<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nmap on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/nmap/</link><description>Recent content in Nmap on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 16 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/nmap/index.xml" rel="self" type="application/rss+xml"/><item><title>CDEF-EtherRAT</title><link>https://hexpysya.github.io/investigations/cdef-etherrat/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-etherrat/</guid><description>An attacker breached Maromalix&amp;rsquo;s public-facing web application by exploiting CVE-2025-55182 (Next.js Deserialization RCE). They deployed a multi-stage implant dubbed EtherRAT, which utilizes a blockchain-based C2 mechanism via Ethereum smart contracts to dynamically resolve infrastructure. The attacker exfiltrated sensitive data, established multiple persistence mechanisms, and ultimately patched the vulnerability to lock out other actors.</description></item><item><title>CDEF-Lockdown</title><link>https://hexpysya.github.io/investigations/cdef-lockdown/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-lockdown/</guid><description>An attacker performed SYN port scanning against an IIS server, enumerated open SMB shares, uploaded a webshell to the Documents share, triggered a reverse shell on port 4443, and established persistence via AgentTesla dropped into the Startup folder, which exfiltrated data via SMTP to cp8nl.hyperhost.ua.</description></item><item><title>HTB-Conversor</title><link>https://hexpysya.github.io/investigations/htb-conversor/</link><pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-conversor/</guid><description>Flask web application vulnerable to path traversal during file uploads. Exploited by uploading Python reverse shell to cron-executed directory → gained www-data shell → extracted MD5 hashes from SQLite database → cracked password for user fismathack → leveraged CVE-2024-48990 in needrestart 3.7 for privilege escalation to root.</description></item></channel></rss>