BabdCatha.net : a blog about cybersecurity.

  • TryHackMe : Expose

    Hi, today, we’ll be taking a look at the Expose room on TryHackMe. From the description, it looks like the machine will have a few exposed services that maybe should not be so visible. Here is a summary, since this box is quite long : Initial recon As usual, let’s start with an Nmap scan…

  • DeconstruCT.F 2023

    Hi all, I participated this year in the DeconstruCT.F event, and I thought I would share my results with you. Summary Avail Your Good Boy Points When reading the rules all the way to the end, we find the first flag of this challenge : And, that gives us our first 100 points of the…

  • The Toast Overlay Attack

    Hi, I recently came across this DEFCON talk from Nikita Kurtin about different tricks he found to bypass the Android permission system. One technique that I particularly liked was the Toast Overlay Attack. So, I wanted to study it in a bit more detail, and implement my own proof of concept for it. On android,…