Blog

Halloween 2025 CTF Announcement 🎃
Capture The Flag

Halloween 2025 CTF Announcement 🎃

infophreak is hosting their 2025 Halloween CTF from October 1st to October 31st. Compete to win prizes and glory!

·Team
Your next cloud with Nextcloud + Backblaze
Cloud

Your next cloud with Nextcloud + Backblaze

In this tutorial, I will be going over how to set up your very own Nextcloud server using Docker Compose on a public cloud provider like DigitalOcean.

·hikiko
TryHackMe Room Writeup: Sakura
Capture The Flag

TryHackMe Room Writeup: Sakura

This writeup covers the TryHackMe "Sakura" room, featuring an OSINT investigation into a fictitious hacker who attacked the OSINT Dojo. This room is designed to test a diverse range of OSINT techniques, including those related to image, social media, and geolocation intelligence.

·SirPicklJohn
OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company
Intelligence

OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company

This article covers a post-incident OSINT investigation that linked a recent business email compromise back to an Australian carpet company, due to a DNS registration mishap by the attacker. Persistence and pivoting are key for investigators!

·SirPicklJohn
What IS the Dark Web Anyway?
Operations Security

What IS the Dark Web Anyway?

A bird's eye view of the Dark Web focused on the essentials. If the inner workings of the Dark Web remain a mystery to you, this post was made to change that.

·r3g1s
OverTheWire Bandit Level 0-5 Walkthrough
Capture The Flag

OverTheWire Bandit Level 0-5 Walkthrough

This is the first in a series of walkthroughs for the OverTheWire Bandit wargame, a beginner-friendly cybersecurity challenge designed to help build proficiency in Linux and foundational security skills.

·En1gma
HackTheBox - Manager (Mobile) Walkthrough
Capture The Flag

HackTheBox - Manager (Mobile) Walkthrough

A client asked me to perform security assessment on this password management application. Can you help me?

·L0WK3Y
TryHackMe - Basic Pentesting Writeup
Capture The Flag

TryHackMe - Basic Pentesting Writeup

This is a write-up of my approach to the Basic Pentesting room on TryHackMe. The room is fairly simple and focuses on testing some fundamental pentesting skills.

·En1gma
Introduction to Physical Security
Physical Security

Introduction to Physical Security

Physical security is essential to any cybersecurity strategy. Without it, attackers can bypass digital defenses. This post explores how physical access controls, surveillance, and safeguards protect systems from real-world threats.

·NickFDI
Simple Way to Lockdown Your Website with Cloudflare Access
Infrastructure

Simple Way to Lockdown Your Website with Cloudflare Access

Do you have a web application running on Docker? Maybe you found an open-source app on GitHub but aren’t quite sure how secure the application is or if it’ll even stay that way in the future. Maybe your app doesn't have features like MFA, and you don’t want to make any changes to the code...

·hikiko
Using Azure Virtual Machines as a Netcat Reverse Shell
Offensive Security

Using Azure Virtual Machines as a Netcat Reverse Shell

This article demonstrates how an Azure VM can be configured as a Netcat reverse shell listener, detailing setup steps (opening ports, running nc), potential security risks, and mitigation strategies. It highlights detection methods via Azure logging and best practices to prevent misuse.

·Javier Guerra
PortSwigger Academy - User Role Controlled by Request Parameter
Web Security

PortSwigger Academy - User Role Controlled by Request Parameter

This lab has an admin panel at /admin, which identifies administrators using a forgeable cookie. Solve the lab by accessing the admin panel and using it to delete the user carlos. You can log in to your own account using the following credentials: wiener:peter

·L0WK3Y
PortSwigger Academy - Unprotected Admin Functionality
Web Security

PortSwigger Academy - Unprotected Admin Functionality

This lab has an unprotected admin panel. Solve the lab by deleting the user carlos.

·L0WK3Y
How to Set Up SonarQube and PostgreSQL Using Docker
Guides

How to Set Up SonarQube and PostgreSQL Using Docker

SonarQube is an open-source SAST platform for continuous inspection of code quality, ensuring clean, maintainable, and reliable code. By integrating it with Docker, you can effortlessly manage its deployment, making it portable and easily scalable...

·L0WK3Y
A DIGITAL EYE - Part 3 WEB OF DIGITAL EYES
Defensive Security

A DIGITAL EYE - Part 3 WEB OF DIGITAL EYES

In the final part of our series, we explore how public street cameras contribute to OSINT and the criminal justice system — serving as silent witnesses that offer valuable intelligence, while also raising important ethical questions about surveillance and privacy.

