<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on XSS3cut10n3r</title><link>https://xss3cut10n3r.com/posts/</link><description>Recent content in Posts on XSS3cut10n3r</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 03 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://xss3cut10n3r.com/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Off the Clock: Chess</title><link>https://xss3cut10n3r.com/posts/chess/</link><pubDate>Fri, 02 Oct 2026 18:00:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/chess/</guid><description>&lt;p&gt;Most of this site is about cybersecurity. This post is about chess instead, which is where a lot of my spare time goes.&lt;/p&gt;&#10;&lt;h3 id="correspondence-chess"&gt;Correspondence chess&lt;/h3&gt;&#10;&lt;p&gt;I&amp;rsquo;m most invested in correspondence chess: the long-form version where a single game can run for weeks and you&amp;rsquo;re free to analyse a position as deeply as you like. That depth is exactly what I love about it. Instead of guessing under a clock, you can actually get to the bottom of a position.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2026: Another One Bites The Dust</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2026/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2026/</guid><description>&lt;p&gt;The 2026 NSA Codebreaker Challenge was my second Codebreaker, and I completed all eight tasks as the 12th student to finish the full challenge. It gave me another opportunity to work across several areas of cybersecurity while building on what I learned from completing the 2025 challenge.&lt;/p&gt;&#10;&lt;p&gt;This year&amp;rsquo;s challenge is still active, so I am not publishing prompts, artifacts, findings, solutions, commands, screenshots, or writeups. Until the challenge ends and publication is permitted, this page contains only a high-level reflection alongside the official task titles and categories.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025: My First Full Challenge</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</link><pubDate>Wed, 29 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</guid><description>&lt;p&gt;The 2025 NSA Codebreaker Challenge was my first Codebreaker, and I completed all seven tasks, becoming one of 82 students to finish the full challenge. It was a chance to connect skills that I had often practiced separately: filesystem forensics, packet analysis, memory analysis, reverse engineering, cryptography, and application security.&lt;/p&gt;&#10;&lt;p&gt;The challenge used a fictional investigation into suspicious activity on a military development network. Each task carried the investigation forward, so an answer was more than a flag - it supplied context for the next question.&lt;/p&gt;</description></item><item><title>About Me</title><link>https://xss3cut10n3r.com/posts/aboutme/</link><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/aboutme/</guid><description>&lt;div style="display: flex; flex-wrap: wrap; align-items: center; gap: 2rem; margin-bottom: 2rem;"&gt;&#10; &lt;img src="https://xss3cut10n3r.com/images/tomi.jpg" alt="Tomi Bodwell Mamic" style="border-radius: 15px; width: 250px; max-width: 100%; height: 250px; object-fit: cover; flex-shrink: 0;"&gt;&#10; &lt;h1 style="margin: 0; font-size: 2.5rem; flex: 1 1 250px;"&gt;Hi, I'm Tomi, a penetration testing intern at LRQA and an Applied Cybersecurity student.&lt;/h1&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;I work in offensive security, with a particular interest in penetration testing, cryptography, and forensics. This site is where I document projects, challenges, and anything else I find worth writing about.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 7: Finale</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</link><pubDate>Sun, 26 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;!-- Paste your Markdown content below this line. --&gt;&#10;&lt;h1 id="task-7---finale---vulnerability-research-exploitation"&gt;Task 7 - Finale - (Vulnerability Research, Exploitation)&lt;/h1&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Now that we have access to the hidden channel the adversary is using, our military counterparts want to act quickly to destroy the adversary&amp;rsquo;s capacity to continue with their attack against our military networks.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Analysts have been quickly scrutinizing the data from the privileged channel. They conclude that the adversary has downloaded a custom app to archive all messages sent in the channel locally to their phone. They have also surmised the adversary is running a recent version of Android on a Google Pixel phone. This is the opportunity we have been waiting for! If we can devise a way to exploit on to the adversary&amp;rsquo;s device we will have the advantage.