<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Posts on z-r0crypt</title>
    <link>https://z-r0crypt.github.io/posts/</link>
    <description>Recent content in Posts on z-r0crypt</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 13 Jun 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://z-r0crypt.github.io/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From OSCP to OSEP: Does it Fill the Red Team Gap?</title>
      <link>https://z-r0crypt.github.io/posts/2025-06-13-oscp-to-osep-red-team-gap/</link>
      <pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2025-06-13-oscp-to-osep-red-team-gap/</guid>
      <description>What OSCP doesn&amp;#39;t teach you and why it matters for real enterprise work. A practitioner&amp;#39;s perspective on the gap between entry-level certification and red team readiness, written after passing OSCP in 2017 and OSEP while actively working in red teaming.</description>
    </item>
    <item>
      <title>SSSD-Extract: Dumping AD Hashes and Domain Info from Linux Systems</title>
      <link>https://z-r0crypt.github.io/posts/2023-08-20-sssd-extract-v2/</link>
      <pubDate>Sun, 20 Aug 2023 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2023-08-20-sssd-extract-v2/</guid>
      <description>How to extract cached Active Directory credentials, group memberships, user accounts and machine accounts from SSSD on domain-joined Linux systems. Includes extended fork with domain enumeration added during OSEP preparation.</description>
    </item>
    <item>
      <title>HTB Machines for OSEP/PEN-300 Preparation: Complete Attack Chain Mapping</title>
      <link>https://z-r0crypt.github.io/posts/2023-04-27-htb-osep-machines/</link>
      <pubDate>Thu, 27 Apr 2023 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2023-04-27-htb-osep-machines/</guid>
      <description>Curated list of HTB machines mapped to every PEN-300 syllabus topic: client-side execution, AV evasion, AD exploitation, MSSQL abuse, lateral movement and more. Includes TJNull OSEP-like list.</description>
    </item>
    <item>
      <title>Dangerous PHP Functions: Code Execution and Exploitation Reference</title>
      <link>https://z-r0crypt.github.io/posts/2021-01-25-dangerous-php-functions/</link>
      <pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2021-01-25-dangerous-php-functions/</guid>
      <description>Complete reference of PHP functions exploitable for RCE, LFI, information disclosure and filesystem manipulation. Includes grep and semgrep patterns for source code review, PHP version notes, and exploitation context for OSWE/AWAE.</description>
    </item>
    <item>
      <title>Cryptography I: Advanced Block Cipher Modes and Padding</title>
      <link>https://z-r0crypt.github.io/posts/2020-02-05-crypto-week2-part2/</link>
      <pubDate>Wed, 05 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2020-02-05-crypto-week2-part2/</guid>
      <description>Deep dive into CBC/CTR implementation details, IV/nonce management, padding oracle attacks, and performance comparison of encryption modes.</description>
    </item>
    <item>
      <title>Cryptography I: Block Ciphers and Modes of Operation</title>
      <link>https://z-r0crypt.github.io/posts/2020-02-03-crypto-week2-part1/</link>
      <pubDate>Mon, 03 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2020-02-03-crypto-week2-part1/</guid>
      <description>Block cipher theory, PRP/PRF security, ECB/CBC/CTR modes, IV construction, and semantic security under chosen-plaintext attack (CPA).</description>
    </item>
    <item>
      <title>OSWE/AWAE Preparation: Complete Study Guide</title>
      <link>https://z-r0crypt.github.io/posts/2020-01-22-oswe-awae-prep/</link>
      <pubDate>Wed, 22 Jan 2020 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2020-01-22-oswe-awae-prep/</guid>
      <description>Complete OSWE/AWAE preparation guide from someone who passed in 2020. Curated resources by vulnerability class, exam strategy, and what actually matters for the 48-hour exam.</description>
    </item>
    <item>
      <title>Microcorruption CTF Tutorial: Embedded Security Reverse Engineering</title>
      <link>https://z-r0crypt.github.io/posts/2019-11-25-microcorruption-ctf/</link>
      <pubDate>Mon, 25 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2019-11-25-microcorruption-ctf/</guid>
      <description>Hands-on guide to MSP430 assembly debugging and memory corruption exploitation in Microcorruption CTF challenges.</description>
    </item>
    <item>
      <title>Cryptography I: Stream Ciphers, PRGs, and Semantic Security</title>
      <link>https://z-r0crypt.github.io/posts/2019-11-24-crypto-stanford-week1/</link>
      <pubDate>Sun, 24 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://z-r0crypt.github.io/posts/2019-11-24-crypto-stanford-week1/</guid>
      <description>Stream cipher security, pseudo-random generators, information-theoretic security, and practical attacks on weak PRGs. Stanford Cryptography I Week 1.</description>
    </item>
  </channel>
</rss>