·bytebasherr
PortSwigger Academy - Authentication Bypass via Information Disclosure
Web Security

PortSwigger Academy - Authentication Bypass via Information Disclosure

This lab's administration interface has an authentication bypass vulnerability, but it is impractical to exploit without knowledge of a custom HTTP header used by the front-end.

·L0WK3Y
PortSwigger Academy - Source Code Disclosure via Backup Files
Web Security

PortSwigger Academy - Source Code Disclosure via Backup Files

This lab leaks its source code via backup files in a hidden directory. To solve the lab, identify and submit the database password, which is hard-coded in the leaked source code.

·L0WK3Y
PortSwigger Academy - Information Disclosure on Debug Page
Web Security

PortSwigger Academy - Information Disclosure on Debug Page

This lab contains a debug page that discloses sensitive information about the application. To solve the lab, obtain and submit the SECRET_KEY environment variable.

·L0WK3Y
Setting up Outline with Docker, Digital Ocean, and Cloudflare
Guides

Setting up Outline with Docker, Digital Ocean, and Cloudflare

A full guide on selfhosting Outline with Docker, Digital Ocean, Cloudflare, and Discord OAuth - Blog by SH3LL

·SH3LL
How To Install ADB Bootloader/Fastboot Drivers on Windows in 2025!
Guides

How To Install ADB Bootloader/Fastboot Drivers on Windows in 2025!

This blog serves to be an updated guide on how to install Bootloader/Fastboot drivers for your Android device. I will be using the Google drivers in this tutorial, so no suspicious downloads will be used at all in this blog!

·L0WK3Y
Intelphreak - February 28, 2025
Intelligence

Intelphreak - February 28, 2025

The Ghost/Cring Ransomware Gang's Unique Success; DMARC Required Under PCI DSS On March 31st of 2025; Apple Removes iCloud Encryption for UK; Recent High Efficacy Social Engineering Tactics; North Korean-Linked Attackers Stole $1.46 Billion in Crypto From Bybit Exchange

·ResidentGood
PortSwigger Academy - Information Disclosure in Version Control History
Web Security

PortSwigger Academy - Information Disclosure in Version Control History

This lab discloses sensitive information via its version control history. To solve the lab, obtain the password for the administrator user then log in and delete the user carlos.

·L0WK3Y
A DIGITAL EYE - Part 2 The Dark Side of Webcam Surveillance
Defensive Security

A DIGITAL EYE - Part 2 The Dark Side of Webcam Surveillance

In this blog post, we are discussing the negatives of webcam surveillance

·bytebasherr
New Insights on the Ghost Ransomware Gang and their Peculiar Success
Research

New Insights on the Ghost Ransomware Gang and their Peculiar Success

This cyber threat intelligence investigation hunts ghosts - seeking to answer why the Ghost/Cring ransomware gang is so successful at eluding security researchers and being profitable, especially when they avoid phishing in favor of targeting known-vulnerabilities in internet-facing systems.

·SirPicklJohn
HackTheBox - APKey Walkthrough
Capture The Flag

HackTheBox - APKey Walkthrough

This app contains some unique keys. Can you get one?

·L0WK3Y
A Demonstration of the Potential for Modern LLM Abuse by Threat Actors
Research

A Demonstration of the Potential for Modern LLM Abuse by Threat Actors

This article details the findings of two studies that highlight how security vulnerabilities in publicly-accessible LLMs can present a threat to public security through the proliferation of malicious knowledge, guidance in committing illegal activities, and generation of malicious content.

·SirPicklJohn
Intelphreak - February 11, 2025
Intelligence

Intelphreak - February 11, 2025

Trump Disbands DHS Advisory Boards, LLM Jailbreaks Are Fueling Threats, DeepSeek Has Global Impact, Vulnerabilities in Contec Patient Monitors Allow PII Leakage & RCE, Subaru STARLINK Vulnerability Allowed Unauthorized Remote Control of Vehicles, 2 Vulnerabilities in Apple Hardware

·ResidentGood
PortSwigger Academy - Information Disclosure in Error Messages
Web Security

PortSwigger Academy - Information Disclosure in Error Messages

This lab's verbose error messages reveal that it is using a vulnerable version of a third-party framework. To solve the lab, obtain and submit the version number of this framework.

