Blog

Research and writeups.

Red team research, Active Directory attacks, defense evasion and hands-on lab writeups, written from the operator seat.

2025 4 posts

From BioTime To System

During an internal assessment, I discovered a web application called BioTime within the target infrastructure. Preliminary research uncovered multiple known vulnerabilities, specifically those listed in 2023 on CVE Details for ZKTeco, including directory traversal and limited write capabilities. Notably, a path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allowed me to read arbitrary files by supplying a crafted payload.

Zero Glow

We'll cover setting up your attack lab, uncovering its hidden vulnerabilities, and crafting exploits to seize control. Learn the precise dorks to unearth countless exposed systems, turning education into a direct path to compromise.