<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Stealthcopter</title><link>https://sec.stealthcopter.com/</link><description>Recent content on Stealthcopter</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 24 Sep 2025 07:30:11 +0000</lastBuildDate><atom:link href="https://sec.stealthcopter.com/index.xml" rel="self" type="application/rss+xml"/><item><title>REGEXSS: How .* Turned Into over $6k in Bounties</title><link>https://sec.stealthcopter.com/regexss/</link><pubDate>Wed, 24 Sep 2025 07:30:11 +0000</pubDate><guid>https://sec.stealthcopter.com/regexss/</guid><description>Overly-greedy regex replacements can break HTML sanitisation and lead to XSS. I&amp;rsquo;ve already pulled in over $6k from this bug class, and there are plenty more out there. Live demo included so you can have a play at exploiting it!</description></item><item><title>Patchstack CTF: Sneaky</title><link>https://sec.stealthcopter.com/patchstack-ctf-sneaky/</link><pubDate>Tue, 25 Feb 2025 20:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/patchstack-ctf-sneaky/</guid><description>Third write-up for the Sneaky Patchstack CTF challenge, exploring visual diffing and fun with PHP filter chains</description></item><item><title>Patchstack CTF: Blocked</title><link>https://sec.stealthcopter.com/patchstack-ctf-blocked/</link><pubDate>Tue, 25 Feb 2025 12:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/patchstack-ctf-blocked/</guid><description>Explore how creative tricks in PHP and WordPress allow you to bypass restrictions in a fun Patchstack CTF (S02E01) challenge and uncover neat tricks with filters and file paths!</description></item><item><title>Patchstack CTF: Cool Templates</title><link>https://sec.stealthcopter.com/patchstack-ctf-cool-templates/</link><pubDate>Sun, 23 Feb 2025 20:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/patchstack-ctf-cool-templates/</guid><description>This writeup explores a Patchstack WordPress CTF challenge where a vulnerable custom footer feature allows for dynamic function execution. The challenge involves bypassing a blocklist and REGEX restrictions on function names to execute arbitrary code.</description></item><item><title>JupiterX Core: Chaining Limited Vulns from SVG to RCE</title><link>https://sec.stealthcopter.com/jupiterx-chaining-svg-to-rce/</link><pubDate>Sat, 11 Jan 2025 12:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/jupiterx-chaining-svg-to-rce/</guid><description>tldr; On their own, these two vulnerabilities in JupiterX Core wouldn&amp;rsquo;t have been very impactful or likely to get a bounty; but by chaining them together, the exploit could be escalated from a simple SVG upload to full Remote Code Execution (RCE).</description></item><item><title>WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)</title><link>https://sec.stealthcopter.com/wpml-rce-via-twig-ssti/</link><pubDate>Wed, 21 Aug 2024 08:30:55 +0000</pubDate><guid>https://sec.stealthcopter.com/wpml-rce-via-twig-ssti/</guid><description>tldr; Server-Side Template Injection (SSTI) is one of my favorite vulnerabilities, but rarely do I see it outside of CTF competitions&amp;hellip;
The WPML Multilingual CMS Plugin for WordPress used by over 1 million sites is susceptible to an Authenticated (Contributor+) Remote Code Execution (RCE) vulnerability through a Twig server-side template injection.</description></item><item><title>Intigriti August 2024 CTF Defcon Challenge: Safe Notes</title><link>https://sec.stealthcopter.com/intigriti-august-2024-ctf/</link><pubDate>Thu, 15 Aug 2024 20:35:20 +0000</pubDate><guid>https://sec.stealthcopter.com/intigriti-august-2024-ctf/</guid><description>tldr; This challenge was fun and engaging, blending CSPT with an open redirect flaw to ultimately pull off a successful XSS attack and grab the flag!</description></item><item><title>Splashing around in the shallow end: My adventure into Bug Bounty Hunting</title><link>https://sec.stealthcopter.com/splashing-around-in-the-shallow-end/</link><pubDate>Mon, 22 Jul 2024 19:45:11 +0000</pubDate><guid>https://sec.stealthcopter.com/splashing-around-in-the-shallow-end/</guid><description>tldr; Reported ~300 vulns in WordPress plugins and themes, made about ~$27k. Have made some of my write-ups public and am working on a WordPress hacking workshop as an introduction to bug bounty.