·L0WK3Y
A DIGITAL EYE - Part 1 Introduction to Webcam Surveillance
Defensive Security

A DIGITAL EYE - Part 1 Introduction to Webcam Surveillance

In this blog post, we are discussing the importance of webcams from a personal security standpoint

·bytebasherr
Intelphreak - January 22, 2025
Intelligence

Intelphreak - January 22, 2025

Phishing Campaigns Target California Fires, TikTok Ban Delayed, UK Considers New Ransomware Laws, Critical MacOS Attacks & Security Bypasses, Treasury Attack Attributed to Silk Typhoon, Critical Aviatrix Exploit, Expired Domains Present New Security Threats, Patch Tuesday Fixes Major Security Issues

·ResidentGood
Intelphreak - January 8, 2025
Intelligence

Intelphreak - January 8, 2025

2024 Cybersecurity Recap, New Non-Social Engineering TTPs, Major Browser Extension Supply Chain Attack, Japan Airlines DDoS Attack, OpenAI Fined €15 Million, HHS Proposes Changes to HIPAA, Researchers Discover New Lazarus Group Malware Campaign, Chinese Nation-State Actors Breach US Treasury Data

·ResidentGood
2024 Recap of Cybersecurity, with Insights for the Future
Research

2024 Recap of Cybersecurity, with Insights for the Future

2024 saw record-breaking breaches, an incredible AI boom, novel techniques and attack chains, and highly sophisticated cybercrime & cyberwarfare operations. Cybersecurity came into the public purview due to the cascading effects of cyber incidents that affected millions of people worldwide.

·SirPicklJohn
Intelphreak - December 23, 2024
Intelligence

Intelphreak - December 23, 2024

Chinese APTs Target U.S. Infrastructure; IOCONTROL Malware Hits OT, IoT, SCADA Devices; Widespread WordPress Exploitation; Prometheus Toolkit Vulnerabilities; Latest On Social Engineering; PUMAKIT Malware Targets Linux Kernels; FTC Warning On Scam Task Jobs

·ResidentGood
Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity
Research

Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity

This cyber threat intelligence investigation covers the who, what, why, when, and how of the recent state-sponsored Chinese cyberattacks on U.S. telecommunications providers, as well as how they fit into a broader picture of cyber-espionage that displays years of rising geopolitical tensions.

·SirPicklJohn
DOCKER GHOST CMS MARIADB 11 to MYSQL 8 MIGRATION GUIDE
Administration

DOCKER GHOST CMS MARIADB 11 to MYSQL 8 MIGRATION GUIDE

Step by step guide for migrating from Mariadb 11 to MySQL8 for self-hosted Ghost CMS using docker. - Blog by SH3LL

·SH3LL
Infophreak 2024 Christmas Giveaway!

Infophreak 2024 Christmas Giveaway!

We are allowing 4 lucky prize winners to choose between 1 month of Hack The Box or 1 month of TryHackMe! Entry is free and requires being a member of our Discord!

·Team
Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities
Research

Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities

Cosmo Whales is an infostealer campaign masquerading as a Web3 videogame. Threat actors have been observed in the wild distributing malware via job advertisements for a Web3 game called Cosmo Whales.

·L0WK3Y
HackTheBoo 2024 Write-Up
Capture The Flag

HackTheBoo 2024 Write-Up

This is a write-up for HackTheBoo 2024 that completed on October 26, 2024. The CTF event included spooky-themed Forensics, Web, Cryptography, Reverse Engineering, Pwn, and Coding challenges.

·hikiko
TryHackMe - Benign Walkthrough
Capture The Flag

TryHackMe - Benign Walkthrough

We will investigate host-centric logs in this challenge room to find suspicious process execution. To learn more about Splunk and how to investigate the logs, look at the rooms splunk101 and splunk201.

·L0WK3Y
Intelphreak - 11:30Z September 18th, 2024
Intelligence

Intelphreak - 11:30Z September 18th, 2024

TfL Cyberattack Updates, Cloudflare Outage Leaves Some Websites Inaccessible, Chinese Aerospace Firm Employee Charged for Phishing Aerospace/Military Entities, TDSSKiller Used to Disable EDRs & Kawasaki Motors Europe Leak, Iran Tries to Hack Iraq, Port of Seattle Attack, New Oracle WebLogic Malware

·ResidentGood
Hosting SilverBullet.md read-only & admin with Docker, DigitalOcean, Cloudflare, and NGINX
Administration

Hosting SilverBullet.md read-only & admin with Docker, DigitalOcean, Cloudflare, and NGINX

Admin and read-only SilverBullet.md setup using Docker, Cloudflare reverse proxy, a DigitalOcean droplet, and NGINX while sharing the same data source. - Blog by SH3LL

·SH3LL
Setting up Ghost CMS with Docker, Digital Ocean, and Cloudflare
Guides

Setting up Ghost CMS with Docker, Digital Ocean, and Cloudflare

A full guide on infophreak's Ghost CMS infrastructure. - Blog by SH3LL

·SH3LL
247CTF - The Encrypted Password Walkthrough
Capture The Flag

247CTF - The Encrypted Password Walkthrough

You won't find the admin's secret password in this binary. We even encrypted it with a secure one-time-pad. Can you still recover the password?

