — and why the 452% SSRF surge in 2024 matters.

Read more

HTTP Request Smuggling: Exploiting Front-End/Back-End Parsing Desync

How attackers exploit disagreements between front-end and back-end servers on where HTTP requests begin and end — and chain CL.TE desync attacks into account takeover, firewall bypass, and cache poisoning.

Read more

Blind SSTI to RCE: Exploiting Template Engines Without Output

How attackers detect and exploit Server-Side Template Injection when the application returns no output — using timing delays, DNS callbacks, and engine fingerprinting to achieve full remote code execution.

Read more

Prototype Pollution to RCE: Node.js Gadget Chains Explained

How injecting properties into JavaScript's Object.prototype poisons the entire Node.js process — and how gadget chains turn that pollution into remote code execution, demonstrated via CVE-2024-38999 in RequireJS.

Read more

Single-Packet Race Condition: Sub-Millisecond Web Exploitation

How the single-packet attack technique eliminates network jitter to exploit sub-millisecond race conditions in web applications — and how CVE-2024-58248 in nopCommerce was exploited using Burp Suite.

Read more

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server

How Orange Tsai's Confusion Attacks exploit URL decoding inconsistencies across Apache modules to chain ACL bypass, SSRF, and unauthenticated RCE — #1 web hacking technique of 2024.

Read more

CVE-2025-69460 – Simple Image Gallery 1.0 - Remote Code Execution (Unauthenticated)

CVE-2025-69460: Unauthenticated Remote Code Execution (RCE) vulnerability in Simple Image Gallery 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Read more

CVE-2025-69457 – Responsive Tourism Website 3.1 - Remote Code Execution (Unauthenticated)

CVE-2025-69457: Unauthenticated Remote Code Execution (RCE) vulnerability in Responsive Tourism Website 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Read more

CVE-2023-38890 – Online Shopping Portal 3.1 Remote Code Execution

CVE-2023-38890: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Online Shopping Portal 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Read more

CVE-2025-69458 – Movie Rating System 1.0 - SQL Injection to RCE (Unauthenticated)

CVE-2025-69458: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Read more

CVE-2025-69459 – Movie Rating System 1.0 - Broken Access Control

CVE-2025-69459: Broken Access Control vulnerability allowing Admin Account Creation in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Read more

Traffic Offense Management System 1.0 - Remote Code Execution (Unauthenticated)

Zero-Day Discovery & Exploit Development: unauthenticated SQL Injection to RCE in Traffic Offense Management System 1.0. Full writeup with PoC exploit code by Tağmaç 'Tagoletta'.

Read more