<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CapsOp</title>
    <description>IT-Security blog of wirehack7. Writing about malware hunting, botnet shutdowns, pentesting and securing IT architecture.</description>
    <link>https://capsop.com/</link>
    <atom:link href="https://capsop.com/rss.xml" rel="self" type="application/rss+xml" />
    <language>en</language>
    <lastBuildDate>Sun, 30 Aug 2026 20:39:16 +0200</lastBuildDate>
    <generator>Jekyll</generator>
    
    <item>
      <title>Pinky&apos;s Palace siege</title>
      <link>https://capsop.com/itsec/english/ctf/vulnhub/2018/09/17/Pinkys-Palace-siege.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/english/ctf/vulnhub/2018/09/17/Pinkys-Palace-siege.html</guid>
      <pubDate>Mon, 17 Sep 2018 00:00:00 +0200</pubDate>
      <category>itsec</category>
      <category>English</category>
      <category>CTF</category>
      <category>vulnhub</category>
      <description>inviting yourself to a party of pinky — </description>
    </item>
    
    <item>
      <title>To the lands of Wakanda 1</title>
      <link>https://capsop.com/itsec/english/ctf/vulnhub/2018/08/15/wakanda1-ctf.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/english/ctf/vulnhub/2018/08/15/wakanda1-ctf.html</guid>
      <pubDate>Wed, 15 Aug 2018 00:00:00 +0200</pubDate>
      <category>itsec</category>
      <category>English</category>
      <category>CTF</category>
      <category>vulnhub</category>
      <description>Breaching the bearier of Wakanda — I created a new ToDo-List for CTF VM’s from Vulnhub, you see it here:My ToDo :)#Pentesting #challenge All downloadable at @VulnHub pic.twitter.com/pjIgn5LImy&amp;mdash; ???????????? (@wirehack7) 12. August 2018So I solved Wakanda 1 and I want to share with you my walkthrough. Let’s start!  Information  First contact  Getting in          Information gathering through LFI      Getting flag1.txt      ...</description>
    </item>
    
    <item>
      <title>DerpNStink won&apos;t stink anymore</title>
      <link>https://capsop.com/itsec/english/2018/06/05/derpnstink.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/english/2018/06/05/derpnstink.html</guid>
      <pubDate>Tue, 05 Jun 2018 00:00:00 +0200</pubDate>
      <category>itsec</category>
      <category>English</category>
      <description>Resolving boot2root DerpNStink VM — Another day another boot2root VM. This time DerpNStink, it’s level is “beginner”. To make things short, let’s dive in.</description>
    </item>
    
    <item>
      <title>SMTP Hacking via SSH TCP Forwarding Attacken</title>
      <link>https://capsop.com/itsec/german/malwaremustdie/2017/03/05/SMTP-Hacking-via-SSH-Relays.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/german/malwaremustdie/2017/03/05/SMTP-Hacking-via-SSH-Relays.html</guid>
      <pubDate>Sun, 05 Mar 2017 00:00:00 +0100</pubDate>
      <category>itsec</category>
      <category>German</category>
      <category>MalwareMustDie</category>
      <description>Neue Kampagne um Mailserver zu kompromitieren — EDIT: Sollten Sie von einer Behörde oder einem anderen Sicherheitsorgan sein so kontaktieren Sie mich, soweit möglich, über meinen Twitter Account: @wirehack7 Hier können wir uns auf weitere Kommunikationswege einigen. Derzeit ist die Datenmenge der gesamten Logs bei ca 5 TB.</description>
    </item>
    
    <item>
      <title>Exorcise the demons of the necromancer</title>
      <link>https://capsop.com/itsec/english/ctf/vulnhub/2016/10/08/necromancer.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/english/ctf/vulnhub/2016/10/08/necromancer.html</guid>
      <pubDate>Sat, 08 Oct 2016 00:00:00 +0200</pubDate>
      <category>itsec</category>
      <category>English</category>
      <category>CTF</category>
      <category>vulnhub</category>
      <description>Curing the vulnerable machine from it's demons — Long time no post, I got kinda busy the last days. This post is again not about malware hunting, which means not that I don’t hunt, I just cannot post about the last happenings and I also don’t want to.So I write about the next vulnerable operating system image which I resolved.</description>
    </item>
    
