Snotra.uk
  1. About Me
  2. Types of Testing
  3. Snotra.cloud
  4. Archives

Jan 20 2025 Bitcoin Mnemonics

Methods to memorise your seed phrase

Posted by Shaun on Mon 20 January 2025 in bitcoin. Tags: bitcoin.

Jan 14 2025 Snotra Kubernetes

Snotra now supports kubernetes!

Posted by Shaun on Tue 14 January 2025 in pentesting. Tags: kubernetes, cloud, pentesting, security, snotra.

Jan 08 2025 AxeOS CSRF Vulnerability

Using CSRF Attack to update the Payout Address on BitAxe Bitcoin Miners

Posted by Shaun on Wed 08 January 2025 in pentesting. Tags: pentesting, Bitcoin, BTC, Web.

Aug 21 2024 Pillaging Data from Private AWS Subnets

Exploiting overly permissive VPC endpoints to exfiltrate data from private AWS subnets

Posted by Shaun on Wed 21 August 2024 in pentesting. Tags: pentesting, aws, cloud.

Aug 15 2024 Bruteforcing Bitcoin Seed Phrases

Checking Bitcoin Seed Phrases for transactions and balances

Posted by Shaun on Thu 15 August 2024 in bitcoin. Tags: btc, python, pentest.

Jun 07 2024 Pwnboxes

Simple method to define and build security testing containers in Podman

Posted by Shaun on Fri 07 June 2024 in pentesting. Tags: cloud, linux, podman, aws, azure, kubernetes, docker.

Jun 07 2024 Securing Jellyfin

How to secure a Jellyfin media server

Posted by Shaun on Fri 07 June 2024 in blueteam. Tags: linux, jellyfin, blueteam.

May 30 2024 Pentesting AWS Enviroments

Attacking AWS Accounts from a black box perspective

Posted by Shaun on Thu 30 May 2024 in aws. Tags: aws, cloud, pentest.

Feb 28 2024 New AWS Tag Checks

Using Snotra to Check For Sensitive Tags

Posted by Shaun on Wed 28 February 2024 in Cloud. Tags: cloud, aws, snotra.

Jan 19 2024 Penetration Testing Training Labs

Labs to learn penetration testing and offensive security

Posted by Shaun on Fri 19 January 2024 in pentesting. Tags: pentesting, training, labs.

Jan 18 2024 Using Atomic Swaps to DCA during high Fees and Obtaining Private UTXOs

Swapping from Lightning to Liquid to avoid high on-chain fees when Dollar Cost Averaging (DCA) and swapping back on-chain to obtain fresh private UTXO's

Posted by Shaun on Thu 18 January 2024 in bitcoin. Tags: btc, liquid, privacy.

Oct 21 2023 Azure Monitor - Activity Logging, Resource Logging and Alerts

Making Sense of Logging in Azure with Azure Monitor, Diagnostic Settings and Activity Log Alerts

Posted by Shaun on Sat 21 October 2023 in Cloud. Tags: cloud, azure.

Oct 14 2023 Penetration Test Reports and Vulnerability Aggregation

Penetration test reports, aggregating findings and thinking more deeply.

Posted by Shaun on Sat 14 October 2023 in pentesting. Tags: pentesting, reporting, Vulnerability_analysis.

Sep 26 2023 AWS and GitHub OIDC Cross Account Roles

AWS and overly permissive GitHub OIDC cross-account role trust policies

Posted by Shaun on Tue 26 September 2023 in pentesting. Tags: aws, cloud, github, pentesting, devops.

Sep 25 2023 Cybersecurity Fundamentals for Kubernetes

Blog post about Kubernetes Security Fundementals

Posted by Shaun on Mon 25 September 2023 in pentesting. Tags: cloud, pentest, kubernetes.

Sep 25 2023 Understanding Cloud Configuration Reviews

Blog post about Cloud Configuration Reviews

Posted by Shaun on Mon 25 September 2023 in pentesting. Tags: cloud, pentest, aws, azure, gcp, m365.

Aug 11 2023 FirewallD VPN Network Lock

Configuring a VPN network lock on Fedora with FirewallD for boht host and podman traffic.

Posted by Shaun on Fri 11 August 2023 in linux. Tags: linux, fedora, firewalld, podman, vpn.

Jul 23 2023 Windows VMs With Virt-Manager

Running Windows VMs on Linux with Qemu/KVM and Virtual Machine Manager

Posted by Shaun on Sun 23 July 2023 in linux. Tags: linux, fedora, VM, windows.

Jul 06 2023 From Domain User to Domain Admin (DA), From DA to Global Admin (GA)

How to own an internal domain and pivot into the cloud

Posted by Shaun on Thu 06 July 2023 in pentesting. Tags: adcs, internal, pentest, rbcd, azure, cloud, azure ad.

Jun 21 2023 Snotra Lambda

Continuous AWS Testing with Snotra, Lambda, Cloud Watch EventBridge and S3.

Posted by Shaun on Wed 21 June 2023 in pentesting. Tags: cloud, aws, snotra.

Aug 02 2022 Python Tools Using ldap3 and Issues with Channel Binding and Signing

Fixing issues in common tools with Python ldap3 when connecting to Domain Controllers with LDAP signing and binding enabled.

Posted by Shaun on Tue 02 August 2022 in pentesting. Tags: ldap, internal, pentest, python, ntlm relay.

May 11 2022 Internal Top Five

A series of blog Posts for Claranet Cyber Security about common high impact issues discoverd on internal penetration tests and how to fix them.

Posted by Shaun on Wed 11 May 2022 in pentesting. Tags: internal, pentest.

Feb 13 2022 Relaying to Active Directory Certificate Services (ADCS) and Resource Based Constrained Delegation (RBCD)

Getting Local Administrator access with NTLM Relay attacks against ADCS and RBCD attacks.

Posted by Shaun on Sun 13 February 2022 in pentesting. Tags: adcs, rbcd, ntlm relay, internal, pentest.

Categories

  1. aws
  2. bitcoin
  3. blueteam
  4. Cloud
  5. linux
  6. pentesting

Tag cloud

  • adcs
  • aws
  • azure
  • azure ad
  • bitcoin
  • blueteam
  • BTC
  • cloud
  • devops
  • docker
  • fedora
  • firewalld
  • gcp
  • github
  • internal
  • jellyfin
  • kubernetes
  • labs
  • ldap
  • linux
  • liquid
  • m365
  • ntlm relay
  • pentest
  • pentesting
  • podman
  • privacy
  • python
  • rbcd
  • reporting
  • security
  • snotra
  • training
  • VM
  • vpn
  • Vulnerability_analysis
  • Web
  • windows

Snotra.uk. Powered by Pelican and m.css.