<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Home on @tmajik</title><link>https://randomaccessvemuri.github.io/cybersec-blog/</link><description>Recent content in Home on @tmajik</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://randomaccessvemuri.github.io/cybersec-blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Rust for Malware Development with Fibers</title><link>https://randomaccessvemuri.github.io/cybersec-blog/blog/rust-malware-development-fibers/</link><pubDate>Sun, 09 Aug 2026 17:50:00 +0530</pubDate><guid>https://randomaccessvemuri.github.io/cybersec-blog/blog/rust-malware-development-fibers/</guid><description>&lt;p>A work-in-progress walkthrough of running shellcode in Rust via Windows fibers instead of threads — VirtualAlloc, VirtualProtect, and CreateFiber with a calc.exe payload.&lt;/p></description></item><item><title>HTB: ServMon</title><link>https://randomaccessvemuri.github.io/cybersec-blog/htb/servmon/</link><pubDate>Tue, 08 Jul 2025 12:02:55 +0100</pubDate><guid>https://randomaccessvemuri.github.io/cybersec-blog/htb/servmon/</guid><description>&lt;center>&lt;img src="https://labs.hackthebox.com/storage/avatars/2bc1a8dc04b09b8ac2db694f25ccf051.png" alt="Busqueda" width="100" />&lt;/center>
&lt;p>An easy Windows box with multiple enumeration rabbit holes. Features NVMS-1000, FTP, locked SMB, and NSClient++. Foothold gained through FTP-disclosed credentials and NVMS-1000 LFI vulnerability that reveals password lists. Password spraying identifies valid credentials between two users. Local NSClient++ access with exposed passwords enables privilege escalation to root via reverse shell execution.&lt;/p></description></item><item><title>HTB: Busqueda</title><link>https://randomaccessvemuri.github.io/cybersec-blog/htb/busqueda/</link><pubDate>Mon, 07 Jul 2025 12:02:55 +0100</pubDate><guid>https://randomaccessvemuri.github.io/cybersec-blog/htb/busqueda/</guid><description>&lt;center>&lt;img src="https://labs.hackthebox.com/storage/avatars/a6942ab57b6a79f71240420442027334.png" alt="Busqueda" width="100" />&lt;/center></description></item><item><title>HTB: Networked</title><link>https://randomaccessvemuri.github.io/cybersec-blog/htb/networked/</link><pubDate>Mon, 07 Jul 2025 12:02:55 +0100</pubDate><guid>https://randomaccessvemuri.github.io/cybersec-blog/htb/networked/</guid><description>&lt;center>&lt;img src="https://labs.hackthebox.com/storage/avatars/a6942ab57b6a79f71240420442027334.png" alt="Busqueda" width="100" />&lt;/center>
&lt;p>A marked easy machine that involves exploiting a python eval statement in Searchor 2.4.0 to gain foothold, finding a gitea server and a .git folder; thus finding cleartext credentials, following which you find some administration scripts. Exploiting said administration scripts leads to root.&lt;/p></description></item></channel></rss>