Security Exploits & Vulnerabilities

Recent successful exploitation of critical vulnerabilities across various platforms, demonstrating practical penetration testing skills and vulnerability research capabilities.

CVE-2025-24071

ZIP Exploitation

NTLM hash leak via malicious ZIP file exploitation. Successfully captured and cracked NTLMv2 hashes using Responder and John the Ripper.

ZIP NTLM Responder

CVE-2025-49113

RoundCube RCE

Remote Code Execution in RoundCube webmail. Gained initial access and extracted encrypted MySQL sessions with 3DES decryption.

RCE 3DES MySQL

CVE-2025-27591

Privilege Escalation

Below utility privilege escalation via symbolic link attack on log files. Achieved root access through /etc/passwd manipulation.

PrivEsc Symlink Root

Shadow Credentials

AD Attack

Advanced Active Directory attack technique using certificate-based authentication to compromise service accounts and escalate privileges.

AD Certificates ESC16

Fork Bomb

DoS Attack

Developed fork bomb implementations in both Bash and C language for system resource exhaustion and denial of service testing.

Bash C DoS

OS Hardening

Defense

Windows and Linux system hardening based on CIS benchmarks and ANSSI GNU/Linux security recommendations. NGINX/Apache2 server security configuration.

CIS ANSSI NGINX

Infrastructure Deployment

Experience in deploying and securing various infrastructure components:

Network Security

  • pfSense Firewall Configuration
  • AdGuard Home DNS Filtering
  • Suricata IDS/IPS Deployment
  • Wazuh SIEM Integration

Application Security

  • Passbolt Password Manager
  • FireflyIII Financial Platform
  • PKI Certificate Authority
  • GLPI Asset Management