Eye of Ra
SECURITY RESEARCHAsbawy

Logs

Dev logs, security research, vulnerability disclosures, and tech ramblings.

Telecommunications2026-08-0715 min

A Technical Dive into 5G Hacking

A complete technical breakdown of 5G Standalone (SA) vulnerabilities, covering RAN hardware exploitation, SBI web vulnerability chains, 5G-AKA cryptographic weaknesses, and Kubernetes CNF compromise.

#5G#Red Team#Kubernetes#SDR#Web Vulnerabilities#Cloud Security#Cryptography
Read Log
Windows2026-07-2420 min

CertiGhost (CVE-2026-54121): How a Low-Privileged AD User Impersonated a Domain Controller via AD CS

A deep dive into CVE-2026-54121 — the CertiGhost vulnerability that let any Domain User forge a Domain Controller certificate through an AD CS chase fallback, escalate to DCSync, and fully compromise the domain.

#Active Directory#CVE-2026-54121#CertiGhost#Red Team#Privilege Escalation#AD CS
Read Log
Web2026-07-0820 min

Source Code Review: Unearthing Critical Flaws in PHP

A direct, no-fluff guide to auditing PHP codebases. Learn to spot critical vulnerabilities, map attack surfaces, and weaponize findings with functional exploits.

#PHP#Code Review#AppSec#Red Team#Bug Bounty
Read Log
Forensics2026-07-0230 min

Battlefield Forensics: Anatomy of the IDF's Captured "Olar" Secure Smartphone in Syria

An analysis of the IDF's captured "Olar" secure smartphone in Syria, detailing its hardware, MDM-enforced kiosk hardening, ORION C4I payload, and the incident's OPSEC implications.

#Mobile Security#OSINT#Android#Hardware
Read Log
Network2026-06-189 min read

Practical Wireless Exploitation for Red Teams

A practical playbook detailing advanced wireless offensive operations, covering corporate Wi-Fi infiltration, BLE MITM, RFID cloning, and IoT vulnerabilities.

#Wireless#Wi-Fi#BLE#RFID#IoT#Offensive Security#Red Teaming
Read Log
Windows2026-06-0912 min

BadSuccessor: dMSA Privilege Escalation in Windows Server 2025

A complete technical breakdown of the BadSuccessor vulnerability in Windows Server 2025, explaining how dMSA migration mechanics can be abused for full domain compromise.

#Active Directory#Windows Server 2025#Privilege Escalation#Red Team#Kerberos#dMSA#BadSuccessor
Read Log
Windows2026-06-0814 min

Shellcode 101: From Assembly to AV Evasion

Go from zero to exploit-ready: learn how shellcode works, how buffer overflows weaponize it, how to survive null bytes, generate payloads with MSFvenom, and slip past modern AV/EDR. The complete guide for CTF players and Red Teamers.

#Offensive Security#Exploit Development#Shellcode#Red Teaming#CTF#Buffer Overflow#x86-64 Assembly#Penetration Testing#MSFvenom#AV Evasion#EDR Bypass
Read Log
Web2026-06-0413 min

CVE-2026-42945 — NGINX Rift: The 18-Year-Old RCE Hiding in Plain Sight

A critical heap buffer overflow in ngx_http_rewrite_module — hiding since 2008, CVSS 9.2, unauthenticated RCE from a single crafted request.

#RCE#CVE#Nginx#Heap Overflow#Exploit
Read Log
Windows2026-06-0327 min

Legacy Lethality: Weaponizing OLE & VBA Macros in the GenAI Era

Enterprise endpoints keep falling to attack primitives from the early 1990s. OLE and VBA macros still dominate initial access because legacy interoperability requirements override security posture. Finance, HR, and operations depend on macro-enabled workflows, and generative AI has collapsed the skill barrier—Q1 2026 telemetry shows over 60% of macro-based malware uses AI-generated obfuscation. This post covers the full attack lifecycle: trigger mechanisms, obfuscation, in-process payload injection, direct syscalls from VBA, XLM abuse, OLE weaponization without macros, and the CVE-2026-21509 kill-bit bypass.

#ole#vba#macros#red-team#malware-analysis#edr-evasion#genai#office
Read Log
Windows2026-05-2813 min

Hijacking Grammarly Desktop: How a Missing DLL Leads to Silent Code Execution

Grammarly Desktop is a widely used writing assistant that runs in the background on Windows, checking grammar and spelling across applications. The application runs as a trusted, signed binary. We found that Grammarly Desktop loads several Windows system libraries from its own local application folder instead of from protected system directories. Because this folder lives inside the user's AppData directory, any code running as that user can place a malicious DLL file there. When Grammarly starts, it loads and executes the attacker's code with the same privileges as the logged-in user. This post explains how the vulnerability works, demonstrates three proof-of-concept attacks, and discusses how to fix the underlying flaw.

#grammarly#dll-hijacking#windows#red-team#penetration-testing#vulnerability
Read Log
Network2026-05-1335 min

Data Exfiltration Guide

A comprehensive red-team reference covering data exfiltration techniques across TCP, SSH, HTTP/HTTPS, ICMP, and DNS — including advanced IP-over-DNS tunneling with Iodine and HTTP tunneling with Neo-reGeorg — with operational security notes and detection guidance for each method.

#data-exfiltration#network#tcp#ssh#http#https#icmp#dns#tunneling#red-team#opsec#penetration-testing
Read Log
Web2023-01-1218 min

CVE-2021-43798 Grafana Directory Traversal Deep Dive

Deep dive into CVE-2021-43798 — unauthenticated directory traversal in Grafana 8.x via /public/plugins/. Covers root cause, manual exploitation, URL normalization pitfalls, high-value loot targets, and automation with GrafTraverse.

#grafana#cve-2021-43798#directory-traversal#lfi#web#red-team#penetration-testing#automation#graftraverse
Read Log

Stay in the loop

Subscribe via RSS to get new posts delivered to your reader. Works with Feedly, Inoreader, Newsblur, and any RSS client.

subscribe via rss