<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://xphantom.nl/</id><title>Ahmed Sherif</title><subtitle>this blog is dedicated to the exciting world of red teaming, offensive security, security research, and security code review. I like to share my insights and experiences on the latest tools, techniques, and trends in cybersecurity. Stay informed and stay ahead of the game with our regular updates and insights.</subtitle> <updated>2025-02-10T11:54:10+01:00</updated> <author> <name>Ahmed Sherif</name> <uri>https://xphantom.nl/</uri> </author><link rel="self" type="application/atom+xml" href="https://xphantom.nl/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://xphantom.nl/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2025 Ahmed Sherif </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Build Your Own Offensive Security Lab A Step-by-Step Guide with Ludus</title><link href="https://xphantom.nl/posts/Offensive-Security-Lab/" rel="alternate" type="text/html" title="Build Your Own Offensive Security Lab A Step-by-Step Guide with Ludus" /><published>2025-02-09T13:33:37+01:00</published> <updated>2025-02-10T11:05:42+01:00</updated> <id>https://xphantom.nl/posts/Offensive-Security-Lab/</id> <content src="https://xphantom.nl/posts/Offensive-Security-Lab/" /> <author> <name>Ahmed Sherif</name> </author> <category term="redteam" /> <summary> TL;DR: If you’re looking to set up your own lab for practicing offensive and defensive security techniques, this post is for you. In this guide, I’ll walk you through my experience with Ludus and demonstrate how to build a red team lab using this tool—the simplest and most efficient method I’ve discovered so far. The lab will feature an Active Directory environment (using GOAD) integrated with... </summary> </entry> <entry><title>From Limited file read to full access on Jenkins (CVE-2024-23897)</title><link href="https://xphantom.nl/posts/crypto-attack-jenkins/" rel="alternate" type="text/html" title="From Limited file read to full access on Jenkins (CVE-2024-23897)" /><published>2024-07-02T13:33:37+02:00</published> <updated>2025-02-10T11:53:47+01:00</updated> <id>https://xphantom.nl/posts/crypto-attack-jenkins/</id> <content src="https://xphantom.nl/posts/crypto-attack-jenkins/" /> <author> <name>Ahmed Sherif</name> </author> <category term="crypto" /> <summary> TL;DR: As a red teamer, you encountered a Jenkins instance that is vulnerable to CVE-2024-23897, which allowed for limited arbitrary file read. Without credentials and with the /script endpoint inaccessible, you sought to leverage this vulnerability by revealing Hudson to decypt the credentials. What is CVE-2024-23897? CVE-2024-23897 is a critical vulnerability in Jenkins that enables att... </summary> </entry> <entry><title>From Code Analysis to RCE (CVE-2023-22953)</title><link href="https://xphantom.nl/posts/code-review-to-RCE/" rel="alternate" type="text/html" title="From Code Analysis to RCE (CVE-2023-22953)" /><published>2024-03-20T13:33:37+01:00</published> <updated>2024-07-25T22:59:08+02:00</updated> <id>https://xphantom.nl/posts/code-review-to-RCE/</id> <content src="https://xphantom.nl/posts/code-review-to-RCE/" /> <author> <name>Ahmed Sherif</name> </author> <category term="codereview" /> <summary> TL;DR: In this article, I detail my journey of discovering CVE-2023-22953 through a source code review process. I explain the steps involved, including taint analysis, manual code review, runtime debugging, and flow analysis. By following these methods, readers can gain insights into identifying and addressing vulnerabilities within their own codebase effectively. Index Introduction Dat... </summary> </entry> <entry><title>SysAid On-Premise 20.1.11 - Unauthenticated RCE</title><link href="https://xphantom.nl/posts/Sysaid-RCE/" rel="alternate" type="text/html" title="SysAid On-Premise 20.1.11 - Unauthenticated RCE" /><published>2020-05-22T13:33:37+02:00</published> <updated>2025-02-09T21:37:36+01:00</updated> <id>https://xphantom.nl/posts/Sysaid-RCE/</id> <content src="https://xphantom.nl/posts/Sysaid-RCE/" /> <author> <name>Ahmed Sherif</name> </author> <category term="cve-2020-10569" /> <summary> Introduction In 2020, I identified a vulnerability in the “SysAid Help Desk Software”. This security flaw was significant enough to be assigned the reference CVE-2020-10569. In this article, I’ll detail my discovery process, explain the nature of the vulnerability, and discuss its implications for users of the software. Sys-Aid Help Desk software Sys-aid help desk is a software to help corpo... </summary> </entry> <entry><title>Building-up and organizing CTF events — Nginx &amp; Docker</title><link href="https://xphantom.nl/posts/ABNAMRO-CTF/" rel="alternate" type="text/html" title="Building-up and organizing CTF events — Nginx &amp;amp; Docker" /><published>2020-02-25T13:33:37+01:00</published> <updated>2024-07-25T22:59:08+02:00</updated> <id>https://xphantom.nl/posts/ABNAMRO-CTF/</id> <content src="https://xphantom.nl/posts/ABNAMRO-CTF/" /> <author> <name>Ahmed Sherif</name> </author> <category term="ctf" /> <category term="ctf-deployment" /> <summary> Medium post </summary> </entry> </feed>
