MouseJacking (With Flipper Zero): Tales from Pen Testing Trenches
We compromised a network through a wireless mouse dongle using a Flipper Zero. An old attack vector, still unpatched, still sitting on plenty of desks.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
113 posts
We compromised a network through a wireless mouse dongle using a Flipper Zero. An old attack vector, still unpatched, still sitting on plenty of desks.
Read the post →Phishing works on people, not systems, which is why filters alone never finish the job. Training, technical controls, and testing that reflects real attacks.
Read the post →MAC address whitelisting is treated as a control. On a recent wireless engagement we were past it in minutes, and here is exactly how that went.
Read the post →Network, web, mobile, API, IoT, wireless, physical, and social engineering. What each type of penetration testing covers, and when you need which one.
Read the post →A plain-language introduction for business owners: what a penetration test is, how it is run, and what you should expect to receive when it is finished.
Read the post →Secrets committed to Bitbucket stay in the history long after the file is deleted. Why repositories leak credentials, and how to scan for them properly.
Read the post →SharePoint is a credential goldmine on internal engagements, because somebody always uploaded the spreadsheet. How we find them, and how to clear them out.
Read the post →Blind cross-site scripting fires somewhere you cannot see, often in an admin panel hours later. How to test for it when there is no visible response.
Read the post →Part five of the mobile series sets up Android Studio and an emulator for testing, including the device configuration that makes traffic interception work.
Read the post →One more account of taking the OSCP, written for anyone weighing it up: what the preparation actually demanded, and what the exam does and does not measure.
Read the post →