-

ELIZA Never Left
From ELIZA in 1966 to XBOW topping HackerOne, we’ve always confessed to machines. A short history of AI and a privacy warning about what we now hand it — fears, finances, marriages.
-

Hackers w/ Handhelds V 2.0
Handheld hacking v2.0: turn the WiFi Pineapple Pager’s captive portal into credential theft — null-route DoH, spoof captive-portal detection, feed a fake Microsoft login to Evilginx.
-

Hackers w/ Handhelds V 1.0
Handheld hacking v1.0: mimic an open AP with the WiFi Pineapple Pager, capture a WPA2 handshake, then crack it with hashcat on a Steam Deck using ROCm GPU acceleration on SteamOS.
-

Hak5 WiFi Pineapple Pager
Hands on with the Hak5 WiFi Pineapple Pager, a pocket-sized Pineapple. We built Snake, Pong, a Packet Catcher, and Null-Buddy — a Tamagotchi that feeds on your recon.db wardriving finds.
-

Living Off The Land: Sliver C2-sharpsh edition
Living off the land with Sliver C2 and sharpsh: enum and lateral movement via native Windows commands — Invoke-Command, comsvcs.dll LSASS dumps, NETLOGON creds — across a GOAD lab.
-

React2Shell (CVE-2025-55182)
CVE-2025-55182: unauthenticated RCE in React Server Components (19.x). We validate with Nuclei, write a Python PoC, then chain Early Bird APC injection and Sliver C2 in a GOAD lab.
-

SheekySlate
Reviving a dead Tegra tablet into a pocket attack rig: RCM secure-boot bypass, custom Linux, ARM64 driver builds for an ALFA AWUS1900, plus Villain C2 and psexec against GOAD.
-

Aromak gets shiny-OSEP!
OSEP is done. A year of course access, a brutal weekend exam, and the full grind from A+ through OSCP and CRTO behind it — an honest “embrace the suck” milestone, not a tutorial.
-

GonkWare v0.55
GonkWare v0.55: a five-tab offensive toolkit with a shellcode generator, Mimikatz parser, Impacket command builder, hash tools, and PowerShell encoder — plus why we’re retiring it.
-

GonkWare v0.49
GonkWare v0.49 lands MSBuild, VBA macro, and HTA runners for fileless delivery, plus threaded shellcode gen, VBA name randomization, and port-validated debug logging. Down to four core files.
-

OOO – DEFCON
DEF CON 2025 plans: Izzny hits PasswordsCon with ‘The HMAC Trap: Security or Illusion?’, plus volunteering at Red Team and NOOB Villages, GonkWare demos, and a pile of Sticker Mule swag.
-

GonkWare v0.43
GonkWare v0.43 adds process injection (defaults to explorer.exe), a dynamic AppLocker bypass, ping-based sleep over obvious calls, and always-on AES. Metasploit setup now auto on Kali and Ubuntu.
-

Out Of Office – BSides Buffalo
Hexxed BitHeadz took ‘A New Host Touches the Beacon’ to BSides Buffalo 2025: updated slides, quest-reward stickers, and GonkWare updates incoming. Recap plus the full talk recording on YouTube.
-

Available Quickhack: GonkWare
Meet GonkWare v0.3: a Tkinter GUI wrapping msfvenom into C# shellcode runners with AES-CBC encryption, sleep evasion, and junk-code obfuscation. Cyberpunk payload gen, roughly 30% to 1.0.
-

Wake Up, Arty: The PHY is Calling
Chasing a dead Ethernet PHY on the Arty A7: an H16 clock-pin conflict and missing MDIO/MDC lines in the constraints file, plus CRC32/FCS and preamble work. Synthesis passes, the link still won’t.
-

Re-Vita-Lized
VITA malware-analysis rig shrinks from four Raspberry Pis to one Docker container. Capa nails capabilities, Yara flags Metasploit shellcode, oletools catches VBA macros, ClamAV keeps missing.
-

Challenge Accepted: FPGA Ethernet Filters
Building an Ethernet packet filter in VHDL on a Digilent Arty A7 100T: five modules doing MAC-based filtering over MII, and the Vivado sim’s uninitialized ‘U’ states still fighting the build.
-

Notepad(p)esky(p)lugins
Weaponizing Notepad++ plugins: a malicious DLL that pops calc, fires a winsock reverse shell, and runs a Havoc C2 beacon from msfvenom shellcode, then checks what Wazuh actually catches.
-

