<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://shushizinho.github.io/</id><title>Ana Silva</title><subtitle>A blog about my CyberSecurity journey.</subtitle> <updated>2025-09-23T15:39:06+00:00</updated> <author> <name>Ana Silva</name> <uri>https://shushizinho.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://shushizinho.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://shushizinho.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2025 Ana Silva </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>TOP secret!</title><link href="https://shushizinho.github.io/posts/TopScretCTF/" rel="alternate" type="text/html" title="TOP secret!" /><published>2025-09-23T00:00:00+00:00</published> <updated>2025-09-23T15:38:28+00:00</updated> <id>https://shushizinho.github.io/posts/TopScretCTF/</id> <content type="text/html" src="https://shushizinho.github.io/posts/TopScretCTF/" /> <author> <name>Ana Silva</name> </author> <category term="Dreamhack" /> <category term="CTF" /> <summary>Introduction In this post, I’ll walk you through solving a fun cryptography CTF challenge I tackled recently in the Dreamhack plataform. It’s a clever combo of RSA encryption and a Vigenère cipher. The key insight? Not everything is as secure as it seems—especially when secrets are tiny. In this challenge we get a public RSA key (N and e=5) and two ciphertexts: enc1 (Vigenère-encrypted FLAG)...</summary> </entry> <entry><title>Security Awareness</title><link href="https://shushizinho.github.io/posts/SecurityAwareness/" rel="alternate" type="text/html" title="Security Awareness" /><published>2025-08-01T00:00:00+00:00</published> <updated>2025-08-01T00:00:00+00:00</updated> <id>https://shushizinho.github.io/posts/SecurityAwareness/</id> <content type="text/html" src="https://shushizinho.github.io/posts/SecurityAwareness/" /> <author> <name>Ana Silva</name> </author> <category term="TryHackMe" /> <summary>Introduction This post covers the TryHackMe room “Security Awareness”, which focuses on understanding the human element in cybersecurity and developing better cyber hygiene practices. The room emphasizes that security awareness is not just an IT concern but a responsibility that extends to every individual within an organization. Task 1: Introduction to Security Awareness What is Security Awa...</summary> </entry> <entry><title>Insecure Deserialisation</title><link href="https://shushizinho.github.io/posts/InsecureDeserialisation/" rel="alternate" type="text/html" title="Insecure Deserialisation" /><published>2025-07-30T00:00:00+00:00</published> <updated>2025-07-30T00:00:00+00:00</updated> <id>https://shushizinho.github.io/posts/InsecureDeserialisation/</id> <content type="text/html" src="https://shushizinho.github.io/posts/InsecureDeserialisation/" /> <author> <name>Ana Silva</name> </author> <category term="TryHackMe" /> <summary>Introduction This post provides a detailed walkthrough of the TryHackMe room “Insecure Deserialisation,” which explores one of the most critical yet underestimated web application vulnerabilities. Insecure deserialisation was ranked as A8 in the OWASP Top 10 2017 and can lead to remote code execution, denial-of-service attacks, and other severe security impacts. Throughout this room, I learne...</summary> </entry> <entry><title>Roundcube: CVE-2025-49113</title><link href="https://shushizinho.github.io/posts/Roundcube/" rel="alternate" type="text/html" title="Roundcube: CVE-2025-49113" /><published>2025-07-29T00:00:00+00:00</published> <updated>2025-07-29T00:00:00+00:00</updated> <id>https://shushizinho.github.io/posts/Roundcube/</id> <content type="text/html" src="https://shushizinho.github.io/posts/Roundcube/" /> <author> <name>Ana Silva</name> </author> <category term="TryHackMe" /> <summary>Introduction This post covers the TryHackMe room “Roundcube: CVE-2025-49113,” which explores what makes this vulnerability possible and demonstrates exploitation in a controlled lab environment. Roundcubeis a free and open-source webmail project that has gained widespread adoption due to its feature-rich interface and multilingual support, available in over eighty languages. Its functionality...</summary> </entry> <entry><title>Active Directory Basics</title><link href="https://shushizinho.github.io/posts/AD-basic/" rel="alternate" type="text/html" title="Active Directory Basics" /><published>2025-07-28T00:00:00+00:00</published> <updated>2025-07-28T15:30:03+00:00</updated> <id>https://shushizinho.github.io/posts/AD-basic/</id> <content type="text/html" src="https://shushizinho.github.io/posts/AD-basic/" /> <author> <name>Ana Silva</name> </author> <category term="TryHackMe" /> <summary>Introduction This post covers the TryHackMe room “Active Directory Basics” which introduces fundamental concepts of Microsoft’s Active Directory service. Active Directory is a critical component in Windows enterprise environments, providing centralized authentication, authorization, and directory services. Task 2: Windows Domains In a Windows domain, credentials are stored in a centralised ...</summary> </entry> </feed>