    <item>
      <title>Hacking SkyDogCTF vulnOS</title>
      <link>https://capsop.com/itsec/2016/07/24/Skydog-CTF.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2016/07/24/Skydog-CTF.html</guid>
      <pubDate>Sun, 24 Jul 2016 00:00:00 +0200</pubDate>
      <category>itsec</category>
      <description>The answer to who let the dogs out — Another day, another vulnerable OS. Well, not really that often, but these days I enjoy it to solve them after work. Nice to get other thoughts and to relax. This time I’m doing SkyDog CTF 1. It has six flags included with a hint for each of them. They are MD5 hashes which obviously need to be cracked then 😄</description>
    </item>
    
    <item>
      <title>Acid Reloaded hacking</title>
      <link>https://capsop.com/itsec/tools/2016/05/22/acid-reloaded.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/tools/2016/05/22/acid-reloaded.html</guid>
      <pubDate>Sun, 22 May 2016 21:28:17 +0200</pubDate>
      <category>itsec</category>
      <category>tools</category>
      <description>Fun with the vulnerable OS Acid Reloaded — We know that there are many ways to gain access to a server out there. We can use several known exploits, unknown 0days and even social engineer to access. These activities are also all depending on training. A good way to train are Capture the Flag events and vulnerable systems which are made to be vulnerable. As CTF events are mostly event and time based I’m focusing on the second way, using ...</description>
    </item>
    
    <item>
      <title>Welcome to Jekyll!</title>
      <link>https://capsop.com/personal/2016/05/21/jekyll.html</link>
      <guid isPermaLink="true">https://capsop.com/personal/2016/05/21/jekyll.html</guid>
      <pubDate>Sat, 21 May 2016 08:38:40 +0200</pubDate>
      <category>personal</category>
      <description>Feel home! — Yep, I recreated the site and switched to Jekyll. As I was already using Markdown to format my posts the porting did not take that much time. Jekyll is nice to build static websites, fits perfect for my blog.Also it has less attack vectors as a dynamic website because nothing get’s intepreted, for example from PHP. No database connection, no GET variables, nothing.GitHub is also beeing used to ...</description>
    </item>
    
    <item>
      <title>IRC driven Botnet</title>
      <link>https://capsop.com/itsec/2015/09/19/irc-driven-botnet.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2015/09/19/irc-driven-botnet.html</guid>
      <pubDate>Sat, 19 Sep 2015 16:00:01 +0200</pubDate>
      <category>itsec</category>
      <description>Analysis and shutdown of a botnet ran by IRC protocol — This is just a short post about an botnet I got mentioned. It is using a Perl script to infect and let the bot join an IRC server. Scriptkiddies kinda love that way, easy to deploy ircd and maintaining.</description>
    </item>
    
    <item>
      <title>PHP fake 0day</title>
      <link>https://capsop.com/itsec/2015/08/08/php-fake-0day.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2015/08/08/php-fake-0day.html</guid>
      <pubDate>Sat, 08 Aug 2015 01:34:01 +0200</pubDate>
      <category>itsec</category>
      <description>Having fun with a false exploit — Today @sh1bumi of @MalwareMustDie found a interesting PHP script. At a first look at seemed like a 0day for websites which are running PHP. “This cannot be, another 0day” we thought, so we analysed the script.(Script is at the end of the post)</description>
    </item>
    