·L0WK3Y
Basic Hardening of a Ubuntu DigitalOcean Droplet
Administration

Basic Hardening of a Ubuntu DigitalOcean Droplet

Just the basics of hardening after deploying a Ubuntu droplet via DigitalOcean - Blog by SH3LL

·SH3LL
How to create a new sudo user
Administration

How to create a new sudo user

Quick reference guide on creating a new sudo user - Blog by SH3LL

·SH3LL
SSH user directory setup on Linux
Administration

SSH user directory setup on Linux

Recommended directories, files, and permissions for each user's SSH config - Blog by SH3LL

·SH3LL
Generating a modern, secure, and widely supported public/private key pair with ECDSA
Administration

Generating a modern, secure, and widely supported public/private key pair with ECDSA

Recommended steps for generating a modern, secure, and widely supported public/private key pair using ECDSA

·SH3LL

Test post

·Cristian Luna
Setting Up Multiple CTFd Instances with Docker, Digital Ocean, and Cloudflare
Guides

Setting Up Multiple CTFd Instances with Docker, Digital Ocean, and Cloudflare

Our first dive into docker, challenges and lessons learned, a full guide on infophreak's CTFd infrastructure. - Blog by SH3LL

·SH3LL
Intelphreak - 10:00Z September 4th, 2024
Intelligence

Intelphreak - 10:00Z September 4th, 2024

IT Outages in Netherlands, PoorTry Windows Driver Evolves, Iran-Sponsored Threat Actor Engages in Intelligence Operations on US & UAE targets, FlyCASS Vulnerability Risks Security Bypass, NK Threat Actors Exploit Chrome Zero-Day, GitHub Comments Distributing Malware, Cicada3301 Targets ESXi Systems

·ResidentGood
Threat Intelligence vs. Threat Hunting: Distinct Roles, Unified Defense
Defensive Security

Threat Intelligence vs. Threat Hunting: Distinct Roles, Unified Defense

This blog aims to provide a clear and comprehensive understanding of threat intelligence and threat hunting, their differences and how they work together.

·L0WK3Y
Intelphreak - 4:00Z August 29th, 2024
Intelligence

Intelphreak - 4:00Z August 29th, 2024

The US Department of State & US Secret Service Have Issued a Reward of Up to $2.5 Million for Information Leading to the Arrest of Volodymyr Kadariya in Any Country

·ResidentGood
TIS-100 | Self-Test Diagnostic
Guides

TIS-100 | Self-Test Diagnostic

TIS-100 is an open-ended programming game by Zachtronics, the creators of SpaceChem and Infinifactory, in which you rewrite corrupted code segments to repair the TIS-100 and unlock its secrets. It’s the assembly language programming game you never asked for!

·L0WK3Y
TryHackMe: ConvertMyVideo
Capture The Flag

TryHackMe: ConvertMyVideo

A thorough walkthrough/writeup of ConvertMyVideo on TryHackMe.

·SH3LL
Malware Report: CrowdStrike's BSOD Bug and the Rise of Fake Support Scams
Research

Malware Report: CrowdStrike's BSOD Bug and the Rise of Fake Support Scams

In a dramatic turn of events, CrowdStrike's latest update inadvertently triggered the dreaded Blue Screen of Death (BSOD) for numerous users. As if the chaos wasn't enough, opportunistic threat actors seized the moment, posing as CrowdStrike support to distribute malware...

·L0WK3Y
PicoCTF - Speeds and Feeds Walkthrough
Capture The Flag

PicoCTF - Speeds and Feeds Walkthrough

There is something on my shop network running at `nc mercury.picoctf.net 16524`, but I can't tell what it is. Can you?

·L0WK3Y
What Is: The EICAR Test File?
Defensive Security

What Is: The EICAR Test File?

Testing and validation form a part of the life cycle of every security system in the cybersecurity world. In the ever-increasing pantheon of tools at the disposal of security researchers stands one that has grown to become a de facto standard for testing...

