Craig Hays·Jun 4, 2023Admin of One — A Powerful Way to Highly Limit Blast RadiusOne of the most important principles of cyber security is Admin of One. By reducing the number of devices a password can manage to a…
InInfoSec Write-upsbyCraig Hays·Sep 22, 2022Nmap OS Detection: Easy, Fast, and Powerful Examples [How To Guide]Nmap OS detection is a quick and powerful way to determine what operating system a remote device is running. Here’s how to use it.
InInfoSec Write-upsbyCraig Hays·Sep 10, 2021How Hackers Use Open-Source Intelligence to Ransomware CompaniesDemonstrating with a real company how a hacker can compromise an organisation in under 2 hours using OSINT and social engineering.A response icon4A response icon4
InInfoSec Write-upsbyCraig Hays·Aug 11, 2021How I Bought a £240.00 Annual Subscription for Bargain £0.01I found a way to alter a premium subscription service price and bought it for a penny. This is how I did it.A response icon1A response icon1
InInfoSec Write-upsbyCraig Hays·Jul 22, 2021Pre-Account Takeover by Reversing a Weak Email Verification Token AlgorithmI spoofed access to other people’s email in order to pre-steal user accounts before they are first registered. Here’s how I did it.A response icon2A response icon2
InInfoSec Write-upsbyCraig Hays·Jun 22, 2021Cracking Encrypted Credit Card Numbers Exposed By APII found an API that exposed encrypted credit card numbers. Here’s how I cracked them to reveal the full card details.A response icon1A response icon1
InInfoSec Write-upsbyCraig Hays·Jun 18, 2021One Time Code Bypass With An Inverted Brute-Force Attack“We’ve sent a six-digit code to your email address. Enter it below to login.”A response icon1A response icon1
InDigital DiplomacybyCraig Hays·Nov 6, 2020Why You Should Never Trust a Free Proxy ServerFree and open proxy servers promise anonymous internet access, but at what cost?A response icon1A response icon1
InThe StartupbyCraig Hays·Oct 30, 2020How Phishing Websites Use Captcha to Fool Browsers and PeopleEvading detection and building trust with Captcha challenges and Smishing attacks.
InThe StartupbyCraig Hays·Oct 25, 2020Phishing Email to Company Devastating Ransomware in 5 HoursHow hackers manually escalated from a malicious email to a devastating, company-wide ransomware takeover in under 5 hours.