</description></item><item><title>Intigriti July 2024 CTF Challenge: Memo</title><link>https://sec.stealthcopter.com/intigriti-july-2024-ctf-challenge-memo/</link><pubDate>Mon, 08 Jul 2024 12:19:58 +0000</pubDate><guid>https://sec.stealthcopter.com/intigriti-july-2024-ctf-challenge-memo/</guid><description>This fun little challenge was to get reflected cross-site scripting (XSS) on a simple web app that is protected by a content security policy (CSP) and DOMPurify. The solution involves DOM clobbering, relative path abuse and a CSP bypass via HTML base tag injection.</description></item><item><title>NahamCon CTF 2024: My Shop Disaster</title><link>https://sec.stealthcopter.com/nahamcon-ctf-2024-my-shop-disaster/</link><pubDate>Mon, 27 May 2024 12:56:01 +0000</pubDate><guid>https://sec.stealthcopter.com/nahamcon-ctf-2024-my-shop-disaster/</guid><description>Solution for the WooCommerce WordPress plugin challenge that PatchStack submitted to the NahamCon 2024 CTF.</description></item><item><title>Unauthenticated RCE in Anti-Malware Security and Brute-Force Firewall GOTMLS WordPress Plugin CVE-2024-22144</title><link>https://sec.stealthcopter.com/cve-2024-22144/</link><pubDate>Tue, 12 Mar 2024 09:54:54 +0000</pubDate><guid>https://sec.stealthcopter.com/cve-2024-22144/</guid><description>Unauthenticated Remote Code Execution (RCE) by chaining multiple vulnerabilities in the Anti-Malware Security and Brute-Force Firewall GOTMLS WordPress Plugin</description></item><item><title>Intigriti February CTF Challenge: Love Letter Storage</title><link>https://sec.stealthcopter.com/intigriti-february-ctf-challenge-love-letter-storage/</link><pubDate>Thu, 22 Feb 2024 00:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/intigriti-february-ctf-challenge-love-letter-storage/</guid><description>tl;dr: Solved an awesome Valentine&amp;rsquo;s Day challenge by @goatsniff from Intigriti. I gained valuable insights into using character conversions to bypass XSS protections and learned about data exfiltration through the manipulation of cookie paths.</description></item><item><title>CVE-2024-0685 Ninja Contact Forms Data Export SQLi</title><link>https://sec.stealthcopter.com/ninja-contact-forms/</link><pubDate>Sat, 10 Feb 2024 15:06:04 +0000</pubDate><guid>https://sec.stealthcopter.com/ninja-contact-forms/</guid><description>The Ninja Forms Contact Form Plugin for WordPress is susceptible to an SQL injection vulnerability when processing data export requests.</description></item><item><title>Intigriti December CTF Challenge: Smarty Pants</title><link>https://sec.stealthcopter.com/intigriti-december-challenge-smarty-pants/</link><pubDate>Thu, 21 Dec 2023 00:01:50 +0000</pubDate><guid>https://sec.stealthcopter.com/intigriti-december-challenge-smarty-pants/</guid><description>I decided to dust off my hacking hat and delve back into CTF challenges with the Intigriti December challenge. Here&amp;rsquo;s my write-up on the journey I had with this interesting puzzle, teaching me new tricks and reinforcing old skills.</description></item><item><title>CVE-2022-39841 Medusa's leaky WebSocket</title><link>https://sec.stealthcopter.com/cve-2022-39841/</link><pubDate>Thu, 15 Sep 2022 08:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/cve-2022-39841/</guid><description>A critical vulnerability in Medusa allows for information leakage, including plaintext credentials, by attaching to an unauthenticated WebSocket and waiting for a user to make a configuration change.</description></item><item><title>dCTF - Just Take Your Time</title><link>https://sec.stealthcopter.com/dctf-just-take-your-time/</link><pubDate>Mon, 17 May 2021 06:29:51 +0000</pubDate><guid>https://sec.stealthcopter.com/dctf-just-take-your-time/</guid><description>Over the weekend I participated in dCTF by DragonSec SI along with some friends. There were some really interesting and unique challenges in this CTF.</description></item><item><title>CVE-2021-31607 SaltStack Minion Privledge Escaltion in Snapper Module</title><link>https://sec.stealthcopter.com/saltstack-snapper-minion-privledge-escaltion/</link><pubDate>Sat, 17 Apr 2021 10:40:52 +0000</pubDate><guid>https://sec.stealthcopter.com/saltstack-snapper-minion-privledge-escaltion/</guid><description>I discovered a command injection vulnerability in SaltStack&amp;rsquo;s Salt that allows privilege escalation using malicious filenames on a minion when the master calls snapper.diff. But&amp;hellip; I was too slow!