Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # RingBuffer's Blog Security Research & Red Team Consultant ## Sitemaps - [XML Sitemap](https://vandanpathak.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Cicada HTB Writeup](https://vandanpathak.com/exploiting-ad/cicada-htb-writeup/) - This write up will focus on solving the Cicada Hack The Box Machine. This is a Windows Easy Box. - [October HTB & ret2libc Writeup](https://vandanpathak.com/htb-writeups/october-htb-ret2libc-writeup/) - Using ret2libc library where ASLR is enabled along with NX-bit (No-Execute) and RELRO (ReLocation Read-Only) partially enabled - [ROP Challenge - Exploiting ret2win Binary](https://vandanpathak.com/kernels-and-buffers/return-oriented-programming-ret2win-rop-emporium/) - A detail guide on how to capture the flag using return oriented programming buffer overflow challenge on ROP Emporium. - [ROP Challenge – Exploiting Split Binary](https://vandanpathak.com/kernels-and-buffers/return-oriented-programming-split-rop-emporium/) - This blog covers the write up for x86 and x64 architecture for the split binary of ROP Emporium Buffer Overflow - [ROP Challenge – Exploiting Callme Binary](https://vandanpathak.com/kernels-and-buffers/return-oriented-programming-callme-rop-emporium/) - This blog covers the basics of Linkers, Procedure Linkage table and walkthrough on how to capture the flag for callme challenge on ROP Emporium. - [ROP Challenge - Exploiting write4 Binary](https://vandanpathak.com/kernels-and-buffers/rop-challenge-write4-rop-emporium/) - ROP Challenge – Exploiting write4 Binary - [Buffer Overflow Exploits Demystified: From Theory to Practice Part 2](https://vandanpathak.com/kernels-and-buffers/buffer-overflow-exploits-demystified-from-theory-to-practice-part-2/) - Buffer Overflow Exploits Demystified: From Theory to Practice Part 2 – Hello once again! If you haven't already read the previous blog "Buffer Overflow Exploits Demystified: From Theory to Practice Part 1", I would recommend taking a look at it before diving into this one. In this blog, we will delve into the practical assessment of buffer overflow. Ground Work In this blog, we will demonstrate - [Attacking AD Certificate Services - Part 3](https://vandanpathak.com/exploiting-ad/adcs-attacking-part-3/) - Attacking Active Directory Certificate Service (ADCS) Part 3 focusing on performing the privilege escalation using vulnerable AD CS service in Windows Domain. - [Attacking AD Certificate Services - Part 2](https://vandanpathak.com/exploiting-ad/adcs-attacking-part-2/) - Attacking Active Directory Certificate Service (ADCS) Part 2 - Focusing on uncovering some critical assets using certify and leveraging Windows Data Protection API - [Attacking AD Certificate Services - Part 1](https://vandanpathak.com/exploiting-ad/adcs-attacking-part-1/) - This blog covers Enumerating the AD services and attacking AD CS in windows environment. - [Attacking Kerberos - Part 1](https://vandanpathak.com/exploiting-ad/attacking-kerberos-protocol/) - Active Directory Exploitation - Attacking Kerberos Part 1 - In Lab exercise - [Buffer OverFlow and Buff.HTB Writeup](https://vandanpathak.com/htb-writeups/buffer-overflow-and-buff-htb-writeup/) - Introduction to Buffer Overflow and Buff.HTB Writeup - [Buffer Overflow Exploits Demystified: From Theory to Practice Part 1](https://vandanpathak.com/kernels-and-buffers/buffer-overflow-exploits-demystified-from-theory-to-practice/) - Buffer Overflow Part 1 - Inhouse Lab Exercise to catch the reverse shell and perform RCE - [Buffer Overflow : Exploiting Easy RM to MP3 Converter](https://vandanpathak.com/kernels-and-buffers/buffer-overflow-exploiting-easy-rm-to-mp3-converter/) - Buffer Overflow Demonstration on Exploiting Easy RM to MP3 Converter - [Return Oriented Programming - Buffer Overflow Part 1](https://vandanpathak.com/kernels-and-buffers/return-oriented-programming-buffer-overflow-part-1/) - Return