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 6: Crossing the Channel</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</link><pubDate>Tue, 21 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;!-- Paste your Markdown content below this line. --&gt;&#10;&lt;h1 id="task-6---crossing-the-channel---vulnerability-research"&gt;Task 6 - Crossing the Channel - (Vulnerability Research)&lt;/h1&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;This high visibility investigation has garnered a lot of agency attention. Due to your success, your team has designated you as the lead for the tasks ahead. Partnering with CNO and CYBERCOM mission elements, you work with operations to collect the persistent data associated with the identified Mattermost instance. Our analysts inform us that it was obtained through a one-time opportunity and we must move quickly as this may hold the key to tracking down our adversary! We have managed to create an account but it only granted us access to one channel. The adversary doesn&amp;rsquo;t appear to be in that channel.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 5: Putting It All Together</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-5---putting-it-all-together---cryptanalysis"&gt;Task 5 - Putting It All Together - (Cryptanalysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;NSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military development network. Unfortunately, we do not yet have enough information to update NSA senior leadership on this threat. We need to move forward with this investigation!&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The team is stumped - they need to identify something about who was controlling this malware. They look to you. &amp;ldquo;Do you have any ideas?&amp;rdquo;&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 4: Unpacking Insight</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</link><pubDate>Mon, 06 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-4---unpacking-insight---malware-analysis"&gt;Task 4 - Unpacking Insight - (Malware Analysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Once back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don&amp;rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 3: Digging Deeper</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</link><pubDate>Sun, 05 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-3---digging-deeper---reverse-engineering"&gt;Task 3 - Digging Deeper - (Reverse Engineering)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to dive deeper and reverse engineer this device. Fortunately, their team managed to pull a memory dump of the device.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Scour the device&amp;rsquo;s memory dump and identify anomalous or malicious activity to find out what&amp;rsquo;s going on.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Your submission will be a list of IPs and domains, one per line. For example:&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 2: The Hunt Continues</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</link><pubDate>Sat, 04 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-2---the-hunt-continues---network-forensics"&gt;Task 2 - The Hunt Continues - (Network Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;With your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;DAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="downloads"&gt;Downloads&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;PCAP to analyze:&lt;/strong&gt; &lt;code&gt;traffic.pcap&lt;/code&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="task"&gt;Task&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Submit all the IP addresses that are assigned to the malicious device, one per line.&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="writeup"&gt;Writeup&lt;/h2&gt;&#10;&lt;p&gt;Upon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 1: Getting Started</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</link><pubDate>Fri, 03 Oct 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-1---getting-started-forensics"&gt;Task 1 - Getting Started (Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;You arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous behaviors, such as: tools randomly failing tests and anti-virus flagging on seemingly clean workstations. They have narrowed in on one machine they would like NSA to thoroughly evaluate.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;They have provided a zipped EXT2 image from this development machine. Help DAFIN-SOC perform a forensic analysis on this - looking for any suspicious artifacts.