The One Where FPGA Says Hello and Lights Up
Zero to VHDL on a Nandland Go Board (iCE40 HX1K): HELLO on a 7-segment display and LEDs on a switch. Design, synthesis, place-and-route, and .pcf pin mapping in iCEcube2.
-

V.I.T.A. (Variations In The Acronym!)
V.I.T.A.: a local malware scanner on four Raspberry Pis so your samples never reach VirusTotal. ClamAV, YARA and ExifTool behind Flask and SQLite, tested with msfvenom payloads.
-

Conjuring Reverse Tunnels with Ligolo
Pivot without port forwarding or admin rights. Ligolo-ng end to end: ip tuntap setup, proxy -selfcert on 11601, listener_add to relay back, and the Wintun driver for Windows hosts.
-

A walk on the blue side: Part 3
Wazuh past the install: catching hoaxshell’s base64 PowerShell, a PHP webshell upload, and file integrity monitoring on /var/www. Detection works, then the tuning bill comes due.
-

OOO – BSides / DefCon
First BSides talk delivered, on the malicious Skyrim mod from A New Host Touches the Beacon, plus a fifth DEF CON volunteering at Red Team Village. Field notes, not a tutorial.
-

A walk on the blue side: Part 2
Wazuh 4.7.4 in Docker with agents on four Raspberry Pis and a Windows VM: hotfix-based vuln detection, rsyslog for the missing auth.log, and Hydra SSH brute force to prove alerts fire.
-

Visible Ink, Invisible Bias
Professionalism is knowledge, skills and abilities, not covered sleeves. A Majora’s Mask tattoo, hiring bias in government and private sector work, and no apology for either one.
-

A walk on the blue side: Part 1
Suricata IDS on a Raspberry Pi 5 cluster with NVMe, then evading it: nmap’s default User-Agent trips alerts until you spoof a Mozilla string. Red team learning by building blue tooling.
-

Ctrl + Alt + LOL: AI Junior Pentester Edition
PentestGPT and shellGPT turned loose on DVWA: what they actually found, where they stalled on enumeration, and why the operator still holds the keyboard. Plus OWASP’s LLM Top 10.
-

Test drive the Pis with The Boyz
Four Raspberry Pi 5s built into an Android pentest lab: adb, apktool, JADX-GUI, Frida, objection, MobSF, Drozer, RMS and Burp on ARM, then AndroGOAT torn apart vuln by vuln.
-

Unraveling the cryptographic thread of HMAC
HMAC end to end in Python: a socket client/server on hmac and hashlib, MD5/SHA1/SHA256 through hashcat modes 50/150/1450, then tampering via Burp’s NoPE to watch integrity checks fail.
-

From Phreaks to Bytes: Hacking Through the Ages
A curated hacker history list: The Cuckoo’s Egg, Cult of the Dead Cow, Mitnick’s books, Code 2600, Zero Days, 2600 magazine, Darknet Diaries. Phone phreaks to Stuxnet, no fluff.
-

CodeCraft Odyssey: A Tribute to 90s Hackers’ Tale
Build the Hackers (1995) desktop on headless Kali: bspwm, sxhkd, Polybar, picom, Dunst, Rofi and Terminator with Nerd Fonts. Configs, keybinds and install scripts included.
-

A New Host Touches the Beacon
A Skyrim SKSE mod that pops a reverse shell when you pick up Meridia’s Beacon. Five PoCs in C++, ending with C2 shellcode hexdumped into the DLL. Untrusted mods are executables.
-

OSCP, a year later
A year past OSCP: the failed attempts, TJ Null’s list, HackTheBox, Obsidian notes, plus a newborn and a leaking roof. Pentest role within a month. Honest reflection, not a study guide.
-

Unmasking the Shadows: WebDetetive Spyware Breach
WebDetetive hid as an Android Wi-Fi app until hackers gutted its dashboard, cut 76,794 victim devices loose and pulled 1.5GB. Stalkerware anatomy, from a domestic abuse survivor.
-

DefCon 31
Four DEF CONs deep: volunteering at Red Team Village, DLL sideloading and Linux memory evasion talks, Mitnick memorial stickers, GothCon and YTCracker. A con recap, not a writeup.
Blogs
1–2 minutes