</description></item><item><title>CVE-2020-28243 (2) SaltStack Minion Denial of Service via Argument Injection</title><link>https://sec.stealthcopter.com/cve-2020-28243-v2/</link><pubDate>Tue, 23 Mar 2021 20:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/cve-2020-28243-v2/</guid><description>Recently I disclosed a local privilege escalation, CVE-2020-28243, in SaltStack&amp;rsquo;s Salt via specially crafted process names. However, due to an incomplete fix, argument injection leading to a low impact denial of service is still possible.</description></item><item><title>CVE-2020-28243 SaltStack Minion Local Privilege Escalation</title><link>https://sec.stealthcopter.com/cve-2020-28243/</link><pubDate>Thu, 25 Feb 2021 19:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/cve-2020-28243/</guid><description>I discovered a command injection vulnerability in SaltStack&amp;rsquo;s Salt that allows privilege escalation via specially crafted process names on a minion when the master calls restartcheck.</description></item><item><title>HTB CTF Write-up: Gunship</title><link>https://sec.stealthcopter.com/htb-ctf-write-up-gunship/</link><pubDate>Thu, 10 Dec 2020 13:02:00 +0000</pubDate><guid>https://sec.stealthcopter.com/htb-ctf-write-up-gunship/</guid><description>The HTB x Uni CTF 2020 - Qualifiers have just finished and I wanted write-up some of the more interesting challenges that we completed.</description></item><item><title>HTB CTF Write-up: Cargo Delivery</title><link>https://sec.stealthcopter.com/htb-ctf-writeup-cargo-delivery/</link><pubDate>Thu, 10 Dec 2020 13:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/htb-ctf-writeup-cargo-delivery/</guid><description>Cargo Delivery was a Python command line application that uses AES CBC encryption and is vulnerable to a padding oracle attack.</description></item><item><title>HTB CTF Write-up: Cached Web</title><link>https://sec.stealthcopter.com/htb-ctf-writeup-cached-web/</link><pubDate>Thu, 10 Dec 2020 13:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/htb-ctf-writeup-cached-web/</guid><description>The HTB x Uni CTF 2020 - Qualifiers have just finished and I wanted to write-up some of the more interesting challenges that we completed.</description></item><item><title>Metasploit Community CTF 2020 (Dec) Write-up: 5-of-clubs (port 8101)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-5-of-clubs-port-8101/</link><pubDate>Mon, 07 Dec 2020 21:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-5-of-clubs-port-8101/</guid><description>Summary The 5-of-clubs challenge was to write a Metasploit module that is uploaded and run on a computer to which you do not have direct access. The module is uploaded along with a resource file that is used to automate Metasploit, the output is logged and can be viewed following execution.</description></item><item><title>Metasploit Community CTF 2020 (Dec) Write-up: 7-of-spades (port 8888)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-7-of-spades-port-8888/</link><pubDate>Mon, 07 Dec 2020 21:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-7-of-spades-port-8888/</guid><description>Summary The 7-of-spades challenge is a basic Python web application that lists information about Metasploit modules. It uses a pickle saved in base64 to a cookie that can be modified to get remote code execution.</description></item><item><title>Metasploit Community CTF 2020 (Dec) Write-up: 9-of-clubs (port 1337)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-9-of-clubs-port-1337/</link><pubDate>Mon, 07 Dec 2020 21:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-9-of-clubs-port-1337/</guid><description>This fun little challenge was solved by our binary exploitation expert: benything.</description></item><item><title>Metasploit Community CTF 2020 (Dec) Write-up: ace-of-clubs (port 9009)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-ace-of-clubs-port-9009/</link><pubDate>Mon, 07 Dec 2020 21:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-ace-of-clubs-port-9009/</guid><description>Summary The ace-of-clubs challenge presented a SSH server on port 9009 that had an easy to guess login. This is followed by a privilege escalation to root in a custom binary using a file overwrite exploit.