<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>XSS3cut10n3r</title><link>https://xss3cut10n3r.com/</link><description>Recent content on XSS3cut10n3r</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 03 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://xss3cut10n3r.com/index.xml" rel="self" type="application/rss+xml"/><item><title>NSA Codebreaker 2025: My First Full Challenge</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</link><pubDate>Sat, 03 Oct 2026 00:08:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</guid><description>&lt;p&gt;The &lt;strong&gt;2025 NSA Codebreaker Challenge&lt;/strong&gt; was my first Codebreaker, and I completed &lt;strong&gt;all seven tasks&lt;/strong&gt;, becoming one of &lt;strong&gt;82 students to finish the full challenge&lt;/strong&gt;. It was a chance to connect skills that I had often practiced separately: filesystem forensics, packet analysis, memory analysis, reverse engineering, cryptography, and application security.&lt;/p&gt;&#10;&lt;p&gt;The challenge used a fictional investigation into suspicious activity on a military development network. Each task carried the investigation forward, so an answer was more than a flag—it supplied context for the next question.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 7: Finale</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</link><pubDate>Sat, 03 Oct 2026 00:07:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The final task supplied a &lt;strong&gt;custom Android APK&lt;/strong&gt; used to archive chat messages. It brought together application reverse engineering, archive handling, and reasoning about how data moves through a program.&lt;/p&gt;&#10;&lt;h3 id="starting-with-the-application"&gt;Starting with the application&lt;/h3&gt;&#10;&lt;p&gt;I first reviewed the supplied dependency licenses. An old library looked like a promising lead, but my notes make clear that the decisive issue emerged from examining the application&amp;rsquo;s own handling of files.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 6: Crossing the Channel</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</link><pubDate>Sat, 03 Oct 2026 00:06:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;Task 6 shifted the investigation into a &lt;strong&gt;Mattermost environment&lt;/strong&gt;. The challenge supplied persistent application data and an account with access to a limited part of the system. The objective concerned reaching the channel used by the fictional adversary.&lt;/p&gt;&#10;&lt;h3 id="reviewing-the-custom-integration"&gt;Reviewing the custom integration&lt;/h3&gt;&#10;&lt;p&gt;I examined the provided bot plugins and found a flaw in the logic used to manage private negotiation channels. The relevant checks established that users belonged to the &lt;strong&gt;current channel&lt;/strong&gt;, but did not adequately establish their authority to access the &lt;strong&gt;destination channel&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 5: Putting It All Together</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</link><pubDate>Sat, 03 Oct 2026 00:05:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-5---putting-it-all-together---cryptanalysis"&gt;Task 5 - Putting It All Together - (Cryptanalysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;NSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military development network. Unfortunately, we do not yet have enough information to update NSA senior leadership on this threat. We need to move forward with this investigation!&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The team is stumped - they need to identify something about who was controlling this malware. They look to you. &amp;ldquo;Do you have any ideas?&amp;rdquo;&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 4: Unpacking Insight</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</link><pubDate>Sat, 03 Oct 2026 00:04:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-4---unpacking-insight---malware-analysis"&gt;Task 4 - Unpacking Insight - (Malware Analysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Once back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don&amp;rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 3: Digging Deeper</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</link><pubDate>Sat, 03 Oct 2026 00:03:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-3---digging-deeper---reverse-engineering"&gt;Task 3 - Digging Deeper - (Reverse Engineering)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to dive deeper and reverse engineer this device. Fortunately, their team managed to pull a memory dump of the device.