    <item>
      <title>Wordlists enjoyment</title>
      <link>https://capsop.com/itsec/2015/04/08/wordlists-enjoyment.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2015/04/08/wordlists-enjoyment.html</guid>
      <pubDate>Wed, 08 Apr 2015 01:34:01 +0200</pubDate>
      <category>itsec</category>
      <description>Having fun with wordlists of real passwords — Today I will write about wordlists for hash cracking. I prefer wordlists for a first run against collected hashes which I want to crack. Why? Because these wordlists are mainly build upon leaked databases with real login data from humans. And humans are tending to make the same password over and over. Even two persons which are unknown to each other might use the same password.Also it will sort...</description>
    </item>
    
    <item>
      <title>phpMyAdmin PMA vuln CVE-2009-1151</title>
      <link>https://capsop.com/itsec/2015/01/18/phpmyadmin-PMA-vuln.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2015/01/18/phpmyadmin-PMA-vuln.html</guid>
      <pubDate>Sun, 18 Jan 2015 00:34:01 +0100</pubDate>
      <category>itsec</category>
      <description>How CVE-2009-1151 is used in the wild — Today we (MalwareMustDie) found this thread of automated exploiting phpMyAdmin instances which are vulnerable to CVE-2009-1151. In short: this uses a false escaped vari                  able which can be used to run code which is then included in config.inc.php, see this interesting blog post for additional information.</description>
    </item>
    
    <item>
      <title>Securing your server</title>
      <link>https://capsop.com/servers/2014/12/10/securing-your-server.html</link>
      <guid isPermaLink="true">https://capsop.com/servers/2014/12/10/securing-your-server.html</guid>
      <pubDate>Wed, 10 Dec 2014 00:34:01 +0100</pubDate>
      <category>servers</category>
      <description>Convert your Linux server to a fort — In this post I will show you a few ways to secure your Debian (or Ubuntu) based server. This contains to secure your SSH connection, protecting against brute force and protecting against port scans. Also I will show you how to easily use iptables via an additional package. This is not the holy grail of security, there are really more things you might do. Like using chroot and other solutions to...</description>
    </item>
    
    <item>
      <title>Kippo installing</title>
      <link>https://capsop.com/itsec/2014/11/26/kippo-installing.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2014/11/26/kippo-installing.html</guid>
      <pubDate>Wed, 26 Nov 2014 15:12:32 +0100</pubDate>
      <category>itsec</category>
      <description>Create a honeypot trap for SSH — Well, I had a post on my own blog describing how to install Kippo as a own honeypot. Due the data loss this post also disappeared. I am writing it again now. So this can be still used as somehow a guide to create own SSH honeypots.</description>
    </item>
    
    <item>
      <title>A new beginning</title>
      <link>https://capsop.com/personal/2014/11/07/beginning.html</link>
      <guid isPermaLink="true">https://capsop.com/personal/2014/11/07/beginning.html</guid>
      <pubDate>Fri, 07 Nov 2014 04:41:23 +0100</pubDate>
      <category>personal</category>
      <description>Let's start the site freshly — Today I am starting my new blog. I had to reinstall the server because of a OS fail and had no backup from my old blog. So I have to start again from the beginning. This time with an own, hand crafted design. I hope you are enyoing it.</description>
    </item>
    
    <item>
      <title>Lightaidra C&amp;amp;C investigation</title>
      <link>https://capsop.com/itsec/2014/05/17/lightaidra-cc-investigation.html</link>
      <guid isPermaLink="true">https://capsop.com/itsec/2014/05/17/lightaidra-cc-investigation.html</guid>
      <pubDate>Sat, 17 May 2014 05:41:23 +0200</pubDate>
      <category>itsec</category>
      <description>Investigating an IRC C&amp;C and hunting the botherder — As mentioned on MalwareMustDie, a trojan downloader got in one of my honeypots. It is the Lightaidra one, a simple coded bot to infect machines like routers. It scans networks and tries to login with standard passwords, if successful it downloads a Shell Script which downloads ELF binaries. They are used that the bot connects to some hardcoded IRC servers with hardcoded credentials. The bots ca...</description>
    </item>
    
  </channel>
</rss>
