Search titles only
By:
Home
Members
Moderators
Current visitors
Escrow
Deposit
Account Upgrades
ADS
Help
WMIX.TO
Komplexes Bot
Log in
Register
What's new
Search
Search titles only
By:
Menu
Log in
Register
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Depov's latest activity
Depov
posted the thread
Ivanti Endpoint Manager: EPMM operating chain from auth bypass to pre-auth RCE
in
Programming
.
Five entries in the CISA KEV catalog in three years - so many times Ivanti EPMM demanded emergency patching as an actively used product...
Jun 21, 2026
Depov
posted the thread
Pentest Password Manager: Attacks and Hardening 1Password, Bitwarden and CyberArk
in
Web
.
Wednesday, 14:20, the third day of the internal pentest in the fintech company. Through Responder and NTM relay, I get foothold at the...
Jun 21, 2026
Depov
posted the thread
Anti-fraud analytics of transactions: free-patterns and scoring rules in practice
in
Web
.
Business logic of the Ford: what is behind the anomalous transaction The scale is specific. According to AFP Payments Fraud and Control...
Jun 21, 2026
Depov
posted the thread
hift-left in practice: the implementation of SAST and DAST in CI/CD without disruption of releases
in
Web
.
CI/CD-pipeline as the surface of the attack: why does it be known to the pentester Before you build scanners, it is worth looking at the...
Jun 21, 2026
Depov
posted the thread
Web | Gallery
in
Web
.
Entry In general, I do not make WriteWP's on the tasks that already have it on the platform. However, after my decision, I decided to...
Jun 18, 2026
Depov
posted the thread
Post-Vante cryptography in the pentest: audit tools and a checklist for searching for weak algorithms
in
Programming
.
At the cryptocurrencies API fintech service, I found TLS 1.0 with RC4 on three internal endpoints - interservice interaction, not...
Jun 18, 2026
Depov
posted the thread
Pentest macOS in 2026: kill chain from fingerprinting to persistence on Apple Silico
in
Programming
.
At the last internal pentest, fintech companies 14 of the 18 workstations were on macOS Sequoia with M3 chips. Cobalt Strike beacon...
Jun 17, 2026
Depov
posted the thread
Stolen Accounting as a Login Point: From Infosilers to National-state Level Attacks
in
Web
.
Over the past two years, I have dealt with more than fifty incidents, where the initial access began with one pair of login/steel logg...
Jun 17, 2026
Depov
posted the thread
ITSM Systems Vulnerabilities: SSRF, STI and Attacks through the integration of Jira, ServiceNow and Freshservice
in
Programming
.
On the telecom operator pentest last year, I killed two days perimeter - WAF, minimum surface, standard story. The entry point was found...
Jun 16, 2026
Depov
posted the thread
API protection from BOLA and IDOR: authorization patterns, policy-as-code and developer checklist
in
Web
.
The attacker substituted someone else's identifier in the request, the server returned the data. No exploit, without bypassing the WAF -...
Jun 16, 2026
Depov
posted the thread
MSP Supply Chain Attack: Kaseyya VSA Demand and RMM Infrastructure Protection
in
Programming
.
The business logic of the attack: why RMM is the perfect engine of scale The MSP provider by definition has privileged access to the...
Jun 16, 2026
Depov
posted the thread
CTF infrastructure deployment: CTFd, kTF and Docker insulation from 50 to 2000 participants
in
Web
.
DownUnderCTF 2023 served more than 2000 teams on 68 assignments, withstood a peak of 32 100 requests per second and cost $ 876 AUD in...
Jun 16, 2026
Depov
posted the thread
Protection against DDoS attacks 2026: a comparison of strategies, detection and checklist for SOC
in
Web
.
Morning. Grafana shows 340 Gbps inbound UDP traffic on the border routers of the fintech company, where six months ago adjusted...
Jun 15, 2026
Depov
posted the thread
Extraction of passwords from memory: how master keys of password managers settle in the RAM-dump
in
Programming
.
On one IR case in a fintech company, we shot the RAM dump via WinPmem - RAT at the developer's workstation found on Thursday morning...
Jun 15, 2026
Depov
posted the thread
Lateral Movement from IT to OT: Industrial Network Pentest Techniques
in
Web
.
At the audit of the energy enterprise, we received domain admin in four hours - Kerberoasting plus a weak password for service earnings...
Jun 12, 2026
Top
Bottom