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Scour the device&amp;rsquo;s memory dump and identify anomalous or malicious activity to find out what&amp;rsquo;s going on.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Your submission will be a list of IPs and domains, one per line. For example:&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 2: The Hunt Continues</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</link><pubDate>Sat, 03 Oct 2026 00:02:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-2---the-hunt-continues---network-forensics"&gt;Task 2 - The Hunt Continues - (Network Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;With your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;DAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="downloads"&gt;Downloads&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;PCAP to analyze:&lt;/strong&gt; &lt;code&gt;traffic.pcap&lt;/code&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="task"&gt;Task&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Submit all the IP addresses that are assigned to the malicious device, one per line.&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="writeup"&gt;Writeup&lt;/h2&gt;&#10;&lt;p&gt;Upon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 — Task 1: Getting Started</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</link><pubDate>Sat, 03 Oct 2026 00:01:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-1---getting-started-forensics"&gt;Task 1 - Getting Started (Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;You arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous behaviors, such as: tools randomly failing tests and anti-virus flagging on seemingly clean workstations. They have narrowed in on one machine they would like NSA to thoroughly evaluate.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;They have provided a zipped EXT2 image from this development machine. Help DAFIN-SOC perform a forensic analysis on this - looking for any suspicious artifacts.&lt;/p&gt;</description></item><item><title>About Me: Cybersecurity, LRQA &amp; AI</title><link>https://xss3cut10n3r.com/hireme/</link><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/hireme/</guid><description>&lt;div style="display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;"&gt;&#10; &lt;img src="https://xss3cut10n3r.com/images/tomi.jpg" alt="Tomi Bodwell Mamic" style="border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;"&gt;&#10; &lt;h1 style="margin: 0; font-size: 2.5rem; flex: 1 1 250px;"&gt;Hey! I'm Tomi, an Associate Security Consultant at LRQA and an Applied Cybersecurity student.&lt;/h1&gt;&#10;&lt;/div&gt;&#10;&lt;h3 id="what-im-working-on-at-lrqa"&gt;What I&amp;rsquo;m Working On at LRQA&lt;/h3&gt;&#10;&lt;p&gt;I&amp;rsquo;m currently working at &lt;strong&gt;LRQA in Birmingham, UK&lt;/strong&gt;, as an &lt;strong&gt;Associate Security Consultant&lt;/strong&gt;, with a focus on &lt;strong&gt;implementing AI into penetration testing workflows&lt;/strong&gt;. My work includes developing vulnerability knowledge bases (VKBs) for local AI penetration testing tooling to help streamline testing automation.&lt;/p&gt;</description></item><item><title>About Me: Cybersecurity, LRQA &amp; AI</title><link>https://xss3cut10n3r.com/posts/hireme/</link><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/hireme/</guid><description>&lt;div style="display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;"&gt;&#10; &lt;img src="https://xss3cut10n3r.com/images/tomi.jpg" alt="Tomi Bodwell Mamic" style="border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;"&gt;&#10; &lt;h1 style="margin: 0; font-size: 2.5rem; flex: 1 1 250px;"&gt;Hey! I'm Tomi, an Associate Security Consultant at LRQA and an Applied Cybersecurity student.&lt;/h1&gt;&#10;&lt;/div&gt;&#10;&lt;h3 id="what-im-working-on-at-lrqa"&gt;What I&amp;rsquo;m Working On at LRQA&lt;/h3&gt;&#10;&lt;p&gt;I&amp;rsquo;m currently working at &lt;strong&gt;LRQA in Birmingham, UK&lt;/strong&gt;, as an &lt;strong&gt;Associate Security Consultant&lt;/strong&gt;, with a focus on &lt;strong&gt;implementing AI into penetration testing workflows&lt;/strong&gt;. My work includes developing vulnerability knowledge bases (VKBs) for local AI penetration testing tooling to help streamline testing automation.