Oriented Programming Buffer Overflow Attack Demonstration - [Unconstrained Delegation Attack](https://vandanpathak.com/exploiting-ad/unconstrained-delegation-attack/) - Active Directory Exploitation - Kerberos Unconstrained Delegation Attack - In Lab Demonstration - [AS-REP Roasting and Forest.HTB](https://vandanpathak.com/htb-writeups/as-rep-roasting-and-forest-htb/) - Windows Exploitation - AS-REP Roasting and DCSync Attack with Forest.HTB Writeup - [Absolute.htb Walkthrough](https://vandanpathak.com/htb-writeups/absolute-htb-walkthrough/) - AD Exploitation - Absolute.HTB writeup - [Attacking Kerberos - Part 2](https://vandanpathak.com/exploiting-ad/kerberoasting/) - Active Directory Exploitation - Attacking Kerberos Part 2 - In Lab exercise - [Flight Hack The Box Writeup](https://vandanpathak.com/htb-writeups/flight-htb-writeup/) - Today, I'm working on another Windows machine, specifically focusing on Windows and excited to explore different ways to breach it. My target for the day is Flight.htb. Let's begin our mission to compromise it. The nmap Vector of the box is posted below. # nmap -p- --min-rate=1000 -T4 -sC -sV 10.10.11.187 Starting Nmap 7.94 ( AD Exploitation - Flight.HTB Writeup - [Bagel Hack The Box Writeup](https://vandanpathak.com/htb-writeups/bagel-htb-walkthrough/) - August 2026 In recent weeks, I have been passionately engaged in the world of Hack The Box. Today, I made the deliberate choice to delve into the intricacies of deserialization vulnerabilities. My primary objective was to acquire profound insights into code reviews and deserialization techniques, leading me to select the HTB machine aptly named 'Bagel.' This Linux-based - [Support.HTB Writeup And RBCD Attack](https://vandanpathak.com/htb-writeups/support-htb-writeup-and-rbcd-attack/) - November 12, 2023 Embarking on a new day of cyber adventures, I set my sights on another Hack The Box challenge. Today, however, I was in the mood for a bit of a breeze. Therefore, I opted for the support.htb Windows box, hoping for a puzzle that would unfold with ease. Let's see what this virtual journey has - [DCSync Attack](https://vandanpathak.com/exploiting-ad/dcsync-attack/) - Active Directory Exploitation - DCSync Attack - In Lab Demonstration - [Attacks on Large Language Model](https://vandanpathak.com/llm-security/introduction-to-llm-vulnerabilities/) - Recently I came across one of the GitHub Repo on vulnerable Large Language Model and securing AI model. I was bit curious to try it out. It's Damm Vulnerable LLM Project. You can find it here DamnVulnerableLLMProject. (Credits: harishsg993010). Let's follow the steps and see how far we can go from here. The instructions were - [Escape.htb - Struggles and Walkthrough](https://vandanpathak.com/htb-writeups/escape-htb-struggles-and-walkthrough/) - Indeed it was one of the great windows machine to capture the flag for. I have had fun solving this one. Although I dig up a lot on HTB Forums and it took me 2 days to compile some of the binaries because of C# and Python dependencies. Let's dive in it. Hope this Blog ## Pages - [Home - RingBuffer's OffSec Blogs](https://vandanpathak.com/) - Red Team OffSec Blogs Security Research & Red Team Consultant - [HTB Writeups](https://vandanpathak.com/htb-writeups/) - [Blog](https://vandanpathak.com/blog/) - Security Research & Red Team Consultant - [Let's connect](https://vandanpathak.com/contact/) - Let's Connect ## Categories - [Exploiting AD](https://vandanpathak.com/category/exploiting-ad/) - Exploiting Active Directories Blogs - [HTB-Writeups](https://vandanpathak.com/category/htb-writeups/) - Hack The Box Writeups - [LLM Security](https://vandanpathak.com/category/llm-security/) - [Kernels and Buffers](https://vandanpathak.com/category/kernels-and-buffers/) - Kernel and Buffer Exploitation ## Tags - [#applicationsecurity#llm#security](https://vandanpathak.com/tag/applicationsecurityllmsecurity/)