Matt Dunn Mathur
Reporting Tools for Large Penetration Tests

Raxis lead penetration tester Matt Dunn has developed three new tools to make it easier[…]

Offensive Security OSCP
So, You Want to Earn Your OSCP?

What’s it like to earn your OSCP? Raxis senior penetration tester Andrew Trexler talks about[…]

Metasploit Module: Azure AD Login Scanner
New Metasploit Module: Azure AD Login Scanner

Raxis’ Matt Dunn has published another Metasploit module, this one describing a vulnerability in Azure’s[…]

Cross-Site Scripting: Filter Evasion & Sideloading Payloads
Cross-Site Scripting (XSS): Filter Evasion and Sideloading

Matt Dunn takes us deeper into cross-site scripting in this video that discusses filter evasion[…]

Introduction to Cross-Site Scripting
Introduction to Cross-Site Scripting

Raxis lead penetration tester Matt Dunn explains cross-site scripting and how it can be used[…]

Clickjacking causes user to unknowingly purchase tickets
Realistically Assessing the Threat of Clickjacking Today

Raxis’ Lead Developer Adam Fernandez discusses clickjacking, explaining what it is and why it represents[…]

LDAP Passback
LDAP Passback and Why We Harp on Passwords

LDAP passback exploits are easy when companies fail to change default passwords on network devices[…]

Remediating Account Enumeration Vulnerabilities
Remediating Account Enumeration Vulnerabilities

Account enumeration reveals to an attacker whether or not he or she has valid user[…]

The rdp_web_login Metasploit Module in Use
New Metasploit Module: Microsoft Remote Desktop Web Access Authentication Timing Attack

Raxis team member Matt Dunn has uncovered a vulnerability in Microsoft’s Remote Desktop Web Access[…]

How to Pull Off a Mousejacking Attack
How to Pull Off a Mousejacking Attack

Raxis demonstrates how to conduct a mousejacking attack as part of a penetration test.

Broadcast Poisoning
AttackTek: How to Launch a Broadcast Resolution Poisoning and SMB Relay Attack

An easy, effective way to test corporate networks is with broadcast poisoning and SMB relay[…]

Goodies for Hoodies: TCP Timestamps
Goodies for Hoodies: TCP Timestamps

Does your pentest always return a low-risk finding about TCP Timestamps? Why worry about that?[…]