← manuelsaraceni.com

Manuel Saraceni / Blog

Cybersecurity notes, tools documentation, CTF writeups, and project showcases.

Categories

Recent Posts

News

Chrome Zero-Day Vulnerability

Analysis of a critical Chrome zero-day vulnerability — CVE details, impact, and mitigation strategies.

chromezero-dayvulnerabilitycve
CTF Writeups/ TryHackMe

TryHackMe: Billing

Writeup for the Billing room on TryHackMe — exploitation of a billing application vulnerability.

tryhackmectfwriteupweb
CTF Writeups/ TryHackMe

TryHackMe: Airplane

Writeup for the Airplane room on TryHackMe — LFI exploitation and privilege escalation.

tryhackmectfwriteuplfi
Tutorials

DNS Zone Transfer

A deep dive into DNS Zone Transfer (AXFR) misconfiguration, how to exploit it during penetration tests, and how to secure against it.

dnspenetration-testingreconnaissanceaxfr
Tools & Utility/ Information Gathering / DNS Enumeration

dnsEnum

A powerful multithreaded Perl script for DNS enumeration and information gathering.

dnsenumerationreconnaissanceperl
Tools & Utility/ Information Gathering / DNS Enumeration

Recon-ng

A powerful modular OSINT and reconnaissance framework with a Metasploit-like interface.

osintreconnaissanceframeworkpython
Tools & Utility/ Information Gathering / DNS Enumeration

Dig

The Domain Information Groper (dig) is one of the most powerful command-line tools for querying DNS records.

dnsdigenumerationnetworking
Tools & Utility/ Information Gathering / DNS Enumeration

Fierce

DNS reconnaissance tool for discovering subdomains, IP ranges, and network information of a target domain.

dnsreconnaissancesubdomainsperl
Tools & Utility/ Information Gathering / DNS Enumeration

Sublist3r

Python tool for enumerating subdomains using OSINT techniques via multiple search engines and services.

subdomainsosintpythonenumeration
Tools & Utility/ Information Gathering / Fuzzing

Gobuster

A fast directory and DNS subdomain brute-forcing tool written in Go.

fuzzingdirectorybruteforcego
Tools & Utility/ Information Gathering / Fuzzing

FFUF

Fast and flexible fuzzing tool for web applications written in Go.

fuzzingwebbruteforcego
Tools & Utility/ Information Gathering / Network Discovery

Nmap

The ultimate network scanning tool for host discovery, port scanning, OS detection, and vulnerability assessment.

nmapnetworkscanningports