</description></item><item><title>Metasploit Community CTF 2020 (Dec) Write-up: queen-of-hearts (port 9008 &amp; 9010)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-queen-of-hearts-port-9008-9010/</link><pubDate>Mon, 07 Dec 2020 21:01:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec-write-up-queen-of-hearts-port-9008-9010/</guid><description>Summary The queen-of-hearts challenge was on two ports, 9010 which contained a downloadable Java .jar file and 9008 which was the service that you needed to interact with. Initially it appeared that it was an insecure deserialisation exploit, and while it is likely that that was also present, the flag could be obtained using a simple logic flaw as the application was relying on a client-side check for authentication status.</description></item><item><title>Metasploit Community CTF 2020 (Dec)</title><link>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec/</link><pubDate>Mon, 07 Dec 2020 21:00:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-community-ctf-2020-dec/</guid><description>Metasploit ran another community CTF this year, and we decided to put forward a team. The team ended up bigger than all other teams I&amp;rsquo;ve been part of before and hence PrettyBeefy team was born.</description></item><item><title>About Me</title><link>https://sec.stealthcopter.com/about/</link><pubDate>Fri, 13 Nov 2020 18:43:47 +0000</pubDate><guid>https://sec.stealthcopter.com/about/</guid><description>@stealthcopter
MSc Computer Security | OSCP
I&amp;rsquo;m an Application Security Professional. I teach developers by creating insecure applications so they don&amp;rsquo;t have to :)
I&amp;rsquo;ve made some open source software that you can find on Github</description></item><item><title>New Metasploit Module: enum_containers</title><link>https://sec.stealthcopter.com/metasploit-1-2-3/</link><pubDate>Thu, 06 Aug 2020 10:10:00 +0000</pubDate><guid>https://sec.stealthcopter.com/metasploit-1-2-3/</guid><description>I wrote a new metasploit module, enum_containers, that enumerates a target post exploit and detects container platforms and lists any containers that are actively running on them.</description></item><item><title>New Metasploit Module: docker_privileged_container_escape</title><link>https://sec.stealthcopter.com/docker_privileged_container_escape/</link><pubDate>Tue, 04 Aug 2020 10:15:00 +0000</pubDate><guid>https://sec.stealthcopter.com/docker_privileged_container_escape/</guid><description>I wrote a new metasploit module, docker_privileged_container_escape, that escapes from a docker container with access to the docker sock obtaining a root shell on the host operating system.</description></item><item><title>Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)</title><link>https://sec.stealthcopter.com/deepce/</link><pubDate>Fri, 31 Jul 2020 18:59:00 +0000</pubDate><guid>https://sec.stealthcopter.com/deepce/</guid><description>I developed a container enumeration script. Think of it like linpeas/linenum but for containers.</description></item><item><title>Portdroid - Network Analysis Kit &amp; Port Scanner</title><link>https://sec.stealthcopter.com/portdroid/</link><pubDate>Mon, 15 Jun 2020 19:54:00 +0000</pubDate><guid>https://sec.stealthcopter.com/portdroid/</guid><description>PortDroid is a Network Analysis Application that helps Network Administrators, Penetration Testers and Hackers with several useful networking tools.</description></item><item><title>RootBeer - Root Detection Library for Android</title><link>https://sec.stealthcopter.com/rootbeer/</link><pubDate>Sat, 08 Feb 2020 21:04:00 +0000</pubDate><guid>https://sec.stealthcopter.com/rootbeer/</guid><description>A tasty root checker library and sample app. We&amp;rsquo;ve scoured the internets for different methods of answering that age old question&amp;hellip; Has this device got root?</description></item><item><title>Python UUEncode Vulnerability</title><link>https://sec.stealthcopter.com/python-uuencode-vulnerability/</link><pubDate>Mon, 02 Dec 2019 22:13:00 +0000</pubDate><guid>https://sec.stealthcopter.com/python-uuencode-vulnerability/</guid><description>tl;dr Found a vuln in some old and mostly unused data format in python, spoke to Guido van Rossum (inventor of Python), and submitted a PR with a fix.
I had a look at the Python source code for and discovered a vulnerability in the UUEncode methods in Python.</description></item></channel></rss>