0xSebin

home-banner-background home-banner-background
0xSebin

0xSebin

  • HOME
  • CATEGORIES
  • TAGS
  • LINKS
  • HOME
  • CATEGORIES
  • TAGS
  • LINKS
41
Tags
8
Categories
17
Posts
0xSebin
Normal one. Normal days.
Tags Categories
Sebin Thomas
41
Tags
8
Categories
17
Posts
  • LLM01: Prompt Injection

    LLM01: Prompt Injection

    Here’s something encrypted, password is required to continue reading.

      2026-08-14  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreLLM01: Prompt Injection 
  • OWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide

    OWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide

    Every company I look at these days has quietly wired a language model into something that matters. A support bot that can read the ticketing system. A coding copilot with access to the repo. An “as...
      2026-08-14  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreOWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide 
  • Common Active Directory Misconfigurations and Where to Find Them

    Common Active Directory Misconfigurations and Where to Find Them

    “You don’t need a zero-day. You just need to look harder.” Every time I drop into an internal network during a pentest or a red team engagement, the story is always the same - the domain is a gol...
      2025-12-26  
    • Real-World Pentest 
     
    • Security 
    • | Active Directory 
    • | Red Team 
    Read moreCommon Active Directory Misconfigurations and Where to Find Them 
  • Gophish - Setting up without Evilginx - Part 2

    Gophish - Setting up without Evilginx - Part 2

    GoPhish End-to-End Setup for Credential CaptureIn this second part, I will be configuring GoPhish from start to end, up to the point where we successfully capture the credentials of a phished user....
      2025-12-25  
    • Phishing 
     
    • Phishing 
    • | Red Teaming 
    • | GoPhish 
    Read moreGophish - Setting up without Evilginx - Part 2 
  • Gophish - Setting up without Evilginx - Part 1

    Gophish - Setting up without Evilginx - Part 1

    Gophish Infrastructure Setup (EC2 · DNS · SMTP)This section covers the infrastructure-level setup required before deploying GoPhish. Proper configuration at this stage is critical to avoid blacklis...
      2025-10-21  
    • Phishing 
     
    • Phishing 
    • | Red Teaming 
    • | GoPhish 
    Read moreGophish - Setting up without Evilginx - Part 1 
  • Certified - Hack The Box

    Certified - Hack The Box

    We began with the low-privileged user JUDITH.MADER@CERTIFIED.HTB, who had the ability to modify the owner of MANAGEMENT@CERTIFIED.HTB. By changing ownership, we added a controlled user to this grou...
      2025-03-15  
    • Hack The Box 
     
    • Active Directory 
    • | Hack The Box 
    • | Impacket 
    Read moreCertified - Hack The Box 
  • Escape Two - HackTheBox

    Escape Two - HackTheBox

    Using rose‘s SMB credentials on DC01, we accessed and extracted credentials from accounts.xlsx, including the MSSQL sa account. With mssqlclient.py, we enabled xp_cmdshell and obtained a shell as s...
      2025-02-24  
    • Hack The Box 
     
    • Active Directory 
    • | Hack The Box 
    • | Impacket 
    Read moreEscape Two - HackTheBox 
  • Baby - Vulnlab - Windows - Easy

    Baby - Vulnlab - Windows - Easy

    Baby is an Easy windows machine from Vulnlab, in which we start with ldapsearch and get a users password from a description and after resetting that users password we will be able to login to winrm...
      2025-02-20  
    • Vulnlab 
     
    • Active Directory 
    • | Impacket 
    • | Vulnlab 
    Read moreBaby - Vulnlab - Windows - Easy 
123
© 2024 - 2026    Sebin Thomas

17 posts in total 42.5k words in total

POWERED BY Hexo THEME Redefine v2.9.0
Blog up for days hrs Min Sec
EXIF