Detection ideas, exploit walkthroughs, hardware research. Written for the next person who has to read them.
A SYN flood weaponises the half-open connection: send the first packet of the handshake, never the third, and let the target's backlog fill with connections that never complete. A lab walkthrough with Metasploit and hping3.
A Meterpreter foothold as a standard user is only the start. Walking a low-priv shell up to NT AUTHORITY\SYSTEM by bypassing UAC — and why the SAM stays locked until you do.
Two legacy name-resolution fallbacks, enabled by default in Windows, will broadcast a credential-bearing authentication to whoever answers first. A step-by-step lab walkthrough — and how to switch it off.
Modern Wi-Fi hands attackers a high-resolution view of the channel for free. A look at what compressed beamforming feedback actually exposes — and where the real risk sits versus the hype.
A forgotten CNAME pointing at a deprovisioned service is a trusted subdomain waiting to be claimed by someone else. How to find them, why they hurt, and how to shut them down.