·L0WK3Y
TryHackMe - Friday Overtime Walkthrough
Capture The Flag

TryHackMe - Friday Overtime Walkthrough

It's a Friday evening at PandaProbe Intelligence when a notification appears on your CTI platform. While most are already looking forward to the weekend, you realize you must pull overtime because SwiftSpend Finance has opened a new ticket, raising concerns about potential malware threats.

·L0WK3Y
Tryhackme - Searchlight IMINT Walkthrough
Capture The Flag

Tryhackme - Searchlight IMINT Walkthrough

·L0WK3Y
Malware Report: Wannacry Ransomware
Malware Analysis/RE

Malware Report: Wannacry Ransomware

Wannacry is a ransomware that utilized the EternalBlue exploit to propagate through the targets network and attacked outdated Windows computers globally in May of 2017.

·L0WK3Y
What Is Malware Analysis?
Defensive Security

What Is Malware Analysis?

Malware analysis is a crucial discipline within the field of cybersecurity that involves the in-depth examination of malicious software, often referred to as "malware."

·L0WK3Y
Tryhackme - REloaded Walkthrough
Capture The Flag

Tryhackme - REloaded Walkthrough

This room is dedicated for the RE challenges, each challenge has unique concepts divided in each binaries. As if now only phase 1 is added will decide about phase 2 on response. Developed by WhiteHeart and tested by IslaMukheef

·L0WK3Y
Hackthebox - Subatomic Walkthrough
Capture The Flag

Hackthebox - Subatomic Walkthrough

Forela is in need of your assistance. They were informed by an employee that their Discord account had been used to send a message with a link to a file they suspect is malware...

·L0WK3Y
Intelphreak - 10:30Z July 29th, 2024
Intelligence

Intelphreak - 10:30Z July 29th, 2024

Threat Actors Use Cloud to Host Campaigns, LASC Network Compromise, E-Commerce Credit Card Skimmers, Evasive Panda Upgrades, “USDoD” CrowdStrike Breach, Videogame Used to Exfiltrate Data, Telegram Zero-Day, Selenium Grid Crypto Mining, Leidos Leak, New Report on North Korean Cyber Campaigns

·ResidentGood
Intelphreak - 10:30Z July 22nd, 2024
Intelligence

Intelphreak - 10:30Z July 22nd, 2024

CrowdStrike Outage, Delinea Fixes Privilege Vulnerability, Malicious NPM Packages Discovered, Cisco Patches Secure Email Gateway, Rite Aid Data Breach, Ransomware Group Continues ESXi Exploitation, FIN7 Rebrands to Sell Malicious Tools, New Research on APT41, Treasury Sanctions Russian Hacktivists

·ResidentGood
Intelphreak - 4:00Z July 15th, 2024
Intelligence

Intelphreak - 4:00Z July 15th, 2024

Increased Hacktivisim Until 2025, NSA Release on PRC APT, AllHere Faces Financial & Privacy Trouble, Shopify Data Breach Origin, Ticketmaster Leaks, RADIUS Vulnerability, Espionage Groups Using ORB Networks, OpenSSH Vulnerability Allows RCE, Research Says Attackers Exploited a Windows Zero-Day

·ResidentGood
Intelphreak - 12:30Z June 25th, 2024
Intelligence

Intelphreak - 12:30Z June 25th, 2024

EU Delays Vote on Surveillance Legislation, CDK Global Cyber Attacks, Espionage Actor Persists via Fortinet/Ivanti/VMWare CVEs, AI & Hydrogen Firms Partner with Nuclear Energy Companies, Army Debuts New AI Program, SneakyChef Deploys SugarGh0st Malware, US Government Clamps Down on Kaspersky

·ResidentGood
Intelphreak - 21:00Z June 18th, 2024
Intelligence

Intelphreak - 21:00Z June 18th, 2024

Microsoft Whistleblower, Sygnia Uncovers China-Linked Threat Actor, UK Hospitals Need Trainees’ Help After Cyber Attack, Talos Intelligence Has Identified a Pakistani APT Targeting Indian Entities, VulnCheck Report Shows 90% Increase in Disclosed Exploited Vulnerabilities Since April

·ResidentGood
Intelphreak - 20:00Z June 10th, 2024
Intelligence

Intelphreak - 20:00Z June 10th, 2024

Microsoft Recall Will Be Opt-In, Study Shows LLMS Can Exploit “Zero-Day” Vulnerabilities, CJEU Rules Copyright Over IP Privacy, Threat Actors Potentially Compromise Snowflake, Cyber Attacks on Russia & Belarus Companies, Global Operation “Endgame” Disrupts Over 100 Malicious Servers

·ResidentGood