&lt;/p&gt;</description></item><item><title>Crypto Cheatsheet for CTFs</title><link>https://xss3cut10n3r.com/posts/crypto-cheatsheet/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/crypto-cheatsheet/</guid><description>&lt;p&gt;Cryptography challenges are one of the most common categories in Capture the Flag (CTF) competitions. This guide provides a focused overview of essential algorithms, how to recognize them, common weaknesses exploited in CTFs, and practical resources for practice.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="common-ctf-crypto-patterns"&gt;Common CTF Crypto Patterns&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Flags often follow formats like &lt;code&gt;CTF{...}&lt;/code&gt;, which can help in known-plaintext scenarios.&lt;/li&gt;&#10;&lt;li&gt;Key reuse across ciphertexts can allow XOR analysis.&lt;/li&gt;&#10;&lt;li&gt;Small RSA exponents (&lt;code&gt;e = 3&lt;/code&gt;) can lead to direct root extraction if the plaintext is small.&lt;/li&gt;&#10;&lt;li&gt;Small primes allow for easy factorization of RSA moduli.&lt;/li&gt;&#10;&lt;li&gt;Padding issues in AES frequently lead to oracle-style attacks.&lt;/li&gt;&#10;&lt;li&gt;Images encrypted with ECB will show visible repeated patterns.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="tools"&gt;Tools&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://gchq.github.io/CyberChef/"&gt;CyberChef&lt;/a&gt; - versatile tool for conversions, encodings, and ciphers.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://www.cachesleuth.com/multidecoder/"&gt;CacheSleuth MultiDecoder&lt;/a&gt; - automated format and cipher detection. Easily my favorite tool.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://www.dcode.fr/en"&gt;dCode&lt;/a&gt; - classical cipher solvers and crypto utilities.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://github.com/RsaCtfTool/RsaCtfTool"&gt;RsaCtfTool&lt;/a&gt; - specialized RSA attack tool.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="core-algorithms"&gt;Core Algorithms&lt;/h2&gt;&#10;&lt;h3 id="rsa"&gt;RSA&lt;/h3&gt;&#10;&lt;p&gt;RSA is an asymmetric encryption algorithm based on modular arithmetic with large primes.&lt;/p&gt;</description></item><item><title>Gaining Interactive Shells</title><link>https://xss3cut10n3r.com/posts/interactive-shells/</link><pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/interactive-shells/</guid><description>&lt;p&gt;Often when uploading a reverse shell on a webserver we are dealing with non-interactive shell. This means it doesn&amp;rsquo;t prompt us for user input or display output in real-time in a traditional terminal window.&lt;/p&gt;&#10;&lt;p&gt;The biggest problem with a non-interactive shell is that you can&amp;rsquo;t run &lt;code&gt;su&lt;/code&gt; or &lt;code&gt;sudo&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Useful ways to upgrade your shell to an interactive one:&lt;/strong&gt;&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;python &lt;span style="color:#f92672"&gt;-&lt;/span&gt;c &lt;span style="color:#e6db74"&gt;&amp;#39;import pty; pty.spawn(&amp;#34;/bin/sh&amp;#34;)&amp;#39;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;When to use it:&lt;/strong&gt; Almost always the first go-to if Python is available on the target. After spawning, run Ctrl-Z and then stty raw -echo; fg on your local terminal to fully fix arrow keys and job control.&lt;/p&gt;</description></item><item><title>Whoami</title><link>https://xss3cut10n3r.com/posts/my-first-post/</link><pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/my-first-post/</guid><description>&lt;h3 id="中國人"&gt;中國人&lt;/h3&gt;&#10;&lt;p&gt;你好！我是一名对网络安全充满热情的人，尤其对渗透测试和道德黑客很感兴趣。我计划在这里记录自己的学习过程，分享在安全、技术和实践方面的心得与体会。希望这个网站能成为我整理经验、总结知识的地方，同时与大家一起在这个领域不断成长。&lt;/p&gt;&#10;&lt;h3 id="русский"&gt;Русский&lt;/h3&gt;&#10;&lt;p&gt;Привет! Я человек, увлеченный кибербезопасностью, особенно меня интересуют тестирование на проникновение и этичный хакеринг. Я планирую здесь документировать свой процесс обучения и делиться своими знаниями и наблюдениями в области безопасности, технологий и лучших практик. Надеюсь, что этот сайт станет для меня местом, где можно систематизировать опыт, аккумулировать знания и расти в этой области вместе с другими.&lt;/p&gt;&#10;&lt;h3 id="english"&gt;English&lt;/h3&gt;&#10;&lt;p&gt;Hello! I’m an individual with a strong interest in cybersecurity. I’m particularly drawn to penetration testing and ethical hacking, and I plan to document my learning journey here. My goal is to explore and share knowledge about security, techniques, and best practices, all in a safe and responsible manner. This website will serve as a place to catalog insights, experiences, and resources as I continue to grow in this field.&lt;/p&gt;</description></item></channel></rss>