隠者 Inja Security
隠者 Inja Security
  • Home
  • ~$ whoami

Certification Review

Offensive Security Web Assessor (OSWA)

As an Offensive Security 200 level course, OSWA can be easily compared to OSCP at a certain level, where you’ll have 5 Web applications as targets with the objective of collecting local.txt and proof.txt flags to score points. Every flag Read more…

By Matheus Boschetti, 2 yearsJanuary 24, 2023 ago
Defense Evasion

Antivirus Evasion: Tearing AMSI Down With 3 Bytes Only

By Matheus Boschetti, 2 yearsJanuary 10, 2023 ago
Certification Review

eLearnSecurity Mobile Application Penetration Tester (eMAPT)

As mobile apps are a very common scope between the projects I currently take, I realized it would be a good idea to get certified on the topic. eMAPT is the only mobile certification besides the GIAC Mobile Device Security Analyst Read more…

By Matheus Boschetti, 3 yearsOctober 16, 2022 ago
Certification Review

Pentester Academy Certified Red Team Professional (CRTP)

Having bought INE’s premium plan, I have access to the Attacking and Defending Active Directory course. After passing the OSCP, my plan was to move further into Red Teaming, and CRTP seemed to be a good fit for the first step. Read more…

By Matheus Boschetti, 3 yearsOctober 9, 2022 ago
Certification Review

eLearnSecurity Web application Penetration Tester (eWPT)

There aren’t many black-box oriented certifications in the market regarding Web applications, where eLS offers two (eWPT and eWPTX) and Offensive Security now has the Web Assessor / OSWA, which costs $2.499,00 on its cheapest version. Background and Preparation After Read more…

By Matheus Boschetti, 3 yearsJuly 8, 2022 ago
Certification Review

Offensive Security Certified Professional (OSCP)

The famous and all mighty HR gatekeeper, no introductions needed. If you live in a cave and haven’t heard of OffSec or the OSCP exam, you can find details here. Background and Preparation This is an exam that I actually Read more…

By Matheus Boschetti, 3 yearsJuly 4, 2022 ago
Binary Exploitation

Windows SEH Overflows: Abusing Windows’ Structured Exception Handling

Introduction Structured exception handling (SEH) is a Microsoft extension to C to handle certain exceptional code situations, such as hardware faults. Developers will often make use of similar constructs among different languages, such as try-catch, try-except or try-finally statements. Such Read more…

By Matheus Boschetti, 3 yearsApril 5, 2022 ago
Certification Review

eLearnSecurity Certified Professional Penetration Tester (eCPPTv2)

February 17, 2022 eLearnSecurity content and certifications are relatively well-known, with an overall good reputation as their materials are up-to-date and their exams practical and real-life applicable. With that said, and taking into account that there are lots of reviews out Read more…

By Matheus Boschetti, 3 yearsFebruary 17, 2022 ago

Posts navigation

Previous 1 2

Recent Posts

  • CVE-2024-29320: SQL Injection in Wallos
  • CVE-2024-27613: Arbitrary File Manipulation in Numbas
  • Bypassing PowerShell CLM with Custom Runspaces
  • Striking Blue: Picking Digital Lockers
  • Leveraging Process Injection for AV Evasion

Archive

  • April 2024
  • March 2024
  • August 2023
  • July 2023
  • June 2023
  • January 2023
  • October 2022
  • July 2022
  • April 2022
  • February 2022

Categories

  • Application Security
  • Binary Exploitation
  • Certification Review
  • Defense Evasion
  • Malware Development
  • Open Source Software (OSS)
  • Phishing
  • Red Team
  • Security Research
  • ~$ whoami
Hestia | Developed by ThemeIsle