&lt;/p&gt;</description></item><item><title>Crypto Cheatsheet for CTFs</title><link>https://xss3cut10n3r.com/posts/crypto-cheatsheet/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/crypto-cheatsheet/</guid><description>&lt;p&gt;Cryptography challenges are one of the most common categories in Capture the Flag (CTF) competitions. This guide provides a focused overview of essential algorithms, how to recognize them, common weaknesses exploited in CTFs, and practical resources for practice.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="common-ctf-crypto-patterns"&gt;Common CTF Crypto Patterns&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Flags often follow formats like &lt;code&gt;CTF{...}&lt;/code&gt;, which can help in known-plaintext scenarios.&lt;/li&gt;&#10;&lt;li&gt;Key reuse across ciphertexts can allow XOR analysis.&lt;/li&gt;&#10;&lt;li&gt;Small RSA exponents (&lt;code&gt;e = 3&lt;/code&gt;) can lead to direct root extraction if the plaintext is small.&lt;/li&gt;&#10;&lt;li&gt;Small primes allow for easy factorization of RSA moduli.&lt;/li&gt;&#10;&lt;li&gt;Padding issues in AES frequently lead to oracle-style attacks.&lt;/li&gt;&#10;&lt;li&gt;Images encrypted with ECB will show visible repeated patterns.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="tools"&gt;Tools&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://gchq.github.io/CyberChef/"&gt;CyberChef&lt;/a&gt; - versatile tool for conversions, encodings, and ciphers.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://www.cachesleuth.com/multidecoder/"&gt;CacheSleuth MultiDecoder&lt;/a&gt; - automated format and cipher detection. Easily my favorite tool.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://www.dcode.fr/en"&gt;dCode&lt;/a&gt; - classical cipher solvers and crypto utilities.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://github.com/RsaCtfTool/RsaCtfTool"&gt;RsaCtfTool&lt;/a&gt; - specialized RSA attack tool.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="core-algorithms"&gt;Core Algorithms&lt;/h2&gt;&#10;&lt;h3 id="rsa"&gt;RSA&lt;/h3&gt;&#10;&lt;p&gt;RSA is an asymmetric encryption algorithm based on modular arithmetic with large primes.&lt;/p&gt;</description></item><item><title>Gaining Interactive Shells</title><link>https://xss3cut10n3r.com/posts/interactive-shells/</link><pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/interactive-shells/</guid><description>&lt;p&gt;Often when uploading a reverse shell on a webserver we are dealing with non-interactive shell. This means it doesn&amp;rsquo;t prompt us for user input or display output in real-time in a traditional terminal window.&lt;/p&gt;&#10;&lt;p&gt;The biggest problem with a non-interactive shell is that you can&amp;rsquo;t run &lt;code&gt;su&lt;/code&gt; or &lt;code&gt;sudo&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Useful ways to upgrade your shell to an interactive one:&lt;/strong&gt;&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;python &lt;span style="color:#f92672"&gt;-&lt;/span&gt;c &lt;span style="color:#e6db74"&gt;&amp;#39;import pty; pty.spawn(&amp;#34;/bin/sh&amp;#34;)&amp;#39;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;When to use it:&lt;/strong&gt; Almost always the first go-to if Python is available on the target. After spawning, run Ctrl-Z and then stty raw -echo; fg on your local terminal to fully fix arrow keys and job control.&lt;/p&gt;</description></item><item><title>Whoami</title><link>https://xss3cut10n3r.com/posts/my-first-post/</link><pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate><guid>https://xss3cut10n3r.com/posts/my-first-post/</guid><description>&lt;h3 id="中國人"&gt;中國人&lt;/h3&gt;&#10;&lt;p&gt;你好！我是一名对网络安全充满热情的人，尤其对渗透测试和道德黑客很感兴趣。我计划在这里记录自己的学习过程，分享在安全、技术和实践方面的心得与体会。希望这个网站能成为我整理经验、总结知识的地方，同时与大家一起在这个领域不断成长。&lt;/p&gt;&#10;&lt;h3 id="русский"&gt;Русский&lt;/h3&gt;&#10;&lt;p&gt;Привет! Я человек, увлеченный кибербезопасностью, особенно меня интересуют тестирование на проникновение и этичный хакеринг. Я планирую здесь документировать свой процесс обучения и делиться своими знаниями и наблюдениями в области безопасности, технологий и лучших практик. Надеюсь, что этот сайт станет для меня местом, где можно систематизировать опыт, аккумулировать знания и расти в этой области вместе с другими.&lt;/p&gt;&#10;&lt;h3 id="english"&gt;English&lt;/h3&gt;&#10;&lt;p&gt;Hello! I’m an individual with a strong interest in cybersecurity. I’m particularly drawn to penetration testing and ethical hacking, and I plan to document my learning journey here. My goal is to explore and share knowledge about security, techniques, and best practices, all in a safe and responsible manner. This website will serve as a place to catalog insights, experiences, and resources as I continue to grow in this field.&lt;/p&gt;</description></item></channel></rss>